Uploaded June 2026 | Updated September 2026, 1 hour ago
IC5 – Integrated CERT Cyber Communications, Collaboration & Coordination Framework (A 5-Layered Framework for National CERTs for Effective Communication, CTI Sharing, and Advisory Dissemination)
Rakesh Kumar Singh (CERT-In (Indian Computer Emergency Response Team), IN), Yudhishthira Sapru (CERT-In (Indian Computer Emergency Response Team), IN)
As cyber incidents multiply in scale and complexity, Computer Emergency Response Teams (CERTs) now play a pivotal role not only in response coordination but also in Cyber Threat Intelligence (CTI) sharing and vulnerability advisory dissemination. Yet, many advisories remain highly technical and inconsistently adopted across varied audiences.
This talk introduces IC5 — the Integrated CERT Cyber Communications, Collaboration & Coordination Framework — a novel, behavioral-based 5-layered model designed to make CERT communications more targeted, trusted, and actionable. Grounded in established behavioral and communication theories IC5 bridges the gap between technical precision and human understanding.
The five layers work sequentially to classify events, set advisory tone, structure audience-specific messages, route them through the right channels, and measure impact through a closed feedback loop. By aligning message framing, motivational triggers, and contextual classification, IC5 improves advisory clarity, adoption rates, and coordination across national and international CERT ecosystems.
The session will demonstrate how IC5 strengthens CTI sharing, vulnerability note dissemination, and advisory communication promoting faster defensive action and a culture of informed cyber resilience.
---
Dr. Yudhishthira Sapru is working with the Indian Computer Emergency Response Team (CERT-In), the national nodal agency for cyber incident response in India. He has over 20 years of experience in cybersecurity, threat intelligence, SOC operations, and program management, and has led several national initiatives on cybersecurity project implementation, cyber resilience, and cyber threat intelligence sharing. He has been involved in successfully managing SOC operations during events of national importance and large-scale cyberattacks. He has also been involved in the formulation of various policies and guidelines aimed at strengthening the cybersecurity posture of Indian organizations. He has also been involved in coordinating with organizations on vulnerability exploitation–related communications. His expertise combines operational experience with policy understanding, helping organizations improve their cybersecurity readiness and response. He is CISSP, ECIH and PMP certified.
Mr. Rakesh Kumar Singh is a Cybersecurity Scientist at CERT-In with 9 years of hands-on experience in national-level cyber defense operations. His core expertise includes SOC operations, network traffic and log analysis, OSINT, threat intelligence, and end-to-end execution of critical national security projects. He has deep technical proficiency in SIEM, SOAR, threat hunting, incident response, and forensic log investigation. He holds CISSP and ECIH certifications, with a strong foundation in both the strategic and operational domains of cybersecurity
IC5 – Integrated CERT Cyber Communications, Collaboration & Coordination Framework (A 5-Layered Framework for National CERTs for Effective Communication, CTI Sharing, and Advisory Dissemination)
Rakesh Kumar Singh (CERT-In (Indian Computer Emergency Response Team), IN), Yudhishthira Sapru (CERT-In (Indian Computer Emergency Response Team), IN)
As cyber incidents multiply in scale and complexity, Computer Emergency Response Teams (CERTs) now play a pivotal role not only in response coordination but also in Cyber Threat Intelligence (CTI) sharing and vulnerability advisory dissemination. Yet, many advisories remain highly technical and inconsistently adopted across varied audiences.
This talk introduces IC5 — the Integrated CERT Cyber Communications, Collaboration & Coordination Framework — a novel, behavioral-based 5-layered model designed to make CERT communications more targeted, trusted, and actionable. Grounded in established behavioral and communication theories IC5 bridges the gap between technical precision and human understanding.
The five layers work sequentially to classify events, set advisory tone, structure audience-specific messages, route them through the right channels, and measure impact through a closed feedback loop. By aligning message framing, motivational triggers, and contextual classification, IC5 improves advisory clarity, adoption rates, and coordination across national and international CERT ecosystems.
The session will demonstrate how IC5 strengthens CTI sharing, vulnerability note dissemination, and advisory communication promoting faster defensive action and a culture of informed cyber resilience.
---
Dr. Yudhishthira Sapru is working with the Indian Computer Emergency Response Team (CERT-In), the national nodal agency for cyber incident response in India. He has over 20 years of experience in cybersecurity, threat intelligence, SOC operations, and program management, and has led several national initiatives on cybersecurity project implementation, cyber resilience, and cyber threat intelligence sharing. He has been involved in successfully managing SOC operations during events of national importance and large-scale cyberattacks. He has also been involved in the formulation of various policies and guidelines aimed at strengthening the cybersecurity posture of Indian organizations. He has also been involved in coordinating with organizations on vulnerability exploitation–related communications. His expertise combines operational experience with policy understanding, helping organizations improve their cybersecurity readiness and response. He is CISSP, ECIH and PMP certified.
Mr. Rakesh Kumar Singh is a Cybersecurity Scientist at CERT-In with 9 years of hands-on experience in national-level cyber defense operations. His core expertise includes SOC operations, network traffic and log analysis, OSINT, threat intelligence, and end-to-end execution of critical national security projects. He has deep technical proficiency in SIEM, SOAR, threat hunting, incident response, and forensic log investigation. He holds CISSP and ECIH certifications, with a strong foundation in both the strategic and operational domains of cybersecurity










