Secure Remote Production with CyberNEMO: The Future of Smart Media

The Media and Broadcasting Industry: New Opportunities, New Cybersecurity Challenges

The media and broadcasting industry is undergoing an unprecedented transformation. The need to produce and distribute high-quality multimedia content with massive bandwidth and minimal latency has driven the adoption of distributed infrastructures across the Edge-Cloud continuum.

However, this technological evolution brings a critical challenge: a significant increase in the surface area exposed to cyberattacks.

What is the CyberNEMO Project?

CyberNEMO (End-to-end CYBERsecurity to NEMO meta-OS) is an innovative initiative funded by the European Union’s Horizon Europe programme.

Its main objective is to add a transversal layer of comprehensive cybersecurity and trust to the IoT-Edge-Cloud computing ecosystem. To achieve massive adoption and technological maturity, CyberNEMO builds upon Zero-Trust cybersecurity systems, privacy-by-design protection, innovation, and collaboration, introducing new methods, tools, and threat analysis platforms.

The Smart Media Pilot: A Critical Environment

One of the key validation environments within the project is Pilot 3: Secure and Intelligent Media Content Supply Chain Ecosystems.

This pilot focuses on validating end-to-end cybersecurity measures throughout the entire lifecycle of professional media workflows.

The pilot addresses the inherent conflict in the media industry: the operational demand for high speed and low latency versus the critical need for robust, multi-layered security.

It focuses on mitigating sophisticated threats that can compromise the supply chain at any point—from the initial content capture (contribution phase), through intermediate processing stages (production phase), to final delivery to users (distribution phase). Protecting this ecosystem requires guaranteeing data sovereignty and system resilience without degrading media quality or introducing unacceptable delays.

The pilot is divided into two main use cases:

  • Secure and Collaborative Multimedia Content Production: Focused on secure content contribution, access control, content integrity verification, and anomaly detection during remote production.
  • Efficient and Secure Distribution across Multi-domain Edge-Cloud: Focused on secure distribution to authorized users, malicious traffic detection, and the implementation of countermeasure actions during content delivery.

How Does CyberNEMO Support the Smart Media Pilot?

The integration of CyberNEMO technologies transforms this pilot into a highly secure environment. By deploying advanced cybersecurity components, CyberNEMO provides fundamental capabilities such as:

  • Zero-Trust Architecture: Implementing strict security policies where no device or user is trusted by default, ensuring that production tools and media streams communicate only through authenticated and authorized channels.
  • Intelligent Anomaly Detection: Using behavioural analysis and security logs (network logs, video quality metrics, and access logs) to identify unusual activities that may indicate cyberattacks, credential theft, or malicious actions during live media transmission.
  • Proactive Mitigation: Detecting malicious traffic or content integrity violations in real time and automatically isolating compromised components without disrupting live production or media distribution workflows.

Building Secure Media Ecosystems

CyberNEMO provides the Smart Media sector with the cybersecurity framework and intelligent tools required to operate decentralised remote production infrastructures with confidence, resilience, and operational continuity.

Read More

ASM Trial #2: Strengthening Cybersecurity for Smart Energy and Smart Water Infrastructures

As part of the CyberNEMO project, ASM Terni contributes as the pilot partner for Trial #2, focused on Smart Energy and Smart Water Critical Infrastructures.

ASM operates essential urban services in Terni, including electricity distribution, water services, and related digital monitoring systems. These infrastructures are increasingly connected through sensors, smart meters, SCADA systems, communication networks, and data platforms. While this digital transformation improves efficiency and service quality, it also introduces new cybersecurity challenges. Within CyberNEMO, ASM provides a real pilot environment where innovative cybersecurity solutions can be validated in practical conditions.

The trial focuses on understanding how cyber threats may affect interconnected energy and water assets. It also supports the analysis of anonymized operational data, network events, and security-related information.

The objective is not only to detect possible cyber incidents, but also to improve preparedness, resilience, and response capabilities. CyberNEMO technologies will help explore advanced monitoring, risk analysis, and mitigation approaches across the cloud-edge-IoT continuum.

For ASM, this represents an important opportunity to connect research outcomes with the needs of real critical infrastructure operators.

The pilot also highlights the importance of protecting citizen services, operational continuity, and data privacy. By participating in CyberNEMO, ASM contributes to building more secure, resilient, and trustworthy smart utility systems.

Trial #2 demonstrates how collaboration between technology providers, researchers, and infrastructure operators can support the future of European critical infrastructure protection.

Read More

From Cyber Threat Reports to Action with Generative AI

Cyber threat intelligence is often hidden inside unstructured sources such as security blogs, advisories, and open-source reports. Although these sources contain valuable information, manually turning them into actionable intelligence is slow, difficult, and not scalable.

STS, within CyberNEMO, proposes an automated pipeline that transforms open-source cyber threat intelligence into structured and usable knowledge. The pipeline combines deterministic methods with Generative AI to support the full process: scraping threat reports, extracting relevant information, converting it into STIX 2.1 objects, storing it in OpenCTI, and using it for threat hunting and response.

The system uses a modular Python architecture and Docker-based deployment to connect different tools in a reproducible way. Stixify is used to convert raw text into structured STIX objects, while OpenCTI currently acts as the central knowledge base for visualization, sharing, and standardization.

The main contribution is showing that Generative AI can strengthen cyber defense when combined with existing standards and tools. Deterministic methods remain useful for clear indicators of compromise, while AI helps extract context, relationships, and more complex threat patterns.

Overall, STS’ initial work shows a practical path toward proactive cyber defense: transforming unstructured threat information into standardized intelligence that can support faster analysis, hunting, and response.

Read More

Protecting People While Sharing Cyber Data: Why Anonymisation Matters in CyberNEMO

Every day, critical infrastructures generate enormous amounts of cyber data, from hospitals and smart energy networks to drones, media platforms, and logistics systems. This information is essential for developing better cybersecurity tools, but it also raises an important question:

How can we share valuable cyber data without exposing people’s privacy?

At CyberNEMO, the answer is anonymisation.

Why Technical Data Isn’t as Anonymous as It Looks

Many people assume that if a dataset doesn’t contain names, it’s already anonymous. Unfortunately, that’s not always true.

Technical information such as IP addresses, timestamps, GPS locations, or device identifiers can often be linked back to individuals, organisations, or specific systems. Even cybersecurity logs can reveal working patterns, locations, or sensitive infrastructure details.

That’s why every dataset collected across CyberNEMO’s pilots is treated as potentially identifying, even when no personal names are present.

Turning Sensitive Data into Safe, Reusable Datasets

CyberNEMO applies several anonymisation techniques that protect privacy while preserving the information researchers need.

Some examples include:

  • Replacing real identities with anonymous labels so users and devices can still be tracked within a dataset without revealing who they are.
  • Masking IP addresses to hide the exact location of computers while keeping network traffic patterns intact.
  • Generalising timestamps, for example recording activity by hour instead of by the exact second.
  • Reducing GPS precision so drone flights and smart infrastructure can be analysed without revealing precise locations.
  • Hiding sensitive server names and service details while maintaining realistic communication patterns.
  • Generalising medical information so healthcare datasets remain useful for cybersecurity research without exposing patient information.

The goal is simple: preserve the value of the data while removing the details that could identify people or critical systems.

Why This Matters

Effective anonymisation allows CyberNEMO to balance two equally important goals:

  • Protect citizens’ privacy and comply with GDPR.
  • Enable researchers, innovators, and cybersecurity experts to work with realistic datasets.

This supports the European vision of privacy by design, helping organisations collaborate without exposing sensitive information.

From Protected Data to Shared Knowledge

Once anonymised and validated, CyberNEMO datasets can be securely shared across the consortium to support the development and validation of cybersecurity technologies.

Following the FAIR principles (Findable, Accessible, Interoperable and Reusable), selected anonymised datasets are planned to be published through trusted open-data repositories such as Zenodo, subject to consortium approval and the necessary legal and ethical clearances.

Publishing datasets through Zenodo provides long-term preservation, persistent Digital Object Identifiers (DOIs), and enables researchers worldwide to discover, cite, and reuse CyberNEMO research outputs.

This approach allows researchers to evaluate new cybersecurity techniques using realistic operational data while fully respecting privacy and data protection requirements.

The benefits extend well beyond the CyberNEMO project:

  • Researchers can develop, benchmark, and validate new cybersecurity detection algorithms using realistic datasets.
  • SMEs and technology providers can accelerate the development of innovative cybersecurity products and services.
  • Public authorities and critical infrastructure operators can promote secure, trustworthy, and responsible data sharing across Europe.
  • The wider research community benefits from reusable datasets that support reproducible research and future innovation in cybersecurity and critical infrastructure protection.

Privacy Enables Innovation

Anonymisation is often viewed as a compliance requirement, but in CyberNEMO it is much more than that.

