A group of companies presented the project in light of the increase in digital threats and the growing exposure of corporate systems on the internet, as they wanted to acquire, increase, or update their cybersecurity knowledge. The rapid digitisation of processes, the interconnection of supply chains and the adoption of Industry 4.0 models have increased the attack surface, exposing technical and organisational vulnerabilities that these companies are only just starting to address. Added to this was the need to understand, and in some cases apply, the obligations of the NIS2 Regulation, for which the companies lacked the necessary skills and tools. The project therefore emerged from a concrete need to raise awareness, assess real risks, and understand legislative aspects, with the ultimate goal of enhancing security and/or regulatory compliance.
In response to the needs of companies, the CyberAges project provided a structured programme combining group training sessions, experience sharing and best practice, with individual activities involving assessment and customisation of advanced security monitoring tools. The group sessions increased awareness of cyber risks and current regulatory obligations, while the individual programme enabled each company to assess its cyber posture and the critical issues of internal digitisation and the supply chain with regard to cybersecurity. The programme also introduced software to address threats in a structured manner through continuous monitoring. Companies were able to transform knowledge and data into operational actions, significantly improving their ability to prevent, detect and manage cyber risk.
The project can be applied to companies of all sizes and in all product sectors, either individually or in groups. In the latter case, the sharing of experiences, skills, and best practices is preserved.
The three-lever growth model (comprising training, assessment and the initiation of a technological innovation process) can also be applied to other aspects of digitisation.