CyberNEMO SAAM: Building a Pan-European Cyber Shield for Critical Infrastructure

CyberNEMO SAAM is a pan-European Knowledge Sharing, risk Assessment, threat Analysis and incidents Mitigation collaborative platform designed to protect Critical Infrastructures (CIs) across Europe. Operating as the federated CTI exchange backbone of the broader CyberNEMO platform, SAAM serves as a pan-European CTI hub that collects, analysis, enriches, and distributes cybersecurity intelligence among interconnected infrastructure operators, national and cross-border cybersecurity authorities and communities. By centralising cyber threat data from diverse CI sectors including energy, transport, healthcare, and finance and structuring it around the widely adopted STIX 2.1 standard, SAAM creates a common operational picture that no single organisation could achieve on its own.

Modern cyber threats do not respect sector or national boundaries. A sophisticated attack on an energy grid can swiftly ripple into transport management systems or hospital networks, creating cascading failures that isolated, manually-processed intelligence cannot prevent. SAAM addresses this gap by positioning itself as the central nervous system of European CI cybersecurity, automatically correlating cross-sector incident patterns, attributing threats to known actors, and generating timely advisories for eligible partners. Governed by the most appropriate authority within the CyberNEMO ecosystem, and fully aligned with NIS2 compliance obligations, SAAM represents a significant step forward in building the collective resilience that Europe’s critical infrastructure communities urgently need.

SAAM delivers four tightly integrated capabilities. Cross-CI Knowledge Sharing enables the seamless exchange of CTI data across sector boundaries and national borders through secure Trusted Circles at Sectoral, National, Cross-Border, and Pan-European level utilizing interoperable standards such as STIX v2.1, TAXII 2.1 and Traffic Light Protocol (TLP) for controlled dissemination. SAAM’s Systemic Risk Analysis Engine applies automated analysis over incoming cyberthreat reports to score, correlate, and contextualise vulnerabilities and attacks. In addiiton, SRAE analysis contributes to the identification of coordinated attacks taking into account potential cascading effects. This contributes to SAAM’s enhanced State Awareness which gives operators and authorities a real-time, holistic view of the threat landscape across interconnected CI domains. Finally, SAAM’s Incident Mitigation translates enriched intelligence into actionable guidance, enabling CSIRTs and CI owners to coordinate responses swiftly and effectively before threats cascade across sectors.

Read More

CyberNEMO Laison Activity with COcyber, CYBERACTIONING, ENSEMBLE, Resilmesh

CyberNEMO has initiated a series of liaison activities with four European cybersecurity projects COcyber, CYBERACTIONING, ENSEMBLE, and Resilmesh towards building a unified and resilient European cybersecurity landscape.

The 1st meeting took place on the 18th of March 2026, with the participation of Andreas Papadakis and Ilias Seitanidis on behalf of the CyberNEMO coordinator (Synelixis).

The activity focuses on four pillars of collaboration:

  • Joint Dissemination, broadening projects’ visibility across the European research community and beyond.
  • Synchronised Advocacy, coordinating the communication campaigns to lead the conversation on cybersecurity and defense challenges at the EU level.
  • Event Co-hosting, co-organising presentations at major industry forums and jointly hosting specialised events that showcase the projects’ collective expertise.
  • Knowledge Exchange into a cybersecurity ecosystem.

Together, the four projects bring complementary strengths: COcyber bridges civilian and defence cybersecurity communities, CyberACTIONING advances cutting-edge network security research. ENSEMBLE focuses on collaborative cybersecurity education and training and ResilMesh tackles resilience in complex networked environments.

Read More

CyberNEMO Exploitation Strategy overview

Europe’s cybersecurity landscape is under mounting pressure. The EU cybersecurity market, already valued at approximately €30 billion in 2023, is growing at a compound annual rate of 9–11%, driven by an escalating threat environment, accelerating digital transformation, and tightening regulation under frameworks such as NIS2, the Cyber Resilience Act, and the AI Act. Ransomware attacks targeting critical infrastructure are rising by over 25% annually, while nation-state actors, supply-chain compromises, and the convergence of IT and Operational Technology (OT) networks continue to expand the attack surface. Across key verticals such as energy, healthcare, cloud, edge computing, IoT, and data management. CyberNEMO’s market analysis reveals a consistent pattern suggesting that demand is surging, solutions are fragmenting, and the gap between security investment and actual resilience is widening. Particularly underserved are small and medium enterprises, operators of critical infrastructure burdened by legacy systems, and the growing edge computing segment, where cybersecurity spending is already struggling to keep pace with infrastructure deployment.

