“TECNALIA is developing a transformative approach in order to automate regulatory compliance and cybersecurity assurance”
The European SECASSURED project is deeply transforming the way companies design, validate and operate their digital systems
It aims to implement a continuous security model based on AI and the use of digital twins. This model is boosting assurance in the entire IoT-edge-cloud ecosystem and responding to the increasing regulatory and operational demands faced by SMEs and industrial organisations in Europe.
The consortium is made up of 19 industry and academia partners from 10 countries, collaborating to build a more secure and resilient digital industry. The participating entities work in a common environment with AI-based security tools, protected virtual spaces and SecDevOps and MLOps processes focused on continuous assessment.
TECNALIA’s contribution to automate cybersecurity compliance and assurance
An AI assistant that translates regulations into concrete actions
TECNALIA is developing a transformative approach in order to automate regulatory compliance and cybersecurity assurance.
- It proposes the integration of large-scale language models, generative AI and advanced analysis technologies to create a two-level assistant.
- This assistant interprets evolving regulations and standards and translates them into actionable safety assurance cases.
- It also links compliance requirements with activities, evidence and assessment results with full traceability and audit readiness.
Simulating attacks with AI to build resilience
TECNALIA is also promoting a complementary AI-based attack simulation service.
- This service uses the generated assurance cases to run security simulations and detect systemic risks, vulnerabilities and threats through red teaming and automated scenario testing.
- This approach accelerates compliance by reducing manual interpretation and builds resilience by validating security controls in advance.
We are helping to create a European model in which security is no longer a reactive process but a continuous, auditable component, aligned with the real needs of companies.
