CyberNEMO joins 1st ECSCI Cluster Webinar of 2026

On 20 July 2026, Synelixis Solutions took part in the 1st Webinar of the 2026 ECSCI (European Cluster for Securing Critical Infrastructures) Webinar Series, representing the CyberNEMO project.

The online event brought together three EU Horizon-funded projects — ResilMesh, SONIC, and MIRANDA, presenting cybersecurity solutions for critical infrastructures.

ResilMesh

ResilMesh presented an intent-based approach to threat hunting, built on high-level, purpose-defined intents and an agent architecture.It leverages OpenC2, with a CACAO-based extension, and NATS messaging, with risk scored through weighted risk factors.

SONIC

SONIC introduced a security marketplace that orchestrates protection functions across multiple providers, complemented by an explainable-AI (XAI) library to help analysts interpret configurations and priorities.

MIRANDA

MIRANDA shifts supply-chain security from the software supply chain toward the service chain, covering not only development but also the operation of running services with supplier registration, dynamic parsing, and generative-AI-based prediction of network traffic, including PI networks and LoRa.

Synelixis identified common grounds with CyberNEMO, including:

  • Taxonomy alignment (MITRE / CVE).
  • Spatio-temporal scalability of asset discovery.
  • Attack-graph construction.

Further details: 1st Webinar of the 2026 ECSCI Cluster Webinar Series .

Read More

CyberNEMO Presents at the AIOTI WG Standardisation Focus Group on EU-Funded Projects

On 3 July 2026, CyberNEMO joined the AIOTI WG Standardisation FG landscape maintenance on EU-funded projects meeting, contributing the project perspective on cybersecurity challenges and standardization for the IoT–Edge–Cloud–Data continuum.

The project was represented by Andreas Papadakis and Ilias Seitanidis from Synelixis Solutions (SYN). More specifically, CyberNEMO presented its partners’ contributions in the following working groups:

  • IDMEF v2 for event detection, extended for the computing continuum.
  • EE-ISAC and STIX-based automation of NIS2 incident reporting flows.
  • CEN/CLC JTC21/WG5 – Cybersecurity for AI Systems: “Artificial Intelligence — Cybersecurity specifications for AI Systems”.
  • CEN/CLC JTC13/WG9 – Horizontal Cybersecurity for Products with Digital Elements (CRA).
  • CNCF Cloud Native Computing Foundation – participation in the CNCF Open Source Working Group.

The Alliance for AI, IoT and Edge Continuum Innovation (AIOTI) is a leading European multi-stakeholder organization dedicated to the Internet of Things, edge computing, and other converging technologies. AIOTI brings together industry, SMEs, start-ups, academia, research centers, and public bodies from across the digital value chain, with the mission to drive policy, research, and innovation in IoT and edge computing.

The AIOTI Working Group on Standardization is a horizontal group focusing on IoT and edge computing high-level architectures, gap analysis, and semantic interoperability. The working group produces, among others, the IoT and Edge Computing EU-Funded Projects Landscape Report.

During the Focus Group session on 3 July 2026, CyberNEMO presented and discussed its results and standardization activities. The CyberNEMO coordinator discussed with George Karagiannis, Chairman of AIOTI WG Standardization, aspects related to securing the compute continuum and its expanding attack surface, the need for real-time threat detection at scale, explainable decision support, and the project’s contribution to standardization efforts.

CyberNEMO’s contribution has been accepted and will be included in the forthcoming AIOTI report.

Read More

CyberNemo Officially Joins the New CRSN European Cluster to Drive AI-Powered Cyber Resilience

We are thrilled to announce that CyberNemo has officially integrated into the newly established European cybersecurity alliance: CRSN (Cyber-Resilience Synergy Network).

