Regulation as a Market Force: How NIS2 and the Cyber Resilience Act Are Reshaping Edge Security in Europe

In order to understand why Europe’s approach to edge security looks different from the rest of the world, it is necessary to start with the regulation. Unlike the US market, where security investment is primarily driven by competitive pressure and incident response, Europe follows a “regulation-first” adoption curve — and two pieces of legislation are currently redefining what that means in practice.

The NIS2 Directive and the Cyber Resilience Act (CRA) are not simply compliance checkboxes. They are market forces. NIS2 converts cybersecurity from a technical option into a boardroom imperative with personal liability for executives. It also mandates supply chain security, meaning operators must ensure the integrity of every connected device in their network — not just their own perimeter. This is a significant expansion of scope: in an edge environment, where a single factory floor can host hundreds of connected sensors and controllers from dozens of vendors, tracing and verifying the security posture of every component is an enormous operational challenge. It is also, notably, the exact kind of challenge that creates demand for standardised, certifiable security solutions.

The CRA goes further. It requires “security by design” and mandates that vendors provide security updates for the entire expected product lifetime of a device. For manufacturers of low-cost IoT hardware — the category of devices most commonly deployed at the edge — this creates a near-prohibitive barrier. The economics of a €15 sensor do not readily support a 10-year software maintenance cycle, which means the CRA will likely consolidate the IoT vendor market toward larger players capable of absorbing that obligation.

The second structural shift reshaping the market is the convergence of IT and OT. Historically, industrial networks were “air-gapped,” physically isolated from the internet. Industry 4.0 has ended that era. Connecting factory machinery to the cloud for predictive maintenance and real-time analytics means that legacy OT systems — often running outdated, unpatchable operating systems — are now reachable from the public internet. The attack surface has expanded from corporate email servers to robotic arms on assembly lines, and the consequences of a breach have shifted from data loss to potential physical disruption of production.

The market response is moving toward micro-segmentation and Virtual Network Functions (VNFs) to recreate “virtual air gaps” in software — maintaining operational connectivity where needed while isolating critical systems from broader network exposure.

Taken together, these regulatory and technical pressures are fostering a uniquely European ecosystem of “Sovereign Edge” providers — companies aligned with initiatives like Gaia-X that prioritise data residency and immunity from extraterritorial laws (such as the US Cloud Act) over pure scalability. Regulation, in other words, is not slowing the market. It is shaping who wins it.

Read More

Privacy Protection Enforcement (PPE)

The Privacy Protection Enforcement (PPE) component has been designed and developed by CyberSocial Lab  within the CyberNEMO project and publicly accessible on the Eclipse Research Labs repository,
Our tool acts as a privacy-aware authorization and enforcement mechanism supporting secure data sharing across the computing continuum. Operating in conjunction with the Computing Continuum Access Security Broker (CASB), the PPE is responsible for ensuring that access to personal and sensitive data is granted only when the applicable processing policies and user consents are satisfied.

The architecture of the PPE has been designed to support secure and trustworthy data exchanges across cloud, edge, and IoT environments, while promoting data sovereignty, privacy preservation, and regulatory compliance. By combining policy-based access control mechanisms with consent management capabilities, the component enables organizations to maintain control over how sensitive data is accessed and processed across distributed infrastructures.

PPE provides a structured framework for defining and enforcing privacy and data access requirements. Indicative controls and verification mechanisms supported by the component include:

  • Validation of consent records before access to protected data is granted.
  • Enforcement of data processing policies applicable to data consumers.
  • Verification of consent validity and policy applicability during access requests.
  • Auditing and traceability of authorization and access control decisions.
  • Verification of cryptographic proofs associated with policies and consents.

The PPE has been designed in alignment with the principles of the General Data Protection Regulation (GDPR), supporting key requirements such as lawful processing, explicit consent management, accountability, transparency. It contributes to ensuring that sensitive data is accessed only when valid consent and an applicable processing policy exist.

Furthermore, the use of cryptographic proofs and immutable audit trails strengthens accountability by providing verifiable evidence of consent and authorization decisions throughout the data lifecycle. The adoption of blockchain-based evidence storage, rather than storing personal data directly on-chain, supports privacy-preserving processing practices while facilitating regulatory compliance across distributed cloud, edge, and IoT environments.

