FROM RESEARCH TO DEPLOYMENT

European Cyber Resilience Forum

Thursday 12 November 2026 · Bucharest & online

One day. Seven use cases. Six SOC capabilities in the making. SOC teams, critical infrastructure operators, national authorities, researchers and technology providers, in Bucharest and online.

Come to see where the technology stands, say what your sector actually needs, and shape the recommendations Europe hears next.

Join the list See the programme Free · in person or online
1
Day, hybrid
6
SOC capabilities
7
Sector use cases
13
Partner organisations

Voices in the Room

The programme brings together institutional, operational and research perspectives. Speakers are being confirmed, and names are announced here as each contributor confirms.

EU

European institutions

Policy and programme perspective on Europe's SOC ecosystem.

NA

National authorities

What NIS2 supervision looks like from the regulator's side.

SOC

SOC and CSIRT leads

Operational reality: alert volume, staffing, interoperability.

CI

Critical infrastructure

Energy, health, maritime, retail and digital services.

R&D

Researchers and builders

The teams developing the CYBERGUARD capabilities.

Six Links in One Chain

More alerts do not make a SOC stronger. What matters is whether the chain holds from the first signal to the fix. The Forum walks through it, link by link.

01
DETECT

Spot the anomaly in the traffic, not just the known signature.

AI-driven anomaly and intrusion detection

02
ANALYSE

Work out what the sample or the behaviour actually does.

Advanced malware analysis toolkit

03
SHARE

Move the intelligence to the next SOC without leaking what should stay private.

Automated CTI sanitiser and CTI ontology

04
DECIDE

Put the alert in context so an analyst can rank it against everything else.

Analyst dashboard and knowledge correlation

05
RESPOND

Contain it, including when the target is the AI system itself.

LLM attack mitigation and defence mechanisms

06
REMEDIATE

Turn the finding into steps an operator can actually carry out.

AI-assisted remediation guidance

These capabilities are in development. The Forum shows where each one stands and what it will take to get it into operational use.

Seven Sectors, Seven Sets of Constraints

CYBERGUARD is validated across seven operational environments. The afternoon sector dialogue brings the operators behind them into the same conversation.

Energy

Industrial control systems

What the operator needed, what the architecture had to accommodate, and where it is now.

Health

Hospital networks

How containment is designed when downtime is not an option.

Retail

Point-of-sale estates

What scales across a large estate of endpoints, and what does not.

Maritime

Fleet IT and OT

Security operations when the asset is at sea and the link is not.

Digital services

Advertising and online platforms

Where automated decisions hold up, and where they need an analyst.

Cybersecurity

A managed SOC, instrumented

What changes in a SOC's own posture once its AI tooling is in scope.

Energy

Cross-operator cooperation

How a threat travels from one operator's detection to a coordinated response.

All seven pilots

Read the full use cases

On the project page

Regulation in the Morning, Operations After Lunch

A single track on Thursday 12 November 2026, 09:30 to 16:00, in the room and streamed. Two panels, a technical snapshot of what the project has built, and a sector dialogue with the operators running the pilots.

Provisional programme. Times are local (EET) and contributors are still being confirmed.

Join the list
09:30

Registration and coffee

You collect your badge and your node number.

10:00

Opening remarks

CYBERGUARD and the European cyber resilience agenda.

10:15

Institutional keynote

Strengthening Europe's SOC ecosystem through AI, threat intelligence and cooperation.

10:35

CYBERGUARD overview

Objectives, consortium, use cases and expected impact.

11:00

Panel 1 · From NIS2 and the CRA to operational resilience

What the regulation asks for, and what it takes to deliver it on the ground.

11:45

Coffee break

12:00

Panel 2 · CTI sharing and SOC interoperability

Why intelligence still does not move cleanly between SOCs, CSIRTs and operators.

12:45

Technical snapshot

Malware analysis, CTI, AI-supported detection and incident response.

13:15

Networking lunch at the wallSignature

The networking hour, with something to actually do.

14:15

Sector dialogue

Cybersecurity needs in energy, healthcare, maritime, retail and digital services.

15:00

Policy and operational recommendations

First directions from CYBERGUARD, and what the room would change.

15:30

Synergies with other EU-funded projects

15:50

Conclusions and next steps

The wall is photographed before anyone leaves.

200 people. 200 nodes.
One European resilience network.

Resilience is a property of the network, not of any one organisation. So we made the network visible: a three-metre panel at the entrance, two hundred empty circles, one of them yours.

01

Find your node

The number is printed on your badge.

02

Write your initials

Inside the circle, in marker.

03

Draw a line

To every person you actually meet.

At 09:00 the wall is blank. At 17:30 it is a map of the room, drawn by the room.

The Network Wall 17:30 · 76 connections
DH NE DV RS IM DO EP DZ GT LL HE SP TH JW AK EL FW RE CZ SK KN MU MG EG WZ FV DF LE ML GN DK EB PS BE VE DN KL LT UN ML OL LN EF LL UK LJ RG PZ AP NC SP NZ HJ
How the panel reads at the end of the day. Every line was drawn by two people who met.

The People Who Rarely Sit at the Same Table

A national authority, the vendor shipping the patch, the CSIRT that saw it first and the operator running the plant rarely plan together. For one day, they do.

National cybersecurity authorities SOC managers and analysts CSIRT teams Critical infrastructure operators NIS2 entities European institutions and agencies Industry and vendors Academia and EU-funded projects

Be First to Know When Seats Open

12 November 2026, in Bucharest and online. Leave your details and you will hear from us before registration opens publicly — the room is capped, and the list is how we fill it.

We use your details only to contact you about this event. Nothing else, no newsletter by default, no sharing with partners.

Data controller: the CYBERGUARD consortium. You can ask us to delete your details at any time by writing to the address on the contact page.

Questions People Actually Ask

When is it?

Thursday 12 November 2026, 09:30 to 16:00 (EET), in Bucharest and streamed online. The venue is being finalised and goes out with your confirmation.

What does it cost?

Nothing. Attendance is free. Travel and accommodation are your own.

Can I attend online?

Yes. The Forum is hybrid. The full programme is streamed, and the sessions that take questions take them from both rooms.

Where in Bucharest?

The venue is being confirmed. It will be centrally located and step-free, with the full address sent with your confirmation.

Is the room capped?

Seats in Bucharest are limited and allocated from the list. Online places are not.

What language?

English throughout, including the sector dialogue and the policy session.

Can I speak or contribute?

Panel places are being confirmed with the consortium, but the policy session takes contributions from the floor. Say so in the form and we will get in touch.

Will it be recorded?

The event is streamed. Which sessions stay available afterwards is still being agreed with the speakers.

Will you photograph me?

There will be a photographer. You will be asked for consent at registration, and you can decline without any fuss.

Do I have to write on the wall?

No. It is an invitation, not an obligation. Plenty of people will just look at it.