It is the foundation that transforms sensitive operational data into trusted, reusable knowledge. Instead of keeping valuable cybersecurity information locked away, anonymisation allows Europe to share what matters while protecting the people behind the data.

That’s how CyberNEMO helps build a stronger, more collaborative, and more privacy-conscious cybersecurity ecosystem.

Read More

Gaps and opportunities in Europe’s Edge Cybersecurity Market: what remains unsolved

Understanding a market means understanding not just where money is flowing, but where genuine needs are going unmet. In European edge security, the gaps are structural and well-documented — and they represent the exact space where projects like CyberNEMO operate.

The SME security divide is perhaps the most acute. Small and Medium Enterprises face a compound problem: the upfront cost of edge infrastructure is already a stretch, and layering credible security on top of it is frequently prohibitive. Survey data identifies “high costs” and “unclear ROI” as the primary barriers to adoption. The consequence is a two-tier market where large industrial players deploy sophisticated edge security, while SMEs — which represent over 99% of European businesses and the backbone of manufacturing — remain largely exposed. ENISA’s Threat Landscape reports that nearly 40% of cyberattacks in Europe already target SMEs, making this divide a systemic risk, not just a commercial gap.

The skills shortage compounds every other problem. According to the 2024 ISC2 Cybersecurity Workforce Study, Europe faces a shortage of approximately 424,000 skilled cybersecurity workers — a gap that widened by nearly 10% in a single year. Within the EU specifically, 65% of organisations reported a cybersecurity staffing shortage in 2024. Edge security demands an especially rare profile: practitioners must simultaneously understand Kubernetes (IT), SCADA systems (OT), and 5G protocols — a combination that barely exists in the current talent pool. This scarcity is a hard ceiling on how fast the market can actually deploy the solutions it needs.

Against these structural challenges, several clear opportunities are emerging for vendors and integrators willing to address root causes rather than symptoms.

Compliance as a Service is the most immediately actionable. NIS2 and the CRA create mandatory audit, documentation, and reporting obligations that are genuinely complex to satisfy at scale. Vendors offering edge platforms that are “pre-certified” — automatically generating required audit logs and compliance artefacts — will face strong demand from organisations that lack the internal capacity to manage this themselves.

Privacy-Enhancing Technologies (PETs) — including Federated Learning and Homomorphic Encryption — are moving from academic research into commercial deployment, enabling “Privacy-by-Design” architectures where data can be processed without being exposed. For healthcare and finance in particular, this is not a differentiator: it is a prerequisite for using edge infrastructure at all.

The Sovereign Stack gap remains largely unaddressed. There is unmet demand for a seamless European alternative that combines the developer experience and scalability of a hyperscaler with the legal certainty of a local provider. And OT/IoT Managed Detection and Response (MDR) — specialist services that understand industrial protocols well enough to distinguish a cyberattack from a mechanical fault — are in high demand and chronically short supply. With the European managed security services market set to grow at roughly 10% CAGR through 2033, the structural shortage of OT-literate security specialists means that supply will struggle to keep pace with demand for years to come.

These are not niche edge cases. They are the dominant unmet needs of the market CyberNEMO is designed to serve.

Read More

Zero Trust, Edge AI, and Confidential Computing — The Technologies Redefining Edge Security

The security architecture being built for the edge is fundamentally different from what came before. Perimeter defence — the logic of a hard external wall and a trusted interior — does not work when the “perimeter” is a sensor on a wind turbine, a camera on a factory floor, or a controller on a substation. These devices sit in physically uncontrolled environments, often connected via public networks, and there are too many of them to manage individually. The industry is converging on a new model built around three core technology trends.

Zero Trust is the foundational shift. In a Zero Trust architecture, no interaction between an edge device and its gateway is assumed safe: every request must be authenticated and authorised, regardless of where it originates or what it claims to be. For edge environments with hundreds or thousands of endpoints, this is architecturally demanding — but it is increasingly the baseline expectation set by both regulators and enterprise customers. NIS2 and the CRA effectively mandate Zero Trust principles without using the term.

Edge AI is making Zero Trust operationally viable at scale. The ENISA Threat Landscape 2024 documents that edge devices such as routers and IoT hardware are prime targets precisely because of outdated firmware and limited local monitoring capabilities. Running AI-native threat detection models directly on the edge node — rather than routing raw telemetry to a central Security Operations Centre — addresses this structural weakness head-on: a smart meter or industrial gateway can apply lightweight anomaly detection locally, flagging suspicious behaviour in milliseconds without transmitting sensitive operational data to the cloud.