CyberNEMO’s competitive advantage rests on five interconnected pillars. As an EU-funded initiative built on EU-sovereign infrastructure, it is fully aligned with the EU Cybersecurity Strategy, directly advancing Europe’s goal of strategic digital autonomy. This is reinforced by a unique public-private partnership model that grants privileged access to CERT and regulatory bodies alongside established relationships with critical infrastructure operators. The platform’s credibility is further substantiated by its validation across six diverse pilot sectors, providing concrete cross-domain applicability evidence that spans energy, healthcare, media, agrifood, logistics, and fintech. By anchoring its open-source core within the Eclipse Foundation, CyberNEMO fosters community-driven development that actively reduces vendor lock-in, encouraging broad adoption while preserving transparency and trust. Finally, the platform has been designed from the outset with regulatory foresight, embedding compliance with NIS2, the Critical Entities Resilience Directive (CER), the AI Act, and the Cyber Resilience Act directly into its architecture — positioning it as a ready-made solution for organisations navigating Europe’s increasingly demanding cybersecurity regulatory landscape.

CyberNEMO, delivers an end-to-end, zero-trust cybersecurity framework purpose-built for the Cloud-Edge-IoT-Data computing continuum. Following IEEE 42010 methodology, stakeholder concerns were systematically mapped to architectural viewpoints. Each viewpoint addresses specific concerns through defined architectural perspectives, conventions, and models covering viewpoints such as development, process, user, business and security ones. CyberNEMO has identified twelve Key Exploitable Results (KERs) that offer capabilities ranging from real-time AI-driven anomaly detection and explainable AI (XAI) to interoperable and standardized threat intelligence sharing, micro-services auditing and certification, and federated risk assessment across borders.

CyberNEMO’s multi-dimensional approach which combines financial self-sufficiency through subscription services, institutional permanence through Eclipse Foundation governance, regulatory foresight and community network effects through open-source engagement aims to position it to deliver lasting value to European Critical Infrastructure and citizens well beyond the project’s formal completion.

Read More

2nd CyberNEMO, INTACT, CASTOR, and MIRANDA European Cybersecurity Cluster online meeting

The CyberNEMO project joined forces with INTACT, CASTOR, and MIRANDA discussing the possibility of collaboration between projects meeting of the European Cybersecurity Cluster, held on January 16th. This collaborative exchange was designed to identify synergies, explore joint opportunities, and align shared goals among the participating projects. The gathering united specialists and leaders from all four initiatives, each focused on strengthening European cybersecurity through pioneering research and practical application.

CyberNEMO presented the current progress and the objectives. CybeNEMO focuses on strengthening resilience and risk preparedness across critical infrastructure and supply chains. It provides a comprehensive, end-to-end security stack—ranging from Zero-Trust Network Access to AI-driven Situation Perception, Comprehension & Protection (SPCP)—while facilitating collaborative auditing and a pan-European platform for shared threat analysis (SAAM).

As the discussions progressed, participants identified several common points for collaboration. They expressed strong interest in pursuing future joint calls and events. In this context, a cross-project event collaborative calendar was established aiming to enhance the inter-project synergy visibility through conferences and workshops that will promote the innovative work carried out by the EU funded projects in the Cybersecurity domain.

The meeting concluded with the partners planning their next actions and scheduling their upcoming meetings.

Read More

CyberNEMO Presented at CONASENSE Workshop – WPMC 2025

On November 10, 2025, the CyberNEMO project was featured at the CONASENSE Workshop, held in Sofia (Bulgaria) as part of the 28th International Symposium on Wireless Personal Multimedia Communications (WPMC 2025).

