CyberNEMO Laison Activity with COcyber, CYBERACTIONING, ENSEMBLE, Resilmesh

CyberNEMO has initiated a series of liaison activities with four European cybersecurity projects COcyber, CYBERACTIONING, ENSEMBLE, and Resilmesh towards building a unified and resilient European cybersecurity landscape.

The 1st meeting took place on the 18th of March 2026, with the participation of Andreas Papadakis and Ilias Seitanidis on behalf of the CyberNEMO coordinator (Synelixis).

The activity focuses on four pillars of collaboration:

  • Joint Dissemination, broadening projects’ visibility across the European research community and beyond.
  • Synchronised Advocacy, coordinating the communication campaigns to lead the conversation on cybersecurity and defense challenges at the EU level.
  • Event Co-hosting, co-organising presentations at major industry forums and jointly hosting specialised events that showcase the projects’ collective expertise.
  • Knowledge Exchange into a cybersecurity ecosystem.

Together, the four projects bring complementary strengths: COcyber bridges civilian and defence cybersecurity communities, CyberACTIONING advances cutting-edge network security research. ENSEMBLE focuses on collaborative cybersecurity education and training and ResilMesh tackles resilience in complex networked environments.

Read More

Advancing Smart Healthcare and Cyber-Resilient Infrastructures

XGL (Xgility) is an innovative solutions provider and research-oriented IT company headquartered in Dublin, Ireland. Bringing together a highly skilled and diverse team of researchers, consultants, and IT specialists, XGL delivers a comprehensive range of services and solutions tailored to the needs of both industry and research partners. The company is distinguished by its agility, technical expertise, and forward-looking approach to technology adoption.

XGL’s core competencies span software development, IT outsourcing, AI-driven decision support systems, cybersecurity expertise, IT consulting, training, and advanced data and document management. Building on its innovation-driven approach, the company is also exploring emerging technologies such as virtual agents and large language models (LLMs) to enhance digital services, automation, and human–machine collaboration. By combining cutting-edge research with hands-on experience in the deployment and management of complex IT solutions, XGL supports organizations in their digital transformation journeys. With a strong emphasis on reliability, scalability, and adaptability, XGL has established itself as a trusted partner capable of addressing diverse technological and business challenges.

Beyond its service portfolio, XGL actively participates in research and innovation through EU-funded projects, where it contributes to the advancement of IT infrastructures, interoperability, and digital resilience. Its longstanding involvement in European research initiatives highlights the company’s ability to bridge the gap between academic innovation and industrial application, translating research outcomes into market-ready solutions through a strong commitment to research-to-market dissemination.

Within the CyberNEMO project, XGL plays a pivotal role by leading Task 5.1: Open Data Management Plan & Trials Set-up and Task 5.4: Smart Healthcare Critical Infrastructures Validation, where it provides guidelines for data management in CyberNEMO and supports the MUP pilot with technical expertise. In addition, XGL contributes to Task 3.2: Intrusion Prevention/Detection/Mitigation DSS (IPDM-DSS) and Task 3.4: Privacy Protection Enforcement (PPE). The company also leads the development of a semantically enhanced Countermeasures Repository, designed to identify and match countermeasures against emerging and existing critical infrastructure threats.

Through its expertise in cybersecurity, AI-driven solutions, and emerging virtual agent technologies, XGL reinforces the collaborative and interdisciplinary character of CyberNEMO. The company remains dedicated to driving innovation, enabling digital transformation, and delivering high-quality IT solutions that create long-term value for stakeholders across both research and industry.

Read More

Mapping Cyber Vulnerabilities to MITRE ATT&CK for Critical Infrastructure Threat Detection

How CyberNEMO is bridging the gap between risk visibility and intelligent response

In today’s hyperconnected world, Europe’s critical infrastructures (CIs) — energy, transport, healthcare, and manufacturing — form the backbone of our digital society. Yet these same systems are among the most vulnerable targets

From ransomware attacks that paralyse hospitals to supply chain breaches rippling through industrial control systems, one reality stands out: we cannot defend what we cannot understand

Why Vulnerability Mapping Matters

Traditional vulnerability scanning stops at detection — identifying weak points without explaining how they might be exploited. But true cyber resilience requires context

By mapping vulnerabilities to the MITRE ATT&CK framework — the global reference for adversarial tactics, techniques, and procedures (TTPs) — defenders can see how attackers think and operate. Each vulnerability becomes a narrative of potential attack paths, not just a static CVE entry. 

