# aramido Computer Security Incident Response ## Document information This document follows [RFC2350](https://www.rfc-editor.org/rfc/rfc2350) in structure and content. ### Note on translation This document is an English translation of the German original, which is available at https://aramido.de/de/portfolio/notfallmanagement/incident-response-forensik/rfc2350_aramido-response-team.txt. We have prepared the translation with care but cannot guarantee that both documents match in every detail. In case of conflict, the German original version prevails. ### Date of last update | Version | Published | | --- | --- | | v1 | 08.06.2026 | | v2 | 31.08.2026 | ### Distribution list for notifications aramido GmbH notifies customers of its Incident Response services about updates of this document. Customer-specific incident notifications are distributed via individually coordinated channels. We maintain a general Threat Intelligence Newsletter for our customers. ### Locations where this document may be found This document can be found on the public website of aramido GmbH: https://aramido.de/en/portfolio/emergency-management/incident-response-forensics/rfc2350_aramido-response-team.txt ### Authenticating this document This document was published with a valid PGP signature. The signature is provided as a separate file and is available at the following URL: - Signature: https://aramido.de/en/portfolio/emergency-management/incident-response-forensics/rfc2350_aramido-response-team.txt.asc The following key was used: - URL: https://aramido.de/pgp/aramido.response-team.asc - Fingerprint: `317AC6BCC65E9DC32BA536BBE83094A566D7CC15` ## Contact information ### Name of the team The aramido Computer Security Incident Response Team (CSIRT) is called aramido Response Team (aRT). ### Address aramido GmbH Durlacher Allee 75-77 76131 Karlsruhe, Germany ### Time zone We are located in Germany, and operate in the following time zones: - CET (Central European Time, UTC+0100) - CEST (Central European Summer Time, UTC+0200) ### Telephone numbers - +49 721 451 99 112 (urgent cases) - +49 721 451 99 10 ### Facsimile number None. ### Other telecommunication None. ### Electronic mail address You can reach out to us at our general contact mail address: `art[at]aramido[dot]de` Customers who have been assigned an individual mail address are kindly asked to use it. Please prefer encrypted and signed mail communication if possible. You will find further information for encrypting messages under the section *Public keys and encryption information*. ### Public keys and encryption information Please use the following PGP public key or S/MIME certificate respectively according to your needs to communicate with `art[at]aramido[dot]de`: ### PGP - https://aramido.de/pgp/aramido.response-team.asc - Fingerprint: `317AC6BCC65E9DC32BA536BBE83094A566D7CC15` ### S/MIME - https://aramido.de/cert/aramido.response-team.pem ### Team members The aRT is represented by Armin Harbrecht in public and exclusively consists of aramido GmbH employees. Names of and contact to our team members will only be disclosed to customers. ### Other information Feel free to contact us or visit [our website](https://aramido.de/portfolio) for further information about our services. ### Points of customer contact Our preferred method of contact is [the contact form on our website](https://aramido.de/kontakt) or your individually assigned contact channel. If your request is urgent, please point this out in the subject of your e-mail and additionally call us at the numbers outlined above. Our office hours are generally 0800 to 1800 Monday to Friday excluding bank holidays in Baden-Wuerttemberg. We additionally offer individual response times for our customers. ## Charter ### Mission statement We aim to build a more secure information society by providing comprehensive security services that proactively reduce risk and reactively minimize the impact of incidents. We adapt our expertise to address our customer's unique needs and strengthen their overall security posture. ### Constituency The aRT supports customers of all sizes and various industries worldwide. We do not collaborate with private individuals. We define the constituency for our services in close cooperation with our customers. ### Sponsorship and affiliation The aRT takes pride in its independence from software and hardware vendors alike. We are not sponsored by or affiliated with any third party to guarantee services tailored to our customer's needs only. ### Authority The authority of the aRT is determined upfront by our customer. We help to anticipate the required degree of autonomy our team needs to execute the given tasks and keep close contact with our customers in case of perceived discrepancies. ## Policies ### Types of incidents and level of support We are ready to take on any incident risking the information security of our customers, including - attempted or successful social engineering attacks - suspected compromise of internal IT infrastructure - suspected breaches of the physical security of the location of IT assets - ransomware attacks - suspected ongoing or performed data leaks by internal or external actors The level of support is defined in the individual service agreement with each customer. ### Co-operation, interaction and disclosure of information The aRT is committed to the confidentiality of its customers' data and respects all relevant legal regulations. This is especially pertinent to the protection of personally identifiable information. To the extent responsibly possible, we would still like to share information and insights. - The aRT has internal processes to ensure the quality and continuous improvement of our services. As part of this process, anonymized cases may be shared and discussed internally. - If an incident might affect other customers, we share warning signs in our Threat Intelligence Newsletter with chosen, interested clients, keeping all details about the incident and the affected organization completely confidential. - We inform the public about the current threat landscape in [our blog](https://aramido.de/blog), at conferences and other industry events. ### Communication and authentication E-Mail sent by us is generally signed and, if possible, encrypted. You can find the certificate and public key for any mail address of `firstname[dot]lastname[at]aramido[dot]de`. - `https://aramido.de/pgp/firstname.lastname.asc` (PGP) - `https://aramido.de/cert/firstname.lastname.pem` (S/MIME) If you need to share large volumes of data, please avoid sending them by e-mail. We will provide you with access to systems specifically designed for transferring large data sets. We encourage you to include your own public keys or certificates to enable encrypted e-mail transmission in both directions. If you are uncertain whether your systems have been compromised, please provide a phone number or another contact method not managed by your organization, so we can establish a trusted communication channel. ## Services ### Core services aRT customers benefit from the following core services of our team: - Incident Response - Incident triage - Incident coordination - Incident resolution - Digital Forensics - Host-based IT forensics for PCs and servers - Network and log data forensics - Malware analysis - Threat hunting ### Adjacent services To further complement our services as an incident response team, aramido GmbH supports its customers both in building a resilient organization with robust IT systems and in handling computer emergencies before, during, and after an incident. This includes, among other technical and organizational measures, the following capabilities: - Incident Management - Business Continuity Management - Emergency Infrastructure Operation - Secure Systems and Infrastructure Development ## Incident reporting forms Incidents are unique, and so is our response. If you suspect a compromise, we encourage you to contact us as early in the process as possible. We will let you know what information is relevant, what should be collected and what to be shared with us. Beginning with your first suspicion, try to take notes of the timeline of events. The more information we have from the start, the quicker our response will be. ## Disclaimers While every precaution will be taken in the preparation of information, notifications and alerts, the aRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.