As an initiative dedicated to digital security innovation, we join forces within this cluster under a shared mission statement: to strengthen Europe’s cyber resilience and protect critical infrastructures by delivering next-generation, AI-driven cybersecurity solutions. Through this alliance, CyberNemo will actively contribute to fostering a trusted digital ecosystem built upon collaborative threat intelligence, autonomous incident response, and comprehensive capacity building across essential sectors.

Our Technological and Strategic Core Within CRSN

By joining CRSN, CyberNemo aligns its research outputs with a unified vision and a strategic DNA anchored on six core pillars:

  1. Autonomous & Proactive Defense: We move away from manual, reactive security models to establish continuous monitoring, predictive threat detection, and automated, zero-touch incident response frameworks. This track leverages breakthrough technologies, including Artificial Intelligence, Machine Learning (AI/ML), Large Language Models (LLMs), and autonomous AI agents capable of independent reasoning and tool orchestration.
  2. Securing Critical Interconnected Ecosystems: We actively cooperate in safeguarding the unified compute continuum and supply chain backbones key to the European economy. This shields critical domains like 5G telecommunications, financial services, smart cities, complex logistics, and “farm-to-fork” food supply networks through Zero-Trust architectures, secure-by-design principles, and privacy-preserving data analytics.
  3. Collaborative Threat Intelligence (CTI): We help eradicate isolated data silos by deploying trusted, cross-border channels for exchanging actionable Cyber Threat Intelligence. By utilizing shared infrastructure with built-in SIEM and MISP architectures, data integrity is fully secured via tamper-proof Distributed Ledger Technologies (Blockchain) and Fully Homomorphic Encryption.
  4. Modernizing Security Operations (SOCs): We drive the transformation of conventional Security Operations Centres into Next-Gen collaborative hubs. Deep deployment of Security Orchestration, Automation, and Response (SOAR) technologies ensures automated incident handling and containment, combined with advanced data analytics to provide human analysts with sharp situational awareness.
  5. Alignment with European Regulation and Trust Models: We ensure built-in and automated compliance with strict European mandates, specifically the NIS2 Directive, GDPR, and the Cyber Resilience Act (CRA). To achieve this, the platform relies heavily on secure-by-design frameworks, Zero-Trust Networking, and Trusted Execution Environments (TEEs).
  6. Empowering the Human Element and Capacity Building: Recognizing that technology alone is insufficient, we support continuous hands-on training. Through specialized learning centers, technical workshops, and live “Cyber Arena” testing environments, the alliance actively bridges the cybersecurity skills gap across the European Union.

Through this integration, CyberNemo strengthens its international network and technological transfer framework, collaborating closely with our partners and leading R&D teams to champion European digital sovereignty.

Read More

CyberNEMO Reaches a Key Milestone with Its Mid-Term Review 

The CyberNEMO consortium has reached an important milestone in the project lifecycle with the successful preparation and execution of its Mid-Term Review with the European Commission. 

This review marks the completion of the first 18 months of the project and provides an opportunity to present the progress achieved across all work packages, highlighting both the technical developments and the collaborative efforts that have driven the project forward. 

During the review, the consortium presented the work carried out so far, including advances in Zero Trust architectures, AI-driven cybersecurity capabilities, security orchestration, pilot preparation, dissemination activities, and collaboration with the wider European cybersecurity ecosystem. The session also provided an opportunity to demonstrate how the project is progressing towards its objective of strengthening cybersecurity across the IoT–Edge–Cloud continuum. 

Managing a project of this scale, involving a large and multidisciplinary consortium, has also generated valuable lessons learned. Throughout the first half of the project, partners have worked together to coordinate complex technical developments, align different areas of expertise, and establish efficient collaboration mechanisms that enable the integration of multiple technologies into a coherent cybersecurity framework. 

The Mid-Term Review is not only an assessment of the work completed so far but also an opportunity to reflect on the challenges encountered and the knowledge gained during the implementation process. These experiences will help guide the next phase of the project and contribute to the successful delivery of its final objectives. 

