Sekoia CERT - RFC 2350
Updated : July 1st, 2026 - Version 3.0 - TLP: CLEAR
1. Document information
This document contains a description of the Sekoia CERT in accordance with RFC 2350 specification. It provides basic information about our team, describes its responsibilities and services offered.
1.1 Date of last update
This is the version 3.0 released on 1st July 2026.
1.2. Distribution list for notifications
There is no distribution list for notifications.
1.3. Locations where this document may be found
The current and latest version of this document is available at the present URL: www.sekoia.com/rfc2350.
1.4. Authenticating this document
This document has been signed with the PGP key of the Sekoia CERT and can be found at the present URL: www.sekoia.com/rfc2350.
1.5. Document identification
Title: Sekoia CERT RFC 2350
Version: 3.0
Document Date: 01 July 2026
Expiration: this document is valid until superseded by a later version.
2. Contact information
2.1. Name of the team
Short name: Sekoia CERT
Full name: Sekoia CERT
2.2. Address
Sekoia CERT
54 rue des Petites Ecuries
75010 PARIS, France
2.3. Time zone
CET/CEST: Europe/Paris (GMT+01:00, and GMT+02:00 on DST)
2.4. Telephone number
+33-183-641-661
2.5. Facsimile number
None available
2.6. Other telecommunications
None available
2.7. Electronic email address
cert@sekoia.com
2.8. Public keys and encrypted information
PGP is used for functional exchanges with external CERT / CSIRT.
User ID: Sekoia CERT <CERT@sekoia.com>
Key ID: DA65 4831 D746 85ED
Fingerprint: 898C C45E 856E FC8A 0AEF 6CDA DA65 4831 D746 85ED
It can be retrieved from one of the usual public key servers.
2.9. Team members
The Sekoia CERT representative is François Deruty, Chief Intelligence Officer at Sekoia.
Substitute: Nicolas Caproni, Head of Sekoia TDR.
The full list of the team members is not publicly available.
The team is made of cybersecurity analysts.
2.10. Other information
Until June 2026 the company was named Sekoia.io, and the CERT named Sekoia.io CERT. Email addresses ending with .io (eg cert@sekoia.io) remain valid.
2.11. Points of customer contact
Sekoia CERT prefers to receive incident reports via e-mail through the email address mentioned in 2.7.
Please use our PGP key to ensure integrity and confidentiality.
In case of emergency, please specify the [URGENT] tag in the subject field in your e-mail.
Sekoia CERT operates during regular business hours (9:00 AM-7:00 PM from Monday to Friday).
3. Charter
3.1. Mission statement
The Sekoia CERT Team’s activities are non-profit and fully funded by Sekoia.io SAS.
The Sekoia CERT Team operates as an internal CERT.
The mission of the Sekoia CERT is to:
- Investigate, respond and coordinate cybersecurity incident that can affect constituency
- Provide cyber threat intelligence report to constituency
- Deploy and maintain tools related to the security incident response
- Maintain relationship with different CERTs
3.2. Constituency
Our constituency includes:
- Sekoia IT system
- Sekoia digital assets
- Sekoia solution
3.3. Sponsorship and/or affiliation
Sekoia CERT is a private CERT in the cybersecurity sector. It is owned, operated and financed by Sekoia.io SAS
3.4. Authority
The Sekoia CERT operates with the authority delegated by the CEO of Sekoia. The Sekoia CERT is responsible for coordinating the incident response and investigating artifacts for Sekoia’s assets.
4. Policies
4.1. Types of incidents and level of support
Sekoia CERT manages all types of cybersecurity incidents that occur, or threaten to occur, within its constituencies.
Sekoia CERT does not have a formal level of support mapped with incident categories. Upon its authority. Sekoia will be asked to ensure different tasks depending on the impacted assets.
4.2. Co-operation, interaction and disclosure of information
Sekoia CERT exchanges all necessary non-restricted information with other CERTs / CSIRTs as well as with other affected parties involved in the incident or incident response process.
Incident or vulnerability related information would not be publicly disclosed without the agreement of all involved parties.
4.3. Communication and authentication
Sekoia CERT recommends sending all information through encrypted email.
Sekoia CERT supports the TLP (Traffic Light Protocol) in order to classify information sharing ability.
5. Services
5.1. Incident response
The Sekoia CERT provides the following incident response services:
- Alerts and warnings
- Incident handling
- Incident analysis
- Incident response
- Crisis management
- Incident coordination
- Vulnerability analysis
- Vulnerability coordination
- Forensic analysis
5.1.1. Incident triage
When an incident is declared to Sekoia CERT, triage is performed first to assess the seriousness of the impacted assets. Then the incident gets a criticality score. The score can be reviewed during the incident handling and defines the priority of the treatment.
5.1.2. Incident coordination
The incident coordination involves the following services:
- Provide a quick treatment action plan after the incident’s detection
- Collection of technical evidence
- Identification of the perimeter impacted by the incident
- Proposition of immediate corrective measures
- Determining the initial cause of the incident
5.1.3. Incident resolution
At the end of an incident, Sekoia CERT provides:
- Proposition of long-term corrective measures
- Informal feedback to the team concerned by the incident
- A forensic investigation report, when necessary
5.2. Proactive activities
Sekoia CERT offers the following proactive activities services:
- Cyber Threat Intelligence
- Threat Hunting
- Technology watch
- Cyber security alerts publication / blogposts
- Knowledge gathering on cyber threat actors
6. Incident reporting forms
Sekoia CERT does not have a public incident reporting form.
7. Disclaimers
N/A