Cybersecurity

Crime is rapidly moving online. An EU-funded project built accurate, human-centric, unbiased AI tools to help investigators turn massive digital evidence into vital clues

Criminal activity has drastically changed today – it is digital, borderless and leaves behind massive trails of information. Modern investigations no longer rely on physical evidence alone. Instead, police must routinely sift through mountains of heterogeneous data including dark-web content, cyber logs, CCTV frames and location tracking.

To remain effective against these threats, law enforcement agencies (LEAs) increasingly need AI to process data at a scale and speed humans cannot manage alone. The EU-funded STARLIGHT(opens in new window) project was established to enhance European strategic autonomy in AI for law enforcement, improving criminal investigations and cybersecurity across the continent.

Why is digital evidence difficult to analyse

“However, moving AI from laboratory conditions into real-world police work is challenging”, notes Cédric Gouy-Pailler, member of the technical management committee. “AI tools that excel in a laboratory often fail to fit real investigative workflows and strict rules for legal evidence. Furthermore, LEAs must navigate a maze of legal regulations regarding personal data privacy, criminal profiling and whether digital evidence will hold up in court.”

There is also the critical threat of algorithmic discrimination, as bias can easily seep into AI systems during data collection, model training or software design. Crucially, AI systems for law enforcement data must be protected from hacker manipulation and cyberattacks.

AI ethics and data management

To overcome these barriers, STARLIGHT organised iterative co-development cycles, workshops and technology ToolFests. These activities brought together LEAs, researchers, industry partners and legal/ethical experts to build practical tools.

Technical teams were not left to guess how to follow the law on their own. Instead, STARLIGHT simplified the legal landscape by mandating the Accountability principles for artificial intelligence(opens in new window) framework for all technology development. This ensured that the tools complied with the EU AI Act and demonstrated that they could be trusted in policing, security and justice.

Adopting an ‘ethics-by-design’ approach, the consortium tackled bias using technical measures and human checks. This included using representative datasets, rewriting code metrics and training officers to understand AI limits.

Operational AI tools for police investigations

STARLIGHT developed and enhanced more than 70 AI tools tailored to LEA needs.

“Rather than building a single software system, STARLIGHT delivered a broad family of solutions that secure digital evidence through a verifiable chain of custody,” notes Nizar Touleimat, project coordinator of STARLIGHT. “This ecosystem includes tools that discover online sources, gather threat intelligence and protect public spaces, allowing investigators to connect hidden clues across massive amounts of text, image and video streams.”

Among these, the Dark Web Monitor automatically collects and classifies illicit content, filtering data so analysts can focus on critical threats while keeping experts in control when AI is uncertain.

For digital forensic teams dealing with hard drives containing digital activity traces, the Cyber Pattern Investigator scans logs using pattern recognition and AI-driven clustering to spot hidden activities and create explainable visual reports.

Other tactical solutions include tools for scanning visual archives, cleaning up critical audio recordings and analysing complex geolocation data to map and forecast suspicious movements.

“STARLIGHT changed how European police design and use AI. Instead of just creating tools and datasets, it built a safe, legal and human-led model for AI use in law enforcement. Its true legacy is connecting police with agencies like Europol to ensure these tools are used successfully across Europe for years to come,” concludes Gouy-Pailler.

Deepfakes, biased algorithms: it’s starting to feel like online disinformation might be around every corner. What can be done?

Content can lead to hate crimes and other violence, but many European Police Authorities do not have access to any specialised tools or technologies to help them tackle the issue – how can they be helped?

As individuals, how can we establish if we are being manipulated? We are increasingly exposed to cyber (dis)information, either passively, through social media feeds, or actively, by using search engines and specific websites that guide us to sites that re-enforce our biases and build walls of prejudice.

Companies are making some effort to identify and remove fake-news websites, and minimise the spread of disinformation on social media, but what about the search engines themselves? Could web crawlers provide an innovative way to help us audit their activity?

The spread of cyber disinformation threatens our democratic values. As the amount of disinformation grows, AI, and language technologies in particular, have a crucial role in detecting it. Machine learning and AI train on large language models, but what about languages that have a smaller footprint online – those that are used less frequently? How can we strengthen AI to combat disinformation in what are called ‘low resource’ languages?

Listen on to hear how these and other cyber risks are being tackled with the help of EU research funding.

