RFC 2350 Request for Comments
1. Document Information
1.1 Date of Last Update
04.08.2026
1.2 Distribution List for Notifications
N/A
1.3 Locations where this Document may be Found
https://www.rbinternational.com/en/raiffeisen/legal/rfc2350.html
2. Contact Information
2.1 Name of the Team
(RCDC) Raiffeisen Group Cyber Defense Center
2.2 Address
Raiffeisen Bank International AG
Am Stadtpark 9
1030 Vienna, AUSTRIA
2.3 Time Zone
Central European Time (CET/CEST), UTC+1/UTC+2
2.4 Telephone Number
RBICDC 24/7 | English hotline +38 348 1998 65
2.5 Facsimile Number
N/A
2.6 Other Telecommunication
For routine communication that does not contain sensitive information, RCDC may use conventional communication channels such as unencrypted e-mail.
For the exchange of sensitive or confidential information, RCDC uses appropriately protected communication channels, including encrypted e-mail and telephone where appropriate.
Where authentication of communication partners is required, RCDC relies on established trust relationships (e.g., FIRST or other trusted CSIRT communities) or alternative verification methods, such as callback procedures, verification through known contacts, or, where necessary, in-person meetings.
2.7 Electronic Mail Address
2.8 Public Keys and Encryption Information
N/A
2.9 Team Members
The CSIRT is staffed by experienced information security professionals with responsibilities covering strategic leadership, operational service management, and incident response.
- Henri Muhaxhiri – Head of the Department
Responsible for the overall leadership of the department, governance, stakeholder management, and ensuring the continuous development of the team's capabilities and services - Heinz-Christian Wiesener – Service Manager
Responsible for the operational management of CSIRT services and for maintaining effective coordination and collaboration with the security community.
2.10 Points of Customer Contact
The preferred method for contacting RCDC is via e-mail at security@rbinternational.com. This contact point can be used for reporting cybersecurity incidents, requesting assistance, and general communication with RCDC. Additional communication channels may beused where required and will be provided to authorized contacts upon request.
3. Charter
3.1 Mission Statement
RCDC's mission is to protect its constituency by providing group-wide cybersecurity monitoring, security event analysis, incident response, and DDoS protection. RCDC supports the timely detection, coordinated handling, and mitigation of cybersecurity threats to strengthen the resilience of the organizations it serves.
3.2 Constituency
RCDC's constituency comprises customers of the RCDC service, including entities within the RBI Group, R-IT, Raiffeisenlandesbank Niederösterreich-Wien AG, and Raiffeisenlandesbank Burgenland und Revisionsverband eGen.
3.3 Sponsorship and/or Affiliation
RCDC operates under the governance of RBI Security Leadership and is the official Computer Security Incident Response Team (CSIRT) of Raiffeisen Bank International (RBI). RCDC provides cybersecurity incident response services for its defined constituency.
3.4 Authority
RCDC operates under the mandate of RBI Security Leadership and is authorized to coordinate the handling of cybersecurity incidents affecting its constituency. Within this mandate, RCDC provides incident response services, coordinates with internal and external stakeholders, and facilitates the exchange of information necessary for effective incident management. RCDC acts in accordance withapplicable organizational policies and relevant legal and regulatory requirements.
4. Policies
4.1 Types of Incidents and Level of Support
RCDC handles cybersecurity incidents affecting its constituency. Support includes incident intake, analysis, coordination, containment, recovery guidance, and communication with relevant internal and external stakeholders. The level of support depends on the severity, impact, and scope of the incident, as well as the resources available.
4.2 Co-operation, Interaction, and Disclosure of Information
RCDC actively participates in the wider cybersecurity community and cooperates with trusted partners, national and international CSIRTs, law enforcement agencies where appropriate, and other relevant stakeholders to improve the prevention, detection, and response to cybersecurity incidents.
Information received during incident handling is treated confidentially and is disclosed only on a need-to-know basis, in accordance with applicable laws, contractual obligations, and established information-sharing agreements. Where appropriate, information is shared using the Traffic Light Protocol (TLP) or other mutually agreed classification schemes.
4.3 Communication and Authentication
The primary communication method is standard e-mail. For communication that does not contain sensitive information, conventional e-mail may be used. For sensitive or confidential information, RCDC uses appropriate security measures, such as encrypted e-mail or other agreed secure communication channels.
The authenticity of communication partners may be verified through established trust relationships, known contact information, organizational directories, or other verification methods as appropriate.
5. Services
5.1 Incident Response
RCDC provides incident response services including incident triage, analysis, investigation, and coordination of response activities. RCDC supports the identification, assessment, and containment of cybersecurity incidents and supports remediation activities with relevant internal teams, service providers, and other stakeholders where required.
6. Incident Reporting Forms
Incidents can be reported via e-mail to security@rbinternational.com.
7. Disclaimers
RCDC takes reasonable care to ensure that information provided in incident reports, advisories, and other communications is accurate and useful. However, the information is provided on a best-effort basis, and RCDC cannot be held responsible for errors, omissions, or impacts resulting from reliance on this information.
8. Information Handling
RCDC classifies and handles information using the Traffic Light Protocol (TLP 2.0); information shared through these external community channels is typically classified TLP:RED.