1.1 Date of last update: This is the latest version 3.0 dated March 18, 2025.
1.2 Distribution Lists: Changes to this document are announced in and through the Cybolt SGIC Portal.
1.3 Document Location: The latest version of the document is published at: https://beaconlab.us/es/RFC2350-3/
2.1 Team Name: “BeaconLab”, Cybolt Cyber Incident Response Center
2.2 Address: Centro Tecnológico Metepec. Adolfo López Mateos 1956. Bellavista Metepec, 52148, Edo. Méx
2.3 Time Zone: CDMX, Mexico (GMT-6)
2.4 Phone Number: (+52) 8007374357 , (+52) 5550157483
2.6 Other Communications: The preferred form of communication is via email, telephone, videoconference, and other telecommunications options that can be coordinated upon request.
2.7 Email Addresses:
2.8 Public Keys and information encryption: The contact emails and associated PGP keys are published at https:/es/contacto/ and are also stored at https://keys.openpgp.org
2.9 Team Members:
Head: Luis Alfredo Herrera Camacho, luis.herrera@cybolt.com
The names and information of the members that make up BeaconLab are not publicly disclosed. In the event that a report is made, staff will identify themselves with their full name through formal communication.
2.10 More Information: General information about the services provided by BeaconLab is published on the web portal https://beaconlab.us/es/nosotros/ and at https://www.cybolt.com
2.11 Hours of Service: BeaconLab is available at the following hours:
For operational inquiries (for example, the status of an existing ticket), contact abuse@beaconlab.mx
For general inquiries (for example, comments or how to subscribe to a mailing list), contact info@beaconlab.mx
2.12 Contact points for the community: Communication between the BeaconLab team and the community at large is through the following means:
3.1 Mission:
3.2 Community served – “Target Community”:
It includes organizations, both national and international, with which Cybolt establishes a contractual relationship. The scope and coordination actions of each managed incident depend on the type of contract subscribed.
3.3 Sponsorship, Affiliation and Authority: BeaconLab is an entity dependent on the Security Managed Services Business Unit of Cybolt. The authority is given by an official mandate from the CEO of Cybolt.
4.1 Type of Incidents and level of support:
BeaconLab responds to all types of cyber security incidents that are reported to it by any client organization, in accordance with the client’s contract.
The scope of a cyber incident management by BeaconLab could include:
4.2 Cooperation, interaction, and disclosure of Information:
The information handled by BeaconLab is treated with absolute confidentiality in accordance with the information security policies and procedures of BeaconLab and Cybolt’s policies, regulations, and standards.
BeaconLab does not publish or share with third parties detailed information about cyber incidents that have been reported to it, unless explicitly authorized by those affected or when requested through judicial channels.
Information about incidents will be shared only on a legitimate need-to-know basis for the incident management itself, both with the victim, the administrators of affected systems, or other CSIRTs, as long as there is a legitimate need to control, remedy, or prevent incidents. Whenever possible, this information will be shared in an anonymized manner and/or without revealing data that could identify victims.
BeaconLab may publish or share statistical information, as well as anonymized information about specific incidents for awareness and training purposes only, without revealing data that could identify victims or disclosing details that put actors involved at risk.
4.3 Communication and Authentication: The means available for communication with BeaconLab are:
5.1 Incident Management
5.1.1 Incident Triage
BeaconLab offers technical and operational support in the various stages of the Incident Management process: detection, analysis, notification, containment, eradication, and recovery. This process includes the evaluation of available information and its prioritization (triage), validation and verification of the same, the scope, the collection of additional necessary evidence, and communication with the pertinent parties.
5.1.2 Incident Coordination
BeaconLab makes its best effort to determine the nature, scope, impact, and those affected by an incident, facilitating contact with other organizations that may be involved and/or affected.
It provides practical and actionable information, guidance, and recommendations to victims so that they can mitigate the cybersecurity incidents that affect them in the best way and provide policies and guides to improve their detection and prevention strategies.
BeaconLab collaborates with other Incident Response Centers (CERT/CSIRT) or Security Operations Centers (SOC) in all sectors through the exchange of information relevant to their target communities.
5.1.3 Recovery and Post-Incident actions
BeaconLab guides those involved with recommendations aimed at containing, mitigating, and remedying the incident, as well as with recommendations to avoid similar incidents in the future.
Likewise, it advises the client on the most appropriate actions, follows up on the Incident Management and the measures that the organization must take to prevent future cyber incidents.
According to the contractual terms, BeaconLab could provide technical and legal advice regarding forensic expertise, digital evidence preservation with chain of custody, digital forensic laboratory, and training in cybercrime investigation.
5.2 Prevention
BeaconLab provides different services in order to raise awareness and prevent any incident. Among them are:
Incident reporting can be done through the specific email mailbox: abuse@
The BeaconLab Team is not responsible for any misuse that may be made of the information contained herein.
The BeaconLab team adheres to the Ethics FIRST working group code of ethics: https://ethicsfirst.org/FIRST_EthicsfIRST_es.pdf
We are a a group of highly trained professionals based in R&D with advanced technical knowledge and experience in the detection, analysis, containment, and recovery of security incidents.
We are a CSIRT, we are Cybolt.
© 2024. Beacon Lab CSIRT, Privacy Policy