As critical infrastructures increasingly rely on interconnected devices, cloud platforms, and edge computing, one question keeps coming up: when something suspicious happens somewhere in that chain, who decides what to do about it and how fast?
Inside the CyberNEMO project, that job belongs to the Continuum Access Security Broker (CASB), a component designed and developed by SPACE Hellas.
What CASB Actually Does
Think of CASB as a dispatcher for security incidents, the same role a control room plays at a power plant or a water treatment facility when something goes wrong, just applied to cybersecurity instead of physical operations. Across a modern IT environment spanning cloud, edge devices, and everything in between many different tools are constantly watching for suspicious behavior: unusual logins, strange network traffic, unexpected system activity. On their own, these are just incoming signals; someone, or something, still has to decide what to actually do about each one.
That’s where CASB comes in and, like any good dispatcher, it can respond in two ways.
Most of the time, CASB reacts automatically: it takes incoming alerts, matches them against known attack patterns, and immediately dispatches the appropriate response for example, restricting network access to an affected device or service. A set of guardrail policies acts as a safety net on this automatic path, stopping any action that could affect sensitive, core parts of the underlying infrastructure itself.
Alongside that, a security operator can also step in directly and dispatch a mitigation themselves through the CASB dashboard (based on Airflow software) useful when a situation calls for human judgement rather than an automatic reaction. Whichever path is used, every action is logged and visible to the team in real time, so nothing happens without a clear, traceable record of what was done and why.
This combination is deliberate. In an active incident, low-risk, well-understood responses can be dispatched instantly without waiting on a person while operators retain the ability to step in and dispatch a response themselves whenever a situation calls for their judgement, with full visibility into everything that happens either way.
Why This Matters for Critical Infrastructure
CyberNEMO’s mission is to strengthen cybersecurity across sectors like energy, water, healthcare, media, and finance sectors where a slow or wrong response to a cyberattack can have real-world consequences. CASB doesn’t work alone: it’s one piece of a larger CyberNEMO security framework, coordinating closely with other components that detect threats, enforce network policies, and maintain an overall picture of the system’s security posture.
By centralizing how response decisions are made rather than leaving each tool to act independently CASB aims to make security responses more consistent, auditable, and easier to manage across large, distributed environments.
Where Things Stand Today
CASB’s architecture is fully designed, and the core building blocks automatic detection-to-response processing, safety guardrails, and the operator dashboard have been implemented and are running in CyberNEMO’s experimental lab infrastructure. The team is now working on broadening guardrail coverage and hardening the component ahead of the next stage: validation within CyberNEMO’s real-world pilot sites.
As with any research project, this is progress-in-motion rather than a finished product and we’ll share concrete results from pilot testing as they become available, rather than before.
What’s Next
Over the coming months, the CASB team at SPACE Hellas will focus on integrating the component more tightly with the rest of the CyberNEMO platform and preparing it for pilot deployment. We’ll follow up with a more detailed look at how CASB performs once it’s tested in a live environment.