PPE integrates with the broader CyberNEMO security ecosystem through the CASB. When a data consumer requests access to protected data, the component evaluates the corresponding policies and consents before authorizing the request. Authorization outcomes can be propagated to other platform components, enabling coordinated security, governance, and compliance operations across the CyberNEMO architecture.

The component is currently under development and will contribute to the implementation of secure, privacy-preserving data sharing services compliant with applicable regulatory requirements across the CyberNEMO computing continuum. In line with the CyberNEMO open-source strategy, the PPE is released under the Apache License 2.0. 

Read More

Europe’s Edge Computing Boom and the Security Gap

Europe’s digital infrastructure is being rewired. Data processing is migrating away from centralised hyperscale data centres toward the logical and physical periphery of networks — the “Edge.” This shift, often described as the evolution toward a Cloud-Edge Continuum, is no longer a future scenario: it is the present reality of Industry 4.0, the Internet of Things, and autonomous systems that simply cannot tolerate the latency of a round-trip to the cloud.

The numbers confirm the scale of what is happening. The European edge computing market is projected to grow from approximately €4.5 billion in 2024 to over €56.6 billion by 2033, driven by a Compound Annual Growth Rate exceeding 31%.To put that in perspective, this is one of the fastest-growing technology segments on the continent, outpacing most of the broader digital economy.

Yet behind these extraordinary growth figures, a structural problem is forming — one that CyberNEMO was built to address. While infrastructure investment accelerates, cybersecurity spending is not keeping pace. Security budgets are actually forecast to drop to 10.9% of overall IT spend in 2025 (Figure 1), even as the threat landscape intensifies.


Figure 1. The average security budget as a percentage of IT spending had been growing steadily until this year. Chart: CFO.com Source: IANS Research and Artico Search

ENISA’s own reporting confirms the picture: EU organisations spent an average of €1.5 million on cybersecurity in 2024, representing roughly 9% of their total IT allocations — and even that figure is under pressure from ongoing budget cuts across the continent.The result is a widening “vulnerability deficit”: European enterprises are deploying more distributed, more exposed infrastructure with proportionally fewer resources dedicated to defending it.

This is not a marginal risk. The broader European cybersecurity market — covering cloud, endpoint, and network security — is valued at approximately €53 billion in 2024 and is expected to reach €100 billion by 2030 at a CAGR of roughly 11.2%.The gap between edge deployment speed and security investment speed is, in other words, a gap between two very large numbers — and it is growing in the wrong direction.

There is also a currency dimension that often goes unnoticed. A significant share of edge hardware and software licences is priced in US dollars, sourced from American hyperscalers (AWS, Microsoft, Google). Euro-denominated European firms are therefore exposed to exchange rate volatility on top of their infrastructure costs. This is one of the quiet drivers behind the “Sovereign Cloud” movement, pushing enterprises toward local providers like Deutsche Telekom or Orange Business whose cost bases sit in euros — and whose legal obligations sit within EU jurisdiction.

The edge is where Europe’s industrial future will be computed. CyberNEMO’s mission is to ensure it is also where it will be secured.

Read More

Partner Spotlight: SPACE Hellas

1. Company Profile and Evolution

Founded in 1985, SPACE Hellas has evolved from a pioneering network service provider into a leading international Digital Integrator and Value-Added Solutions Provider. With nearly 40 years of sustainable growth, the company holds a dominant position in the high-technology arena, designing and supporting complex ICT, Hybrid Cloud, and Security solutions for the enterprise, government, and defense sectors.

Headquartered in Athens and listed on the Athens Stock Exchange, SPACE Hellas has expanded its footprint across the EMEA region with subsidiaries in five countries. The company is distinguished by its 24/7 state-of-the-art Network and Security Operations Center (NOC/SOC) and an extensive technical support network that handles over 45,000 calls annually. This evolution is underpinned by a commitment to quality and security, evidenced by a robust portfolio of ISO certifications and over 700 vendor-leading accreditations.

2. Focus on Research and Development

Innovation is a core pillar of SPACE Hellas’ strategy. The company’s dedicated R&D Department focuses on bridging the gap between niche scientific research and commercial exploitation. With a track record of participating in and coordinating over 45 European and National projects (including Horizon Europe, H2020, and EDF), the organization actively shapes the future of the computing continuum.