Javier Serrano, from the Universidad Politécnica de Madrid (UPM) and Technical Programme Chair of the workshop, delivered an invited talk titled:
“Securing Distributed Media Workflows: CyberNEMO’s Zero Trust Approach for Edge-Cloud Multimedia Production and Delivery.”

The presentation introduced CyberNEMO’s vision to bring end-to-end security and trust to the Edge–Cloud–IoT computing continuum, by means of an open-source metasystem for resilience, threat detection, and risk mitigation. The talk focused on the UPM-led media trial, which validates CyberNEMO’s solutions in the context of real-time, distributed content production and delivery.

Two real-world scenarios were presented:

  1. Collaborative content production, where IoT-based media is captured and processed over edge and cloud.
  2. Secure content distribution, ensuring low-latency and protected delivery to end users.

CyberNEMO applies Zero Trust principles, AI-powered intrusion detection, and federated orchestration to safeguard these workflows while maintaining performance and scalability.

The session concluded with an open discussion on the applicability of CyberNEMO’s architecture to other domains such as health, mobility and critical infrastructure, and its relevance for future 6G security paradigms.

CyberNEMO thanks the CONASENSE community for the opportunity to contribute to this forward-looking dialogue.

Read More

CyberNEMO Strengthens Ties with European Cybersecurity Projects to Accelerate Joint Innovation

The CyberNEMO project joined forces with INTACT, CASTOR, and MIRANDA for the first meeting of the European Cybersecurity Cluster, held on October 6th. This collaborative exchange was designed to identify synergies, explore joint opportunities, and align shared goals among the participating projects. The meeting brought together experts and coordinators from all four initiatives, each dedicated to advancing Europe’s cybersecurity resilience through cutting-edge research, innovation, and real-world implementation.

CyberNEMO vision and objectives have been presented. Specifically, the project aims to enhance resilience, risk preparedness, awareness, detection, and mitigation in Critical Infrastructures and supply chains. The project delivers full-stack, end-to-end protection—from low-level Zero-Trust Network Access to human-AI explainable Situation Perception, Comprehension & Protection (SPCP) tools—alongside collaborative microservices for auditing, certification, and accreditation, and a pan-European platform for shared risk assessment, threat analysis, and incident mitigation (SAAM).

As the discussions progressed, participants identified several promising avenues for collaboration. They expressed strong interest in pursuing future joint calls and complementary research initiatives, while INTACT and CyberNEMO agreed to maintain their dialogue during their upcoming plenary meetings, which will take place concurrently at the same venue. Another key area of potential cooperation is standardization, where the exchange of expertise among projects could significantly accelerate the development of harmonized frameworks and enhance interoperability across the European cybersecurity landscape.

The meeting concluded with a shared understanding that collaboration is essential to advancing Europe’s cybersecurity landscape in an increasingly interconnected world.

Read More

CyberNEMO Featured in AIOTI Report on the EU-Funded IoT and Edge Computing Projects Landscape

AIOTI published the release 4 of the report on IoT and Edge Computing EU Funded Projects Landscape. The main objective of this report  is to provide the landscape of EU funded projects focusing on IoT and edge computing, which can be used to: 1) leverage on existing IoT and edge computing research and innovation activities in Europe, and 2) provide input to IoT and edge computing standardisation gap analysis activities.

In the AIOTI report “EU-funded research projects landscape on IoT and Edge Computing”, the CyberNEMO project is presented through several key categories of information. These include reference links to its official pages, a project abstract outlining its objectives and focus on end-to-end cybersecurity across the IoT–Edge–Cloud continuum, and its planned duration. The entry also highlights main IoT and Edge research challenges addressed by the project, such as zero trust architectures, privacy-preserving AI, federated security management, and secure lifecycle operations. Additionally, it describes CyberNEMO’s dissemination and standardization activities involving collaboration with major European and international organizations, its validation across critical infrastructure sectors like energy, healthcare, and fintech, and key thematic areas such as resilience, cyber threat intelligence sharing, and privacy-by-design principles.