Owen Conlan(opens in new window), is a fellow of Trinity College(opens in new window), Dublin, and professor in the School of Computer Science and Statistics(opens in new window). He is also co-director of the Trinity Centre for Digital Humanities(opens in new window). Owen is very interested in user control over personalised AI-driven systems, which he explored through the VIGILANT project.

Joana Gonçalves-Sá(opens in new window) is a researcher both at the Nova Laboratory for Computer Science and Informatics(opens in new window) and in the Laboratory of Instrumentation and Experimental Particle Physics(opens in new window), Lisbon, where she leads the Social Physics and Complexity research group. Her focus in on human and algorithmic biases, using fake news as a model system, the subject of her FARE_AUDIT project.

Marián Šimko(opens in new window) is an expert researcher at the Kempelen Institute of Intelligent Technologies(opens in new window) in Slovakia. He focuses on natural language processing, information extraction, low-resource language processing and the interpretability of neural models. The DisAI project focused on developing new approaches for language processing to improve performance of large language learning models for less frequently used languages.

A closer look at how Europe’s flagship cybersecurity directive is being translated from policy to practice.

At the 2025 Barcelona Cybersecurity Congress, one directive resonated across keynotes, panels, and informal conversations: NIS2. Two standout sessions in particular—one focused on practical implementation experiences, and another offering a data-driven regulatory overview—captured the multi-layered challenges organizations face in adapting to this directive. Though its enforcement deadline has passed, the directive’s implementation remains fragmented, uneven, and fraught with real-world complications. As Europe pushes toward a more secure digital future, the cybersecurity community gathered in Barcelona to take stock of where things stand—and where they need to go.

The NIS2 Directive—short for the Directive on Security of Network and Information Systems—is the EU’s most comprehensive attempt yet to build cyber resilience across critical infrastructure and essential services. It replaces the 2016 NIS Directive, expanding its reach to more sectors, tightening reporting deadlines, and increasing accountability at the executive level. It’s a response to an evolving threat landscape—but also a pressure test for cross-border coordination and organizational culture.

Organizational Perspectives on Implementation

One of the most anticipated sessions at BCC25, titled “NIS2: Challenges, Opportunities, and Experiences in the Implementation of the New Directive,” brought together perspectives from public and private institutions to discuss how organizations are adapting to the evolving demands of the directive.

The panel brought together perspectives from public and private sector leaders, including David Esteban Haro (CISO, Barcelona City Council), Óscar López Santín (Cybersecurity Manager, Agrolimen Group), and Javier Montoya Tomás (Director of Cybersecurity, Continuity and Risk, Aigües de Barcelona), with moderation by Malu Ribalta Ribelles (Director of Public Affairs and Communication, ISMS Forum).

Proportionality, a principle central to the directive, became a recurring theme. It’s supposed to ensure that cybersecurity measures are scaled appropriately to the size and risk profile of each organization. But translating that into action has been elusive. Óscar López from Agrolimen summed up the dilemma: “We have many small suppliers. We’re not just auditing them—we’re helping them, even doing the consultancy work ourselves. It's the only way to guarantee security across the supply chain. But it’s a huge task. We have to prioritize.”

Beyond budgets and compliance plans, there was a call for a broader shift in mindset. David Esteban from the Ajuntament de Barcelona stressed that cybersecurity can no longer live in a technical silo. “The biggest challenge is cultural,” he said. “The CISO must speak the language of the business to gain alignment and trust.”

Javier Montoya of Aigües de Barcelona offered a glimpse into how his team approached this challenge by steadily bringing the board into the conversation, without panic or pressure. “We framed risk in calm, constructive terms—not threats or fear. It's about preparing for what’s coming, not panicking.”

Across sectors, the impact of NIS2 is unfolding differently. For financial institutions already working under frameworks like DORA, the shift has felt like a compliance formality. For healthcare organizations, it’s a storm—too many regulations, too few resources, too much exposure. Manufacturers sit somewhere in the middle, dealing with complex IT/OT integration and a growing reliance on consumer-grade technology in industrial environments.