Space Hellas’ R&D expertise spans several critical domains:

  • Cybersecurity & Cyber Defense: Leading initiatives in threat hunting, incident response, and zero-trust architectures (e.g., PANDORA, PALANTIR).
  • Future Networks: Expertise in 5G/6G ecosystems, satellite communications, and software-defined infrastructures.
  • Smart & Secure Cities: Developing AI-driven solutions for IoT, situational awareness, and critical infrastructure protection.
  • Space Technologies: Advancing Earth Observation and satellite payload data management.

3. SPACE Hellas Role in CyberNEMO

In the CyberNEMO project, SPACE Hellas leverages its extensive experience in security orchestration to lead the development of the Computing Continuum Access Security Broker (CASB) component. Acting as a strategic technical partner, SPACE Hellas is responsible for the architectural design and implementation of this critical security layer, which ensures protected data flows across the project’s meta-Operating System.

Beyond its technical leadership in Task 3.3, the organization plays a horizontal role in ensuring system-wide interoperability. By defining the interaction between the CASB, the Event Bus, and the Intelligent Policy Decision Making (IPDM-DSS) framework, SPACE Hellas ensures that security policies are consistently enforced across diverse pilot environments. Furthermore, the company contributes its operational expertise to the project’s validation trials, ensuring that the developed security innovations are robust, scalable, and ready for deployment in real-world critical infrastructures like energy, water, and healthcare.

Read More

CyberNEMO Releases the Network Policy Manager (CNPM)

The alpha version of the CyberNEMO Network Policy Manager (CNPM), a policy enforcement component of the CyberNEMO cybersecurity platform, developed by Synelixis SA and publicly accessible on the Eclipse Research Labs repository, undergone under initial testing and validation in the Smart Agriculture / Supply Chain pilot.

CNPM is designed for the cloud–edge–IoT continuum as it operates natively within Kubernetes, the de facto orchestration standard for containerised applications. It is based on Cilium networking layer that enables fine-grained, identity-aware security controls across distributed clusters. Each cluster in a CyberNEMO deployment runs its own CNPM instance, ensuring that policy management remains local, responsive, and aligned with the specific security posture of that environment.

CNPM provides the operators a structured, template-driven workflow for defining and enforcing network security policies. Indicative policies that CNPM can create and enforce include:

  • Deny-all ingress rules that block all inbound traffic to a namespace by default, enforcing an explicit allowlist model.
  • Least-privilege access controls that permit only the minimum necessary communication between services.
  • Source-based filtering, restricting traffic to specific IP ranges or trusted origins.
  • Port-level controls, limiting exposure to only the protocols and ports a service legitimately requires.

Policies can be generated from reusable templates, validated before deployment, and pushed directly to the cluster, reducing the risk of misconfiguration and ensuring consistency across environments.

CNPM integrates with the CyberNEMO event bus, receiving mitigation instructions from upstream platform components such as the Cloud Access Security Broker (CASB) and the Intrusion Prevention Detection and Mitigation Decision Support System (IPDM-DSS), closing the loop between threat detection and network-level response.

The module is released under the Apache License 2.0.

Read More

Meet White Shark: The Eyes and Ears of the Network

In the architectural hierarchy of CyberNEMO, the White Shark probe acts as the primary sensory organ, providing the critical observability required for a secure meta-Operating System. While other components focus on high-level orchestration or AI-driven analysis, White Shark operates at the “ground level,” functioning as a high-precision network probe that monitors the most fundamental unit of connectivity: the network socket.

Technical Architecture and Integration

Technically, White Shark is designed for seamless deployment within Kubernetes-based environments, where it integrates into the data plane to capture real-time telemetry. Its architecture is built around a lightweight footprint to minimize overhead while maintaining the ability to collect granular network metrics across the distributed Computing Continuum. As a key asset within Work Package 2 (WP2), it is specifically engineered to support Zero Trust Network Access (ZTNA) by providing the visibility needed to enforce “explicit verification” for every connection within the cluster.

Point-to-Point Measurement for High Precision

The defining feature of White Shark is its use of point-to-point measurement. Unlike traditional tools that provide broad averages, White Shark retrieves specific metrics—including latency, throughput, and jitter—directly between two communication endpoints. This socket-level approach bypasses the “fog” created by virtual network overlays and high-level abstractions, ensuring that the captured data reflects the actual communication experience of the microservices. This high-fidelity data is essential for differentiating between standard network fluctuations and subtle anomalies.