Read More

Cybersecurity in the Computing Continuum – The CyberNEMO Challenge

In today’s hyperconnected world, the Computing Continuum (CC)—spanning IoT devices, edge computing, and cloud infrastructure—presents both unprecedented opportunities and complex cybersecurity challenges. The CyberNEMO project, funded by the European Union’s Horizon Europe programme, is tackling this head-on with an end-to-end cybersecurity approach that integrates risk analysis, ethics and regulatory governance and compliance.

The recently published deliverable D1.1 outlines the threat and ethics assessment conducted across four critical sectors:

  • Smart energy and water infrastructures

  • Secure media content supply chains

  • Healthcare systems

  • Smart farming and logistics

Each of the four trials serves as a living lab to validate CyberNEMO’s technologies:

  • Smart meters and EV charging stations are protected against ransomware and data breaches using Zero Trust Network Architecture (ZTNA) and AI-based anomaly detection.

  • Media content is securely produced and distributed using microservices, encryption, and federated learning.

  • Hospitals defend against insider threats and phishing attacks while ensuring personal and confidential data sharing in compliance with GDPR and other relevant regulations.

  • Smart farming systems use drones, IoT sensors, and blockchain to ensure traceability and cybersecurity in the olive oil supply chain

These trials demonstrate the scalability and adaptability of CyberNEMO across diverse sectors and regulatory environments

Using the MITRE ATT&CK framework, the project identified 44 unique threat types and over 100 functional and non-functional requirements, as well as 23 ethics and regulatory concerns and corresponding requirements. These threats and challenges range from credential theft and ransomware to data manipulation, ethics of AI and denial-of-service attacks.

At the heart of CyberNEMO is a meta-operating system (meta-OS) that orchestrates secure interactions across the CC. This system integrates:

  • Zero Trust Network Access (ZTNA): Every device, user, and service is treated as untrusted by default.

  • Federated Machine Learning (FML): Enables decentralized threat detection without compromising data privacy.

  • Secure Access Service Edge (SASE): Ensures secure connectivity across heterogeneous networks.

  • Digital Twins and Blockchain: Provide traceability, auditability, and resilience in supply chains 

This architecture is designed to be ethics-by-conception, modular, scalable, and interoperable, supporting a wide range of use cases and regulatory contexts

CyberNEMO is not just about technology, it’s about building a secure, ethical, and resilient digital future.

You can explore the official project page on the EU CORDIS portal or follow updates from the coordinating partner Synelixis 

Read More

4th General meeting Of CyberNEMO

CyberNEMO partners have started a two-day Plenary Meeting that is in its 4th edition. The city of Lisbon has been the scenario of this venue. The project is along the 10th month of the project and the members have been evaluating the current status of CyberNEMO.

Duting the first day the partners talked about the availability of the components and the integrated version of the platform. Also the neccesity of testing the risk methodology as it is nearly finalised. Lastly the group discussed the ethics and regulatory aspects that need to be taken into account, but also next deliverables to be submitted.

Read More

CyberNEMO at SecSoft 2025 – Presenting Research on Verifiable Evidence for Zero Trust Networks

The CyberNEMO project was represented at the SecSoft 2025 workshop, held on June 27th in Budapest in conjunction with the IEEE NetSoft 2025 conference. The workshop brought together researchers, practitioners, and industry partners working on topics related to security, privacy, and trust in software-defined and AI-enabled network environments.

As part of the program, Ana Méndez, researcher from TID in the CyberNEMO consortium, presented the paper: “Transparent Notary Service: A Transparency Framework for Secure and Verifiable Network Evidence.”

This contribution introduces a lightweight, cryptographically verifiable notarization system that supports secure evidence handling and traceability in Zero Trust architectures. The work proposes a novel way to register and verify signed statements. such as access events, policy attestations, or network anomalies, using append-only logs and COSE-based signatures.

In addition to the paper, the CyberNEMO project poster was also presented at the event, outlining the project’s approach to trusted automation, distributed identity, and evidence-based orchestration in future 6G and cloud-native infrastructures.

The session was a valuable opportunity to share ongoing results, exchange ideas with other European and international initiatives, and highlight CyberNEMO’s commitment to building transparent and trustworthy network systems.

Read More