By correlating technical weaknesses (CVE/CVSS) with ATT&CK techniques, CI operators can: 

  • Prioritise what matters most — focusing on vulnerabilities exploited by active adversaries.
  • Enhance detection logic — linking vulnerabilities to ATT&CK techniques like privilege escalation, lateral movement, or data exfiltration.
  • Enable AI-driven threat prediction — modelling how small weaknesses could evolve into full-scale attack chains.

Embedding AI Closer to the Threat Surface

CyberNEMO’s approach brings AI intelligence directly to the edge, transforming how vulnerabilities are monitored and analysed in distributed systems. 

By embedding AI in IoT gateways and edge devices, threat detection becomes continuous, adaptive, and privacy-preserving. These local models evolve with each new observed attack, strengthening defences autonomously and enhancing cross-domain resilience

This shift — from centralised analysis to distributed intelligence — is key to protecting the complex, hybrid environments that define modern critical infrastructure. 

From Zero Trust to Full-Stack Protection

As CI systems increasingly span IoT–edge–cloud architectures, the attack surface expands. MITRE ATT&CK provides a shared taxonomy for identifying and analysing threats across layers — whether it’s an IoT device communicating with a suspicious domain (ATT&CK T1071) or an insider escalating privileges (T1068). 

When integrated with Zero Trust principles, ATT&CK mapping enables defenders to: 

  • Dynamically verify every entity and data flow.
  • Feed contextual intelligence into security enforcement engines.
  • Apply risk-based adaptive access control, tightening security automatically when certain attack techniques are detected.

Together, these approaches move organisations from reactive defence to proactive, intelligent protection

Collaboration and Knowledge Sharing

Mapping vulnerabilities to MITRE ATT&CK isn’t just a technical process — it’s a collaborative intelligence effort

CyberNEMO is shaping a distributed European sharing platform that empowers CI operators, CERTs, and CSIRTs to:

  • Exchange ATT&CK-aligned threat data in real time.
  • Maintain interoperability across domains and sectors.
  • Strengthen Europe’s collective cyber resilience.

By aligning on a common threat language, Europe’s CI defenders can respond faster and smarter — together. 

Building a Culture of Cyber Sustainability

Ultimately, mapping vulnerabilities to MITRE ATT&CK helps organisations do more than just patch; it helps them learn, adapt, and evolve

By connecting the technical (AI, Zero Trust, machine learning pipelines) with the human (awareness, collaboration, and shared intelligence), CyberNEMO fosters a culture of cybersecurity for sustainability — one that endures and grows stronger over time. 

The Path Forward

CyberNEMO’s work on vulnerability-to-ATT&CK mapping marks a crucial step toward AI-empowered, collaborative cyber defence across Europe’s critical infrastructure. 

It bridges the gap between visibility and action, turning fragmented vulnerability data into a living intelligence fabric that evolves with every threat. 

Because in this new era of cyber-physical convergence, context is the ultimate defence.

Read More

2nd CyberNEMO, INTACT, CASTOR, and MIRANDA European Cybersecurity Cluster online meeting

The CyberNEMO project joined forces with INTACT, CASTOR, and MIRANDA discussing the possibility of collaboration between projects meeting of the European Cybersecurity Cluster, held on January 16th. This collaborative exchange was designed to identify synergies, explore joint opportunities, and align shared goals among the participating projects. The gathering united specialists and leaders from all four initiatives, each focused on strengthening European cybersecurity through pioneering research and practical application.

CyberNEMO presented the current progress and the objectives. CybeNEMO focuses on strengthening resilience and risk preparedness across critical infrastructure and supply chains. It provides a comprehensive, end-to-end security stack—ranging from Zero-Trust Network Access to AI-driven Situation Perception, Comprehension & Protection (SPCP)—while facilitating collaborative auditing and a pan-European platform for shared threat analysis (SAAM).

As the discussions progressed, participants identified several common points for collaboration. They expressed strong interest in pursuing future joint calls and events. In this context, a cross-project event collaborative calendar was established aiming to enhance the inter-project synergy visibility through conferences and workshops that will promote the innovative work carried out by the EU funded projects in the Cybersecurity domain.

The meeting concluded with the partners planning their next actions and scheduling their upcoming meetings.

Read More

Cybersecurity for Smart Healthcare

Medical University of Plovdiv, Bulgaria was established in 1945. It includes the Faculties of Medicine, Dental medicine, Pharmacy, Public Health, a Department of Languages and Specialized training, a medical college and six University Hospitals. Facilities include laboratories, clinics and units for diagnostics and treatment, research activities and training of students. Every year both Bulgarian and foreign students are trained at the Medical University of Plovdiv. Medical University of Plovdiv is organizing and leading the postgraduate specialization in all medical specialties and is also providing education at above 10 Master and 30 PhD programs.


