Why Sockets Matter in Kubernetes: Beyond the Abstraction

In a standard Kubernetes (K8s) deployment, the sheer level of abstraction is a double-edged sword. While it simplifies orchestration, it often obscures the granular reality of network traffic. For the CyberNEMO project, specifically within WP2, we move past these high-level views to focus on the network socket. Why? Because sockets represent the “ground truth” of connectivity. In a distributed meta-OS, understanding the real-time state of point-to-point communication is the only way to ensure Cybersecurity and Privacy by Design.

Capturing the “Ground Truth” with White Shark

Traditional Kubernetes monitoring often looks at service-level averages, which can mask micro-bursts of latency or intermittent failures. By monitoring at the socket level, our White Shark probe can collect raw, high-fidelity data—including latency, throughput, and jitter—directly from the source. This allows us to see exactly how data moves between specific pods, bypassing the “fog” of virtualized overlays. This level of precision is essential for building a verifiable data plane, ensuring that every packet follows its intended path without manipulation.

Building a Stronger Zero Trust Foundation

Ultimately, focusing on sockets supports the Zero Trust principle of “explicit verification”. In CyberNEMO, we don’t just trust that a connection is secure because it’s inside the cluster. Instead, we use socket-based telemetry to constantly validate that communication patterns match the intended security policies.

Read More

The use of Explainable AI methods for monitoring assets, detecting cyberattacks, and suggesting mitigation actions

As cyberattacks become more frequent and complex, organizations are turning to Artificial Intelligence (AI) to defend their digital assets. Standard AI is incredibly fast at spotting patterns, but it often works like a “black box”—it might tell a security team, “This file is a virus,” or “there is a cyberattack going on from this IP addresss” without ever explaining why. For a security professional, a simple “Yes” or “No” isn’t enough. If the AI is wrong, it could block an important company document or block services that the company provides; if it’s right, the team still needs to know how the attacker got in to stop it from happening again. This is where Explainable AI (XAI) comes in.

What is Explainable AI (XAI)?

XAI is a set of tools and methods designed to make the “internal thought process” of an AI understandable to humans. In cybersecurity, XAI doesn’t just detect a threat; it provides a rational justification for its decision.

For monitoring assets and detecting attack instead of just monitoring for “bad” things, XAI helps security teams understand what “normal” looks like. If the AI flags a login attempt as suspicious, XAI can point to specific reasons: “The user is logging in from a new country” or “This account is suddenly accessing 2,000 files it never touched before.” XAI can generate maps or charts showing exactly where a network’s behavior deviated from the norm, helping humans spot the “smoking gun” quickly.

For suggesting mitigations XAI doesn’t just sound the alarm; it helps build the shield. By explaining the nature of the attack, it can suggest the best way to stop it.If the AI explains: “This is a Brute Force attack targeting the HR database,” the suggested action is clear: “Temporarily lock the targeted accounts and require a password reset.”

The Importance of the “User-in-the-Loop”

The most critical part of XAI is that it keeps a human—the User-in-the-Loop—at the center of the decision. Cybersecurity is high-stakes; a mistake could shut down a hospital’s network or a city’s power grid. XAI increases trust, facilitates collaboration and provides accountability.

  • Trust and Validation: When an AI can explain itself, a human expert can quickly verify if the alert is a real threat or a “false positive” (a mistake).
  • Collaboration: Humans bring “common sense” and context that AI lacks. For example, the AI might flag a large data transfer as an attack, but a human knows it’s just the annual company backup. XAI allows the human to see the AI’s logic, agree or disagree, and teach the system to be better next time.
  • Accountability: If something goes wrong, XAI provides a clear “paper trail” showing why a certain decision was made, which is essential for legal and safety audits.

