The ICT environments of critical infrastructures (such as energy distribution systems) are composed of a large number of systems connected to form a complex system of systems. Recent initiatives to upgrade power systems into smart grids target an even tighter integration with information technologies to enable the integration of renewable energy sources, local and bulk generation and demand response. To fully estimate the security of an enterprise’s system architecture, a large number of issues must be considered. Enterprise systems security managers must be able to assess how vulnerabilities in one system influence vulnerabilities in other systems. In addition, security managers must be able to assess how individual vulnerabilities influence the security of the entire system of systems, given the protection solutions that are used in different locations in the architecture.

The project will deliver and validate a tool that helps to

1) Better understand current cyber security levels across complex enterprise-wide architectures, including relationships and interdependencies between systems

2) Prioritize areas to address and cyber security investments to pursue

3) Proactively manage cyber security e.g. when building or modifying architectures.

The solution is based on a cybersecurity metamodel that

  • Describes the qualitative structure (which assets, attacks and defences that should be included, and how these should be associated
  • Populates this qualitative structure with quantitative data (how likely different attacks are to succeed given the system parameter values and the presence or absence of different defences, using Bayesian networks).

The tool generates a vulnerability “heat map” for each system configuration, allowing a user-friendly and visual comparison of the different alternatives. The project will validate the tool in 2 pilots with energy utilities in Sweden and Germany. The project duration is 24 months and the requested EC funding €1.6M.

Thursday, 8 March, 2018

Project type:


A Holistic framework: Business Process Re-engineering and functional toolkit for GDPR compliance

BPR4GDPR is one of the GDPR cluster projects that will provide a holistic framework able to support end-to-end GDPR-compliant intra- and interorganisational ICT-enabled processes at various scales, while also being generic enough, fulfilling operational requirements covering diverse application domains. Read this to find out more.

Future Events

IAM Online Europe live webinar - AARC Extensions to the REFEDS Assurance Framework

AARC is holding a live webinar on 27 June 2019 at 15:00 CEST, that will explain extensions to the REFEDS Assurance Framework and implementations that were devised in the AARC project.

Representation of the State of Hessen to the EU
04/07/2019 to 05/07/2019

Project CyberSec4Europe (Cyber Security for Europe) is holding it next event - "Representation of the State of Hessen to the EU" in Brussels, Belgium on 4-5 July 2019. 

Other three pilots are invited during CyberSec4Europe meetings.