GRYPHON-EWS is an EU-funded project building the next generation of threat intelligence, defense, and incident response, powered by behavioural analysis and collective, sector-wide protection.
In an era where ransomware and cybercrime-as-a-service and APT groups threaten Europe's critical infrastructure, GRYPHON-EWS delivers a complementary layer of intelligent defense that works alongside existing security stack.
Overview & Impact
What We Do
GRYPHON-EWS is a cutting-edge, AI-driven, threat intelligence, defence and incident response platform built around contextual behavioural analysis. It complements various cyber security tools like EPP/EDR/XDR/SIEM tools, adding a layer of cross-client actionable intelligence and monitoring that enables sector-based threat pattern detection across multiple organisations.
Built as an essential component for Security Operations Centres (SOCs) and Managed Security Services Providers(MSSPs), the platform goes beyond traditional security. By combining endpoint protection, external threat intelligence, vulnerability scanning and automated defense, GRYPHON-EWS creates a collective shield for the sectors that matter most: energy, healthcare, transportation or financial services.
Our Core Mission
Over a 36-month project, GRYPHON-EWS will develop, deploy and promote a robust early warning system to:
- Detect Malicious Intent by identifying APT groups and advanced ransomware attacks before they strike.
- Raise Awareness about cyber threats and Disseminate Results to key stakeholders in the cybersecurity ecosystem across EU Member States with the ultimate goal of advancing collective cyber defence.
- Drive Adoption through strategic partnerships, including the Global Channel Partner Program and direct engagement with critical infrastructure operators.
Built for Europe's Regulatory Landscape
GRYPHON-EWS is designed to help organisations meet the demands of Europe's evolving cybersecurity frameworks, including the NIS2 Directive (2022/2555 and 2024/2690),
the Digital Operational Resilience Act (DORA) (2022/2554),
the EU Cyber Resilience Act (CRA) (2024/2847),
and the EU Cyber Solidarity Act (2025/38).
Proven Track Record
GRYPHON-EWS builds on the proven IstroSec's product - GRYPHON Ransomware Protection Toolkit (RPT). Since its commercialization in January 2025, the foundational GRYPHON RPT has safeguarded over 11,500 endpoints across servers and workstations with zero ransomware breaches reported. GRYPHON-EWS extends these capabilities with advanced external threat and vulnerability intelligence, taking collective defense to the next level.
Why GRYPHON-EWS?
Project Roadmap
The GRYPHON-EWS project follows a structured, six-phase approach to develop, validate, and deploy a cutting-edge Early Warning System. From rigorous governance to real-world testing and market adoption, every work package (WP) is designed to strengthen Europe's cyber resilience.
Project Management & Quality Assurance
The backbone of the projectEnsuring the project runs efficiently, transparently, and to the highest standards. We coordinate administrative matters, establish a robust Project Quality Plan, and ensure strict adherence to financial, reporting, and ethical guidelines throughout the 36-month duration.
Requirements, Regulatory & Ethics Compliance
Building on a solid standardWe align the GRYPHON-EWS solution with Europe's evolving regulatory landscape (including NIS2 and DORA). This phase gathers precise user and technical requirements to ensure the new Threat Intelligence module meets the real-world needs of critical infrastructure operators.
Optimization & Scaling Up
Reaching Technology Readiness Level 9 (TRL9)We are enhancing and scaling the existing GRYPHON defense and incident response toolkit to ensure robust performance across diverse environments. Key modules being optimized include:
- Incident Response: Streamlining and automating detection and response.
- Proactive Patch Management: Strengthening pre-emptive defense mechanisms.
- MDR Platform: Enhancing Managed Detection and Response capabilities.
Threat Intelligence & MSSP Modules
The heart of the Early Warning SystemDeveloping the new cross-client capabilities that define GRYPHON-EWS. We are building Threat Intelligence and MSSP (Managed Security Service Provider) modules that extend detection beyond individual organizations, facilitating the publication and sharing of Advanced Cyber Threat Intelligence (CTI).
