CyberNEMO presented in ECSCI 2nd Webinar

CyberNEMO as part of the ECSCI cluster participated in the 2026 ECSCI cluster Webinar series aiming to empower the cross-project collaboration and promote the work carried out within the participating projects to a wider audience. In this context, Andreas Papadakis, representative of Synelixis the Project Coordinator of CyberNEMO, presented the project’s objectives and status within the framework of the second webinar of the ECSCI webinar series.

The key points that were stressed out throughout the presentation were:

  • The key enablers of CyberNEMO.
  • The challenges the project aims to address.
  • The CyberNEMO components & their functionalities towards providing a concrete and concealed protection across the various functionalities of a modern ICT-CC platform.
  • The importance of the existence of a well-built Risk assessment mechanism & a well established risk methodology.
  • The validation domains that CyberNEMO framework is validated as well as the cross-domain CTI exchange through the SAAM platform.
Read More

CyberNEMO Holds its 7th General Assembly in Fornebu, Norway

The CyberNEMO consortium is meeting this week in Fornebu, Norway, for its 7th General Assembly, hosted by DNV.

This plenary gathering represents an important moment in the project’s evolution, bringing together partners to review progress, align on next steps, and reinforce collaboration across the consortium in the 2nd half of the project.

Discussions during the meeting focus on key areas such as AI-driven cybersecurity, risk assessment and mitigation, system integration, and validation of technologies in complex IoT–Edge–Cloud environments. The sessions also address the project’s broader impact, including dissemination, standardisation, and engagement with stakeholders.

A central objective of this General Assembly is to advance the integration of CyberNEMO components into a cohesive framework, moving from individual developments toward interoperable and scalable solutions for securing critical infrastructures.

Beyond the technical work, the meeting provides a valuable opportunity to strengthen collaboration, ensuring alignment and continuity as the project progresses toward its next milestones.

Read More

CyberNEMO joins 1st ECSCI Cluster Webinar of 2026

On 20 July 2026, Synelixis Solutions took part in the 1st Webinar of the 2026 ECSCI (European Cluster for Securing Critical Infrastructures) Webinar Series, representing the CyberNEMO project.

The online event brought together three EU Horizon-funded projects — ResilMesh, SONIC, and MIRANDA, presenting cybersecurity solutions for critical infrastructures.

ResilMesh

ResilMesh presented an intent-based approach to threat hunting, built on high-level, purpose-defined intents and an agent architecture.It leverages OpenC2, with a CACAO-based extension, and NATS messaging, with risk scored through weighted risk factors.

SONIC

SONIC introduced a security marketplace that orchestrates protection functions across multiple providers, complemented by an explainable-AI (XAI) library to help analysts interpret configurations and priorities.

MIRANDA

MIRANDA shifts supply-chain security from the software supply chain toward the service chain, covering not only development but also the operation of running services with supplier registration, dynamic parsing, and generative-AI-based prediction of network traffic, including PI networks and LoRa.

Synelixis identified common grounds with CyberNEMO, including:

  • Taxonomy alignment (MITRE / CVE).
  • Spatio-temporal scalability of asset discovery.
  • Attack-graph construction.

Further details: 1st Webinar of the 2026 ECSCI Cluster Webinar Series .

Read More

CyberNEMO Presents at the AIOTI WG Standardisation Focus Group on EU-Funded Projects

On 3 July 2026, CyberNEMO joined the AIOTI WG Standardisation FG landscape maintenance on EU-funded projects meeting, contributing the project perspective on cybersecurity challenges and standardization for the IoT–Edge–Cloud–Data continuum.

The project was represented by Andreas Papadakis and Ilias Seitanidis from Synelixis Solutions (SYN). More specifically, CyberNEMO presented its partners’ contributions in the following working groups:

  • IDMEF v2 for event detection, extended for the computing continuum.
  • EE-ISAC and STIX-based automation of NIS2 incident reporting flows.
  • CEN/CLC JTC21/WG5 – Cybersecurity for AI Systems: “Artificial Intelligence — Cybersecurity specifications for AI Systems”.
  • CEN/CLC JTC13/WG9 – Horizontal Cybersecurity for Products with Digital Elements (CRA).
  • CNCF Cloud Native Computing Foundation – participation in the CNCF Open Source Working Group.

The Alliance for AI, IoT and Edge Continuum Innovation (AIOTI) is a leading European multi-stakeholder organization dedicated to the Internet of Things, edge computing, and other converging technologies. AIOTI brings together industry, SMEs, start-ups, academia, research centers, and public bodies from across the digital value chain, with the mission to drive policy, research, and innovation in IoT and edge computing.

The AIOTI Working Group on Standardization is a horizontal group focusing on IoT and edge computing high-level architectures, gap analysis, and semantic interoperability. The working group produces, among others, the IoT and Edge Computing EU-Funded Projects Landscape Report.

During the Focus Group session on 3 July 2026, CyberNEMO presented and discussed its results and standardization activities. The CyberNEMO coordinator discussed with George Karagiannis, Chairman of AIOTI WG Standardization, aspects related to securing the compute continuum and its expanding attack surface, the need for real-time threat detection at scale, explainable decision support, and the project’s contribution to standardization efforts.

CyberNEMO’s contribution has been accepted and will be included in the forthcoming AIOTI report.

Read More

CyberNemo Officially Joins the New CRSN European Cluster to Drive AI-Powered Cyber Resilience

We are thrilled to announce that CyberNemo has officially integrated into the newly established European cybersecurity alliance: CRSN (Cyber-Resilience Synergy Network).

As an initiative dedicated to digital security innovation, we join forces within this cluster under a shared mission statement: to strengthen Europe’s cyber resilience and protect critical infrastructures by delivering next-generation, AI-driven cybersecurity solutions. Through this alliance, CyberNemo will actively contribute to fostering a trusted digital ecosystem built upon collaborative threat intelligence, autonomous incident response, and comprehensive capacity building across essential sectors.

Our Technological and Strategic Core Within CRSN

By joining CRSN, CyberNemo aligns its research outputs with a unified vision and a strategic DNA anchored on six core pillars:

  1. Autonomous & Proactive Defense: We move away from manual, reactive security models to establish continuous monitoring, predictive threat detection, and automated, zero-touch incident response frameworks. This track leverages breakthrough technologies, including Artificial Intelligence, Machine Learning (AI/ML), Large Language Models (LLMs), and autonomous AI agents capable of independent reasoning and tool orchestration.
  2. Securing Critical Interconnected Ecosystems: We actively cooperate in safeguarding the unified compute continuum and supply chain backbones key to the European economy. This shields critical domains like 5G telecommunications, financial services, smart cities, complex logistics, and “farm-to-fork” food supply networks through Zero-Trust architectures, secure-by-design principles, and privacy-preserving data analytics.
  3. Collaborative Threat Intelligence (CTI): We help eradicate isolated data silos by deploying trusted, cross-border channels for exchanging actionable Cyber Threat Intelligence. By utilizing shared infrastructure with built-in SIEM and MISP architectures, data integrity is fully secured via tamper-proof Distributed Ledger Technologies (Blockchain) and Fully Homomorphic Encryption.
  4. Modernizing Security Operations (SOCs): We drive the transformation of conventional Security Operations Centres into Next-Gen collaborative hubs. Deep deployment of Security Orchestration, Automation, and Response (SOAR) technologies ensures automated incident handling and containment, combined with advanced data analytics to provide human analysts with sharp situational awareness.
  5. Alignment with European Regulation and Trust Models: We ensure built-in and automated compliance with strict European mandates, specifically the NIS2 Directive, GDPR, and the Cyber Resilience Act (CRA). To achieve this, the platform relies heavily on secure-by-design frameworks, Zero-Trust Networking, and Trusted Execution Environments (TEEs).
  6. Empowering the Human Element and Capacity Building: Recognizing that technology alone is insufficient, we support continuous hands-on training. Through specialized learning centers, technical workshops, and live “Cyber Arena” testing environments, the alliance actively bridges the cybersecurity skills gap across the European Union.

Through this integration, CyberNemo strengthens its international network and technological transfer framework, collaborating closely with our partners and leading R&D teams to champion European digital sovereignty.

Read More

CyberNEMO Reaches a Key Milestone with Its Mid-Term Review 

The CyberNEMO consortium has reached an important milestone in the project lifecycle with the successful preparation and execution of its Mid-Term Review with the European Commission. 

This review marks the completion of the first 18 months of the project and provides an opportunity to present the progress achieved across all work packages, highlighting both the technical developments and the collaborative efforts that have driven the project forward. 

During the review, the consortium presented the work carried out so far, including advances in Zero Trust architectures, AI-driven cybersecurity capabilities, security orchestration, pilot preparation, dissemination activities, and collaboration with the wider European cybersecurity ecosystem. The session also provided an opportunity to demonstrate how the project is progressing towards its objective of strengthening cybersecurity across the IoT–Edge–Cloud continuum. 

Managing a project of this scale, involving a large and multidisciplinary consortium, has also generated valuable lessons learned. Throughout the first half of the project, partners have worked together to coordinate complex technical developments, align different areas of expertise, and establish efficient collaboration mechanisms that enable the integration of multiple technologies into a coherent cybersecurity framework. 

The Mid-Term Review is not only an assessment of the work completed so far but also an opportunity to reflect on the challenges encountered and the knowledge gained during the implementation process. These experiences will help guide the next phase of the project and contribute to the successful delivery of its final objectives. 

Looking ahead, CyberNEMO now enters its second half with a strong focus on system integration, pilot validation, stakeholder engagement, and the demonstration of its technologies in real-world environments. The consortium remains committed to delivering innovative cybersecurity solutions that contribute to a more secure, resilient, and trustworthy European digital ecosystem.

Read More

Zero Trust, Edge AI, and Confidential Computing — The Technologies Redefining Edge Security

The security architecture being built for the edge is fundamentally different from what came before. Perimeter defence — the logic of a hard external wall and a trusted interior — does not work when the “perimeter” is a sensor on a wind turbine, a camera on a factory floor, or a controller on a substation. These devices sit in physically uncontrolled environments, often connected via public networks, and there are too many of them to manage individually. The industry is converging on a new model built around three core technology trends.

Zero Trust is the foundational shift. In a Zero Trust architecture, no interaction between an edge device and its gateway is assumed safe: every request must be authenticated and authorised, regardless of where it originates or what it claims to be. For edge environments with hundreds or thousands of endpoints, this is architecturally demanding — but it is increasingly the baseline expectation set by both regulators and enterprise customers. NIS2 and the CRA effectively mandate Zero Trust principles without using the term.

Edge AI is making Zero Trust operationally viable at scale. The ENISA Threat Landscape 2024 documents that edge devices such as routers and IoT hardware are prime targets precisely because of outdated firmware and limited local monitoring capabilities. Running AI-native threat detection models directly on the edge node — rather than routing raw telemetry to a central Security Operations Centre — addresses this structural weakness head-on: a smart meter or industrial gateway can apply lightweight anomaly detection locally, flagging suspicious behaviour in milliseconds without transmitting sensitive operational data to the cloud.

In many industrial and healthcare contexts, local inference is the only architecture that simultaneously meets latency, bandwidth, and data sovereignty requirements.

Confidential Computing addresses a different but equally critical problem: what happens when sensitive workloads must run on third-party infrastructure? Hardware-based Trusted Execution Environments (TEEs) — such as Intel SGX — process data inside an encrypted enclave, meaning the infrastructure provider physically cannot access the raw data being computed. This allows organisations to use shared or commercial edge infrastructure without surrendering data confidentiality — a capability that is increasingly essential as edge deployments scale beyond what any single organisation can own outright.

Two further developments are reshaping the threat landscape itself. Private 5G Networks combined with Multi-access Edge Computing (MEC) enable compute to be placed at mobile base stations, offering high security through physical isolation of industrial traffic from public networks. ModelOps Security (AI TRiSM) is emerging as a response to adversarial attacks that target not the network infrastructure, but the integrity of the AI model itself. Recent incident analysis of cloud-edge deployments documents cases where attackers manipulated communication links between edge and cloud nodes to modify sensor data — underscoring that in environments where AI drives automated decisions, securing the model pipeline is as critical as securing the network.

These technologies are not on the horizon. They are being deployed now, in real industrial environments, by the same organisations that CyberNEMO works with.

Read More

MoniKube: Security-Aware Infrastructure Discovery for Cloud-Native Environments

As organizations continue to adopt Kubernetes and cloud-native technologies, their infrastructures become increasingly complex and difficult to manage. Distributed clusters, virtual machines, containers, and interconnected services provide scalability and flexibility, but they also create significant challenges in maintaining visibility, understanding asset relationships, and identifying security risks.

MoniKube is a distributed security-aware monitoring and intelligence platform designed to address these challenges. By continuously monitoring Kubernetes and cloud-native environments, collecting telemetry data, and performing vulnerability assessments, it automatically discovers infrastructure components and builds a comprehensive representation of the operational environment. The platform correlates infrastructure, monitoring, and security information to provide organizations with a deeper understanding of their assets, dependencies, and overall security posture.

At the core of MoniKube is a security-aware knowledge graph that transforms distributed infrastructure data into a centralized and interactive model. By mapping assets and their relationships, the platform enables operators and security teams to explore infrastructure topology, understand dependencies between systems, identify exposed components, and gain valuable insights into potential risk and exposure pathways.

MoniKube discovers Kubernetes resources through the Kubernetes API and can optionally enrich the model with host-level Docker workloads. The platform integrates Trivy-based vulnerability and misconfiguration scanning, allowing assets to be continuously assessed for security weaknesses. Vulnerability information, exposure indicators, runtime metrics, and security scores are incorporated directly into the graph, enabling users to filter, compare, and prioritize risks from a single dashboard.

Beyond infrastructure discovery, MoniKube can ingest information from external security and monitoring solutions, including IDS, SIEM, and IDMEF-compatible sources. This allows the knowledge graph to remain synchronized with operational reality while providing a unified view across cloud-native and traditional systems.

MoniKube combines vulnerability information, runtime monitoring metrics, and exposure indicators into a unified security-scoring framework. It can integrate information from both cloud-native and traditional systems, creating a unified view of infrastructure regardless of underlying technology. Beyond infrastructure monitoring and security assessment, MoniKube introduces the ability to generate exportable infrastructure models that can serve as the foundation for digital twins, automating much of this process by capturing the security characteristics of operational environments and transforming them into reusable digital representations. The result is a comprehensive solution that helps organizations gain visibility into complex environments, strengthen their security posture, and transform operational infrastructure data into actionable security intelligence.

Read More

CyberNEMO Tools: First Validation Results in the Supply Chain / Smart Agriculture Pilot

CyberNEMO has started initial validation of its integrated tools within the pilots and specifically the Supply Chain / Smart Agriculture pilot, led by ENTERSOFTONE and technically supported by SYNELIXIS. The validation largely covers the end-to-end cybersecurity risk management process, i.e. from scope establishment to detection, decision support and countermeasure enforcement, across the computing continuum composed by:

-The dedicated pilot cluster hosted in a commercial cloud provider

-The NEMO and CyberNEMO clusters hosted by OneLab facility of Sorbonne University.

In terms of tools, Monikube extracts topology discovery, asset reading, and vulnerability identificationand assessment. AI-FWaaS detects cybersecurity incidents while the IPDM DSS correlates threat intelligence with asset risk profiles to generate response recommendations. The CyberNEMO Policy Manager (CNPM) enforces network policies as countermeasures across the infrastructure.

Services run across the pilot’s Kubernetes cluster and the shared OneLab infrastructure, which hosts both CyberNEMO and NEMO project clusters while the multi-site architecture allows for local and centralised deployment modes.

Read More

CyberNEMO contributes to AIOTI – Mutual Reinforcement

CyberNEMO has submitted its contribution to the AIOTI report on the IoT and Edge Computing EU-funded Projects Landscape (Release 5.0).

CyberNEMO brings to AIOTI a timely contribution at the frontier of the IoT and edge security agenda. Specifically, CyberNEMO contribution referred to a set of research challenges confronted by the project including:

  • Zero Trust and dynamic identity management across heterogeneous continuum environments.
  • AI-powered runtime threat detection and self-healing architectures at the edge.
  • Privacy-preserving federated learning for secure AI model lifecycle management.
  • Kubernetes and container security at scale in multi-cluster deployments.
  • Federated and decentralised security policy management.
  • Cross-domain Cyber Threat Intelligence sharing with IDMEFv2 and STIX.
  • Secure lifecycle and update management for distributed IoT/edge services.
  • Explainable, human-centric decision support for security operators.

Through AIOTI, the project is acquiring access to a high-impact dissemination channel reaching the European research, standardisation, and policy communities and positioning the project within the broader IoT and edge computing ecosystem.

Read More