MUP does not has IT specialists that are involved into the information systems managing therefore MUP works in collaboration with XGILITY LIMITED (XGL) which is actively contributing its expertise to the CyberNEMO project. The team involved in CyberNEMO project is dealing with Smart Healthcare Critical Infrastructure – examines real-world vulnerabilities across hospitals, medical centres, and national healthcare data flows, where cloud, edge, and IoT devices all play a role in processing and storing sensitive health information. MUP is leading a trial focused on: Authentication and authorization protection, ensuring that unauthorized users cannot access or manipulate sensitive patient records, financial claims, or hospital logistics.
The main objective is to ensure healthcare system resilience, where hospitals, ministries, and practitioners share knowledge on threats, zero-day vulnerabilities, and mitigation practices to strengthen collective defense.

Read More

CyberNEMO Presented at CONASENSE Workshop – WPMC 2025

On November 10, 2025, the CyberNEMO project was featured at the CONASENSE Workshop, held in Sofia (Bulgaria) as part of the 28th International Symposium on Wireless Personal Multimedia Communications (WPMC 2025).

Javier Serrano, from the Universidad Politécnica de Madrid (UPM) and Technical Programme Chair of the workshop, delivered an invited talk titled:
“Securing Distributed Media Workflows: CyberNEMO’s Zero Trust Approach for Edge-Cloud Multimedia Production and Delivery.”

The presentation introduced CyberNEMO’s vision to bring end-to-end security and trust to the Edge–Cloud–IoT computing continuum, by means of an open-source metasystem for resilience, threat detection, and risk mitigation. The talk focused on the UPM-led media trial, which validates CyberNEMO’s solutions in the context of real-time, distributed content production and delivery.

Two real-world scenarios were presented:

  1. Collaborative content production, where IoT-based media is captured and processed over edge and cloud.
  2. Secure content distribution, ensuring low-latency and protected delivery to end users.

CyberNEMO applies Zero Trust principles, AI-powered intrusion detection, and federated orchestration to safeguard these workflows while maintaining performance and scalability.

The session concluded with an open discussion on the applicability of CyberNEMO’s architecture to other domains such as health, mobility and critical infrastructure, and its relevance for future 6G security paradigms.

CyberNEMO thanks the CONASENSE community for the opportunity to contribute to this forward-looking dialogue.

Read More

Maggioli: Evolving Through Digital Innovation

Company Profile and Evolution

Maggioli’s history spans over a century, originating as a publishing and printing company. This foundation in knowledge dissemination set the stage for a significant evolution towards digital, which began in 1988 with the establishment of the Maggioli Informatica Business Unit. This marked the company’s strategic entry into the Information and Communications Technology sector, focusing on the development of software, services, and projects for Digital Transformation.

Today, Maggioli is a major player in the ICT market. The Group employs over 3,000 people across more than 70 offices in Italy and abroad, with a technical-commercial presence in Spain, Greece, Belgium, and Colombia. This international scale supports a large and diverse client base of over 45,000 customers. A majority of these clients (72%) are in the public sector, giving the company extensive experience in serving governmental and administrative bodies.

Digital Transformation represents the core of Maggioli’s business, accounting for 86% of its activities. The Group’s consolidated turnover for 2024 is projected to exceed €400 million, reflecting a consistent growth strategy.

Focus on Research and Development

Research and Development is a central component of Maggioli’s strategy. The company has a team of over 100 people dedicated to R&D, located primarily in Italy and Greece. This team is currently engaged in over 30 active research projects across various innovative domains.

Among these dedicated research areas is Cyber and Physical Security, which aligns directly with the objectives of the CyberNEMO project. This focus on security complements the company’s broader expertise in areas such as Smart Cities, Industry 4.0, and Sustainable Energy, positioning Maggioli at the forefront of European innovation initiatives.

Maggioli’s Role in CyberNEMO

Within CyberNEMO, Maggioli holds a significant leadership role, guiding the overall strategy for the development of the project’s core security technologies.

The company’s responsibilities include leading the practical development of the project’s frontline cyber defenses, such as cloud-native intelligent firewalls and secure domain name systems. Additionally, Maggioli is responsible for the work on Explainable Artificial Intelligence (XAI). This research is critical for ensuring that the advanced AI tools developed in the project are transparent and trustworthy for security operators in real-world scenarios.

Maggioli’s established expertise and dedicated R&D capabilities provide a strong foundation for its contributions to the CyberNEMO project.

Read More

XGL in CyberNEMO

XGL (Xgility) is an innovative solutions provider and research-oriented IT company headquartered in Dublin, Ireland. Bringing together a highly skilled and diverse team of researchers, consultants, and IT specialists, XGL delivers a comprehensive range of services and solutions tailored to the needs of both industry and research partners. The company is distinguished by its agility, technical expertise, and forward-looking approach to technology adoption.