In many industrial and healthcare contexts, local inference is the only architecture that simultaneously meets latency, bandwidth, and data sovereignty requirements.

Confidential Computing addresses a different but equally critical problem: what happens when sensitive workloads must run on third-party infrastructure? Hardware-based Trusted Execution Environments (TEEs) — such as Intel SGX — process data inside an encrypted enclave, meaning the infrastructure provider physically cannot access the raw data being computed. This allows organisations to use shared or commercial edge infrastructure without surrendering data confidentiality — a capability that is increasingly essential as edge deployments scale beyond what any single organisation can own outright.

Two further developments are reshaping the threat landscape itself. Private 5G Networks combined with Multi-access Edge Computing (MEC) enable compute to be placed at mobile base stations, offering high security through physical isolation of industrial traffic from public networks. ModelOps Security (AI TRiSM) is emerging as a response to adversarial attacks that target not the network infrastructure, but the integrity of the AI model itself. Recent incident analysis of cloud-edge deployments documents cases where attackers manipulated communication links between edge and cloud nodes to modify sensor data — underscoring that in environments where AI drives automated decisions, securing the model pipeline is as critical as securing the network.

These technologies are not on the horizon. They are being deployed now, in real industrial environments, by the same organisations that CyberNEMO works with.

Read More

MoniKube: Security-Aware Infrastructure Discovery for Cloud-Native Environments

As organizations continue to adopt Kubernetes and cloud-native technologies, their infrastructures become increasingly complex and difficult to manage. Distributed clusters, virtual machines, containers, and interconnected services provide scalability and flexibility, but they also create significant challenges in maintaining visibility, understanding asset relationships, and identifying security risks.

MoniKube is a distributed security-aware monitoring and intelligence platform designed to address these challenges. By continuously monitoring Kubernetes and cloud-native environments, collecting telemetry data, and performing vulnerability assessments, it automatically discovers infrastructure components and builds a comprehensive representation of the operational environment. The platform correlates infrastructure, monitoring, and security information to provide organizations with a deeper understanding of their assets, dependencies, and overall security posture.

At the core of MoniKube is a security-aware knowledge graph that transforms distributed infrastructure data into a centralized and interactive model. By mapping assets and their relationships, the platform enables operators and security teams to explore infrastructure topology, understand dependencies between systems, identify exposed components, and gain valuable insights into potential risk and exposure pathways.

MoniKube discovers Kubernetes resources through the Kubernetes API and can optionally enrich the model with host-level Docker workloads. The platform integrates Trivy-based vulnerability and misconfiguration scanning, allowing assets to be continuously assessed for security weaknesses. Vulnerability information, exposure indicators, runtime metrics, and security scores are incorporated directly into the graph, enabling users to filter, compare, and prioritize risks from a single dashboard.

Beyond infrastructure discovery, MoniKube can ingest information from external security and monitoring solutions, including IDS, SIEM, and IDMEF-compatible sources. This allows the knowledge graph to remain synchronized with operational reality while providing a unified view across cloud-native and traditional systems.

MoniKube combines vulnerability information, runtime monitoring metrics, and exposure indicators into a unified security-scoring framework. It can integrate information from both cloud-native and traditional systems, creating a unified view of infrastructure regardless of underlying technology. Beyond infrastructure monitoring and security assessment, MoniKube introduces the ability to generate exportable infrastructure models that can serve as the foundation for digital twins, automating much of this process by capturing the security characteristics of operational environments and transforming them into reusable digital representations. The result is a comprehensive solution that helps organizations gain visibility into complex environments, strengthen their security posture, and transform operational infrastructure data into actionable security intelligence.

Read More

Who Secures Europe’s Edge? A Map of the Key Players

The European edge security market is not dominated by a single category of player. It is a fragmented, competitive landscape where global hyperscalers, European industrial giants, telecom operators, and specialist security firms are all competing — and sometimes partnering — to own different layers of the stack. Understanding who does what, and where the tensions lie, is essential for anyone operating in or procuring from this market.

Hyperscalers — Microsoft (Azure IoT Edge), AWS (Greengrass), and Google Cloud (Distributed Cloud) — dominate the software stack and developer ecosystems. Their “cloud-to-edge” integration is technically seamless and benefits from enormous R&D investment. But they carry a structural liability in the European context: exposure to the US Cloud Act creates trust and sovereignty friction that no product feature can fully resolve, particularly for government, defence, and critical infrastructure customers.

