Cybersecurity is a fundamental property in the complete lifecycle for digital systems, and cyber-physical systems in particular, as a means of enabling safety and resilience. We aim to develop cybersecurity principles, methods and tools for the future of assurance of cyber-physical systems.
Cybersecurity assurance is the act of providing confidence to an organization that their digital systems, infrastructure, data, and processes are protected and functioning as intended, even in the face of cyber threats. Cybersecurity assurance must be continuous and cannot be done at isolated points in time only. Technologies, vulnerabilities, and threats are constantly changing, and stakeholders like vendors and system owners need continuous insight into the cybersecurity state of their systems. Emerging regulations introduce new compliance requirements for both providers and owners of digital systems and services.
We investigate how best practices from IT and OT/security and safety could be combined and addressed in the same risk approach. Cyber risk quantification, monitoring and continuous risk management of cyber-physical systems, and how new technologies such as AI and quantum will both challenge and support cybersecurity practices are among our strategic research challenges.
Explore our cybersecurity research projects
CyberNEMO
Building on the NEMO (Next Generation Meta Operating System) project, the CyberNEMO project strengthens end‑to‑end cybersecurity and trust across IoT-Edge-Cloud environments (often called the computing continuum). This EU‑funded research initiative brings together DNV and 22 partner organizations to advance cybersecurity resilience, risk preparedness, situational awareness, threat detection, and mitigation for critical infrastructure and its supply chains.
CertifAI
The EU‑funded CertifAI research project brings together DNV and 11 partner organizations. The aim of the project is to investigate and develop AI‑empowered approaches to the certification of information and communication technology (ICT) systems, driven by emerging EU cybersecurity legislation.