Closed

Novel applications of AI and other enabling technologies for security operation centres

DIGITAL JU Simple Grants

Basic Information

Identifier
DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH
Programme
Deployment Actions in the area of Cybersecurity
Programme Period
2021 - 2027
Status
Closed (31094503)
Opening Date
January 16, 2024
Deadline
March 26, 2024
Deadline Model
single-stage
Budget
€22,250,000
Min Grant Amount
0
Max Grant Amount
0
Expected Number of Grants
0
Keywords
DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECHDIGITAL-ECCC-2024-DEPLOY-CYBER-06Artificial intelligenceArtificial intelligence, intelligent systems, multi agent systemsCybersecurityCybersecurity DomainsCybersecurity-aware culture (e.g. including children education)High-performance computing (HPC)Security

Description

Expected Outcome:

Deliverables

  • Deployment of Artificial Intelligence and Advanced Key Technologies as enablers for SOCs
  • Tools for creation, analysis and processing of CTI that allow for faster and more scalable SOC operations
  • Original European CTI feeds or services
Objective:

This topic addresses enabling technologies (such as AI) for SOCs, including National SOCs which provide a central operational capacity and support other SOCs at national level and play a central role as a hub within a context of SOCs, and also Cross-border SOC platforms where such technologies can strengthen capacities to analyse, detect and prevent cyber threats and incidents, and to support the production of high-quality intelligence on cyber threats.

These enabling technologies should allow more effective creation and analysis of Cyber Threat Intelligence (CTI), as well as faster and scalable processing of CTI and identification of patterns that allow for rapid detection and decision making.

Scope:

Actions in this topic should develop and deploy systems and tools for cybersecurity based on enabling technologies (such as AI), addressing aspects such as threat detection, vulnerability detection, threat mitigation, incident recovery through self-healing, data analysis and data sharing. Activities should include at least one of the following:

  • Continuous detection of patterns and identification of anomalies that indicate potential threats, recognising new attack vectors and enabling advanced detection in an evolving threat landscape.
  • Creation of CTI based on novel threat detection capabilities.
  • Enhancing speed of incident response through real-time monitoring of networks to identify security incidents and generating alerts or triggering automated responses.
  • Mitigating malware threats by analysing code behaviour, network traffic, and file characteristics, reducing the window of opportunity for attackers to exploit malware.
  • Identification and management of vulnerabilities.
  • Recovery from incidents through self-healing capacities.
  • Reducing the chances of attacks and pre-emptively identifying weaknesses through automated vulnerability scanning and penetration testing.
  • Protecting sensitive data through the analysis of access patterns and detection of abnormal behaviour.
  • Enabling organisations to leverage and share CTI and other actionable information for analysis and insights without compromising data security and privacy, through anonymisation and de-identification. Tool and service providers are welcome to apply to this topic, also when in a consortium with National SOCs. Links with stakeholders in the area of High-Performance Computing should be made where appropriate, as well as activities to foster networking with such stakeholders.

Tool and service providers are welcome to apply to this topic, also when in a consortium with National SOCs. Links with stakeholders in the area of High-Performance Computing should be made where appropriate. In well justified cases, access requests to the EuroHPC high performance computing infrastructure could be granted.

The systems, tools and services developed under this topic will be made available for licencing to National and/or Cross-Border SOC platforms under favourable market conditions.

These actions aim at creating or strengthening national and/or cross-border SOCs, which occupy a central role in ensuring the (cyber-)security of national authorities, providers of critical infrastructures and essential services. SOCs are tasked with monitoring, understanding and proactively managing cybersecurity threats. In light of the crucial operative role of SOCs for ensuring cybersecurity in the Union, the nature of the technologies involved as well as the sensitivity of the information handled, SOCs must be protected against possible dependencies and vulnerabilities in cybersecurity to pre-empt foreign influence and control. As previously noted, participation of non-EU entities entails the risk of highly sensitive information about security infrastructure, risks and incidents being subject to legislation or pressure that obliges those non-EU entities to disclose this information to non-EU governments, with an unpredictable security risk. Therefore, based on the outlined security reasons, the actions relating to SOCs are subject to Article 12(5) of Regulation (EU) 2021/694, in consistency with WP 2021/2022.

Eligibility & Conditions

Conditions

Conditions



1. Admissibility conditions: described in section 5 of the call document 

Proposal page limits and layout: described in Part B of the Application Form available in the Submission System

2. Eligible countries: described in section 6 of of the call document

3. Other eligibility conditions: described in section 6 of the call document

4. Financial and operational capacity and exclusion: described in section 7 of the call document

  • Award criteria, scoring and thresholds: described in section 9 of the call document

  • Indicative timeline for evaluation and grant agreement: described in section 4 of the call document

6. Legal and financial set-up of the grants: described in section 10 of the call document

Documents



Call document is accessible here

Standard application form — call-specific application form is available in the Submission System

Detailed budget table - available in the Submission System

DIGITAL EUROPE PROGRAMME General MGA v1.0

Guidance Classification of information in DIGITAL projects

Guidelines on How to Complete your Ethics Self-Assessment

Guidance on participation in DEP - restricted calls 

Support & Resources

For help related to this call, please contact us here

Funding & Tenders Portal FAQ – Submission of proposals.

IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc.

Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and submission to reporting on your on-going project. Valid for all 2021-2027 programmes.

Latest Updates

Last Changed: July 17, 2024

For information on the evaluations results of this call we invite you to consult the Flash call info (evaluation results) in the following link.

Last Changed: January 16, 2024
The submission session is now available for: DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STANDARDPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-TRANSITIONEUPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH(DIGITAL-JU-SIMPLE), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRA(DIGITAL-JU-SME), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STRENGTHENCRA(DIGITAL-JU-GFS), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-PQCINDUSTRY(DIGITAL-JU-SIMPLE)