← All research projects

DIGITAL EUROPE · Cybersecurity

ORPHEUS

Operational Resilience Platform for Holistic European Unified Security

Suite5 in ORPHEUS

Suite5 is the Scientific Coordinator of ORPHEUS and leads the work strand delivering the agentic-AI hotline and the cyber range. Its own technical contribution centres on the hotline: the core reasoning and orchestration engine that turns a conversation or an alert into a structured incident case, and the human-in-the-loop oversight and escalation framework that keeps automated decisions bounded, reviewable and safe to act on when the incident is high-impact or the model is uncertain.

Suite5 also contributes to requirements and architecture definition and takes part in the pilot on SME incident response and cross-border CSIRT collaboration, where the hotline and the incident lifecycle layer are exercised with SMEs and national CSIRTs under real operating conditions. Beyond the project, Suite5 is one of the partners exploiting the agentic-AI hotline assistant as a managed incident reporting, triage and guidance service for SMEs.

About the project

Small and medium-sized enterprises make up the overwhelming majority of European businesses, yet most operate without dedicated security staff, without complete visibility of their own systems and dependencies, and without a dependable route to expert help when an incident occurs. ORPHEUS addresses that implementation gap by joining prevention, incident readiness and response support into a single operational service continuum, rather than adding another set of standalone tools that need specialist configuration to be useful.

The platform brings together four connected capabilities. A Cybersecurity Toolkit maps IT, OT and AI assets and the dependencies between them, detects vulnerabilities and misconfigurations, and produces risk assessments and evidence packages aligned with the Cyber Resilience Act. A multilingual, non-commercial cyber helpline, driven by agentic AI, triages incidents, recommends immediate containment actions and escalates to human experts with the evidence already gathered. An Incident Lifecycle Management Layer turns a report into a tracked case and generates authority-ready notifications for structured exchange with national CSIRTs and CERTs. A modular cyber range converts recurring incident patterns and regulatory obligations into practical exercises for SME staff and first responders.

ORPHEUS is validated in four real-world settings: secure uptake of generative AI services by SMEs, cross-border incident response with national CSIRTs, SME cyber-resilience training, and a small manufacturing plant with OT/ICS equipment. SMEs are recruited across several NIS2-relevant sectors through innovation clusters and European Digital Innovation Hubs.

Interested in this line of work?

Talk to us about the capabilities behind ORPHEUS — as a research collaboration or a commercial engagement.

Get in touch