Looking ahead, CyberNEMO now enters its second half with a strong focus on system integration, pilot validation, stakeholder engagement, and the demonstration of its technologies in real-world environments. The consortium remains committed to delivering innovative cybersecurity solutions that contribute to a more secure, resilient, and trustworthy European digital ecosystem.

Read More

Zero Trust, Edge AI, and Confidential Computing — The Technologies Redefining Edge Security

The security architecture being built for the edge is fundamentally different from what came before. Perimeter defence — the logic of a hard external wall and a trusted interior — does not work when the “perimeter” is a sensor on a wind turbine, a camera on a factory floor, or a controller on a substation. These devices sit in physically uncontrolled environments, often connected via public networks, and there are too many of them to manage individually. The industry is converging on a new model built around three core technology trends.

Zero Trust is the foundational shift. In a Zero Trust architecture, no interaction between an edge device and its gateway is assumed safe: every request must be authenticated and authorised, regardless of where it originates or what it claims to be. For edge environments with hundreds or thousands of endpoints, this is architecturally demanding — but it is increasingly the baseline expectation set by both regulators and enterprise customers. NIS2 and the CRA effectively mandate Zero Trust principles without using the term.

Edge AI is making Zero Trust operationally viable at scale. The ENISA Threat Landscape 2024 documents that edge devices such as routers and IoT hardware are prime targets precisely because of outdated firmware and limited local monitoring capabilities. Running AI-native threat detection models directly on the edge node — rather than routing raw telemetry to a central Security Operations Centre — addresses this structural weakness head-on: a smart meter or industrial gateway can apply lightweight anomaly detection locally, flagging suspicious behaviour in milliseconds without transmitting sensitive operational data to the cloud.

In many industrial and healthcare contexts, local inference is the only architecture that simultaneously meets latency, bandwidth, and data sovereignty requirements.

Confidential Computing addresses a different but equally critical problem: what happens when sensitive workloads must run on third-party infrastructure? Hardware-based Trusted Execution Environments (TEEs) — such as Intel SGX — process data inside an encrypted enclave, meaning the infrastructure provider physically cannot access the raw data being computed. This allows organisations to use shared or commercial edge infrastructure without surrendering data confidentiality — a capability that is increasingly essential as edge deployments scale beyond what any single organisation can own outright.

Two further developments are reshaping the threat landscape itself. Private 5G Networks combined with Multi-access Edge Computing (MEC) enable compute to be placed at mobile base stations, offering high security through physical isolation of industrial traffic from public networks. ModelOps Security (AI TRiSM) is emerging as a response to adversarial attacks that target not the network infrastructure, but the integrity of the AI model itself. Recent incident analysis of cloud-edge deployments documents cases where attackers manipulated communication links between edge and cloud nodes to modify sensor data — underscoring that in environments where AI drives automated decisions, securing the model pipeline is as critical as securing the network.

These technologies are not on the horizon. They are being deployed now, in real industrial environments, by the same organisations that CyberNEMO works with.

Read More

MoniKube: Security-Aware Infrastructure Discovery for Cloud-Native Environments

As organizations continue to adopt Kubernetes and cloud-native technologies, their infrastructures become increasingly complex and difficult to manage. Distributed clusters, virtual machines, containers, and interconnected services provide scalability and flexibility, but they also create significant challenges in maintaining visibility, understanding asset relationships, and identifying security risks.

MoniKube is a distributed security-aware monitoring and intelligence platform designed to address these challenges. By continuously monitoring Kubernetes and cloud-native environments, collecting telemetry data, and performing vulnerability assessments, it automatically discovers infrastructure components and builds a comprehensive representation of the operational environment. The platform correlates infrastructure, monitoring, and security information to provide organizations with a deeper understanding of their assets, dependencies, and overall security posture.

