GA:101308832PROGRAMME:HORIZON-CL3NODES:14COUNTRIES:9CONSENSUS:60/75/90TARGET:<15MINSTART:2026-10-01
Horizon Europe · Innovation ActionGA 101308832TRL 4 → 7

Collective cyber defence, without surrendering sovereignty.

Europe's defenders work in isolation while attackers coordinate across borders. LATTICE builds the federated layer that lets organisations detect, decide and respond together — with no central authority and no sharing of sensitive data.

lattice-project.eu · October 2026 – September 2029 · Coordinated by LIST, Luxembourg

€5.14M
EU FUNDING · ECCC
36 MO
10.2026 → 09.2029
TRL 4→7
LAB → OPERATIONAL
4 PILOTS
LIVE TELEMETRY · DE EL NL LU
Axonometric blueprint of four operations rooms — a cloud platform, a hospital SOC, a university SOC and a national CSIRT — connected by annotated data-flow trajectories carrying encrypted packets.
How a federation shares threat intelligence · AI-generated illustration

The problem

Attackers coordinate across borders. Defenders don't.

Hospitals discover ransomware days after neighbouring facilities faced identical threats. Financial institutions miss sector-wide campaigns. Fragmented defence across 27 Member States costs European organisations an estimated €43 billion every year.

Speed asymmetry194 days vs 84 min

Median time to identify an intrusion, against the time attackers need for lateral movement. That separation is what makes purely reactive defence impossible.

Coordination lag12–24 h

Documented delay to establish cross-border sharing during incidents today. LATTICE targets coordinated response in under 15 minutes.

Privacy dilemma62%

Share of EU organisations kept out of threat-intelligence sharing by GDPR exposure concerns. Collective defence fails when most defenders cannot participate.

These figures — and the market figures quoted elsewhere on this site — were accurate when last checked, in November 2025.

The approach

Three innovations, one federated system

LATTICE removes the false choice between isolated defence and centralised aggregation. Peer-to-peer by design, it lets thousands of organisations in the scope of the EU's NIS2 directive act as one — while each keeps full custody of its data and decisions.

Innovation 01 · WP4

Jury Protocol — federated consensus

Graduated response across autonomous security operations centres (SOCs) with no central authority: 60% consensus triggers enhanced monitoring, 75% coordinated investigation, 90% full containment. Byzantine-fault-tolerant with up to 33% of nodes acting maliciously.

Target: cross-border coordination < 15 min
Innovation 02 · WP3

Privacy-preserving correlation

Peer-to-peer secure multi-party computation correlates threats over encrypted telemetry. Organisations verify that attack patterns match — without revealing detection methods or vulnerable systems. Zero-knowledge proofs, evaluated against NIST SP 800-226.

Target: 99.9% privacy guarantee
Innovation 03 · WP5

Federated digital twin network

Shared cyber-range infrastructure to rehearse dangerous responses safely before they touch production. Roughly 10× cheaper than the €500K–€2M of a dedicated range — opening pre-deployment validation to the SMEs that make up 70% of NIS2 entities.

Validation cycles: 6–8 weeks → 24–48 h

Evidence

Four pilots. Real telemetry. Six months continuous.

These are not demos. Each pilot runs continuously for six months on live security telemetry — real events, no synthetic data — producing the operational evidence for technology readiness level 7 (TRL 7) by September 2029.

GermanyPilot 1

Cross-sector threat intelligence

Federated detection and adversary emulation spanning telecom, finance, utilities and education infrastructure — sectors that today discover shared campaigns in isolation.

Lead: Mitigant
GreecePilot 2

Healthcare under protection

A live 250-bed hospital defended by the federation — with digital-twin validation keeping false positives away from patient safety, and patient privacy untouched.

Leads: Digital for Planet · Medisys
NetherlandsPilot 3

Federated SOC collaboration

Real-time coordination between security operations centres processing over one million events a day — operational secrecy intact on every side.

Lead: Eindhoven University of Technology
LuxembourgPilot 4

EU-wide vulnerability intelligence

Accelerated advisory distribution across European CSIRTs, integrated with the national CSIRT's production MISP platform serving 1,000+ organisations worldwide.

Lead: Luxembourg House of Cybersecurity
All pilot details →

Consortium

Fourteen partners. Nine countries. One network.

Coordinated by the Luxembourg Institute of Science and Technology, LATTICE pairs security operations centres and a national CSIRT with universities advancing privacy technology — and puts SMEs in the lead, carrying 49.8% of the work.

14+1
partners + affiliated entity
9
countries
7
SMEs · 49.8% of effort
5
universities
  • LIST
    Luxembourg · Coordinator
  • University of Liverpool
    United Kingdom
  • University of Aberdeen
    United Kingdom
  • TU Eindhoven
    Netherlands
  • Vrije Universiteit Amsterdam
    Netherlands
  • Red Alert Labs
    France
  • ITTI
    Poland
  • Mitigant
    Germany
  • Maggioli
    Italy
  • Netcompany
    Luxembourg
  • Digital for Planet
    Switzerland
  • Luxembourg House of Cybersecurity
    Luxembourg
  • Medisys
    Greece
  • Harokopio University of Athens
    Greece
  • Anadelta Technologies
    Greece · Affiliated
Partner roles →

Resources

Open by design

Open source

Every core component ships under the EUPL

European code, European licence. The alpha platform reaches GitHub in 2028; the full release with deployment guides follows as the project closes in September 2029, alongside contributions to MISP, ETSI, CEN-CENELEC, W3C and ISO/IEC standards work.

From the consortium's research

  • Chen et al. — When Machine Unlearning Jeopardizes Privacy · ACM CCS 2021 · VU Amsterdam
  • Chen et al. — FACE-AUDITOR: Data Auditing in Facial Recognition Systems · USENIX Security 2023 · VU Amsterdam
  • Sharma et al. — Blockchain and Federated Learning-enabled Secure Computing for IoT · IEEE EuroS&PW 2022 · Aberdeen

All publications and project outputs →

News

Latest from the project

Run a SOC, a CSIRT, or critical infrastructure?

The federation is built to grow beyond the consortium. Talk to us about early access, the open-source alpha, or joining the stakeholder group.