The counterweight is a group of European Industrial and Security Sovereigns. Siemens Industrial Edge offers measured boot and digital signatures to ensure only authorised software runs on edge devices. Bosch IoT Suite provides secure Over-the-Air (OTA) updates. Thales leverages its defence background for high-grade encryption and identity management. Eviden (Atos) focuses on cybersecurity, encryption technologies, and trusted digital infrastructures aligned with European security requirements. These companies hold a structural “home court advantage”: deep OT expertise, long-standing relationships with EU institutions, and a trusted status that no marketing spend can replicate.

Telecommunications providers — Deutsche Telekom, Orange Business, and Telefónica — occupy a distinct strategic position: they own the network (5G/fibre) and the physical edge locations. They are moving up the value chain toward “Managed Edge Services,” bundling connectivity with security. Orange Business combines its network with Orange Cyberdefense to offer SASE (Secure Access Service Edge) and Virtual Network Edge solutions. Deutsche Telekom promotes Campus Networks for Industry 4.0, packaging connectivity and security together for industrial customers.

Providers like OVHcloud, T-Systems, and CloudFerro are carving out a distinct niche, capitalising on enterprise distrust of hyperscalers by offering sovereign cloud and edge infrastructure with contractual guarantees of data residency. This segment is growing directly in proportion to regulatory pressure — every new NIS2 enforcement action is, indirectly, a sales event for sovereign infrastructure providers.

Finally, as the talent shortage bites across the board, Managed Security Service Providers (MSSPs) are becoming increasingly critical. The European managed security services market is valued at over $11 billion in 2025 and is projected to grow at a CAGR of approximately 10% through 2033, reflecting the reality that most organisations — and virtually all SMEs — cannot build in-house edge security expertise. MSSPs are, in practice, becoming the primary delivery mechanism for edge security for a large portion of the market.

Read More

Why Micro-Segmentation Matters in Kubernetes

Kubernetes revolutionised the deployment of cloud-native applications by making workloads portable, scalable, and easy to orchestrate. However, while Kubernetes excels at managing applications, its networking model introduces an important challenge for network services: a lack of flexibility in its networking model.

Most Kubernetes deployments rely on a flat network approach where every pod can potentially communicate with every other pod inside the cluster. Although Network Policies can restrict some traffic flows, workloads still fundamentally share the same networking space. For traditional microservice applications, which are usually application-layer oriented, this behaviour may be acceptable, but for network functions, multi-tenant platforms, or security-sensitive services, this approach quickly becomes limiting. This is where micro-segmentation becomes critical.

Micro-segmentation is the practice of dividing an infrastructure into isolated virtual network segments, where workloads only communicate with the components explicitly allowed to them. Instead of treating the cluster as a single trusted environment, micro-segmentation applies the principles of least privilege directly to network connectivity.

The benefit of applying micro-segmentation over K8s platforms can be substantial. First, micro-segmentation improves security by reducing lateral movement. If one workload becomes compromised, attackers cannot freely traverse the infrastructure to reach other services. Each segment behaves as an isolated environment with controlled entry and exit points.

Second, it enables the deployment of advanced network services inside Kubernetes. Functions such as firewalls, routers, proxies, or content delivery components often require separated Layer 2 or Layer 3 domains to operate correctly. In a flat network, these services lose much of their networking context because every workload remains directly reachable.

Third, micro-segmentation simplifies multi-tenant deployments. Different applications, customers, or services can coexist within the same Kubernetes infrastructure while remaining logically isolated from one another. This becomes increasingly important in edge computing, telecom platforms, and distributed cloud environments.

At the infrastructure level, achieving true micro-segmentation requires more than simple traffic filtering. It requires programmable virtual networking capable of creating isolated communication domains between workloads, independently of where they are physically deployed. This becomes even more relevant in distributed cloud-edge environments, where services may span multiple Kubernetes clusters and heterogeneous infrastructures.

To address these challenges, the CyberNEMO Zero Trust Network Access (ZTNA) framework extends the capabilities of the NEMO meta Network Cluster Controller (mNCC) to provide secure micro-segmentation mechanisms for both intra-cluster and inter-cluster communications. By enabling isolated virtual networking domains across cloud-native infrastructures, CyberNEMO introduces a flexible networking foundation for advanced network services, secure workload isolation, and distributed edge deployments. In next posts, we will explore in more detail the technology behind this functionality:

L2S-M.Why Micro-Segmentation Matters in Kubernetes

Kubernetes revolutionised the deployment of cloud-native applications by making workloads portable, scalable, and easy to orchestrate. However, while Kubernetes excels at managing applications, its networking model introduces an important challenge for network services: a lack of flexibility in its networking model.