The main differences between standard AI and explainable AI (XAI) are the following. In terms of output standard AI could mention that “High Risk is detected” but explainable AI would say “High Risk: Unusual data flow to an unknown IP is detected.” The human role is highly elevated in XAI from blindly trust or ignore the human to review evidence and take informed action. In addition, the learning process becomes stronger because instead of AI algorithms learning alone the human can provide feedback to refine the AI algorithms.

XAI transforms AI from a mysterious oracle into a transparent partner, ensuring that while the computer does the “heavy lifting” of data analysis, the human stays in control of the final defense strategy.

Read More

CyberNEMO SAAM: Building a Pan-European Cyber Shield for Critical Infrastructure

CyberNEMO SAAM is a pan-European Knowledge Sharing, risk Assessment, threat Analysis and incidents Mitigation collaborative platform designed to protect Critical Infrastructures (CIs) across Europe. Operating as the federated CTI exchange backbone of the broader CyberNEMO platform, SAAM serves as a pan-European CTI hub that collects, analysis, enriches, and distributes cybersecurity intelligence among interconnected infrastructure operators, national and cross-border cybersecurity authorities and communities. By centralising cyber threat data from diverse CI sectors including energy, transport, healthcare, and finance and structuring it around the widely adopted STIX 2.1 standard, SAAM creates a common operational picture that no single organisation could achieve on its own.

Modern cyber threats do not respect sector or national boundaries. A sophisticated attack on an energy grid can swiftly ripple into transport management systems or hospital networks, creating cascading failures that isolated, manually-processed intelligence cannot prevent. SAAM addresses this gap by positioning itself as the central nervous system of European CI cybersecurity, automatically correlating cross-sector incident patterns, attributing threats to known actors, and generating timely advisories for eligible partners. Governed by the most appropriate authority within the CyberNEMO ecosystem, and fully aligned with NIS2 compliance obligations, SAAM represents a significant step forward in building the collective resilience that Europe’s critical infrastructure communities urgently need.

SAAM delivers four tightly integrated capabilities. Cross-CI Knowledge Sharing enables the seamless exchange of CTI data across sector boundaries and national borders through secure Trusted Circles at Sectoral, National, Cross-Border, and Pan-European level utilizing interoperable standards such as STIX v2.1, TAXII 2.1 and Traffic Light Protocol (TLP) for controlled dissemination. SAAM’s Systemic Risk Analysis Engine applies automated analysis over incoming cyberthreat reports to score, correlate, and contextualise vulnerabilities and attacks. In addiiton, SRAE analysis contributes to the identification of coordinated attacks taking into account potential cascading effects. This contributes to SAAM’s enhanced State Awareness which gives operators and authorities a real-time, holistic view of the threat landscape across interconnected CI domains. Finally, SAAM’s Incident Mitigation translates enriched intelligence into actionable guidance, enabling CSIRTs and CI owners to coordinate responses swiftly and effectively before threats cascade across sectors.

Read More

CyberNEMO Exploitation Strategy overview

Europe’s cybersecurity landscape is under mounting pressure. The EU cybersecurity market, already valued at approximately €30 billion in 2023, is growing at a compound annual rate of 9–11%, driven by an escalating threat environment, accelerating digital transformation, and tightening regulation under frameworks such as NIS2, the Cyber Resilience Act, and the AI Act. Ransomware attacks targeting critical infrastructure are rising by over 25% annually, while nation-state actors, supply-chain compromises, and the convergence of IT and Operational Technology (OT) networks continue to expand the attack surface. Across key verticals such as energy, healthcare, cloud, edge computing, IoT, and data management. CyberNEMO’s market analysis reveals a consistent pattern suggesting that demand is surging, solutions are fragmenting, and the gap between security investment and actual resilience is widening. Particularly underserved are small and medium enterprises, operators of critical infrastructure burdened by legacy systems, and the growing edge computing segment, where cybersecurity spending is already struggling to keep pace with infrastructure deployment.

