This technical paper analyses the growing cybersecurity risks associated with modern software supply chains, where development increasingly relies on third-party components, tools, and open-source dependencies. It examines the software development lifecycle, identifies key vulnerabilities introduced by complex dependency chains, and highlights the implications of upstream compromises. The paper provides recommendations aligned with relevant frameworks and best practices to reduce risk exposure, strengthen secure development processes, and enhance the resilience of the software ecosystem.
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Emerging Technologies
Cyber Ranges Glossary: Key Terms and Concepts
- Published date:
- Author: CYBER RANGES
This glossary provides a concise reference guide to the core terminology used in the field of cyber ranges. Covering concepts such as attack simulation, cyber exercises, orchestration, red and blue teams, virtual machines, and offensive cyber capabilities, it helps readers build a common understanding of the technical and operational language surrounding cyber range environments and cybersecurity training.
- Compliance Standards
Actions Beyond Words: Automating Audits for Streamlined Cybersecurity Compliance in Europe
- Published date:
- Author: ECSO (European Cyber Security Organisation)
This ECSO publication explores how the Open Security Controls Assessment Language (OSCAL) could support the automation and standardisation of cybersecurity compliance processes across Europe. Set against the growing complexity of EU cybersecurity legislation, it examines how machine-readable control frameworks and OSCAL-based governance, risk, and compliance tools can enable faster assessments, continuous monitoring, and more efficient audits. The document also outlines the conditions needed for broader adoption, including pilot testing, institutional support, and alignment across national authorities and supply chains.
- Application Security
KIOKU: Gamified Scenario-Based Cybersecurity Training for SMEs (NeRO Project)
- Published date:
- Author: NERO - AdvaNced cybErsecurity awaReness ecOsystem for SMEs
KIOKU is an online, gamified cybersecurity training platform offering AI-supported, scenario-based learning tailored to SMEs in healthcare, finance, and logistics. Participants engage in realistic cyber incident scenarios from the perspectives of IT personnel, non-IT staff, and managers, receiving immediate feedback on their decisions. With multiple difficulty levels and performance analytics dashboards, KIOKU supports behavioural learning, strengthens cyber awareness, and enhances organisational decision-making and resilience across diverse workplace environments.
- Compliance Standards
NIS2 Implementation – Challenges, Fragmentation and Readiness Across the EU
- Published date:
- Author: European Cyber Security Organisation
This white paper provides a comprehensive analysis of the current state of NIS2 implementation across EU Member States and affected organisations. Drawing on a Europe-wide survey of cybersecurity practitioners and sectoral case studies, it highlights fragmentation in national transpositions, inconsistencies in incident reporting timelines and classification approaches, and significant gaps in budget allocation and management engagement. The report offers actionable recommendations to support harmonised implementation and strengthen organisational readiness under the NIS2 Directive.
- Forensic Analysis and Incident Response
Cybersecurity Exercise Methodology
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Cybersecurity Exercise Methodology provides an end-to-end framework for planning, conducting, and evaluating cybersecurity exercises. Based on lessons learned and industry best practices, it ensures the right stakeholders are involved at the appropriate stages of exercise design and execution. The methodology is complemented by a practical support toolkit, including templates and guiding materials to help organisations implement effective and structured cyber exercises.
- Risk Management
Protecting Data from Ransomware and Data Loss (NIST NCCoE, 2020)
- Published date:
- Author: National Institute of Standards and Technology
This NIST NCCoE guide provides practical recommendations to help Managed Service Providers (MSPs) design, maintain, and test backup files to reduce the impact of ransomware and other data loss events (e.g., hardware failure, accidental or malicious deletion). It supports implementation of the NIST Cybersecurity Framework subcategory PR.IP-4 by outlining considerations for backup planning, selecting backup services/products, ensuring backup availability and integrity, and strengthening disaster recovery readiness. The guidance is adaptable—MSPs can apply only the recommendations relevant to their operational context.
- Data Protection and Privacy
Online Tracking and User Protection Mechanisms: Technical Implementation of User Consent and Do Not Track (DNT)
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This ENISA study examines online tracking technologies and the technical mechanisms available to protect users’ privacy, with a particular focus on user consent, privacy settings, and the implementation of the Do Not Track (DNT) standard. Set against the evolving EU legal landscape, including the GDPR and the proposed ePrivacy Regulation, the report analyses tracking risks and provides targeted recommendations for service providers, user agents, policymakers, and regulators to strengthen user protection and ensure meaningful, technically valid consent online.
- Risk Management
Guide for Conducting Risk Assessments
- Published date:
- Author: National Institute of Standards and Technology (NIST)
NIST Special Publication 800-30 Rev. 1 provides structured guidance for conducting cybersecurity risk assessments across information systems and organizations. It supports decision-making at all levels of the risk management hierarchy by outlining methodologies to identify threats, vulnerabilities, impacts, and residual risks. The guide complements NIST SP 800-39 and serves as a foundational reference for integrating risk assessment into enterprise-wide risk management and security control selection.
- Risk Management
#StopRansomware Guide: Prevention and Response Best Practices
- Published date:
- Author: Cybersecurity and Infrastructure Security Agency (CISA)
This guide from CISA, MS-ISAC, NSA, and the FBI provides actionable best practices for preventing and responding to ransomware and data extortion attacks. It includes two core parts: (1) Prevention guidance based on common attack vectors, including credential compromise and social engineering, and (2) A detailed response checklist with detection and threat hunting steps. The guide aligns recommendations with CISA’s Cross-Sector Cybersecurity Performance Goals and highlights the evolving tactics of ransomware actors, including double extortion. Ideal for IT and cybersecurity professionals across sectors.