GRYPHON-EWS
Strengthening Europe's Cyber Resilience
(Project Summary)
GRYPHON-EWS is an EU-funded project building the next generation of threat intelligence, defence, and incident response, powered by behavioural analysis and collective, sector-wide protection.
In an era where ransomware and cybercrime-as-a-service threaten Europe’s critical infrastructure, GRYPHON-EWS delivers a complementary layer of intelligent defence that works alongside your existing security stack.
What We Do
GRYPHON-EWS is a cutting-edge, AI-driven, threat intelligence, defence and incident response platform built around behavioural analysis. Unlike standalone solutions, it complements your existing EPP/EDR/XDR/SIEM/CTI tools, adding a layer of cross-client monitoring that enables sector-based threat pattern detection across multiple organisations.
Built as an essential component for Security Operations Centres (SOCs) and Managed Security Service Providers (MSSPs), the platform goes beyond traditional security. By combining endpoint protection, external threat intelligence, vulnerability scanning and automated defence, GRYPHON-EWS creates a collective shield for the sectors that matter most: energy, healthcare, transportation and financial services.
Proven Track Record
GRYPHON-EWS builds on the proven IstroSec ransomware protection toolkit. Since its commercialization in January 2025, the foundational GRYPHON RPT has safeguarded over 11,500 endpoints across servers and workstations with zero ransomware breaches reported. GRYPHON-EWS extends these capabilities with advanced external threat and vulnerability intelligence, taking collective defence to the next level.
Built for Europe’s Regulatory Landscape
GRYPHON-EWS is designed to help organisations meet the demands of Europe’s evolving cybersecurity framework, including the NIS2 Directive, the Digital Operational Resilience Act (DORA), the EU Cyber Resilience Act (CRA), and the EU Cyber Solidarity Act.
Our Mission
Over a 36-month project, GRYPHON-EWS will develop, deploy and promote a robust early warning system to:
- Detect Malicious Intent by identifying APT groups and advanced ransomware attacks before they strike.
- Raise Awareness about cyber threats and Disseminate Results to key stakeholders in the cybersecurity ecosystem across EU Member States with the ultimate goal of advancing collective cyber defence.
- Drive Adoption through strategic partnerships, including the Global Channel Partner Program and direct engagement with critical infrastructure operators.
Why GRYPHON-EWS?
| Aspect | Description |
|---|---|
| Unique Capability | Cross-client monitoring for sector-wide threat detection |
| Complementary, Not Competitive | Works with your existing security stack |
| Behavioural Analysis | Detects threats by how they act, not just what they are |
| Collective Defence | Strengthens protection across organisations in the same sector |
| EU-Aligned | Built for Europe’s regulatory and threat landscape |
Project Roadmap
The GRYPHON-EWS project follows a structured, six-phase approach to develop, validate, and deploy a cutting-edge Early Warning System. From rigorous governance to real-world testing and market adoption, every work package (WP) is designed to strengthen Europe’s cyber resilience.
WP1: Project Management & Quality Assurance
The backbone of the project.
Ensuring the project runs efficiently, transparently, and to the highest standards. We coordinate administrative matters, establish a robust Project Quality Plan, and ensure strict adherence to financial, reporting, and ethical guidelines throughout the 36-month duration.
WP2: Requirements, Regulatory & Ethics Compliance
Building on a solid standard.
We align the GRYPHON-EWS solution with Europe’s evolving regulatory landscape (including NIS2 and DORA). This phase gathers precise user and technical requirements to ensure the new Threat Intelligence Module meets the real-world needs of critical infrastructure operators.
WP3: Optimization & Scaling Up
Reaching Technology Readiness Level 9 (TRL9).
We are enhancing and scaling the existing Gryphon Ransomware and Advanced Attack Protection Suite to ensure robust performance across diverse environments. Key modules being optimized include:
- Incident Response: Streamlining and automating detection and response.
- Proactive Patch Management: Strengthening pre-emptive defence mechanisms.
- MDR Platform: Enhancing Managed Detection and Response capabilities.
WP4: Threat Intelligence & MSSP Modules
The heart of the Early Warning System.
Developing the new cross-client capabilities that define GRYPHON-EWS. We are building Threat Intelligence and MSSP (Managed Security Service Provider) modules that extend detection beyond individual organizations, facilitating the publication and sharing of Advanced Cyber Threat Intelligence (CTI).
WP5: Deployment & Validation
Proving it works in the real world.
We deploy GRYPHON-EWS in selected environments to validate functionality through rigorous testing. The system is stress-tested against simulated ransomware and APT attacks to ensure accuracy in real-time threat detection and cross-client pattern analysis. User feedback is used to refine algorithms and ensure the system is ready for wide-scale sector adoption.
WP6: Communication, Dissemination & Exploitation
Driving adoption and awareness.
