Enhancing the capacity of the Hellenic Consolidated Security Operation Center
Digital Europe Programme
Project no. 101127713
ABOUT
The proposal on enhancing the capacity of the Hellenic Consolidated Security Operation Center, aims to improve national cybersecurity resilience with faster detection and response to cybersecurity incidents and threats through the strengthening of the newly deployed EL-SOC, a national hub for sectoral SOCs, currently operating in the National Cybersecurity Authority of Greece (NCSA).
In particular, the project aims to develop EL-SOC’s cyber threat detection and analysis capabilities by leveraging all technologies to increase situational awareness and strengthen national-level capabilities.
The enhancement of the EL-SOC’s operation is directly linked to the implementation of relevant EU initiatives.
The EL-SOC Project specifically aims at acquiring technologies and services that will upgrade EL-SOC’s operational capacity in the following areas:
- Information collection and processing using state-of-the-art tools
- Appropriate infrastructures development to leverage the shared pool of knowledge among the national SOC networks (i.e., through creating a Data Lake)
- Information analysis and detection of threats/attacks
- Creation of reports and appropriate channels of information sharing
- Incident response
- Management, security, maintenance and operation of the SOC core infrastructure
- Improved stakeholders’ coordination and collaboration in responding to cyber incidents among stakeholders
OBJECTIVES
- Objective 1: To perform real-time control and analysis of data from public network traffic to detect malicious behavior and incidents affecting the resilience of network and information systems.
- Objective 2:To create a common pool of knowledge shared with the National SOC Network, providing support, guidance, and good practice, build on processes and procedures in investigating security threats/incidents and/or providing Incident Response services methodologies towards the mitigation of identified threats.
- Objective 3: To use state-of-the-art tools, platforms, infrastructure and technologies for the secure processing and exchange of critical information within the National SOC Network, utilizing artificial intelligence and machine learning tools
- Objective 4: To support and ensure increased availability, quality, usability, and interoperability of data within the National SOC Network, to develop awareness
- Objective 5: To provide data, support, and information to National SOC Network, the existing CERTs/CSIRTs, Information Analysis and Sharing Centers (ISACs), national critical infrastructures of the public or private sector, as well as to cooperate with cybersecurity organisations and companies at national and European level
- Objective 6: To participate along with other member states’ SOCs in cross-border SOC platforms at EU level as a central hub and single point of reference for all national SOCs, so as to contribute to the common cybersecurity situational awareness across the EU.
According to L.5002/2022
Article 31
Consolidated Security Operations Center (EL-SOC) – National SOC Network
EL-SOC is established and operates in the National Cybersecurity Authority which is under the supervision of the Ministry of Digital Governance. It is hosted in premises of National Cybersecurity Authority and its purpose is to act as the central point of the National SOC Network, which consists of independent and sectoral SOCs and support organizations in identifying, managing, responding and recovering from cyber attacks.
EL-SOC in particular:
- performs real-time monitoring and analysis of data from public network traffic to detect malicious behavior and incidents affecting the resilience of network and information systems,
- creates a common pool of knowledge, shared with the National SOC Network, providing support, guidance and good practices,
- uses state-of-the-art tools, platforms and technologies for the secure processing and exchange of data and ‘big data’ within the National SOC Network, including artificial intelligence (AI) and machine learning technologies,
- supports and ensures increased availability of information data within the National SOC Network and develops a common situational awareness,
- provides support to the National SOC Network, to existing CERTs/CSIRTs, to Information Analysis and Sharing Centers (ISACs), to critical infrastructures of the country and, where appropriate, cooperates with cybersecurity organizations and enterprises at national level,
- may, as the single central hub and single central reference point of existing SOCs at national level, exchange data with corresponding SOCs of other European Union (EU) Member States in the context of the implementation of the European Cybersecurity Strategy
PARTNERS
National Cyber Security Authority
Computer Technology Institute & Press DIOPHANTUS
Project Details
- Project number: 101127713
- Call: DIGITAL-ECCC-2022-CYBER-03
- Topic: DIGITAL-ECCC-2022-CYBER-03-SOC
- Type of action: DIGITAL JU Simple Grants
- Project starting date: 1 January 2024
- Project end date: 31 December 2026