The European Regulatory Landscape

Separately, a session titled “NIS2 Directive Implementation State of Play: National Transposition, Entities Readiness Level, and Sectoral Applications,” led by Régis Cazenave of ECSO, presented a data-driven overview of the current regulatory landscape. He noted that only eleven EU member states had fully transposed NIS2 into national law. ECSO maintains an up-to-date NIS2 Transposition Tracker, visualizing the state of implementation across the EU. He highlighted the burden of fragmented incident reporting requirements across countries and introduced ECSO’s roadmap to coherence: nine key recommendations ranging from a unified EU reporting mechanism to the formal recognition of existing international standards. “Otherwise,” he noted, “companies are forced to fill out different reports for each country impacted by a single incident.”

Régis Cazenave, ECSO, explica los retos de NIS2 en BCC25

The ECSO survey results—based on feedback from 155 organizations across 23 countries—provided an inside look at how stakeholders are experiencing the transition. More than half of the respondents were newly regulated under NIS2, facing steep learning curves and operational stress. Many reported difficulty interpreting the directive, challenges coordinating across internal departments, and a lack of specific national guidance. The survey also revealed that in many organizations, NIS2-related efforts now account for 5% to 10% of the cybersecurity budget—an indicator of both its weight and urgency.

Cazenave also emphasized the need for alignment in incident classification across the EU. Different member states are using varying criteria and timelines for reporting, ranging from six-hour windows in Germany to broader thresholds in others. This creates a patchwork of obligations that’s especially difficult for cross-border companies to manage. Inconsistencies extend to how sectors are classified as well. While some countries have opted for minimal transposition, others have expanded the directive’s scope to include additional sectors and smaller organizations.

ECSO’s roadmap didn’t just critique—it also offered a way forward: encourage harmonized tools, accept compliance via well-known international standards like ISO 27001, and provide extra support for smaller, newly regulated entities. The emphasis was clear: compliance must be achievable and scalable.

Bridging the Divide

While challenges remain, the message from BCC25 was grounded in realism and forward motion. The road to NIS2 compliance is uneven, the directive’s rollout incomplete, and the tools scattered. But the ambition—to strengthen Europe’s digital resilience—is widely shared.

The task now is to close the gap not only between countries, but between intention and implementation. In Barcelona, the conversation began to bridge that divide.

Researchers, policy makers and law enforcement personnel co-create guidelines and recommendations for the ethical use of AI in crime prevention.

The world is changing rapidly, and artificial intelligence (AI) is central to the transformation. While AI is capable of revolutionising fields such as housing, healthcare, transportation and education, the deployment of AI by law enforcement agencies (LEAs) raises ethical concerns. The EU-funded ALIGNER project brought together European actors concerned with AI and policing to discuss how to strengthen law enforcement and benefit the public.

Advisory boards and workshops

Communication is key to the aims of ALIGNER, and to facilitate interdisciplinary discussions the project established two advisory boards. One board was composed of LEAs, including the Basque, Munich and Swedish police forces, which were among the project partners. The second board included scientific, industrial and ethical experts. Combined, the advisory boards represented more than 60 experts involved in over 30 research projects.

The project identified four areas essential to developing a roadmap for addressing AI technology in law enforcement. For each topic, ALIGNER hosted a workshop to facilitate discussion among stakeholders. Two of the workshops addressed how criminals are using emerging AI technologies and how AI can be used by LEAs to counteract this trend. A third workshop focused on legal and ethical concerns of AI deployment in policing, and a final workshop addressed LEA capability enhancement needs and policy recommendations.

Informing the AI Act

The workshops allowed ALIGNER to get input and feedback from target groups in an effective manner. The relevance and immediacy of these dialogues was particularly helpful considering the European Commission’s broad initiative to address the impact of AI on society. ALIGNER coordinated with other projects funded under the H2020-SU-AI-2020 call, particularly popAI and Starlight.

All of these projects serve to support the Artificial Intelligence Act (AI Act), a major piece of European legislation. This confluence of legislation and funded projects was an interesting and fruitful challenge for ALIGNER. According to project coordinator Daniel Lückerath: “We were working on a project whose objective was to give policy and research recommendations on AI, while the EU AI Act was being developed and discussed in parallel.”

Roadmaps and assessments

Major outputs of ALIGNER include publicly accessible deliverables that support LEAs, policy makers and researchers in meeting AI-related objectives. The policy and research roadmap gives an overview of AI technology needs and challenges faced by LEAs. The roadmap provides nine policy recommendations, such as specific training of law enforcement officers to improve awareness of the risks inherent in AI systems. It also identifies 19 areas where additional research is needed, for example, exploring how AI can impact the fairness and transparency of judicial decisions.