Driving Intelligence: The Link to NADA

The precision of White Shark is not just for monitoring performance; it is the essential fuel for NADA (Network Anomaly Detection AI). By providing a continuous stream of verifiable point-to-point data, White Shark allows NADA to analyze temporal and contextual patterns with extreme accuracy. Together, they form a proactive security loop: White Shark captures the “ground truth” of the network, and NADA interprets that truth to identify, ensuring the CyberNEMO environment remains resilient and secure.

Read More

Sphynx Cybersecurity Solutions and Contributions to CyberNEMO

Sphynx is research-driven a cybersecurity company, initially founded in Switzerland and currently operating in Switzerland, Greece, and Cyprus.  

We develop cutting edge cybersecurity technologies and provide services to our clients in the areas of security operation centres, managed security, cyber threat intelligence, incident response, training and certification.  

Our solutions are powered by products that have been developed in-house, including the Sphynx Security and Privacy Assurance Suite (SPA Suite) and the Sphynx Cyber Range platform. These products incorporate novel event processing, vulnerabilities detection, cyber threat intelligence, incident response and systems emulation capabilities which are based on machine learning, auto ML and generative AI. Sphynx has a strong R&D team that helps maintaining the cutting-edge features and technology of its products. 

At Sphynx, we are proud of our an extensive track record of participating in European and national R&D projects. Sphynx participates as a partner in CyberNEMO through its  Swiss arm,  Sphynx Technology Solutions AG (STS). Within CyberNEMO, STS mainly contributes to Task 4.1: Micro-services Auditing, Certification & Accreditation, Task 4.2: XAI Tools for continuous system risk analysis and Task 4.3: Strategies & Tools for cooperative remediation and mitigation. As part of those tasks the company develops a Proactive Cyber-Defense with Real-time Threat Intelligence Extraction, Prediction and Response; The primary objective is to minimize human workload and reduce the potential for error in the large-scale processing of Open-Source Cyber Threat Intelligence (OSCTI) by developing an automated, standards-compliant toolchain capable of transforming raw, unstructured intelligence into actionable defensive artefacts. The implemented system follows a hybrid, modular pipeline that integrates multiple stages of the cyber threat intelligence lifecycle.

Read More

From NEMO to CyberNEMO: The Evolution of Network Monitoring

The transition from the NEMO project to CyberNEMO marks a critical evolution in how we approach network visibility within distributed systems. In the original NEMO project, the primary challenge was establishing reliable performance monitoring across diverse infrastructure. Our response, developed by UPM within the networking work package, was White Shark. White Shark was designed as a network probe, focusing on the fundamental socket layer to measure point-to-point communication metrics like latency, throughput, and jitter. This provided a foundational level of observability, allowing operators to understand how the network was performing at any given moment.

However, as we moved into CyberNEMO, the landscape shifted dramatically. The emergence of a true “computing continuum”—spanning Cloud, Edge, and IoT devices—introduced complexity and a expanded attack surface. Simple performance monitoring was no longer sufficient. We realized that the massive stream of high-fidelity network telemetry generated by White Shark was not just performance data; it was a rich, untapped source of security intelligence. The data that previously told us if the network was fast, could now tell us if the network was being compromised.

This realization led to the development of the NADA (Network Anomaly Detection AI) component in CyberNEMO. NADA represents the intelligent brain that sits atop the White Shark sensing layer. Its purpose is to ingest the granular, socket-level data captured by the probe and use advanced machine learning algorithms to identify temporal and contextual anomalies.

The journey from NEMO to CyberNEMO is therefore characterized by a shift from reactive performance observation to proactive, AI-driven security validation. By enriching the data previously used only for network optimization, we have created a robust mechanism for enforcing Zero Trust principles by design. This evolutionary step ensures that CyberNEMO doesn’t just provide a high-performance network, but a verifiably secure and resilient foundation for the next generation of meta-operating systems.

Read More

The MITRE ATT&CK framework for attacks

Understanding the MITRE ATT&CK Framework

In the world of cybersecurity, defenders and hackers are locked in a constant game of cat and mouse. For a long time, defenders focused on who was attacking them (attribution). However, names and locations change. The MITRE ATT&CK® framework shifted the focus to something more permanent: how they attack. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge. Think of it as a comprehensive, living encyclopedia of “bad guy” behavior. It is a globally accessible knowledge base that tracks the specific actions cybercriminals take from the moment they start scouting a target to the moment they steal data or cause damage.