Deployment & Validation
Proving it works in the real worldWe deploy GRYPHON-EWS in selected environments to validate functionality through rigorous testing. The system is stress-tested against simulated ransomware and APT attacks to ensure accuracy in real-time threat detection and cross-client pattern analysis. User feedback is used to refine algorithms and ensure the system is ready for wide-scale sector adoption.
Communication, Dissemination & Exploitation
Driving adoption and awarenessWe raise awareness among industry leaders, cybersecurity professionals, and critical infrastructure operators. This phase focuses on:
- Knowledge Sharing: Engaging with cybersecurity communities and professional networks.
- Strategic Exploitation: Executing a market adoption plan through strategic partnerships and leveraging existing distribution channels to penetrate diverse markets effectively.
Project Timeline
2026: Foundation & Initial Developmen
- January 2026: Project officially begins.
- March 2026: Setting up the Project finalized.
- June 2026:Completion of the Project Quality Plan Scale-up Plan and Design of Threat Intelligence Module based on user and technical requirements.
- December 2026:Completion of scale-up infrastructure deployment and Year 1 KPI review.
2027: Testing, Scaling & Support
- March 2027:Launch of the EU-level customer support centre and full automation of testing processes.
- June 2027: : Mid-term Review Meeting.
- December 2027: Official release of GRYPHON-EWS and Year 2 KPI review and project output assessment.
2028: Final Validation & Market Readiness
- April 2028 Report of first EWS version deployment.
- December 2028 Final Review Meeting, Year 3 KPI review, and project closure.
Project Traffic Light
Legend: Delivered on time In Progress Due in less than 8 weeks
| Category | Title | Target Date | Status |
|---|---|---|---|
| Requirements, Regulatory & Ethics Compliance | Requirements analysis complete | 30 Jun 2026 | |
| Optimization & Scaling Up | Completion of infrastructure modifications | 30 Jun 2026 | |
| Optimization & Scaling Up | Scale-up plan | 30 Jun 2026 | |
| Threat Intelligence & MSSP Modules | Completion of threat intelligence and module system design | 30 Jun 2026 | |
| Threat Intelligence & MSSP Modules | Threat intelligence module design documentation | 30 Jun 2026 | |
| Communication, Dissemination & Exploitation | Communication and dissemination plan | 30 Jun 2026 | |
| Communication, Dissemination & Exploitation | Market research | 31 Oct 2026 | |
| Threat Intelligence & MSSP Modules | CTI extraction and verification mechanisms operational | 31 Dec 2026 | |
| Optimization & Scaling Up | Completion of deployment of scale-up infrastructure | 31 Dec 2026 | |
| Communication, Dissemination & Exploitation | Exploitation plan | 31 Dec 2026 | |
| Requirements, Regulatory & Ethics Compliance | Regulatory and ethical compliance assessment | 31 Mar 2027 | |
| Optimization & Scaling Up | EU-level customer support centre built | 31 Mar 2027 | |
| Optimization & Scaling Up | Test and validation results | 31 Mar 2027 | |
| Threat Intelligence & MSSP Modules | Verified CTI repository and sharing protocols | 31 Mar 2027 | |
| Threat Intelligence & MSSP Modules | CTI feed development and integration report | 31 Mar 2027 | |
| Deployment & Validation | Continuous deployment operational | 31 Aug 2027 | |
| Deployment & Validation | First GRYPHON-EWS version ready | 31 Dec 2027 | |
| Communication, Dissemination & Exploitation | Standard communication and dissemination materials ready | 31 Dec 2027 | |
| Deployment & Validation | Report of the first EWS version deployment | 30 Apr 2028 | |
| Deployment & Validation | Simulated attack validation report | 31 Jul 2028 | |
| Deployment & Validation | Cross-client threat pattern validation complete | 31 Oct 2028 | |
| Communication, Dissemination & Exploitation | Launch of the global channel partner programme | 31 Oct 2028 | |
| Deployment & Validation | User feedback and optimisation report | 31 Dec 2028 |