Home » CYBERWIZ Project

The ICT environments of critical infrastructures (such as energy distribution systems) are composed of a large number of systems connected to form a complex system of systems. Recent initiatives to upgrade power systems into smart grids target an even tighter integration with information technologies to enable the integration of renewable energy sources, local and bulk generation and demand response. To fully estimate the security of an enterprise’s system architecture, a large number of issues must be considered. Enterprise systems security managers must be able to assess how vulnerabilities in one system influence vulnerabilities in other systems. In addition, security managers must be able to assess how individual vulnerabilities influence the security of the entire system of systems, given the protection solutions that are used in different locations in the architecture.

The project will deliver and validate a tool that helps to

1) Better understand current cyber security levels across complex enterprise-wide architectures, including relationships and interdependencies between systems

2) Prioritize areas to address and cyber security investments to pursue

3) Proactively manage cyber security e.g. when building or modifying architectures.

The solution is based on a cybersecurity metamodel that

  • Describes the qualitative structure (which assets, attacks and defences that should be included, and how these should be associated
  • Populates this qualitative structure with quantitative data (how likely different attacks are to succeed given the system parameter values and the presence or absence of different defences, using Bayesian networks).

The tool generates a vulnerability “heat map” for each system configuration, allowing a user-friendly and visual comparison of the different alternatives. The project will validate the tool in 2 pilots with energy utilities in Sweden and Germany. The project duration is 24 months and the requested EC funding €1.6M.

Thursday, 8 March, 2018


On 18 July 2019, will organize a webinar in collaboration with the GDPR Cluster projects entitled “GDPR compliance in the emerging technologies”.

Future Events

The 14th International Conference on Availability, Reliability and Security (ARES 2019), will be held from August 26 to August 29, 2019 at the University of Kent, Canterbury, UK.

26/08/2019 to 29/08/2019

PROTECTIVE is co-organising the 2nd International Workshop on Cyber Threat Intelligence Management(CyberTIM 2019) as apart of the ARES 2019 conference in the UK on 26-29 August 2019.

26/08/2019 to 29/08/2019