CyberNEMO’s competitive advantage rests on five interconnected pillars. As an EU-funded initiative built on EU-sovereign infrastructure, it is fully aligned with the EU Cybersecurity Strategy, directly advancing Europe’s goal of strategic digital autonomy. This is reinforced by a unique public-private partnership model that grants privileged access to CERT and regulatory bodies alongside established relationships with critical infrastructure operators. The platform’s credibility is further substantiated by its validation across six diverse pilot sectors, providing concrete cross-domain applicability evidence that spans energy, healthcare, media, agrifood, logistics, and fintech. By anchoring its open-source core within the Eclipse Foundation, CyberNEMO fosters community-driven development that actively reduces vendor lock-in, encouraging broad adoption while preserving transparency and trust. Finally, the platform has been designed from the outset with regulatory foresight, embedding compliance with NIS2, the Critical Entities Resilience Directive (CER), the AI Act, and the Cyber Resilience Act directly into its architecture — positioning it as a ready-made solution for organisations navigating Europe’s increasingly demanding cybersecurity regulatory landscape.

CyberNEMO, delivers an end-to-end, zero-trust cybersecurity framework purpose-built for the Cloud-Edge-IoT-Data computing continuum. Following IEEE 42010 methodology, stakeholder concerns were systematically mapped to architectural viewpoints. Each viewpoint addresses specific concerns through defined architectural perspectives, conventions, and models covering viewpoints such as development, process, user, business and security ones. CyberNEMO has identified twelve Key Exploitable Results (KERs) that offer capabilities ranging from real-time AI-driven anomaly detection and explainable AI (XAI) to interoperable and standardized threat intelligence sharing, micro-services auditing and certification, and federated risk assessment across borders.

CyberNEMO’s multi-dimensional approach which combines financial self-sufficiency through subscription services, institutional permanence through Eclipse Foundation governance, regulatory foresight and community network effects through open-source engagement aims to position it to deliver lasting value to European Critical Infrastructure and citizens well beyond the project’s formal completion.

Read More

What is a Network Socket? The Building Block of CyberNEMO Connectivity

In the complex architecture of the CyberNEMO meta-Operating System, ensuring secure and reliable communication across the computing continuum is paramount. While high-level security frameworks like Zero Trust Network Access (ZTNA) provide the overarching strategy, the actual heavy lifting of data exchange happens at a much more fundamental level: the network socket.

A network socket is essentially an internal endpoint for sending or receiving data at a single node in a computer network. Think of it as a virtual “plug” that allows two different processes—whether they are on the same machine or across the world—to talk to each other. In a Kubernetes (K8s) environment, which serves as the foundation for CyberNEMO’s deployment, sockets are the critical bridges between containerized microservices. They enable the point-to-point communication necessary for workloads to function as a unified system.

Why Sockets Matter for Network Measurement

Within the WP2 (Work Package 2), the focus is on “Cybersecurity and Privacy by Design”. To achieve this, we cannot rely on surface-level metrics. We need to measure real communication at the socket level. This is where components like White Shark come into play.

Originally developed for the NEMO project, White Shark is a specialized network probe designed to collect and retrieve high-fidelity network data. By tapping into socket communication, White Shark can measure point-to-point metrics—such as latency and throughput—directly between two endpoints. This provides a level of precision that traditional network monitors often miss, as it captures the actual data flow as seen by the applications themselves, rather than just the underlying infrastructure.

From Raw Data to Intelligence: The Role of NADA

Capturing socket-level data is only half the battle; the next step is making sense of it. In CyberNEMO, this data is fed into the Network Anomaly Detection AI (NADA). NADA’s purpose is to identify temporal and contextual anomalies—suspicious patterns in the network traffic that could indicate a security breach.

Read More

Advancing Smart Healthcare and Cyber-Resilient Infrastructures

XGL (Xgility) is an innovative solutions provider and research-oriented IT company headquartered in Dublin, Ireland. Bringing together a highly skilled and diverse team of researchers, consultants, and IT specialists, XGL delivers a comprehensive range of services and solutions tailored to the needs of both industry and research partners. The company is distinguished by its agility, technical expertise, and forward-looking approach to technology adoption.

