OWASP Juice Shop is an intentionally insecure web application designed for hands-on security training, awareness exercises, capture-the-flag challenges, and testing of security tools. Built with modern web technologies, it includes vulnerabilities from the OWASP Top 10 and other common application security flaws, allowing learners to practice identifying and exploiting weaknesses in a safe environment. It is widely used for ethical hacking, secure coding awareness, and application security education.
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Compliance Standards
EU AI Act: Cybersecurity, Risk Management and Trustworthy AI Governance Framework
- Published date:
- Author: European Parliament & Council of the European Union
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) establishes a risk-based framework for the secure and trustworthy development, deployment, and use of AI systems across the European Union. From a cybersecurity perspective, the regulation introduces strict requirements for high-risk AI systems, including risk management, robustness, resilience against attacks, and protection against data manipulation and system vulnerabilities. It also sets obligations for general-purpose AI models to address systemic risks, enhance transparency, and ensure secure lifecycle management. By integrating cybersecurity into AI governance—alongside compliance, monitoring, and incident response—the AI Act strengthens the resilience of digital systems and mitigates emerging threats associated with AI technologies.
- Introductory Courses to Cybersecurity
Cybersecurity Essentials: Basic Online Safety Course for Everyday Digital Use
- Published date:
- Author: Cyber Citizen
This free, self-paced online course introduces the essentials of cybersecurity for everyday users. It covers core topics such as password security, phishing, social media privacy, and personal data protection, helping learners recognise common cyber threats and take simple steps to protect their devices, accounts, and information. Designed for beginners and available in all 24 official EU languages, the course supports safe and confident use of digital services in daily life.
- Compliance Standards
ECSO Reaction to the Cybersecurity Act Revision and NIS2 Directive Amendments
- Published date:
- Author: European Cyber Security Organisation (ECSO)
This ECSO publication provides a policy analysis of the proposed revision of the Cybersecurity Act and amendments to the NIS2 Directive. It highlights key priorities for strengthening the EU cybersecurity framework, including the need for harmonised baseline security requirements, proportionate implementation based on organisational size and risk, and improved coordination among Member States. Drawing on stakeholder consultations, the report offers recommendations to enhance legal clarity, reduce fragmentation, and support effective governance across the European cybersecurity landscape.
- Threat Intelligence
Software Supply Chain Security: Risks, Dependencies and Best Practices for Secure Development
- Published date:
- Author: European Cyber Security Organisation (ECSO)
This technical paper analyses the growing cybersecurity risks associated with modern software supply chains, where development increasingly relies on third-party components, tools, and open-source dependencies. It examines the software development lifecycle, identifies key vulnerabilities introduced by complex dependency chains, and highlights the implications of upstream compromises. The paper provides recommendations aligned with relevant frameworks and best practices to reduce risk exposure, strengthen secure development processes, and enhance the resilience of the software ecosystem.
- Emerging Technologies
Cyber Ranges Glossary: Key Terms and Concepts
- Published date:
- Author: CYBER RANGES
This glossary provides a concise reference guide to the core terminology used in the field of cyber ranges. Covering concepts such as attack simulation, cyber exercises, orchestration, red and blue teams, virtual machines, and offensive cyber capabilities, it helps readers build a common understanding of the technical and operational language surrounding cyber range environments and cybersecurity training.
- Compliance Standards
Actions Beyond Words: Automating Audits for Streamlined Cybersecurity Compliance in Europe
- Published date:
- Author: ECSO (European Cyber Security Organisation)
This ECSO publication explores how the Open Security Controls Assessment Language (OSCAL) could support the automation and standardisation of cybersecurity compliance processes across Europe. Set against the growing complexity of EU cybersecurity legislation, it examines how machine-readable control frameworks and OSCAL-based governance, risk, and compliance tools can enable faster assessments, continuous monitoring, and more efficient audits. The document also outlines the conditions needed for broader adoption, including pilot testing, institutional support, and alignment across national authorities and supply chains.
- Application Security
KIOKU: Gamified Scenario-Based Cybersecurity Training for SMEs (NeRO Project)
- Published date:
- Author: NERO - AdvaNced cybErsecurity awaReness ecOsystem for SMEs
KIOKU is an online, gamified cybersecurity training platform offering AI-supported, scenario-based learning tailored to SMEs in healthcare, finance, and logistics. Participants engage in realistic cyber incident scenarios from the perspectives of IT personnel, non-IT staff, and managers, receiving immediate feedback on their decisions. With multiple difficulty levels and performance analytics dashboards, KIOKU supports behavioural learning, strengthens cyber awareness, and enhances organisational decision-making and resilience across diverse workplace environments.
- Compliance Standards
NIS2 Implementation – Challenges, Fragmentation and Readiness Across the EU
- Published date:
- Author: European Cyber Security Organisation
This white paper provides a comprehensive analysis of the current state of NIS2 implementation across EU Member States and affected organisations. Drawing on a Europe-wide survey of cybersecurity practitioners and sectoral case studies, it highlights fragmentation in national transpositions, inconsistencies in incident reporting timelines and classification approaches, and significant gaps in budget allocation and management engagement. The report offers actionable recommendations to support harmonised implementation and strengthen organisational readiness under the NIS2 Directive.
- Forensic Analysis and Incident Response
Cybersecurity Exercise Methodology
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Cybersecurity Exercise Methodology provides an end-to-end framework for planning, conducting, and evaluating cybersecurity exercises. Based on lessons learned and industry best practices, it ensures the right stakeholders are involved at the appropriate stages of exercise design and execution. The methodology is complemented by a practical support toolkit, including templates and guiding materials to help organisations implement effective and structured cyber exercises.