Roadmap Timeline

Comprehensive cybersecurity threat intelligence

2020-2027

Problem description

The problem definition is complex as the topic by itself:

  • Phenomena: evolution and development of cyber-attacks and exploitation of different kinds of vulnerabilities have formed new categories of cyber-threats: complex by initial design, well planned, organized over the time by several stages, having good social engineering component, having political or ideological motives and/or linkage with high value industrial or geopolitical gains. New, high complexity, threats requires new approaches and methods on how to tackle them.
  • Approach: for more complex, multi-stage, full-spectrum cybersecurity incidents traditional cybersecurity function organization is not sufficient and not effective anymore. Considering this part of phenomena, detected cybersecurity incidents (ones being part of the large multistage operation), puts us in the situation where we can only fight consequences. We need capabilities to fight phenomena on early phases of multi-stage operations, meaning – moving from incidents to threats, from reactive to predictive organization of cybersecurity.
  • Governing cybersecurity: to address complex, multi-stage, full-spectrum, uniquely designed cyber-attacks, cybersecurity must be organized cross-institutionally and cross-border. Single institution perimeter protection oriented cybersecurity organization is not efficient and does not provide sufficient context information in order to spot correlation, make a prediction and decide on adequate measures on early stage. We need to bring cybersecurity towards a collaborative organization.
  • Data sharing: collaborative organization of cybersecurity naturally requires wider data access and data/information sharing, which is challenge by itself. GDPR and other privacy, security and confidentiality
  • Concept: historically organization of cybersecurity function had more technical roots and IT perimeter security organization. Nowadays, cybersecurity is an important piece of differently targeted attacks and requires a comprehensive approach to uniting both societal and technological sides of threats to tackle them. Such an operation like Elections Interference is a combination of direct attacks, public brand and reputation attacks, information lacking, fake news, propaganda, the polarization of society, etc. Social engineering plays a more and more significant role in cyber threats therefore
  • Analysis model: diverse cybersecurity information and indicators of threats are hardly incorporable into a single analytical model. Empirically we can state that in such a situation, visual analytics techniques is the way to solve it; however, which one is the most efficient for cybersecurity threats is an open question for now.
  • Regulatory: organizing cybersecurity function around early phases of the kill chain, rises lots of regulatory questions and demands: how to define the threat, how to measure it, what privacy, ethical and other standards should be applied in order to maintain the balance between enforcement and individual rights.
  • Legal: tackling the cyber threats – what legal framework should be applicable for the process, especially considering globality of the phenomena – most of the top tier threats are coming from abroad and originates outside the EU.
Research aspect:
  • Building comprehensive cybersecurity threats situational awareness picture
  • Visual Analytics methods applied for comprehensive cybersecurity threats analysis
  • Different origination and nature data sharing among diverse actors
  • Cybersecurity threats analysis regulatory framework
  • Legal basis for comprehensive cybersecurity threat processing


Industrial demand:
  • Need for EU proprietary tools, technologies and solutions to assure top tier cybersecurity threats prevention.
  • Potential application in automotive, energy, critical infrastructure sectors


Social aspect:
  • General need to ensure the public safety of democratic processes inside the EU (avoiding Elections Interference and other negative ideology-driven societal impacts)
  • The more informed and trusted decision-making process in cybersecurity


Final goal:
  • Early-stage cybersecurity threats detection, prediction and response capability
  • Capability to tackle complex cybersecurity threats (Full spectrum, Multi-Stage, Unique, long-term, APT’s)


Benefits for EU:
  • EU cybersecurity institutions will have capabilities to address complex, advances cyber threats
  • EU institutions will have capability will have the knowledge and capabilities to work with cyber threats (early phases of kill chain)
  • Solutions developed in a targeted timeframe will put EU industries, SME’s, Academia into the lead position in this field.


Domain (JRC Taxonomy): Top-Tier Cybersecurity Threats

Sector (JRC Taxonomy): Defense, Governmental and public authorities, Public Safety as direct sectors

Relation to emerging technologies: Threats intelligence, All-data based analytics, Visual analytics, Predictive analytics of cyber threats

More details in the complete roadmap