A coordinated framework for cyber resilient supply chain systems over complex ICT infrastructures


Horizon 2020


01. 09. 2020 - 31. 08. 2023


Traditional cyber security measures are no longer enough to protect organizations from persistent and sophisticated cyber attacks. While they reduce the risks, cyber resilience goes further. This approach not only helps businesses prevent attacks; it also ensures their operations continue if the attacks do happen. Cyber resilience reduces the severity of attacks by enabling rapid recovery from disruptions and restoring regular delivery mechanism.

Cyber security resilience frameworks provide organizations with a comprehensive and effective security approach. And the aim of FISHY project is to develop a coordinated framework for cyber resilience provisioning that guarantees a trusted supply chain of ICT systems, built upon distributed, dynamic, and often fundamentally insecure and heterogeneous ICT infrastructures.

The FISHY platform will be able to securely orchestrate a supply chain, consisting of complex ICT systems end-to-end: from the edge and cloud infrastructure and IoT ecosystem to the networking infrastructure. It will also enable risks and vulnerabilities management related functionalities, accountability and mitigation strategies, security metrics, and evidence-based security assurance.

FISHY implements new strategies to leveraging data analytics, distributed ledger technology, intent-based security service orchestration, artificial intelligence, and programmable network infrastructure.

The platform will facilitate adaptive system reconfigurations and defy cyber attacks’ effects in real-time.

XLAB’s role

XLAB’s role in the project is mainly to lead the technology radar with the creation of business models, analysis and exploitation related tasks. Additionally, XLAB will create a framework for exploitation leads for the platform and its parts. Moreover, XLAB will contribute technical components, such as Vulnerability Assessment Tool, orchestrator and other security sensors, supporting real-time metrics related to vulnerability assessment of the IT system as part of the supply chain.