Back to glossary

CERT (Computer Emergency Response Team)

3 min read

A CERT, or Computer Emergency Response Team, is a specialist unit whose job is to respond to and manage information security incidents, and to coordinate that response with others.

July 30, 2026
Compartir:

A CERT, or Computer Emergency Response Team, is a specialist unit whose job is to respond to and manage information security incidents.

CERTs exist to protect the integrity, confidentiality and availability of information in digital environments, acting as a point of coordination and response when something goes wrong.

What a CERT does

Fast response. The main function is a quick, orderly response to a security incident: identification, containment, eradication and recovery of the affected systems.

Coordination. CERTs work closely with other security teams, government agencies, private sector organisations and service providers, both to coordinate the response and to share what they know about the threat.

Prevention. Beyond response, CERTs also work on prevention and mitigation: proactive measures that harden systems, and awareness work so that people recognise what they are looking at.

Why it matters

Incidents get handled, not improvised. A standing team with a mandate is what keeps the impact contained and the recovery quick.

Digital assets are protected. By spotting and answering threats early, a CERT protects sensitive data, critical systems and the underlying infrastructure.

The community works together. Cooperation between CERTs, nationally and internationally, is what makes an effective answer possible against threats that cross borders and sectors.

A worked example

A company detects suspicious activity on its network that looks like an attack in progress. The internal security team activates the organisation’s CERT.

The CERT analyses the activity in detail, identifies the attack vector and works out how far the incident goes.

It puts containment measures in place to stop the attack spreading, and works with other internal teams, digital forensics among them, to collect evidence and understand what actually happened.

At the same time the CERT may share what it knows with external CERTs, government bodies and other trusted partners, both to warn them and to get help.

Once the situation is under control, the CERT leads the post-incident review: what was learned, and which security measures need to change so the same thing does not happen again.

Where to read more

“Cyber Defense Incident Responder”, US-CERT (United States Computer Emergency Readiness Team): an overview of what a CERT is and how one operates, including the role of the incident responder and the work of coordinating with other security bodies.

“CERT Coordination Center”, Carnegie Mellon University: a reference point for the security community, with good practice, security alerts and educational material.

“What is a CSIRT and how can it help me?”, ENISA (European Union Agency for Cybersecurity): an introduction to national CERTs and their role in protecting against threats at national and cross-border level.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.