CSIRT Capacity Building: The Missing Governance Layer
Earlier in this series
In an earlier piece, I explained what a CSIRT is and why a government should care. Short version: it is the institution that answers the phone when something breaks at national scale.
This piece is about the harder question. Not what a CSIRT is, but how a country actually builds one that works. Because most attempts fail, and they fail in a predictable way: they treat a governance problem as a shopping problem.
The shopping-problem failure mode
Here is the pattern I mean. A government, often with donor support, decides it needs national incident-response capacity. A budget appears. The budget buys things: a SIEM, big wall monitors, workstations, a training week from a vendor. There is a ribbon-cutting.
Two years later, the room exists and almost nothing else does. Nobody is legally required to report incidents to the team. The team has no authority to enter a ministry's network even when invited. Funding was a one-time capital grant, so there is no money for retention, and the trained analysts have left for banks. The wall monitors show a demo feed.
None of this is a technology failure. Every missing piece — mandate, authority, financing, trust — is governance. That is the layer that gets skipped, because governance is slow and unphotogenic, and hardware is neither.
What the governance layer actually contains
Strip away the tooling and a functioning national CSIRT rests on four things.
A mandate. A written answer to: what is this team responsible for, and for whom? Government networks only? Critical infrastructure? Any citizen who reports? Ambiguity here is fatal, because during a real incident nobody has time to negotiate scope.
Legal authority. Something in law — statute, decree, regulation — that lets the team request information, coordinate across ministries, and receive incident reports without every exchange being a favor. In my SOC days, doing enterprise monitoring and incident response, even inside a single company the escalation paths had to be written down and agreed in advance. Across ministries and private operators, informal goodwill does not survive contact with a real crisis.
Recurring financing. Not a grant. A budget line that survives election cycles, pays competitive-enough salaries, and covers the boring costs: memberships, travel to exercises, license renewals, training.
Trust relationships. A CSIRT is only as useful as the reports it receives, and organizations only report to institutions they trust not to punish or embarrass them. Trust is built slowly, through consistent behavior, and it is destroyed instantly. It cannot be procured.
Notice that a well-resourced technical team controls none of these four directly. All of them are decisions made above the team's head. That is why I call capacity building a governance project that happens to have a technical deliverable.
Ghana: a decade of doing it in the right order
The example I keep returning to is Ghana, because its build-out ran over roughly a decade and — unusually — did the governance work in a sensible sequence.
The trajectory, as publicly documented: Ghana stood up a national CERT function in the mid-2010s, then developed a national cybersecurity policy and strategy, then passed a dedicated Cybersecurity Act in 2020 that created a national authority with real legal standing. On top of that legal spine, sectoral CERTs were established — for areas like banking, telecoms, and government — feeding into the national level. Reporting obligations and the regulation of critical information infrastructure got an explicit legal basis rather than resting on circulars and goodwill.
The results have been noticed internationally. Ghana's standing in the ITU's Global Cybersecurity Index rose substantially over that period, and it has been widely reported as one of Africa's stronger performers in recent editions. I will not quote a precise rank, because these indices shift between editions and I would rather hedge than assert a number I cannot pin down as of this writing. The direction of travel, though, is not in dispute.
What I want to highlight is not the ranking. It is the sequence: institution, then strategy, then law, then sector structure — with the technical capability growing inside that scaffolding rather than instead of it. Compare that with the shopping-problem pattern above, which runs the sequence backwards and ends with equipment and no institution.
Ghana's build was not fast, and I am sure it was not smooth from the inside; decade-long institutional projects never are. That is rather the point. Anyone selling a two-year national CSIRT is selling the room, not the institution.
What this looks like from the practitioner's seat
I have never built a national CSIRT. I have built the same structure in miniature, twice — incident-response and triage procedures for a company's IT operation, and later detection and response playbooks in an enterprise SOC — and the miniature version teaches the same lesson.
The playbooks that worked were never the technically sophisticated ones. They were the ones where, before any tooling, we had settled who owns the decision, who must be told, and what the responder is allowed to do without asking. When those answers existed, mediocre tools were enough. When they did not, no tool helped.
Scale that up and you have national capacity building. The screens are the last five percent.
Questions to ask instead of "what should we buy"
If I were advising a government at the start of this road, I would put the procurement catalog away and ask five questions:
- Who, by law, must report an incident to this team — and who must this team notify?
- What can the team do inside another organization's network, and on whose authorization?
- Where does next year's salary budget come from, and the year after?
- Which sector will trust this team first, and what will we do to earn the second sector?
- Who is politically accountable when a national incident is handled badly?
A government that can answer these has done the hard part. The technical build that follows is genuinely the easier half, and there is no shortage of people who can deliver it.
I will pick up one thread from this piece later in the series: what the minimum viable version of this whole governance stack looks like for a state starting from very little. Ghana had a decade. Not everyone does, and there is an honest 80/20 answer to what matters first.