Most Kubernetes deployments rely on a flat network approach where every pod can potentially communicate with every other pod inside the cluster. Although Network Policies can restrict some traffic flows, workloads still fundamentally share the same networking space. For traditional microservice applications, which are usually application-layer oriented, this behaviour may be acceptable, but for network functions, multi-tenant platforms, or security-sensitive services, this approach quickly becomes limiting. This is where micro-segmentation becomes critical.

Micro-segmentation is the practice of dividing an infrastructure into isolated virtual network segments, where workloads only communicate with the components explicitly allowed to them. Instead of treating the cluster as a single trusted environment, micro-segmentation applies the principles of least privilege directly to network connectivity.

The benefit of applying micro-segmentation over K8s platforms can be substantial. First, micro-segmentation improves security by reducing lateral movement. If one workload becomes compromised, attackers cannot freely traverse the infrastructure to reach other services. Each segment behaves as an isolated environment with controlled entry and exit points.

Second, it enables the deployment of advanced network services inside Kubernetes. Functions such as firewalls, routers, proxies, or content delivery components often require separated Layer 2 or Layer 3 domains to operate correctly. In a flat network, these services lose much of their networking context because every workload remains directly reachable.

Third, micro-segmentation simplifies multi-tenant deployments. Different applications, customers, or services can coexist within the same Kubernetes infrastructure while remaining logically isolated from one another. This becomes increasingly important in edge computing, telecom platforms, and distributed cloud environments.

At the infrastructure level, achieving true micro-segmentation requires more than simple traffic filtering. It requires programmable virtual networking capable of creating isolated communication domains between workloads, independently of where they are physically deployed. This becomes even more relevant in distributed cloud-edge environments, where services may span multiple Kubernetes clusters and heterogeneous infrastructures.

To address these challenges, the CyberNEMO Zero Trust Network Access (ZTNA) framework extends the capabilities of the NEMO meta Network Cluster Controller (mNCC) to provide secure micro-segmentation mechanisms for both intra-cluster and inter-cluster communications. By enabling isolated virtual networking domains across cloud-native infrastructures, CyberNEMO introduces a flexible networking foundation for advanced network services, secure workload isolation, and distributed edge deployments. In next posts, we will explore in more detail the technology behind this functionality: L2S-M.

Read More

CyberNEMO’s Alignment with ENISA NIS360 Objectives

NIS360 evaluates the cybersecurity maturity and criticality of sectors covered by the NIS2 Directive, focusing on areas such as risk management, operational preparedness, information sharing, institutional capacity, and the resilience of sectoral ecosystems. CyberNEMO demonstrates a strong alignment with the objectives of ENISA’s NIS360 framework in several sectors that are explicitly covered by both the project’s pilot activities and the NIS360 assessment. In particular, the project addresses cybersecurity challenges in healthcare, water services, public-sector digital services, and ICT-enabled critical infrastructures through a comprehensive Zero Trust architecture spanning the IoT–Edge–Cloud–Data continuum. By integrating AI-driven threat detection, continuous monitoring, policy enforcement, risk assessment, and incident mitigation capabilities, CyberNEMO contributes directly to the enhancement of cybersecurity preparedness, operational resilience, and risk management maturity that NIS360 identifies as priorities for these critical sectors.

The alignment is particularly evident in the healthcare and water domains, which NIS360 highlights as sectors requiring sustained efforts to improve cybersecurity maturity and resilience. CyberNEMO’s solutions support secure access management, protection of sensitive operational and personal data, continuous threat monitoring, and coordinated incident response across distributed infrastructures. Through its SAAM platform, the project also strengthens collaboration, information sharing, and cyber situational awareness among stakeholders, addressing key NIS360 objectives related to ecosystem cooperation and collective resilience across critical services.

CyberNEMO validates these capabilities through dedicated pilots operating in sectors that fall within the scope of NIS360. The healthcare pilot focuses on securing access to electronic health records and healthcare information systems using Zero Trust principles and advanced cyber-defence mechanisms. The energy pilot addresses the protection of operational technologies and critical service infrastructures against cyber threats, while cross-organizational federation scenarios demonstrate secure collaboration, threat intelligence exchange, and coordinated incident management among critical-sector stakeholders. These pilots provide practical evidence of how CyberNEMO technologies can support the improvement of cybersecurity maturity in sectors that NIS360 identifies as strategically important for the resilience of the European Union.

Read More