CyRille - Future-Proof Through Cyber Resilience

Cyberattacks on critical infrastructure are not a question of ‘if’, but of ‘when’. As part of the CyRille project, the Fraunhofer IOSB-AST is developing practical assessments and training programmes within the framework of the Cybersecurity Learning Lab, with the aim of sustainably increasing the resilience of KRITIS facilities.

The Situation: Critical Infrastructure in the Crosshairs

Critical infrastructure facilities – ranging from energy supply and healthcare to water management – are increasingly the target of complex cyber-attacks. A successful attack can have far-reaching consequences: supply shortages, disruptions to public safety or economic damage on a significant scale. The Federal Office for Information Security (BSI) classifies such facilities as requiring special protection. At the same time, the current threat landscape shows that purely preventative measures alone are not sufficient. Rather, organisations must be able to detect attacks at an early stage, respond to them in a targeted manner and restore normal operations as quickly as possible – in short: they must become cyber-resilient.

Target

This is precisely where the CyRille project comes in. As part of the Cybersecurity Learning Lab at Fraunhofer IOSB-AST, practice-oriented services are being developed to help KRITIS operators systematically assess and specifically improve their cyber resilience. The project has two main strands:

  1. Customised cyber resilience assessments – bespoke analyses that determine an organisation’s current level of cyber resilience and provide specific recommendations for action.
  2. Targeted professional development programmes – modular training courses designed to enable staff at all levels to recognise threats and respond appropriately.

Our Approach

CyRille is based on a holistic cyber resilience cycle comprising five phases that build on one another:

  1. Identify: Identify critical systems, processes and dependencies
  2. Protective measures: Implement and maintain appropriate protective measures
  3. Detection: Detecting security incidents and anomalies at an early stage
  4. Responding: Responding to incidents in a structured and effective manner
  5. Recovery: Rapidly restore affected systems and return to normal operations

This cycle forms the foundation for both the assessments and the training programmes. It ensures that technical, organisational and human aspects are given equal consideration – from risk analysis through incident response to business continuity management.

Our Expertise

Fraunhofer IOSB-AST is contributing its extensive expertise from the Cybersecurity Learning Lab to the project. For many years, we have been conducting research and providing training at the interface between IT security and industrial infrastructures. In the CyRille project, we are drawing on this experience to:

  • to develop sector-specific assessment methods that go beyond generic security audits and address the specific requirements of KRITIS sectors,
  • realistic training scenarios in which participants can practise dealing with cyber attacks under controlled conditions – from detection through to escalation and recovery,
  • to provide field-tested assessment tools that enable the maturity level of cyber resilience to be measured and compared, and
  • to continuously evaluate the effectiveness of the measures developed and to refine them on the basis of the results.

Through the close integration of research, consultancy and professional development, CyRille facilitates a seamless transfer of knowledge – from the latest threat research right through to the day-to-day operations of the participating organisations.

Impact and Outlook

With CyRille, Fraunhofer IOSB-AST is making an important contribution to safeguarding infrastructure that is vital to society. The project is providing new impetus for the systematic assessment and sustainable strengthening of resilience against cyber threats. The methods and formats developed are designed to be transferable to different KRITIS sectors and can be incorporated into the Cybersecurity Learning Lab’s service portfolio in the long term.