A noteworthy outcome of the project is the ALIGNER fundamental rights impact assessment (AFRIA). Composed of two complementary templates that help LEAs identify and assess the impact of an AI system on the fundamental rights of individuals, AFRIA helps to ensure compliance with the AI Act.

AI compliance with ethical principles was a major focus of ALIGNER. As Lückerath shares: “AI cannot and will not replace human decision-making, but it is an important tool to support the decisions humans make.” With the AI Act and projects like ALIGNER, the EU is preparing for a fast-approaching, unprecedented future.

Improved cybersecurity defences for electronic commerce have emerged from EU-funded projects

What do a Greek pharmacy, a Spanish multinational bank, a German foundation specialised in the digital economy and a UK university have in common?

They all helped develop software tools with EU funding to counter cyber and physical threats to e-commerce in the European single market, the world’s most lucrative.

Prime targets

Called ENSURESEC, the project sought to ensure that small and medium-sized enterprises, or SMEs, in particular have adequate technological knowledge and defences against hackers and fraudsters.

‘SMEs have fewer resources,’ said Luis Carrascal, a cybersecurity expert at French software company Inetum. ‘They can’t just hire large teams of cybersecurity experts. The majority of SME employees also lack a basic understanding of cybersecurity.’

SMEs are defined as businesses that employ fewer than 250 people and have annual turnover of no more than €50 million. They account for almost all companies in Europe, making them regular targets of cyber-attacks.

Nearly a third of European SMEs faced at least one cybercrime in 2021, according to a Eurobarometer survey.

A typical example involves a “ransomware” attack in which hackers enter a company’s computer systems, encrypt their data and demand a ransom. A European network of small businesses reported a 57% increase in ransomware attacks on SMEs in 2023 compared with the previous year.

‘Attack surface’

Theodoros Sakopoulos, who owns an online pharmacy called ToFarmakeioMou in the Greek capital Athens, simulated a hybrid physical and digital attack during ENSURESEC.

In the mock theft, hackers tried to jam the GPS tracker of a drug delivery by the business so they could intercept the truck and steal its contents. Sensor devices were developed to track the shipment and notify the pharmacy when any order got tampered with.

Sakopoulos was among 22 participants in ENSURESEC, which ran for two years until mid-2022. Other participants included Spain-based CaixaBank, the IOTA Stiftung – a German foundation advancing research into the digital economy – and the University of Greenwich in the UK.

‘The attack surface is huge in e-commerce,’ said Augustin Lemesle, a research engineer at the French Alternative Energies and Atomic Energy Commission, or CEA, which also took part in the project. ‘You can be attacked from everywhere.’

Lemesle was the technical coordinator of ENSURESEC, whose participants came from 14 European countries. Other participants included the Spanish office of French software company Atos and Belgian university KU Leuven.

AI vigilance

One of the project’s software tools uses artificial intelligence (AI) to monitor a company’s internal networks, which are shielded from the outside internet. They’re the grand prize for hackers, who seek entry to gain access to sensitive data.

That’s why monitoring such internal networks for suspicious activity is key for keeping a company safe.

Doing that manually is hard because of the high number of people using these networks and because of their complexity. By contrast, an AI system can do this automatically 24 hours a day and report anything out of the ordinary.

‘We need to ensure that a company reacts well when a threat appears,’ said Lemesle.

Online buying has boomed since the Covid-19 pandemic erupted in 2020.

The turnover of European e-commerce increased by 6% to €899 billion in 2023 compared with the previous year. Growing numbers of SMEs are serving their customers through the internet, which makes them a bigger target for attacks.

‘E-commerce is very closely linked to consumers,’ said Lemesle. ‘If something goes wrong there, it has a very big impact on society. Everyone is using e-commerce, which puts our personal data and security at risk.’

Easy-to-use kit

Inetum’s Carrascal led a separate EU-funded research project to develop cybersecurity defences that are easier for smaller European businesses to use.

Called CyberKit4SME, the project ended in November 2023 after three and a half years.

Carrascal said the difficulty for smaller businesses isn’t an insufficient number of software options to address cybersecurity but rather their complexity.

‘There are already a lot of software tools on the market,’ he said. ‘The issue is that they’re complicated to operate. That’s a problem for SMEs, which don’t have big IT teams.’ One of the software options from the project helps SMEs store and access their data more securely.