At the core of MoniKube is a security-aware knowledge graph that transforms distributed infrastructure data into a centralized and interactive model. By mapping assets and their relationships, the platform enables operators and security teams to explore infrastructure topology, understand dependencies between systems, identify exposed components, and gain valuable insights into potential risk and exposure pathways.

MoniKube discovers Kubernetes resources through the Kubernetes API and can optionally enrich the model with host-level Docker workloads. The platform integrates Trivy-based vulnerability and misconfiguration scanning, allowing assets to be continuously assessed for security weaknesses. Vulnerability information, exposure indicators, runtime metrics, and security scores are incorporated directly into the graph, enabling users to filter, compare, and prioritize risks from a single dashboard.

Beyond infrastructure discovery, MoniKube can ingest information from external security and monitoring solutions, including IDS, SIEM, and IDMEF-compatible sources. This allows the knowledge graph to remain synchronized with operational reality while providing a unified view across cloud-native and traditional systems.

MoniKube combines vulnerability information, runtime monitoring metrics, and exposure indicators into a unified security-scoring framework. It can integrate information from both cloud-native and traditional systems, creating a unified view of infrastructure regardless of underlying technology. Beyond infrastructure monitoring and security assessment, MoniKube introduces the ability to generate exportable infrastructure models that can serve as the foundation for digital twins, automating much of this process by capturing the security characteristics of operational environments and transforming them into reusable digital representations. The result is a comprehensive solution that helps organizations gain visibility into complex environments, strengthen their security posture, and transform operational infrastructure data into actionable security intelligence.

Read More

CyberNEMO Tools: First Validation Results in the Supply Chain / Smart Agriculture Pilot

CyberNEMO has started initial validation of its integrated tools within the pilots and specifically the Supply Chain / Smart Agriculture pilot, led by ENTERSOFTONE and technically supported by SYNELIXIS. The validation largely covers the end-to-end cybersecurity risk management process, i.e. from scope establishment to detection, decision support and countermeasure enforcement, across the computing continuum composed by:

-The dedicated pilot cluster hosted in a commercial cloud provider

-The NEMO and CyberNEMO clusters hosted by OneLab facility of Sorbonne University.

In terms of tools, Monikube extracts topology discovery, asset reading, and vulnerability identificationand assessment. AI-FWaaS detects cybersecurity incidents while the IPDM DSS correlates threat intelligence with asset risk profiles to generate response recommendations. The CyberNEMO Policy Manager (CNPM) enforces network policies as countermeasures across the infrastructure.

Services run across the pilot’s Kubernetes cluster and the shared OneLab infrastructure, which hosts both CyberNEMO and NEMO project clusters while the multi-site architecture allows for local and centralised deployment modes.

Read More

CyberNEMO contributes to AIOTI – Mutual Reinforcement

CyberNEMO has submitted its contribution to the AIOTI report on the IoT and Edge Computing EU-funded Projects Landscape (Release 5.0).

CyberNEMO brings to AIOTI a timely contribution at the frontier of the IoT and edge security agenda. Specifically, CyberNEMO contribution referred to a set of research challenges confronted by the project including:

  • Zero Trust and dynamic identity management across heterogeneous continuum environments.
  • AI-powered runtime threat detection and self-healing architectures at the edge.
  • Privacy-preserving federated learning for secure AI model lifecycle management.
  • Kubernetes and container security at scale in multi-cluster deployments.
  • Federated and decentralised security policy management.
  • Cross-domain Cyber Threat Intelligence sharing with IDMEFv2 and STIX.
  • Secure lifecycle and update management for distributed IoT/edge services.
  • Explainable, human-centric decision support for security operators.

Through AIOTI, the project is acquiring access to a high-impact dissemination channel reaching the European research, standardisation, and policy communities and positioning the project within the broader IoT and edge computing ecosystem.

