eCSIRT (CZ)

DATASYS eSOC CSIRT Accreditation Candidate

Fields describing the team

Team Details

Official Name

DATASYS eSOC CSIRT

Short Name

eCSIRT (CZ)

Country

Czech Republic

Established

01 Jan 2022

Host Organisation

DATASYS s.r.o.

Constituency

Constituency Type

  • Commercial Organisation
  • Financial Sector
  • Government

Country of constituency

  • Czech Republic

ASNs, Domains, IP ranges

  • datasys.cz
  • esoc.cz
  • logmanagement.cz
  • faxchange.cz
  • faxchange.eu
  • mobilchange.cz
  • mobilchange.eu
  • ums.cz
  • workmate.cz
  • 86.49.172.145
  • 185.154.62.114
  • 87.249.140.58
  • 93.153.125.192/27
  • 94.113.255.160/27
  • 77.95.41.159
  • 77.78.101.16/28

The eCSIRT provides services to external and them internal clients (managed security services) who have signed a Service Level Agreement (SLA) for 24/7 Monitoring and Incident Response. The constituency consists of organizations operating in Government, State organization, in the energy, healthcare, finance, service provision and other sectors in the Czech Republic, specifically targeting their ICT infrastructure. The eCSIRT has the authority to monitor, collect logs, analyze traffic, and initiate predefined incident response procedures on IT assets under its management, as defined in the client's contractual agreement. The team acts as the trusted point of contact for its constituency in security matters. The constitution is aimed at entities with a direct contractual relationship and covers the monitored infrastructure, including cloud environments, network devices and endpoints defined within the scope of the ELISA SIEM platform deployment. eCSIR Summary The service provides continuous security monitoring of clients' ICT infrastructure on a 24x7x365 basis. It is delivered as either an internal or external service with clearly defined parameters and SLA agreements tailored to each client's requirements. The primary platform for service delivery is our proprietary SIEM solution ELISA, which handles log collection, integration, and analysis from network devices and other security tools. The service encompasses Network Behavior Anomaly Detection, continuous evaluation of security events and incidents, and activation of predefined response procedures upon threat detection. The service can also be operated on top of alternative SIEM platforms based on client requirements. An integral part of the service is knowledge-based client support, including consultations, security issue resolution, and assistance with security infrastructure configuration. Where required, the service can be extended to include vulnerability scanning and security audits, enabling proactive identification of weaknesses within the client's infrastructure. In the areas of Cyber Threat Intelligence (CTI) and threat hunting, we are actively building our own research capabilities, which we are currently in the early stages of developing. Findings regarding attacker techniques, tactics, and procedures (TTPs) are progressively being integrated into the service's detection and analytical processes.

Team Contact Information

Main Number

Emergency Number

Fax Number

-

Postal Address

DATASYS eSOC CSIRT
Zengrova 85
703 00 Ostrava
Czech Republic

Automated Reporting Email

Business Hours

7:00 - 17:00

Timezone

Europe/Prague

Cryptography

PGP key(s) of the team

Type:   EdDSA/256    Expires: never
Fpr:    3A6F C754 C25E 5DCB D126 8FBA C862 2DB3 040B 4C8E
Sub:    ECDH/256  Usage: Encrypt
UID:    esoc_datasys.cz <esoc@datasys.cz>

Classification

Current State

Accreditation Candidate
Last change: 16 Apr 2026

Entry Date

06 Nov 2025

Date of Accreditation

History

Date Description
06 Nov 2025 eCSIRT (CZ) is now an accreditation candidate team
06 Nov 2025 eCSIRT (CZ) has completed the re-listing process
17 Aug 2022 eCSIRT (CZ) is now a listed team