XGL’s core competencies span software development, IT outsourcing, AI-driven decision support systems, cybersecurity expertise, IT consulting, training, and advanced data and document management. Building on its innovation-driven approach, the company is also exploring emerging technologies such as virtual agents and large language models (LLMs) to enhance digital services, automation, and human–machine collaboration. By combining cutting-edge research with hands-on experience in the deployment and management of complex IT solutions, XGL supports organizations in their digital transformation journeys. With a strong emphasis on reliability, scalability, and adaptability, XGL has established itself as a trusted partner capable of addressing diverse technological and business challenges.

Beyond its service portfolio, XGL actively participates in research and innovation through EU-funded projects, where it contributes to the advancement of IT infrastructures, interoperability, and digital resilience. Its longstanding involvement in European research initiatives highlights the company’s ability to bridge the gap between academic innovation and industrial application, translating research outcomes into market-ready solutions through a strong commitment to research-to-market dissemination.

Within the CyberNEMO project, XGL plays a pivotal role by leading Task 5.1: Open Data Management Plan & Trials Set-up and Task 5.4: Smart Healthcare Critical Infrastructures Validation, where it provides guidelines for data management in CyberNEMO and supports the MUP pilot with technical expertise. In addition, XGL contributes to Task 3.2: Intrusion Prevention/Detection/Mitigation DSS (IPDM-DSS) and Task 3.4: Privacy Protection Enforcement (PPE). The company also leads the development of a semantically enhanced Countermeasures Repository, designed to identify and match countermeasures against emerging and existing critical infrastructure threats.

Through its expertise in cybersecurity, AI-driven solutions, and emerging virtual agent technologies, XGL reinforces the collaborative and interdisciplinary character of CyberNEMO. The company remains dedicated to driving innovation, enabling digital transformation, and delivering high-quality IT solutions that create long-term value for stakeholders across both research and industry.

www.xgility.eu

Read More

Netcompany SEE & EUI in CyberNEMO

Netcompany SEE & EUI is a leading European IT Solutions and Services company with proven expertise in conceptual system architecture and system design, advanced application development and integration / communication services, information portal management, communication services, and project management, offering innovative and added-value solutions of the highest quality to a wide range of international and national public and private organizations.

Furthermore, Netcompany SEE & EUI based on its expertise is responsible for undertaking and coordinating the activities of CyberNEMO cybersecure federated ZT architecture definiton. At the same time, Netcompany SEE & EUI leads the activities of the Cybersecurity & Privacy by Collaboration Work Package having the responsibility to design and implement Strategies & Tools for cooperative remediation and mitigation such as the Knowledge Sharing, risk Assessment, threat Analysis and incidents Mitigation (SAAM) framework. Lastly, Netcompany SEE & EUI leads the Exploitation activities of CyberNemo aiming to ensure effective communication and outreach of project results, focusing on engaging stakeholders and identifying opportunities to exploit project outcomes.

Read More

CyberNEMO Strengthens Ties with European Cybersecurity Projects to Accelerate Joint Innovation

The CyberNEMO project joined forces with INTACT, CASTOR, and MIRANDA for the first meeting of the European Cybersecurity Cluster, held on October 6th. This collaborative exchange was designed to identify synergies, explore joint opportunities, and align shared goals among the participating projects. The meeting brought together experts and coordinators from all four initiatives, each dedicated to advancing Europe’s cybersecurity resilience through cutting-edge research, innovation, and real-world implementation.

CyberNEMO vision and objectives have been presented. Specifically, the project aims to enhance resilience, risk preparedness, awareness, detection, and mitigation in Critical Infrastructures and supply chains. The project delivers full-stack, end-to-end protection—from low-level Zero-Trust Network Access to human-AI explainable Situation Perception, Comprehension & Protection (SPCP) tools—alongside collaborative microservices for auditing, certification, and accreditation, and a pan-European platform for shared risk assessment, threat analysis, and incident mitigation (SAAM).

As the discussions progressed, participants identified several promising avenues for collaboration. They expressed strong interest in pursuing future joint calls and complementary research initiatives, while INTACT and CyberNEMO agreed to maintain their dialogue during their upcoming plenary meetings, which will take place concurrently at the same venue. Another key area of potential cooperation is standardization, where the exchange of expertise among projects could significantly accelerate the development of harmonized frameworks and enhance interoperability across the European cybersecurity landscape.

The meeting concluded with a shared understanding that collaboration is essential to advancing Europe’s cybersecurity landscape in an increasingly interconnected world.

Read More