Modern cyberattacks don’t respect organizational boundaries, neither organizations are operating in isolation from each other. A breach at an energy provider can ripple into telecoms, finance or healthcare within hours. Yet, most organizations still defend themselves in isolation, filing incident reports through manual, paper-based processes that arrive too late to help anyone else.

SAAM was built to change that. SAAM is a collaborative platform for sharing cyber threat intelligence, assessing systemic risk, and coordinating incident response across Critical Infrastructures (CIs) throughout Europe, realizing in practice the share-to-benefit paradigm.

Instead of static, form-based notifications, SAAM enables continuous, machine-readable and explainable threat intelligence exchange, aligned with the EU’s NIS2 Directive, the Cyber Resilience Act (CRA), the AI Act, and the Critical Entities Resilience (CER) Directive.

How the Platform Works

At its core, SAAM is a centralized but distributed, multi-tenant, event-driven platform built around a simple principle: organizations get more value out of the system the more they contribute to it, forming a pan-European “knowledge sharing” ecosystem.

Here’s the flow:

  1. Ingestion: Distributed Critical Infrastructure operated CyberNEMO installations generate threat intelligence structured to SAAM’s own STIX 2.1 data model and send it through TAXII 2.1 to SAAM.
  2. Analysis: Everything moves through an Apache Kafka event-streaming backbone into the Systemic Risk Analysis Engine (SRAE), which enriches each event using severity, confidence, and mappings to the MITRE ATT&CK and D3FEND frameworks, identifying cascading effects and potential coordinated attacks.
  3. Governed sharing: The Sharing Engine applies policy- and Traffic-Light-Protocol-driven distribution rules based on impact scope, sector, geography, and membership in “Trusted Circles” before pushing enriched alerts out to the right stakeholders, organized by sector, country, cross-border region, or the whole of Europe.
  4. Knowledge retention: SAAM insights and findings are stored in a pan-European Knowledge Base and made accessible to its user base through a web-based Visualization Environment.

Security is baked in throughout as SAAM adopts Zero-Trust principles via a Keycloak-based Identity Management System (IMS), enforcing OAuth 2.0, OIDC, and SAML 2.0 across every component.

Built for Different Users, Different Needs

SAAM is designed around four distinct roles:

  • Cybersecurity Experts get a personalised view of their organisation’s threat exposure alerts, a submission tracker, a STIX viewer, and access to the shared knowledge base.
  • CTI & Risk Analysts work across sectors and borders to spot threat trends invisible at the level of a single organisation, mapping activity to MITRE ATT&CK and producing human-readable risk assessments.
  • Cybersecurity Authorities — national CSIRTs and sector ISACs — get a bird’s-eye view across sectors for cross-border situational awareness.
  • System Administrators manage the platform itself: infrastructure health, identity and access management, onboarding new partners, sharing policies, and audit logs.

Explainable AI at the Center

Predicting how a threat might arise or an attack cascade from one Critical Infrastructure to another is only useful if humans can understand why the system reached that conclusion.

SAAM’s Systemic Risk Analysis Engine combines several modelling approaches: LSTM networks for tracking long, multi-stage attack sequences, Transformer variants (Informer/Autoformer) for spotting complex patterns in parallel, and an optional Graph Neural Network layer that models how risk propagates across interconnected infrastructures.

Every prediction is made explainable using SHAP and LIME, with a large language model translating the technical output into plain-language narratives for human operators.

This isn’t just a nice-to-have; it directly supports the AI Act’s requirements for transparency and human oversight, while an anonymization layer keeps the system aligned with GDPR data-minimization principles.

Built With Regulation in Mind, Not as an Afterthought

SAAM’s cloud-native and modular architecture is designed to evolve alongside the harmonized regulatory objectives still being developed for the AI Act and CRA, while already supporting NIS2 incident reporting, CER risk assessment, and GDPR data-protection obligations.

More than that, SAAM follows the CyberNEMO Risk Methodology to work at the broadest possible tier of risk propagation from individual products and organisations, up through value chains, to society-level risk, closing the loop on how risk moves between interdependent organizations linked by sector or geography.

That’s the core reason CyberNEMO chose a federated design over a centralized one: risk doesn’t respect a single organization’s walls, so the platform that tracks it can’t either.

What’s Next

By pairing standardized, explainable threat-intelligence exchange with a trust-based sharing model, SAAM offers a concrete path away from isolated incident notification and toward proactive, coordinated cyber-defense across Europe.

Future work includes real-world pilot validation across energy, water, agriculture and healthcare Critical Infrastructures, along with continuous alignment as harmonized EU standards mature.