We raise awareness among industry leaders, cybersecurity professionals, and critical infrastructure operators. This phase focuses on:
- Knowledge Sharing: Engaging with cybersecurity communities and professional networks.
- Strategic Exploitation: Executing a market adoption plan through strategic partnerships and leveraging existing distribution channels to penetrate diverse markets effectively.
Project Timeline
2026: Foundation & Initial Development
- January 2026: Project officially begins.
- April 2026: Project administration and financial management setup.
- June 2026: Kick-Off Meeting, completion of the Project Quality Plan, and finalization of user/technical requirements analysis.
- September 2026: Publication of the User and Technical Requirements Specification.
- December 2026: Completion of scale-up infrastructure deployment and Year 1 KPI review.
2027: Testing, Scaling & Support
- March 2027: Launch of the EU-level customer support centre and full automation of testing processes.
- June 2027: Mid-term Review Meeting.
- December 2027: Year 2 KPI review and project output assessment.
2028: Final Validation & Market Readiness
- December 2028: Final Review Meeting, Year 3 KPI review, and project closure.
Project Deliverables & Timeline
| Category | Title | Target Date | Status |
|---|---|---|---|
| Requirements, Regulatory & Ethics Compliance | Requirements analysis complete | 30 Jun 2026 | ✓ |
| Optimization & Scaling Up | Completion of infrastructure modifications | 30 Jun 2026 | ✓ |
| Requirements, Regulatory & Ethics Compliance | Regulatory and ethical compliance assessment | 27 Mar 2027 | ✓ |
| Deployment & Validation | User feedback and optimisation report | 16 Dec 2028 | ⏳ |
| Threat Intelligence & MSSP Modules | Completion of threat intelligence and module system design | 30 Jun 2026 | ✓ |
| Threat Intelligence & MSSP Modules | Threat intelligence module design documentation | 30 Jun 2026 | ✓ |
| Threat Intelligence & MSSP Modules | Verified CTI repository and sharing protocols | 27 Mar 2027 | ✓ |
| Threat Intelligence & MSSP Modules | CTI feed development and integration report | 27 Mar 2027 | ✓ |
| Threat Intelligence & MSSP Modules | CTI extraction and verification mechanisms operational | 27 Dec 2026 | ✓ |
| Deployment & Validation | Cross-client threat pattern validation complete | 17 Oct 2028 | ⏳ |
| Optimization & Scaling Up | EU-level customer support centre built | 27 Mar 2027 | ✓ |
| Optimization & Scaling Up | Test and validation results | 27 Mar 2027 | ✓ |
| Optimization & Scaling Up | Completion of deployment of scale-up infrastructure | 27 Dec 2026 | ✓ |
| Deployment & Validation | Continuous deployment operational | 24 Aug 2027 | ⏳ |
| Deployment & Validation | First GRYPHON-EWS version ready | 22 Dec 2027 | ⏳ |
| Deployment & Validation | Report of the first EWS version deployment | 20 Apr 2028 | ⏳ |
| Deployment & Validation | Simulated attack validation report | 19 Jul 2028 | ⏳ |
| Optimization & Scaling Up | Scale-up plan | 30 Jun 2026 | ✓ |
| Communication, Dissemination & Exploitation | Market research | 28 Oct 2026 | ✓ |
| Communication, Dissemination & Exploitation | Exploitation plan | 27 Dec 2026 | ✓ |
| Communication, Dissemination & Exploitation | Launch of the global channel partner programme | 17 Oct 2028 | ⏳ |
| Communication, Dissemination & Exploitation | Communication and dissemination plan | 30 Jun 2026 | ✓ |
| Communication, Dissemination & Exploitation | Standard communication and dissemination materials ready | 22 Dec 2027 | ⏳ |
Project Roadmap
Project Management & Quality Assurance
The backbone of the projectEnsuring the project runs efficiently, transparently, and to the highest standards. We coordinate administration, quality assurance, reporting, financial management, risk management and ethical compliance during the entire 36-month project.
Requirements, Regulatory & Ethics Compliance
Building on a solid standardGathering user requirements while ensuring compliance with NIS2, DORA, CRA and the EU Cyber Solidarity Act. The platform is designed around the needs of European critical infrastructure.
Optimization & Scaling Up
Reaching Technology Readiness Level 9Optimizing and scaling the existing GRYPHON platform.
- Incident Response
- Patch Management
- MDR Platform
- Infrastructure Scaling
Threat Intelligence & MSSP Modules
The heart of the Early Warning SystemDeveloping cross-client behavioural analytics, shared Threat Intelligence, verified CTI repositories and MSSP capabilities for sector-wide protection.
Deployment & Validation
Real-world validationTesting the platform against ransomware, APT simulations and large-scale deployments to validate detection accuracy and operational readiness.
Communication, Dissemination & Exploitation
Driving adoptionBuilding awareness across Europe, executing dissemination activities, launching the partner programme and preparing the commercial exploitation strategy.