CSIRTeaming: Forging Resilient Incident Management Teams with Psychological Safety @FIRSTdotorg
CSIRTeaming: Forging Resilient Incident Management Teams with Psychological Safety  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
CSIRTeaming: Forging Resilient Incident Management Teams with Psychological Safety and High Reliability Principles

Yoshiki Sugiura (NTT-CERT, JP)

In the face of sophisticated attacks and escalating pressure, CSIRT/Incident Management Teams must fundamentally rethink their operating model. The root cause of recurrent incidents, despite having comprehensive procedures, often lies not just in technical vulnerabilities but in the “Human Element” — the structure of the team itself. Simple oversights like unpatched VPNs or basic account takeovers, which should have been preventable, often stem from a lack of field reports, stagnant organizational learning, and team dysfunction.

Drawing on the speaker’s 26 years of security experience and research into High Reliability Organizations (HRO), this presentation proposes “CSIRTeaming” — the optimal model for modern incident response. By applying the HRO core concept of Mindfulness alongside Dr. Amy C. Edmondson’s ideas of Psychological Safety and Teaming, organizations can embrace a “Preoccupation with Failure,” “Reluctance to Simplify,” and dynamically learn.

This approach complements the technical focus of The Art of Incident Management (FIRSTCON24), establishing the cultural foundation needed to make frameworks like the P/CSIRT Services Framework and SIM3 truly effective and to build genuinely resilient security organizations.

---

Yoshiki Sugiura has been working in CSIRTs for 26 years. He used to be a member of JPCERT/CC from 1998 to 2002. He works for IL-CSIRT and NTT-CERT. He is also a board member of Nippon CSIRT Association. He is a certified trainer and auditor for SIM3. His current working area is management of CSIRT.
CSIRTeaming: Forging Resilient Incident Management Teams with Psychological SafetyMind the Match: Why Vulnerability Matching Is Harder Than You ThinkOpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open SourceRouting Security for Enterprises: Secure Your Supply ChainEmbracing the Era of Transparency: Automating VEX Application for Scalable, Context-Aware SecurityAttack or Noise?: Tracking and Evaluating the Impact of Internet-Wide Survey ScannersAI Is Writing Your Bug Reports. Can You Tell?Dark Silicon: Unmasking GPU Threats in the Age of AIAxiomatic Events that Evolved Vulnerability DatabasesOrganizational Context Matters: Security Control Effectiveness on Vulnerabilities for PrioritizationNIST’s National Vulnerability Database Update and the Vulnerability Enrichment Ecosystem
FIRST |

CSIRTeaming: Forging Resilient Incident Management Teams with Psychological Safety

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER