National CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination Cases @FIRSTdotorg
National CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination Cases  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 2 hours ago
Michał Dondajewski (CERT.PL, PL)

This session presents practical lessons from CERT.PL CNA’s role as a national CVD hub mediating between mostly Polish security researchers and product vendors, including both successful collaborations and difficult, low‑engagement cases. Using anonymised coordination examples, the talk explores researcher and vendor motivations and the operational constraints faced by a national CSIRT, such as limited influence over remediation decisions and communication bottlenecks. The session will also describe improvements introduced into CERT.PL’s CVD process: diversified contact channels to reach vendors, the adoption of a 90‑day default disclosure window, and the systematic involvement of sectoral CSIRTs where appropriate to share context and reduce fragmented communication. Attendees will leave with actionable patterns and anti‑patterns for enhancing their own CVD workflows, especially when acting as intermediaries between independent researchers and domestic vendors with varying maturity levels.

---

Michał Dondajewski is a CSIRT Collaboration Senior Specialist at CERT Polska, responsible for fostering national and international partnerships in cybersecurity. He coordinates projects that enhance the resilience of cybersecurity incident response teams and promotes best practices in threat intelligence sharing. He manages the Coordinated Vulnerability Disclosure (CVD) process and assigns CVE identifiers, ensuring effective communication between stakeholders. With a strong technical background, he is passionate about building secure digital ecosystems through global collaboration and knowledge exchange.
National CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination CasesFrom Roadmap to Results: Measuring CWE Adoption to Enable PreventionFiltering the Noise: Crafting an Actionable Threat Feed from Community-Shared IntelligenceThe Convergence of Threat Behaviors Across IntrusionsForecasting Cybersecurity Data: Making Sense of the SenselessHow EPSS Is Wrong and Useful at the Same TimeWhy is Finnish Healthcare Doing So Well Against Ransomware?The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For ThemLessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is Useful
FIRST |

National CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination Cases

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER