Horizon Europe · Innovation ActionGA 101308832TRL 4 → 7
Collective cyber defence, without surrendering sovereignty.
Europe's defenders work in isolation while attackers coordinate across borders. LATTICE builds the federated layer that lets organisations detect, decide and respond together — with no central authority and no sharing of sensitive data.
lattice-project.eu · October 2026 – September 2029 · Coordinated by LIST, Luxembourg
€5.14M
EU FUNDING · ECCC
36 MO
10.2026 → 09.2029
TRL 4→7
LAB → OPERATIONAL
4 PILOTS
LIVE TELEMETRY · DE EL NL LU
How a federation shares threat intelligence · AI-generated illustration
01
The problem
Attackers coordinate across borders. Defenders don't.
Hospitals discover ransomware days after neighbouring facilities faced identical threats. Financial institutions miss sector-wide campaigns. Fragmented defence across 27 Member States costs European organisations an estimated €43 billion every year.
Speed asymmetry194 days vs 84 min
Median time to identify an intrusion, against the time attackers need for lateral movement. That separation is what makes purely reactive defence impossible.
Coordination lag12–24 h
Documented delay to establish cross-border sharing during incidents today. LATTICE targets coordinated response in under 15 minutes.
Privacy dilemma62%
Share of EU organisations kept out of threat-intelligence sharing by GDPR exposure concerns. Collective defence fails when most defenders cannot participate.
These figures — and the market figures quoted elsewhere on this site — were accurate when last checked, in November 2025.
02
The approach
Three innovations, one federated system
LATTICE removes the false choice between isolated defence and centralised aggregation. Peer-to-peer by design, it lets thousands of organisations in the scope of the EU's NIS2 directive act as one — while each keeps full custody of its data and decisions.
Innovation 01 · WP4
Jury Protocol — federated consensus
Graduated response across autonomous security operations centres (SOCs) with no central authority: 60% consensus triggers enhanced monitoring, 75% coordinated investigation, 90% full containment. Byzantine-fault-tolerant with up to 33% of nodes acting maliciously.
Target: cross-border coordination < 15 min
Innovation 02 · WP3
Privacy-preserving correlation
Peer-to-peer secure multi-party computation correlates threats over encrypted telemetry. Organisations verify that attack patterns match — without revealing detection methods or vulnerable systems. Zero-knowledge proofs, evaluated against NIST SP 800-226.
Target: 99.9% privacy guarantee
Innovation 03 · WP5
Federated digital twin network
Shared cyber-range infrastructure to rehearse dangerous responses safely before they touch production. Roughly 10× cheaper than the €500K–€2M of a dedicated range — opening pre-deployment validation to the SMEs that make up 70% of NIS2 entities.
Validation cycles: 6–8 weeks → 24–48 h
03
Evidence
Four pilots. Real telemetry. Six months continuous.
These are not demos. Each pilot runs continuously for six months on live security telemetry — real events, no synthetic data — producing the operational evidence for technology readiness level 7 (TRL 7) by September 2029.
GermanyPilot 1
Cross-sector threat intelligence
Federated detection and adversary emulation spanning telecom, finance, utilities and education infrastructure — sectors that today discover shared campaigns in isolation.
Lead: Mitigant
GreecePilot 2
Healthcare under protection
A live 250-bed hospital defended by the federation — with digital-twin validation keeping false positives away from patient safety, and patient privacy untouched.
Leads: Digital for Planet · Medisys
NetherlandsPilot 3
Federated SOC collaboration
Real-time coordination between security operations centres processing over one million events a day — operational secrecy intact on every side.
Lead: Eindhoven University of Technology
LuxembourgPilot 4
EU-wide vulnerability intelligence
Accelerated advisory distribution across European CSIRTs, integrated with the national CSIRT's production MISP platform serving 1,000+ organisations worldwide.
Coordinated by the Luxembourg Institute of Science and Technology, LATTICE pairs security operations centres and a national CSIRT with universities advancing privacy technology — and puts SMEs in the lead, carrying 49.8% of the work.
European code, European licence. The alpha platform reaches GitHub in 2028; the full release with deployment guides follows as the project closes in September 2029, alongside contributions to MISP, ETSI, CEN-CENELEC, W3C and ISO/IEC standards work.
The consortium meets at LIST to open the 36-month programme. First on the board: requirements and a federated architecture specification, privacy gateway development, and the groundwork for four operational pilots running by 2029.