A second looks at how people behave on the company’s networks and where dangers may lie.

The human dimension is the weakest link in a company’s cybersecurity setup. People might, for example, click on an infected link, giving hackers access to the company’s internal networks.

Yet another piece of software from the project seeks to spot security vulnerabilities through the modelling of IT systems.

‘It allows companies to create a virtual model of their information system, which helps them analyse possible threats,’ said Carrascal.

At present, this kind of software requires an information-technology expert to go through a company’s software system and list all the places where it can be accessed from the public internet. This creates a list of possible hacking entry points that in turn need to be protected.

By automating more of this process, CyberKit4SME has made it easier for smaller companies to improve the security of their computer systems.

Market tests

Both CyberKit4SME and ENSURESEC are keen for their technologies to enter the marketplace.

ENSURESEC has grounds for optimism.

Some companies are already selling tools developed during the project, while other tools have been made open-source, according to Lemesle.

‘There’s real demand for our technology,’ he said.

Other technologies that emerged in ENSURESEC need further development, some of which is being done in new EU-funded research projects, according to Lemesle.

CyberKit4SME too has been disseminating some its software for free.

Of six technologies developed in the project, four have been made fully open-source and one partly, according to Carrascal.

‘Anyone can use them,’ he said.

Furthermore, some project partners are considering creating a startup business to commercialise the whole toolkit, according to Carrascal.

‘Attackers will keep exploiting less prepared organisations,’ he said. ‘That’s why we need to invest in better protecting them.’

Author: Tom Cassauwers

This article was originally published in Horizon the EU Research and Innovation Magazine

The proposal aims to curb cybercrime, which cost the global economy an estimated €5.5 trillion in 2021

Lawmakers are seeking to strengthen cybersecurity requirements across the European Union, advancing new legislation to bolster security requirements for all digital hardware and software products. The proposed law, titled the Cyber Resilience Act, would cover everything from computers and mobile phones to smart kitchen appliances and digital children’s toys.

"When it comes to cybersecurity, Europe is only as strong as its weakest link: be it a vulnerable Member State or an unsafe product along the supply chain,” said Thierry Breton, the EU’s commissioner for the internal market.

The proposed legislation, which was unveiled by the European Commission earlier this month, mandates that products are designed, developed and produced in ways that mitigate cybersecurity risks. This includes, for example, requirements to sell products in a secure default configuration, to maintain a thorough product identification system and to ensure that exploitable vulnerabilities can be addressed through security updates, among other cybercrime disclosure rules.

In recent years, the number of personal devices that are connected to the internet has grown significantly.

Yet many of these so-called Internet of Things products are highly vulnerable to hacks and cybercrimes. In fact, ransomware attacks occur worldwide every 11 seconds and cost the global economy an estimated €20 billion last year, according to the EU. Meanwhile, DDoS attacks—malicious efforts to disrupt or cut off access to internet services or websites—cost just the EU economy roughly €65 billion in 2020.

In Belgium, for example, nearly 1,000 businesses were hit by cybercrimes in 2021—a 300% increase compared to the year prior, according to an analysis by Mastercard. The majority of cyber attacks entailed malware and ransomware strikes.

“We deserve to feel safe with the products we buy in the single market,” said Margrethe Vestager, executive vice president of the European Commission for A Europe Fit for the Digital Age. “The Cyber Resilience Act will ensure the connected objects and software we buy comply with strong cybersecurity safeguards.”

Reinforced cybersecurity protocols are also expected to help companies and manufacturers—especially smaller businesses that may not have the technical resources or financial means to survive a cyberattack.

Earlier this year, the World Economic Forum’s Global Cybersecurity Outlook reported that the average cost of a cyber breach for a company was $3.6 million. Moreover, targeted companies saw stock prices fall and spent on average 280 days identifying and responding to a cyberattack.

“Technology leaders, companies and their boards of directors would do well to pay attention to these developments and recognize that cyber strategy is a business strategy and understanding cyber risk is part of good governance in the digital age,” said Daniel Dobrygowski, the head of governance and trust at the Forum’s Centre for Cybersecurity.

The proposed Cyber Resilience Act was welcomed by industry groups such as the TIC Council, a global organisation covering the independent testing, inspection and certification sectors. “The proposal constitutes a good first step towards a more cyber-resilient single market,” said Martin Michelot, the TIC Council’s executive director for Europe.

