CIRCAT aims to strengthen the cybersecurity resilience of large industrial installations and other critical infrastructure sectors identified under the NIS2 Directive by deploying AI-driven cybersecurity tools and advanced cyber range capabilities. The project will support organisations in improving their cybersecurity posture through continuous risk assessment, penetration testing, and specialised cybersecurity training within realistic and controlled Cyber Range environments.
The project will implement continuous monitoring and near real-time risk assessment mechanisms to provide organisations with enhanced visibility of cyber risks and vulnerabilities by integrating AI-based threat detection, vulnerability prioritisation, and automated mitigation strategies that enable proactive cyber defence, optimise resource allocation, and reduce incident response times. Furthermore, CIRCAT will integrate Cyber Threat Intelligence (CTI) feeds into its Cyber Range infrastructure to support realistic simulations of advanced cyberattacks across enterprise networks, cloud environments, Industrial Control Systems (ICS), and IoT infrastructures, enabling penetration testing and cybersecurity exercises under near real-world conditions. Finally, the project will establish a scalable Cyber Range network to facilitate collaborative and cross-border cybersecurity exercises among EU Member States, strengthening cyber resilience, operational preparedness, coordinated incident response, and knowledge sharing across Europe's critical infrastructure sectors.
MKLab serves as the project's Technical Manager. It is also responsible for the Work Package focused on cyber threat intelligence collection and analysis for threat mitigation, the development of a near real-time risk monitoring framework, and development of a Collaborative Intrusion Detection System (CIDS). In addition, MKLabcontributes to the development of advanced CR environment that will be able to host complex and realistic scenarios, also by covering scenarios with cascading effects in cross-border incidents. These scenarios will be used in meaningful exercises to train employees of organisations in order to obtain a better understanding of the operational needs of an incident and to improve their preparedness and response.
DIGITAL-ECCC-2024-DEPLOY-CYBER-07-LARGEOPER