XGL’s core competencies span software development, IT outsourcing, AI-driven decision support systems, cybersecurity expertise, IT consulting, training, and advanced data and document management. Building on its innovation-driven approach, the company is also exploring emerging technologies such as virtual agents and large language models (LLMs) to enhance digital services, automation, and human–machine collaboration. By combining cutting-edge research with hands-on experience in the deployment and management of complex IT solutions, XGL supports organizations in their digital transformation journeys. With a strong emphasis on reliability, scalability, and adaptability, XGL has established itself as a trusted partner capable of addressing diverse technological and business challenges.

Beyond its service portfolio, XGL actively participates in research and innovation through EU-funded projects, where it contributes to the advancement of IT infrastructures, interoperability, and digital resilience. Its longstanding involvement in European research initiatives highlights the company’s ability to bridge the gap between academic innovation and industrial application, translating research outcomes into market-ready solutions through a strong commitment to research-to-market dissemination.

Within the CyberNEMO project, XGL plays a pivotal role by leading Task 5.1: Open Data Management Plan & Trials Set-up and Task 5.4: Smart Healthcare Critical Infrastructures Validation, where it provides guidelines for data management in CyberNEMO and supports the MUP pilot with technical expertise. In addition, XGL contributes to Task 3.2: Intrusion Prevention/Detection/Mitigation DSS (IPDM-DSS) and Task 3.4: Privacy Protection Enforcement (PPE). The company also leads the development of a semantically enhanced Countermeasures Repository, designed to identify and match countermeasures against emerging and existing critical infrastructure threats.

Through its expertise in cybersecurity, AI-driven solutions, and emerging virtual agent technologies, XGL reinforces the collaborative and interdisciplinary character of CyberNEMO. The company remains dedicated to driving innovation, enabling digital transformation, and delivering high-quality IT solutions that create long-term value for stakeholders across both research and industry.

Read More

Mapping Cyber Vulnerabilities to MITRE ATT&CK for Critical Infrastructure Threat Detection

How CyberNEMO is bridging the gap between risk visibility and intelligent response

In today’s hyperconnected world, Europe’s critical infrastructures (CIs) — energy, transport, healthcare, and manufacturing — form the backbone of our digital society. Yet these same systems are among the most vulnerable targets

From ransomware attacks that paralyse hospitals to supply chain breaches rippling through industrial control systems, one reality stands out: we cannot defend what we cannot understand

Why Vulnerability Mapping Matters

Traditional vulnerability scanning stops at detection — identifying weak points without explaining how they might be exploited. But true cyber resilience requires context

By mapping vulnerabilities to the MITRE ATT&CK framework — the global reference for adversarial tactics, techniques, and procedures (TTPs) — defenders can see how attackers think and operate. Each vulnerability becomes a narrative of potential attack paths, not just a static CVE entry. 

By correlating technical weaknesses (CVE/CVSS) with ATT&CK techniques, CI operators can: 

  • Prioritise what matters most — focusing on vulnerabilities exploited by active adversaries.
  • Enhance detection logic — linking vulnerabilities to ATT&CK techniques like privilege escalation, lateral movement, or data exfiltration.
  • Enable AI-driven threat prediction — modelling how small weaknesses could evolve into full-scale attack chains.

Embedding AI Closer to the Threat Surface

CyberNEMO’s approach brings AI intelligence directly to the edge, transforming how vulnerabilities are monitored and analysed in distributed systems. 

By embedding AI in IoT gateways and edge devices, threat detection becomes continuous, adaptive, and privacy-preserving. These local models evolve with each new observed attack, strengthening defences autonomously and enhancing cross-domain resilience

This shift — from centralised analysis to distributed intelligence — is key to protecting the complex, hybrid environments that define modern critical infrastructure. 

