by Massimo Cossentino, Giuseppe Papuzzo, Vishal Sonth and Fabio Martinelli (ICAR-CNR)

Cyberattacks against Europe’s digital infrastructures are growing in scale and sophistication, yet organisations still manage technical risk, situational awareness, incident response and cyber-insurance in separate silos. The Horizon Europe project SYNAPSE integrates all of these into a single platform, combining AI-driven threat intelligence, standardised incident-response orchestration and blockchain-based cyber-insurance.

Operators of essential services (OES) and their supply chains face a rapidly expanding threat landscape, while the NIS2 Directive requires continuous, evidence-based cybersecurity and resilience management. In practice, most organisations — especially SMEs — still assess technical vulnerabilities, business impact and insurance exposure through disconnected tools: threat intelligence is rarely correlated with an organisation’s own assets, incident-response procedures are often static rather than executable, and cyber-insurance is still largely underwritten through questionnaires rather than through continuous monitoring of security posture.

SYNAPSE is a three-year Horizon Europe project (Grant Agreement No. 101120853) coordinated by CNR, bringing together 15 partners from 8 countries. Its goal is to integrate technical and economic risk assessment, AI-enhanced situational awareness, coordinated incident response, preparedness training and cyber-insurance enablement into a single platform, validated at Technology Readiness Level 7 across four real-world pilots — energy (Germany), a healthcare supply chain (Cyprus), a cybersecurity insurer, and a fourth pilot selected through the project’s open call.

The SYNAPSE architecture (Figure 1) integrates its capabilities as interoperable building blocks. A Multi-layer Security & Privacy Monitoring toolset supplies raw evidence to Integrated Risk Management, which combines technical risk assessment with a model-driven economic risk assessment — translating technical findings into asset valuation, impact cost and insurance-relevant figures, as detailed in Figure 2 — and to SYNAPSE Smart Contracts, which use the Hyperledger Fabric blockchain to support dynamic, evidence-based cyber-insurance policies and claims. The same evidence feeds AI-enhanced Situational Awareness, whose outputs trigger Incident Response & Business Continuity, centred on a Cybersecurity Orchestration, Automation & Response (COAR) engine that executes machine-readable “SYNAPSE Playbooks”, complemented by a Cyber Range that lets teams rehearse the same playbooks used in real incidents as part of hands-on Preparedness training. An Information Exchange, Alerting & Reporting layer lets SYNAPSE instances at different organisations and national cybersecurity authorities share playbooks, models and indicators, enabling shared situational awareness and coordinated response rather than single-organisation defence alone. A role-based dashboard presents the relevant subset of this information to operators, analysts and insurance experts.

Figure 1: SYNAPSE conceptual architecture.
Figure 1: SYNAPSE conceptual architecture.
Figure 2: The SYNAPSE approach to integrated cybersecurity risk & resilience management.
Figure 2: The SYNAPSE approach to integrated cybersecurity risk & resilience management.

Several components push beyond the state of the art. An AI-based CTI Extractor turns unstructured threat reports into structured STIX 2.1 intelligence while preserving a traceable link back to the source passage, so analysts can verify or correct AI-generated content rather than trusting it blindly. A companion Threat Hunting Engine detects malicious infrastructure ahead of reactive feeds — in longitudinal validation, roughly a third of the infrastructure it flagged remained unseen by mainstream sources three days later, with a false-positive rate of 0.31%. SYNAPSE researchers have also published peer-reviewed results on LLMs for security triage: one study achieved up to 97% accuracy inferring phishing intent from email content alone [2]; another shows a constrained, multi-role “agentic” LLM workflow raises malicious-alert classification accuracy from near 0% to over 90% [3]. On the response side, SYNAPSE’s COAR engine executes playbooks built on the OASIS CACAO standard [1]. To the consortium’s knowledge it is the first fully open orchestration engine of its kind, allowing response procedures to be automated, shared and rehearsed via the Cyber Range across organisations.

By combining technical and economic risk assessment, AI-driven threat intelligence, standards-based response orchestration and cyber-insurance enablement in one federatable platform, SYNAPSE aims to help operators of essential services meet the resilience expectations of NIS2 and strengthen the collective resilience of Europe’s digital infrastructures, contributing to a more autonomous European cybersecurity capacity. Updates and public deliverables are available on the project website [L1].

Links:
[L1] https://www.synapse-project.eu 

References:
[1] B. Jordan, A. Thomson, “CACAO Security Playbooks Version 1.0”, OASIS Committee Specification 02, https://docs.oasis-open.org/cacao/security-playbooks/v1.0/security-playbooks-v1.0.html
[2] E. Eilertsen, V. Mavroeidis, G. Grov, “LLM-Powered Intent-Based Categorization of Phishing Emails”, IEEE CSR 2025.
[3] E. Eilertsen, V. Mavroeidis, G. Grov, “Towards Agentic Investigation of Security Alerts”, IEEE BigData 2025.

Please contact:
Massimo Cossentino
ICAR-CNR, Italy
This email address is being protected from spambots. You need JavaScript enabled to view it.