The legislation was first put forth by European Commission President Ursula von der Leyen in November 2021. If the act is approved by the European Parliament and the European Council, EU countries will have two years to adapt the new rules.

“Digital trust is a necessity in a global economy reliant on ever-increasing connectivity, data use and new innovative technologies,” said Akshay Joshi, the head of industry and partnerships at the Forum’s Centre for Cybersecurity. “As common citizens increasingly become wary of the technologies they interact with, this regulation will further enhance transparency and allow end users to make informed choices.”

The EU’s Cyber Resilience Act joins several other pieces of legislation proposed around the world that aim to curb cybercrime, which cost the global economy €5.5 trillion in 2021. By 2025, cybercrime damages are expected to surpass €10 trillion.

Earlier this year, the United States enacted a new law bolstering cybercrime disclosure requirements for companies working in critical infrastructure sectors. The policy followed a major ransomware attack in May 2021 against Colonial Pipeline, which operates the country's largest pipeline system for jet fuel, gasoline and diesel. The attack, which was reportedly launched through an old corporate virtual private network, paralysed pipelines across the US East Coast and resulted in Colonial Pipeline paying roughly $5 million worth of Bitcoin to the hackers. The US Justice Department later recovered nearly half of the ransom payment.

The US Securities and Exchange Commission and the US Congress are also pursuing new regulations to strengthen and standardise cybersecurity benchmarks and cybercrime disclosure requirements.

“Regulation has an important role to play in incentivizing cyber resilience,” Dobrygowski added.

Source: Spencer Feingold Digital Editor, Public Engagement, World Economic Forum

The Conference has long been involved with the evolving impacts of technology and innovation on cities

U.S. Conference of Mayors (USCM) President Miami Mayor Francis Suarez named Seattle Mayor Bruce Harrell as the first chair of the organization’s new Standing Committee on Technology and Innovation. The new committee will examine broadband deployment, cybersecurity, and city digital services, as well as promote best practices and help set the Conference’s policy on these and other related issues.

The Committee’s initial work in the coming months will prioritize a focus on broadband, especially accessing funding included in the Infrastructure Investment and Jobs Act (IIJA) for infrastructure deployment and digital equity. Additionally, it will concentrate on the threat of cybersecurity attacks that continue to plague cities across the country. The Committee’s purview will also include issues such as government procurement, the gig economy, disinformation on the internet, artificial intelligence, cryptocurrency, the metaverse, consumer privacy, smart cities, and data governance.

“With Mayor Harrell’s leadership, this new standing committee will keep mayors and cities at the cutting-edge of what’s possible in the market and in government,” said Mayor Suarez. “Technology changes rapidly, and we want to ensure mayors and cities stay nimble and are the drivers of digital progress.”

“I’m honored to lead this effort and committee at the U.S. Conference of Mayors,” said Mayor Harrell. “Seattle is known for big, progress-driving ideas and an unyielding commitment to innovation. My goal is to bring forward that same spirit and work together with my fellow mayors to expand our embrace of technology and big ideas, delivering new opportunities and positive change from inside city hall to residents all across our communities.”

The Conference has long been involved with the evolving impacts of technology and innovation on cities. A task force on technology and innovation was established in 2012 as an initial venue for discussion. However, given the increasing need for the organization to adopt policy on these issues, Task Force Chair Austin Mayor Steve Adler proposed the creation of the Technology and Innovation Standing Committee. Mayor Suarez and the Executive Committee unanimously agreed to establish the committee at USCM’s Annual Meeting in Reno this past June. It joins the Conference’s twelve other standing committees on topics such as health, housing, energy, and transportation.

“We thank Mayor Suarez and Mayor Adler for proposing, and the Executive Committee for establishing, this needed standing committee on technology and innovation,” said Tom Cochran, USCM CEO and executive director. “The Conference is so pleased to have Mayor Harrell guide its work on new and emerging technologies. Broadband and cybersecurity are pressing issues for cities, especially as new federal dollars become available from the bipartisan Infrastructure Investment and Jobs Act. With this standing committee, the Conference can help mayors continue to make cities hubs for innovation.”

 

Connectivity, data, and AI will change the way we live, work and operate in society

Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cybersecurity leader, today released a visionary new report and video dramatization articulating how the world might look at the start of the next decade - and how the security sector might respond to evolving cybercrime innovation.