The Anatomy of an Attack

The framework is organized into a matrix that reads like a story of a digital break-in. It breaks down an attack into two main components: (a) Tactics (The “Why”): These are the attacker’s technical goals. For example, a tactic might be “Initial Access” (getting into the network) or “Exfiltration” (taking the data out). (b) Techniques (The “How”): these are the specific methods used to achieve a tactic. If the goal is “Initial Access,” the technique might be a “Phishing” email. By using this common language, security teams across different companies can share information instantly. If a bank in London discovers a new way hackers are bypassing passwords, they can label it with an ATT&CK ID (like T1078), and a hospital in New York will immediately know exactly what to look for.

Mitigations: Building the Shield

The framework isn’t just a list of threats; it’s a roadmap for defense. For every technique listed in the matrix, MITRE provides mitigations, i.e., specific actions organizations can take to prevent a technique from working.

TacticTechnique (Example)Mitigation (Defense action)
Initial AccessPhishingSecurity awareness training and email filtering.
PersistenceCreate AccountUse Multi-Factor Authentication (MFA) and monitor new user creation.
ExfiltrationTransfer Data to CloudBlock unauthorized cloud storage sites on the company network.

Why It Matters

While ATT&CK is a technical tool, its impact reaches everyone. When organizations use this framework, they move away from “guessing” what might happen and start “knowing” what to defend against. It allows companies to test their security systems against real-world scenarios, ensuring that your personal data and the services you rely on—like banking, healthcare, and power—are protected by more than just a firewall and a prayer. MITRE ATT&CK is a resource that has turned cybersecurity from a dark art into a measurable science by documenting the “playbook” of the adversary.

Read More

AI’s role in cyber risk assessment, monitoring and mitigation

AI: The New Digital Watchman

In the fast-moving world of the internet, new threats appear every second. Traditional security tools are like a library catalog—they work great for finding things we already know about, but they struggle with anything new. Artificial Intelligence (AI) has changed the game by acting less like a catalog and more like a highly trained digital watchman that never sleeps and learns as it goes. It contributes in monitoring, risk assessment and mitigation.

In monitoring it acts like the guard that never blinks. AI’s greatest strength is its ability to watch millions of events at once without getting tired. It can perform behavioral analysis and phishing detection. In behavioral analysis instead of just looking for “bad files,” AI looks for “bad behavior.” If an employee who usually only checks email suddenly starts downloading the entire company’s client list at 2:00 AM, the AI flags it as an anomaly. In phishing detectionAI can read the intent behind an email. It can spot the subtle signs of a scam—like a slightly misspelled link or a tone that is “too urgent”—and stop the email before it ever hits your inbox.

In risk assessment it can find the weak spots. Before an attack even happens, AI helps companies understand their “Cyber Risk”—basically, a score of how likely they are to be hacked. Often prioritizing is what matters. A large company might have thousands of software “vulnerabilities” (tiny bugs). AI can scan all of them and tell the security team, “These three are the most dangerous because hackers are currently using them to attack other companies.”. It can also support simulating attacks. AI can run “digital drills,” pretending to be a hacker to find paths through a network that a human might never think to check.

Finally, in mitigation, it can act at machine speed. When an attack happens, every second counts. AI allows a company to respond at “machine speed” rather than waiting for a human to wake up and read an alert. It can contribute in automated containment. If AI detects a virus spreading on one laptop, it can instantly “quarantine” that device, cutting its connection to the rest of the office so the virus can’t jump to other computers. Moreover, it can provide smart recommendations. If a threat is detected, AI can provide a “playbook” for the human staff, saying: “I’ve blocked the suspicious IP address. I recommend you reset these three user passwords and check this specific server for damage.”

While AI is fast, it isn’t perfect. It can sometimes mistake a legitimate heavy workload for an attack (a “false positive”). This is why the best cybersecurity is based on the human-AI partnership and uses a “Human-in-the-loop” approach. The AI handles the “heavy lifting” by filtering out 99% of the noise, allowing human experts to focus their energy on the most complex and dangerous 1% of threats.

Compared to traditional methods for security, AI-powered security offers many advantages. Instead of looking for known signatures (like finderprints) it looks for unknown patterns that may indicate suspicious behovior. Instead of requiring manual updates to stay current, it learns and adapts to new threats automatically. Moreover, it does not become overwhelmed by too much data; instead, it gets better the more data is processes.

AI has turned cybersecurity from a game of “catch-up” into a proactive defense, allowing us to predict and stop threats before they can do real damage.

Read More