Building a Regional ISAC for West Africa that Works: Governance, Tools and Community Maturity @FIRSTdotorg
Building a Regional ISAC for West Africa that Works: Governance, Tools and Community Maturity  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 2 hours ago
Don Stikvoort (Open CSIRT Foundation, NL), Miroslaw Maj (Open CSIRT Foundation, NL)

This session presents practical, experience‑based insights from a two‑year effort to build and operationalize the ECOWAS ISAC, bringing together West African countries from Nigeria to Sénégal and Cabo Verde. It highlights how the project bridged the gap between the traditional information‑sharing mission of an ISAC and the more operational, incident‑focused functions typically associated with CSIRTs.

The presentation shows how SIM3 was used to structure governance, roles, and capabilities, creating a clear and realistic maturity roadmap. It also demonstrates how established standards and tools—such as the FIRST CSIRT Services Framework and MISP—were adapted to define feasible services, strengthen collaboration, and enable consistent information exchange.

Participants will also learn how table‑top exercises and cyber‑attack simulations were used to validate workflows and build trust. The session concludes with lessons learned and actionable recommendations for regions or sectors seeking to develop or mature their own ISAC communities.

---

Don Stikvoort - Stichting Open CSIRT Foundation, chairman of the board.

Don Stikvoort is founder of the companies “S-CURE” and “Cross Your Limits”. S-CURE offers senior consultancy in the area of cyber security – specialising in CSIRT matters. Cross Your Limits coaches and trains in the human area. Based in Europe, Don’s client base is global.

After his MSc degree in Physics, he became Infantry platoon commander in the Dutch Army. In 1988 he joined the Dutch national research network SURFnet. In that capacity he was among the pioneers who together created the European Internet since November 1989. He recognised “security” as a future concern in 1991, and was chair of the 2nd CSIRT in Europe (now SURFcert) from 1992-8, and FIRST member since 1992. Today Don is a FIRST Liaison Member. Together with Klaus-Peter Kossakowski he initiated and built the closer cooperation of European CSIRTs starting in 1993 – this led to the emergence of TF-CSIRT in 2000. In 1998 he finished the "Handbook for Computer Security Incident Response Teams (CSIRTs)" together with Kossakowski and Moira J. West-Brown of CERT/CC. He was active in the IETF and RIPE (cocreator of the IRT-object). Don chaired the Program Committee for the 1999 FIRST conference in Brisbane, Australia, and kick-started the international FIRST Secretariat in the same year. From 2001-2011 his company ran TF-CSIRT’s Trusted Introducer service. He wrote and taught several training modules for the CSIRT community.

In 1998 Don started his first company. A first assignment was to build the network connecting over 10,000 schools in The Netherlands. Many CSIRTs were created with his help and guidance, among which the Dutch national team (NCSC-NL). Second opinions, audits and maturity assessments in this field have become a specialty – and in that capacity Don developed SIM3 in 2008, the maturity model for CSIRTs which is used worldwide today for maturity assessments and certifications. SIM3 has is now under the wings of the “Open CSIRT Foundation” (OCF). Don was one of the founders in 2016 and now chairs its board.


Mirosław Maj (Open CSIRT Foundation, Cybersecurity Foundation) has nearly 30 years of experience in ICT security and has played a major role in shaping cybersecurity capabilities in Poland and abroad. He is the co-founder of the Open CSIRT Foundation, responsible for developing SIM3 maturity model and supporting the Trusted Introducer service certifying security teams worldwide, as well as the founder and president of the Cybersecurity Foundation and co-founder of ComCERT.PL. A former head of CERT Polska, he co created CyberBastion - a simulation and training platform powering the multi-edition CyberBastion League.

He advised the Polish Minister of National Defence on cyberdefence development, is a member of the Polish Digitalization Council, and serves as an expert for ENISA, co-authoring numerous European cybersecurity reports. His international work includes major projects in Georgia, CIS countries and the UN, supporting the creation and maturity of national CERTs. He has organized ten editions of Cyber-EXE exercises for key sectors and national-level NIS-based testing. A regular FIRST speaker and founder of the Security Case Study conference, he also lectures on cybersecurity at several universities.
Building a Regional ISAC for West Africa that Works: Governance, Tools and Community MaturityThe EUs Cybersecurity Resilience Act (CRA) has Begun – How Can Manufacturers Confidently Addres ...Chaos Stack: Designing Layered Tabletop Exercises for Complex Crisis Simulation99 Bottles of Trust on the Wall: Approaches to Building Convivial CommunitiesEverything Everywhere All at Once…in 2038Understanding Scammer Threats: Detection Strategies Aligned with Thailand’s Cybersecurity Act 2562CTI-Transmute: Harmonizing Threat Intelligence in a Multi-Standard EcosystemAccuracy Is Not Enough: Detecting Hidden Risk in CVE Impact PredictionIntroducing StealerLens: An LLM-Powered Forensics Microscope to Accelerate InfoStealer ...Itinerary to Defeat Yet Another Beacon ImplementationCVE Record Format - Purl and CPE WorkshopBeyond CVEs: Mastering the Landscape with Vulnerability-Lookup
FIRST |

Building a Regional ISAC for West Africa that Works: Governance, Tools and Community Maturity

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER