DNV Cybersecurity Research Day 2026: Continuous Risk Management and Certification of Critical Systems – a Challenge in Cybersecurity

Cybersecurity assurance cannot be achieved at isolated points in time. Technologies, vulnerabilities, and threats evolve constantly, and system owners need continuous insight into their security posture. Emerging regulations, including the EU Cyber Resilience Act, the AI Act, and NIS2, are further raising the bar for both providers and operators of digital systems.

DNV Cybersecurity Research Day 2026: Continuous Risk Management and Certification of Critical Systems – a Challenge in Cybersecurity is dedicated to cybersecurity assurance through continuous risk management and certification of critical systems. CyberNEMO project will present research results, covering methods and tools currently in development

The event is expected to bring together industry leaders, CISOs, researchers, and regulatory authorities to share the latest knowledge and discuss the road ahead. Framing the regulatory context and exploration of what organisations need to succeed with cybersecurity assurance in practice are also included in the agenda.

Read More

CyberNEMO Releases the Network Policy Manager (CNPM)

The alpha version of the CyberNEMO Network Policy Manager (CNPM), a policy enforcement component of the CyberNEMO cybersecurity platform, developed by Synelixis SA and publicly accessible on the Eclipse Research Labs repository, undergone under initial testing and validation in the Smart Agriculture / Supply Chain pilot.

CNPM is designed for the cloud–edge–IoT continuum as it operates natively within Kubernetes, the de facto orchestration standard for containerised applications. It is based on Cilium networking layer that enables fine-grained, identity-aware security controls across distributed clusters. Each cluster in a CyberNEMO deployment runs its own CNPM instance, ensuring that policy management remains local, responsive, and aligned with the specific security posture of that environment.

CNPM provides the operators a structured, template-driven workflow for defining and enforcing network security policies. Indicative policies that CNPM can create and enforce include:

  • Deny-all ingress rules that block all inbound traffic to a namespace by default, enforcing an explicit allowlist model.
  • Least-privilege access controls that permit only the minimum necessary communication between services.
  • Source-based filtering, restricting traffic to specific IP ranges or trusted origins.
  • Port-level controls, limiting exposure to only the protocols and ports a service legitimately requires.

Policies can be generated from reusable templates, validated before deployment, and pushed directly to the cluster, reducing the risk of misconfiguration and ensuring consistency across environments.

CNPM integrates with the CyberNEMO event bus, receiving mitigation instructions from upstream platform components such as the Cloud Access Security Broker (CASB) and the Intrusion Prevention Detection and Mitigation Decision Support System (IPDM-DSS), closing the loop between threat detection and network-level response.

The module is released under the Apache License 2.0.

Read More

CyberNEMO attends the CEI-Sphere and LSP O-CEI and COP-Pilot Webinar on Privacy-Enhancing Technologies

CyberNEMO partners (Synelixis and Maggioli) attended the webinar on Privacy-Enhancing Technologies for Information Security in Edge-Cloud Applications, organized by CEI-Sphere and Large Scale Pilots O-CEI and COP-Pilot.

The webinar explored the growing challenge of securely sharing and processing data across distributed environments, from industrial platforms to smart infrastructures, where large numbers of devices, man-in-the-middle threats, and purpose limitation requirements create complex security landscapes. Protecting sensitive data today goes well beyond personal data as business data sovereignty is equally at stake.

Presentations from Fraunhofer ISST and insights from the O-CEI and COP-PILOT Large-Scale Pilots highlighted how technologies such as Federated Machine Learning (FML), Trusted Execution Environments, Homomorphic Encryption, and Zero-Knowledge Proofs can be embedded directly into system design. The “black sheep problem” in FML, identifying and mitigating malicious or corrupted participants in federated learning, is a as a shared concern directly relevant to CyberNEMO’s work on ZT-FML.

CyberNEMO identified synergies in two areas a) the Zero-Trust Federated Machine Learning (ZT-FML) and b) the use of LLMs and MCP-based architectures for privacy-aware decision support functionality.

Read More

CyberNEMO Meets IDMEFv2: Employing, Supporting and Contributing to Incident the Detection Standard

CyberNEMO project, represented by the Coordinator Synelixis and partner Maggioli, met Gilles Lehmann, lead of the IDMEFv2 Task Force, on 30 April 2026, for a focused exchange on IDMEFv2 standardisation developments and its usage in the context of the project.

In the context of IDMEFv2 standardisation effort, draft v08 has been published in April 2026 and the IETF meeting scheduled for July 2026, where the standard is seeking to advance towards an Experimental RFC status.

CyberNEMO is as one of the projects employing IDMEFv2 (link). Specifically, IDMEFv2 is used in the communication backbone between heterogeneous security detectors and the Decision Support System. By adopting a standardised, JSON-based incident description format, the project enables diverse sensors to feed alerts into a unified pipeline. The usage of IDMEFv2 across the computing continuum allows for suggestions to the standard on behalf of the CyberNEMO consortium, an effort led by partner Maggioli who provides one of the main detector AI-based Firewall as a Service.

Both sides concluded that this partnership is going to level up the standard and bring some serious momentum to the project, while this contribution is foreseen to have a significant impact on the domain and will play a pivotal role in future developments.

Read More

EC Cybersecurity cluster 3rd meeting

The CyberNEMO project was present in the 3rd meeting of the European Cybersecurity Cluster along with INTACT, CASTOR, and MIRANDA following the meeting that took place on January 16th. This strategic gathering was scheduled to review the projects’ updates since their last meetup and align the shared goals of these leading EU-funded initiatives.

Among the various topics discussed, for CyberNEMO, the presentation of the CyberNEMO Decision Support component was an important milestone. In addition, the projects demonstrated significant interest in co-organizing a workshop in Paris this fall.

The exchange was further enriched by the introduction of three new projects to the cluster: Mediate, CoCyber and GuardAI, expanding the group’s collective expertise in securing the digital landscape.

Read More

CyberNEMO in ECSCI: Advancing Critical Infrastructure Security in Europe

CyberNEMO participates in the European Cluster for Securing Critical Infrastructures (ECSCI), a European collaborative initiative that brings together EU-funded projects and key stakeholders working on the protection and resilience of critical infrastructures.

The ECSCI cluster is creating synergies and fosters emerging disruptive solutions to security issues via cross-projects collaboration and innovation. The cluster has experienced growth, fostering a dynamic and evolving ecosystem for cybersecurity innovation in Europe.

Through its participation, CyberNEMO contributes to joint efforts on:

  • Knowledge exchange and best practices in cybersecurity for critical infrastructures
  • Alignment with European policies and regulatory frameworks (e.g. CRA, NIS2, AI Act and vertical cybersecurity standards)
  • Collaboration on interoperable and scalable security solutions
  • Joint dissemination, communication, and stakeholder engagement activities
Read More

CyberNEMO Holds its 6th General Assembly in Rome

The CyberNEMO consortium is meeting this week in Rome, Italy, for its 6th General Assembly, hosted by Engineering Ingegneria Informatica.

This plenary gathering represents an important moment in the project’s evolution, bringing together partners to review progress, align on next steps, and reinforce collaboration across the consortium in the view of the upcoming 1st half review.

Discussions during the meeting focus on key areas such as AI-driven cybersecurity, risk assessment and mitigation, system integration, and validation of technologies in complex IoT–Edge–Cloud environments. The sessions also address the project’s broader impact, including dissemination, standardisation, and engagement with stakeholders.

A central objective of this General Assembly is to advance the integration of CyberNEMO components into a cohesive framework, moving from individual developments toward interoperable and scalable solutions for securing critical infrastructures.

Beyond the technical work, the meeting provides a valuable opportunity to strengthen collaboration, ensuring alignment and continuity as the project progresses toward its next milestones.

Read More

CyberNEMO SAAM: Building a Pan-European Cyber Shield for Critical Infrastructure

CyberNEMO SAAM is a pan-European Knowledge Sharing, risk Assessment, threat Analysis and incidents Mitigation collaborative platform designed to protect Critical Infrastructures (CIs) across Europe. Operating as the federated CTI exchange backbone of the broader CyberNEMO platform, SAAM serves as a pan-European CTI hub that collects, analysis, enriches, and distributes cybersecurity intelligence among interconnected infrastructure operators, national and cross-border cybersecurity authorities and communities. By centralising cyber threat data from diverse CI sectors including energy, transport, healthcare, and finance and structuring it around the widely adopted STIX 2.1 standard, SAAM creates a common operational picture that no single organisation could achieve on its own.

Modern cyber threats do not respect sector or national boundaries. A sophisticated attack on an energy grid can swiftly ripple into transport management systems or hospital networks, creating cascading failures that isolated, manually-processed intelligence cannot prevent. SAAM addresses this gap by positioning itself as the central nervous system of European CI cybersecurity, automatically correlating cross-sector incident patterns, attributing threats to known actors, and generating timely advisories for eligible partners. Governed by the most appropriate authority within the CyberNEMO ecosystem, and fully aligned with NIS2 compliance obligations, SAAM represents a significant step forward in building the collective resilience that Europe’s critical infrastructure communities urgently need.

SAAM delivers four tightly integrated capabilities. Cross-CI Knowledge Sharing enables the seamless exchange of CTI data across sector boundaries and national borders through secure Trusted Circles at Sectoral, National, Cross-Border, and Pan-European level utilizing interoperable standards such as STIX v2.1, TAXII 2.1 and Traffic Light Protocol (TLP) for controlled dissemination. SAAM’s Systemic Risk Analysis Engine applies automated analysis over incoming cyberthreat reports to score, correlate, and contextualise vulnerabilities and attacks. In addiiton, SRAE analysis contributes to the identification of coordinated attacks taking into account potential cascading effects. This contributes to SAAM’s enhanced State Awareness which gives operators and authorities a real-time, holistic view of the threat landscape across interconnected CI domains. Finally, SAAM’s Incident Mitigation translates enriched intelligence into actionable guidance, enabling CSIRTs and CI owners to coordinate responses swiftly and effectively before threats cascade across sectors.

Read More

CyberNEMO Laison Activity with COcyber, CYBERACTIONING, ENSEMBLE, Resilmesh

CyberNEMO has initiated a series of liaison activities with four European cybersecurity projects COcyber, CYBERACTIONING, ENSEMBLE, and Resilmesh towards building a unified and resilient European cybersecurity landscape.

The 1st meeting took place on the 18th of March 2026, with the participation of Andreas Papadakis and Ilias Seitanidis on behalf of the CyberNEMO coordinator (Synelixis).

The activity focuses on four pillars of collaboration:

  • Joint Dissemination, broadening projects’ visibility across the European research community and beyond.
  • Synchronised Advocacy, coordinating the communication campaigns to lead the conversation on cybersecurity and defense challenges at the EU level.
  • Event Co-hosting, co-organising presentations at major industry forums and jointly hosting specialised events that showcase the projects’ collective expertise.
  • Knowledge Exchange into a cybersecurity ecosystem.

Together, the four projects bring complementary strengths: COcyber bridges civilian and defence cybersecurity communities, CyberACTIONING advances cutting-edge network security research. ENSEMBLE focuses on collaborative cybersecurity education and training and ResilMesh tackles resilience in complex networked environments.

Read More