This project aims to develop an advanced methodology for analyzing and managing cybersecurity risks in data spaces, an increasingly relevant model for building the European digital economy. These environments allow multiple organizations to share data while maintaining control over it, preserving organizational autonomy, information privacy, and regulatory compliance, as required by the European Data Strategy. However, this distributed architecture presents new cybersecurity challenges that cannot be addressed using traditional approaches designed for centralized systems.
The proposed methodology will specifically address the risks associated with node autonomy, semantic interoperability, technological heterogeneity, geographical distribution, and regulatory differences between entities. To this end, a systematic process will be established to identify, classify, prioritize, and mitigate risks, while simultaneously defining a collaborative governance model that respects the independence of each participant and aligns with current legal requirements (such as the GDPR and the Data Governance Act).
The methodology will be supported by the development of four key technological components.
The first component will be a risk ontology, formally representing assets, threats, vulnerabilities, controls, and regulations. This ontology will facilitate semantic interoperability between entities and allow for the partial automation of risk analysis, increasing its efficiency and accuracy.
The second component will consist of a vulnerability and attack pattern ontology, built from the integration of widely recognized standards such as CVE, CWE, CPE, CAPEC, and ATT&CK. This ontology will allow for the linking of assets and services to known vulnerabilities, facilitate attack simulation, and support the definition of countermeasures tailored to each environment.
The third component will be an automation module based on Large Scale Language Models (LLMs), trained to assist in tasks such as mapping vulnerabilities to assets, recommending controls, and classifying threats. Special attention will be paid to the safe and ethical use of these models, minimizing risks such as unrealistic responses, biases, or information leaks. The fourth component will be an extended methodology for developing ethical and trustworthy AI, based on expanding CRISP-DM with principles such as explainability, legality, and beneficence. This framework will enable the risk analysis systems developed to be not only technically effective but also socially responsible, especially in sensitive domains such as healthcare and public administration.
The project will be validated in a shared data space environment, adapted to platforms such as GAIA-X or IDS, and tested through a collaborative use case in which data is distributed among multiple independent entities. Its effectiveness will be evaluated in terms of security, privacy, fairness, traceability, and interoperability, ensuring that the solutions can be applied in real-world scenarios with a high degree of confidence.
Overall, the RADAR project will significantly contribute to strengthening cybersecurity, digital resilience, and trust in data spaces, promoting a secure, ethical, and sustainable data-sharing model in line with European strategic priorities.