From Zero Trust to Full-Stack Protection

As CI systems increasingly span IoT–edge–cloud architectures, the attack surface expands. MITRE ATT&CK provides a shared taxonomy for identifying and analysing threats across layers — whether it’s an IoT device communicating with a suspicious domain (ATT&CK T1071) or an insider escalating privileges (T1068). 

When integrated with Zero Trust principles, ATT&CK mapping enables defenders to: 

  • Dynamically verify every entity and data flow.
  • Feed contextual intelligence into security enforcement engines.
  • Apply risk-based adaptive access control, tightening security automatically when certain attack techniques are detected.

Together, these approaches move organisations from reactive defence to proactive, intelligent protection

Collaboration and Knowledge Sharing

Mapping vulnerabilities to MITRE ATT&CK isn’t just a technical process — it’s a collaborative intelligence effort

CyberNEMO is shaping a distributed European sharing platform that empowers CI operators, CERTs, and CSIRTs to:

  • Exchange ATT&CK-aligned threat data in real time.
  • Maintain interoperability across domains and sectors.
  • Strengthen Europe’s collective cyber resilience.

By aligning on a common threat language, Europe’s CI defenders can respond faster and smarter — together. 

Building a Culture of Cyber Sustainability

Ultimately, mapping vulnerabilities to MITRE ATT&CK helps organisations do more than just patch; it helps them learn, adapt, and evolve

By connecting the technical (AI, Zero Trust, machine learning pipelines) with the human (awareness, collaboration, and shared intelligence), CyberNEMO fosters a culture of cybersecurity for sustainability — one that endures and grows stronger over time. 

The Path Forward

CyberNEMO’s work on vulnerability-to-ATT&CK mapping marks a crucial step toward AI-empowered, collaborative cyber defence across Europe’s critical infrastructure. 

It bridges the gap between visibility and action, turning fragmented vulnerability data into a living intelligence fabric that evolves with every threat. 

Because in this new era of cyber-physical convergence, context is the ultimate defence.

Read More

Cybersecurity for Smart Healthcare

Medical University of Plovdiv, Bulgaria was established in 1945. It includes the Faculties of Medicine, Dental medicine, Pharmacy, Public Health, a Department of Languages and Specialized training, a medical college and six University Hospitals. Facilities include laboratories, clinics and units for diagnostics and treatment, research activities and training of students. Every year both Bulgarian and foreign students are trained at the Medical University of Plovdiv. Medical University of Plovdiv is organizing and leading the postgraduate specialization in all medical specialties and is also providing education at above 10 Master and 30 PhD programs.


MUP does not has IT specialists that are involved into the information systems managing therefore MUP works in collaboration with XGILITY LIMITED (XGL) which is actively contributing its expertise to the CyberNEMO project. The team involved in CyberNEMO project is dealing with Smart Healthcare Critical Infrastructure – examines real-world vulnerabilities across hospitals, medical centres, and national healthcare data flows, where cloud, edge, and IoT devices all play a role in processing and storing sensitive health information. MUP is leading a trial focused on: Authentication and authorization protection, ensuring that unauthorized users cannot access or manipulate sensitive patient records, financial claims, or hospital logistics.
The main objective is to ensure healthcare system resilience, where hospitals, ministries, and practitioners share knowledge on threats, zero-day vulnerabilities, and mitigation practices to strengthen collective defense.

Read More

Maggioli: Evolving Through Digital Innovation

Company Profile and Evolution

Maggioli’s history spans over a century, originating as a publishing and printing company. This foundation in knowledge dissemination set the stage for a significant evolution towards digital, which began in 1988 with the establishment of the Maggioli Informatica Business Unit. This marked the company’s strategic entry into the Information and Communications Technology sector, focusing on the development of software, services, and projects for Digital Transformation.