By 2030, connectivity will impact every aspect of daily life, on both the physical and psychological levels. Malicious threat actors will evolve to use and abuse technological innovation - as they always do. Click here to learn more about Project 2030.

"Project 2030 is not a definitive vision of what will be, but a thought-provoking take on what could be - detailing a future that is plausible based on current technology and trends," said Rik Ferguson, vice president of security for Trend Micro. "We hope this possible future will spark a debate within the security industry and wider society. Only by carefully anticipating future scenarios can we offer governments, businesses, and individuals a way to prepare for the cyber challenges of the coming decade."

The report itself looks at the world in 2030 through the eyes of a fictional citizen, a business, and a government. It offers a detailed analysis of evolving cyber threats and how these might impact security stakeholders.

Among the predictions are:

  • AI tools democratize cybercrime on a whole new scale to individuals with no technical skill
  • Attacks cause chaos with supply chains and physical harm to humans through their cyber-implants
  • Social engineering and misinformation become more visceral and harder to ignore when delivered via ubiquitous Heads Up Displays (HUDs)
  • Massive IoT (MIoT) environments attract sabotage and extortion attacks targeting manufacturing, logistics, transportation, healthcare, education, retail, and the home environment
  • AI-powered obfuscation makes attribution virtually impossible, pushing the security industry's focus towards incident response and IAM at the edge
  • 5G and 6G connectivity everywhere drive more sophisticated and precise attacks
  • "Everything as a Service" turns cloud providers into hugely lucrative targets for cyber-attackers
  • Gray markets emerge for those that want tools to confound workplace monitoring
  • Techno-nationalism becomes a key geostrategic tool of some of the world's most powerful nations, with the gulf between them and the have-nots widening further

"The exponential growth of modern technology has brought abundant future possibilities, along with cybersecurity challenges," said Dr. Victoria Baines, cybersecurity futurist. "These scenarios and their associated threats will require changes to the business and regulation of cybersecurity. The cybersecurity industry must evolve both technology and training to prepare for a future in which everything is connected and at risk."

A successor to Trend Micro's acclaimed 2012 report, Project 2020, the new paper was compiled from open-source research, vendor threat landscape reports, scientific abstracts, patents, an invitation-only online survey, and a CISO poll. The video dramatization of the report is meant to be an engaging, entertaining way to visualize the future and enable organizations to think about how they will need to adapt to new realities.

 

All the responsible need to comply with the new norms

The Government of India issued a set of guidelines for cybersecurity in the power sector. The move aims to create a secure power cyber ecosystem. The Ministry of Power in an official statement said, “Central Electricity Authority (Technical Standards for Connectivity to the Grid) Amendment Regulations, 2019, has framed Guidelines on Cyber Security in Power Sector to be adhered by all Power Sector utilities to create the cyber secure ecosystem.”

Furthermore, the statement read, “This is the first time that a comprehensive guideline has been formulated on cybersecurity in the power sector. The guideline lays down required actions for cyber security preparedness across various utilities.”

The Centre has formulated the new norms following intensive deliberations with stakeholders. Also, inputs from cybersecurity experts like CERT-In, NCIIPC, NSCS and IIT-Kanpur and subsequent deliberations in the power ministry.

The Centre’s guidelines lay down a cybersecurity assurance framework strengthening the regulatory framework that puts in place mechanisms for security threat early warning, vulnerability management and response to security threats and secures remote operations and services among others.

All the responsible entities including system integrators, equipment manufacturers, vendors, suppliers, service providers, and original equipment manufacturers (OEMs) for IT hardware and software need to comply with the new norms. As per the guidelines, emphasis has been given on mandating ICT-based procurement from identified ‘trusted sources’ and ‘trusted products’. Otherwise, the product has to be tested for malware/ hardware trojan ahead of deployment for use in the power supply system.

Further, the Ministry’s statement said that the move will boost research and development in the cybersecurity domain and will open up the market for setting up cyber testing infrastructure in the public as well as private sectors. Moreover, the CEA is working on a cybersecurity regulatory framework too. The guidelines are a precursor to the same.

 

Featured

Most Read

We use cookies

We use cookies on our website. Some of them are essential for the operation of the site, while others help us to improve this site and the user experience (tracking cookies). You can decide for yourself whether you want to allow cookies or not. Please note that if you reject them, you may not be able to use all the functionalities of the site.