An initial budget of the CSIRT is drawn up in the initial phase of the CSIRT establishment. The ENISA guide on How to set up CSIRT and SOC recommends that the budget for the initial year should cover at least:
Budget Item | Average cost per year |
CSIRT staff members (including managers) | EUR 40 000–60 000 |
Minimum three staff members depending on the constituency size and mandate, CSIRTs typically employ the following numbers of staff: small – 3–7, medium – 10–15, large – 30–60. | EUR 120 000–180 000 |
12 additional employees (six teams of two staff members to cover 24/7, with each shift covering 8 hours) if required to provide operations 24/7 for 365 days a year | EUR 480 000 |
Office rental per staff member per year | EUR 3 000–4 000 |
Staff training and conference attendance per person per year | EUR 3 000–10 000 |
Depending on the scope, consultancy services for the establishment of a CSIRT (design and implementation) | EUR 75 000 -1 000 000 (over a 1- 3-years) |
Hardware, networking and specialised equipment for performing specific CSIRT operations (use of cloud services reduce initial investments in hardware) | EUR 100 000–300 000 |
Software and software services (open-source solutions may reduce costs) | EUR 50 000 |
Reflection point
The ENISA guide: How to set up CSIRT and SOC states that “The discrepancy between the detailed mandate and the budget is a common reason why CSIRTs do not fulfil their mandate.”
– Where does the national CSIRT derive its mandate?
– What are the sources of funding for the national CSIRT in your country?
– Which funding model is used in your country?
– What are the initial and operating budget considerations?
Leave your comment below.