Today, Maggioli is a major player in the ICT market. The Group employs over 3,000 people across more than 70 offices in Italy and abroad, with a technical-commercial presence in Spain, Greece, Belgium, and Colombia. This international scale supports a large and diverse client base of over 45,000 customers. A majority of these clients (72%) are in the public sector, giving the company extensive experience in serving governmental and administrative bodies.

Digital Transformation represents the core of Maggioli’s business, accounting for 86% of its activities. The Group’s consolidated turnover for 2024 is projected to exceed €400 million, reflecting a consistent growth strategy.

Focus on Research and Development

Research and Development is a central component of Maggioli’s strategy. The company has a team of over 100 people dedicated to R&D, located primarily in Italy and Greece. This team is currently engaged in over 30 active research projects across various innovative domains.

Among these dedicated research areas is Cyber and Physical Security, which aligns directly with the objectives of the CyberNEMO project. This focus on security complements the company’s broader expertise in areas such as Smart Cities, Industry 4.0, and Sustainable Energy, positioning Maggioli at the forefront of European innovation initiatives.

Maggioli’s Role in CyberNEMO

Within CyberNEMO, Maggioli holds a significant leadership role, guiding the overall strategy for the development of the project’s core security technologies.

The company’s responsibilities include leading the practical development of the project’s frontline cyber defenses, such as cloud-native intelligent firewalls and secure domain name systems. Additionally, Maggioli is responsible for the work on Explainable Artificial Intelligence (XAI). This research is critical for ensuring that the advanced AI tools developed in the project are transparent and trustworthy for security operators in real-world scenarios.

Maggioli’s established expertise and dedicated R&D capabilities provide a strong foundation for its contributions to the CyberNEMO project.

Read More

XGL in CyberNEMO

XGL (Xgility) is an innovative solutions provider and research-oriented IT company headquartered in Dublin, Ireland. Bringing together a highly skilled and diverse team of researchers, consultants, and IT specialists, XGL delivers a comprehensive range of services and solutions tailored to the needs of both industry and research partners. The company is distinguished by its agility, technical expertise, and forward-looking approach to technology adoption.

XGL’s core competencies span software development, IT outsourcing, AI-driven decision support systems, cybersecurity expertise, IT consulting, training, and advanced data and document management. Building on its innovation-driven approach, the company is also exploring emerging technologies such as virtual agents and large language models (LLMs) to enhance digital services, automation, and human–machine collaboration. By combining cutting-edge research with hands-on experience in the deployment and management of complex IT solutions, XGL supports organizations in their digital transformation journeys. With a strong emphasis on reliability, scalability, and adaptability, XGL has established itself as a trusted partner capable of addressing diverse technological and business challenges.

Beyond its service portfolio, XGL actively participates in research and innovation through EU-funded projects, where it contributes to the advancement of IT infrastructures, interoperability, and digital resilience. Its longstanding involvement in European research initiatives highlights the company’s ability to bridge the gap between academic innovation and industrial application, translating research outcomes into market-ready solutions through a strong commitment to research-to-market dissemination.

Within the CyberNEMO project, XGL plays a pivotal role by leading Task 5.1: Open Data Management Plan & Trials Set-up and Task 5.4: Smart Healthcare Critical Infrastructures Validation, where it provides guidelines for data management in CyberNEMO and supports the MUP pilot with technical expertise. In addition, XGL contributes to Task 3.2: Intrusion Prevention/Detection/Mitigation DSS (IPDM-DSS) and Task 3.4: Privacy Protection Enforcement (PPE). The company also leads the development of a semantically enhanced Countermeasures Repository, designed to identify and match countermeasures against emerging and existing critical infrastructure threats.

Through its expertise in cybersecurity, AI-driven solutions, and emerging virtual agent technologies, XGL reinforces the collaborative and interdisciplinary character of CyberNEMO. The company remains dedicated to driving innovation, enabling digital transformation, and delivering high-quality IT solutions that create long-term value for stakeholders across both research and industry.

www.xgility.eu

Read More