Read More

Privacy Protection Enforcement (PPE)

The Privacy Protection Enforcement (PPE) component has been designed and developed by CyberSocial Lab  within the CyberNEMO project and publicly accessible on the Eclipse Research Labs repository,
Our tool acts as a privacy-aware authorization and enforcement mechanism supporting secure data sharing across the computing continuum. Operating in conjunction with the Computing Continuum Access Security Broker (CASB), the PPE is responsible for ensuring that access to personal and sensitive data is granted only when the applicable processing policies and user consents are satisfied.

The architecture of the PPE has been designed to support secure and trustworthy data exchanges across cloud, edge, and IoT environments, while promoting data sovereignty, privacy preservation, and regulatory compliance. By combining policy-based access control mechanisms with consent management capabilities, the component enables organizations to maintain control over how sensitive data is accessed and processed across distributed infrastructures.

PPE provides a structured framework for defining and enforcing privacy and data access requirements. Indicative controls and verification mechanisms supported by the component include:

  • Validation of consent records before access to protected data is granted.
  • Enforcement of data processing policies applicable to data consumers.
  • Verification of consent validity and policy applicability during access requests.
  • Auditing and traceability of authorization and access control decisions.
  • Verification of cryptographic proofs associated with policies and consents.

The PPE has been designed in alignment with the principles of the General Data Protection Regulation (GDPR), supporting key requirements such as lawful processing, explicit consent management, accountability, transparency. It contributes to ensuring that sensitive data is accessed only when valid consent and an applicable processing policy exist.

Furthermore, the use of cryptographic proofs and immutable audit trails strengthens accountability by providing verifiable evidence of consent and authorization decisions throughout the data lifecycle. The adoption of blockchain-based evidence storage, rather than storing personal data directly on-chain, supports privacy-preserving processing practices while facilitating regulatory compliance across distributed cloud, edge, and IoT environments.

PPE integrates with the broader CyberNEMO security ecosystem through the CASB. When a data consumer requests access to protected data, the component evaluates the corresponding policies and consents before authorizing the request. Authorization outcomes can be propagated to other platform components, enabling coordinated security, governance, and compliance operations across the CyberNEMO architecture.

The component is currently under development and will contribute to the implementation of secure, privacy-preserving data sharing services compliant with applicable regulatory requirements across the CyberNEMO computing continuum. In line with the CyberNEMO open-source strategy, the PPE is released under the Apache License 2.0. 

Read More

CyberNEMO at the EE-ISAC / JE-ISAC / E-ISAC Joint Webinar

On May 28, CyberNEMO partners (Synelixis, Maggioli and Netcompany) attended and participated in the joint webinar “North America, Japan and Europe: Ensuring Trust in Global Energy Infrastructure”, organised by the European Energy Information Sharing and Analysis Centre (EE-ISAC), the Japanese ISAC (JE-ISAC), and the North American E-ISAC.

Aspects related to trust, threat intelligence sharing, and operational coordination were discussed. The webinar covered the current state and future direction of Cyber Threat Intelligence (CTI) sharing among ISACs and their members. The necessity for anonymisation, the adoption of TLP classification levels, the automation based on APIs and the role of STIX for structured threat information have been presented and discussed. The increasing presence of AI-driven threat campaigns and AI tools for in-depth threat analysis were also pointed out, while a challenging point has been the one-way incident reporting practices and the still-evolving automation of information flows between operators, C-SIRTs, ENISA, and ISACs.

CyberNEMO project coordinator discussed with EE-ISAC representative Thomas Krauhausen (https://www.ee-isac.eu/who-we-are/) on the information flow from an energy operator, through C-SIRT, ENISA, and ISAC structures, to other EU operators and the role of STIX to enable automation that accelerates NIS2-mandated steps while enriching the semantic quality of shared data. The discussion confirmed that STIX-based automation remains a priority direction.

The presentations and discussions validated pillars of the SAAM platform currently under development within CyberNEMO. The challenges reported by ISAC practitioners, fragmented communication flows, limited automation are aligned with SAAM objectives.

Read More