SIEMBIOT Project Completion

Results and next steps for cyber resilience

SIEMBIOT Project Completion
The Results Remain. The Mission Continues.

On 27 August, at the Diplomatic Club in Bucharest, the closing conference of the European SIEMBIOT project brought together more than 200 representatives from public authorities, companies, the cybersecurity industry, organisations from essential sectors, research, and academia. The event marked the completion of the project’s implementation period and highlighted both the results achieved and the current challenges shaping cyber resilience.

Developed under the Digital Europe Programme by the Romanian National Cyber Security Directorate (DNSC), together with Expertware, the consortium leader, SIEMBIOT addresses a concrete need: connecting the information and capabilities required to identify, analyse, and manage cyber risks.

The Results Remain. The Mission Continues.

With a total investment of over €3.3 million, the project has transformed technical expertise and operational experience into concrete capabilities for cyber threat prevention, detection, analysis, and response.

The platform integrates monitoring and detection, Cyber Threat Intelligence, vulnerability management, cybersecurity maturity assessment, and testing and analysis capabilities. Data from different components can be aggregated and correlated to identify patterns and anomalies that are difficult to detect when events are analysed separately.

SIEMBIOT in Action

During the conference, participants had the opportunity to see SIEMBIOT in action through a live demonstration delivered by Tiberiu Baraboi, CEO of Expertware and project coordinator. The demonstration showcased the components developed within the platform, as well as tools for assessing cybersecurity maturity against NIS2 requirements.

The demonstration also highlighted how the capabilities developed through SIEMBIOT help transform collected data into relevant information for identifying and managing threats. Continuous monitoring, alert investigation and triage, logging, vulnerability identification, and security testing provide organisations with a broader view of their infrastructure and enable them to understand an event quickly enough to take action.

SIEMBIOT in Action

The conference was opened by Luca Tagliaretti, Executive Director of the European Cybersecurity Competence Centre (ECCC), who congratulated the SIEMBIOT consortium on its achievements and brought a European perspective on cybersecurity investment, innovation, and the development of sustainable capabilities. He also highlighted new funding opportunities and upcoming European calls in the field of cybersecurity.

Resilience means business continuity

The first panel, “From Cyber Intelligence to Cyber Policy”, brought together Andi Mihai (DNSC), Raluca Anton (Deloitte), Alexandru Georgescu (ICI Bucharest), Ioana Manea (Cyber Arena), Alexandru Șerbănescu (ELI-NP), and Viorel Manole (PATROMIL) for a discussion on policy, skills, research, and organisational responsibility.

One of the main conclusions was that cyber resilience should not be confused with compliance alone. A successful audit does not automatically demonstrate that an organisation can continue operating during an incident.

The relevant question is a practical one: if an attack happens on Sunday evening, can essential services still be delivered on Monday morning?

To answer this question, organisations need to know which systems are critical, how much loss they can tolerate, and how quickly those systems need to be recovered. Backups, response plans, and recovery mechanisms need to be tested regularly, not only before an audit or after an incident has occurred.

Resilience means business continuity
More data does not automatically mean more security

More data does not automatically mean more security

The second panel, “Cyber Resilience in the Real World”, brought together Tudor Cristea (CrowdStrike), Corina Vasile (ANIS), Gerald Dincă (Sanador), Florin Pană (Vodafone), Tiberiu Baraboi (Expertware), and Alexandru Vîlcu (HPE), focusing on the operational reality of cybersecurity.

The volume of data and alerts continues to grow, but the challenge lies in identifying the information that matters and getting it to the person who needs to act. At the same time, attacks are unfolding faster, reducing the time available for detection and response.

Cloud, AI, and the use of valid credentials are blurring the traditional boundary between the inside and outside of an organisation. In this context, identity, access, and behavioural monitoring are becoming increasingly important components of security.

Technology alone, however, does not create resilience. A security tool needs to be properly configured, monitored, and integrated into effective processes, while a backup is only useful if the data can actually be restored when needed. The same principle applies to compliance: security cannot be assessed once and then considered resolved.

Requirements such as those introduced by NIS2 call for a continuous approach, in which asset inventories, vulnerabilities, risks, and controls are monitored and reassessed as infrastructure and threats evolve.

Beyond internal processes, resilience also depends on organisations’ ability to learn from one another. The conference highlighted the importance of sharing information about incidents and anomalies, particularly in a context where organisations often use the same technologies and face similar threats. The experience gained from one incident can therefore become a valuable source of learning for the wider community.

SIEMBIOT continues beyond the project

SIEMBIOT continues beyond the project

The closing conference marks the completion of one stage, but the challenges that led to SIEMBIOT remain.

Over the three years of implementation, DNSC contributed to the development of the project through its expertise and institutional perspective, as well as through awareness, training, and cybersecurity capacity-building activities. The Romanian National Cyber Security Directorate is the national competent public authority for Romania’s civilian cyberspace, with responsibilities that include managing cyber risks and incidents.

Expertware contributed the experience gained over 20 years of activity in IT and cybersecurity, technology development, and European research and innovation projects. The company has an international portfolio and experience in complex projects and environments, including critical infrastructure and organisations with demanding security and resilience requirements.

Reflecting on three years of development and the project’s results, Tiberiu Baraboi, CEO of Expertware, summarised what SIEMBIOT has meant for the team:

“SIEMBIOT is a dream come true. A company from Romania can achieve great things. We want to secure AI, and we want you to hear about Expertware ten years from now, wherever you are in the world.”

SIEMBIOT is completing its implementation period as a European project, but the technology, expertise, and collaborations developed through it are entering a new stage. The next steps focus on building on the results achieved, further developing the platform, and establishing new collaborations across the national and European cybersecurity ecosystem.

Attacks are becoming faster, infrastructures more complex, and organisations are having to manage ever-growing volumes of information. In this context, resilience is not measured by the number of tools deployed or the requirements checked off during an audit, but by the ability to understand what is happening, respond in time, and keep operating when something critical stops working.

Cloud image

90 Days of Enterprise-Grade Cyber Defense

Step into the future of cybersecurity with full access to a unified, intelligent platform — free for 90 days. Empower your security team with:

  • Advanced SIEM for real-time visibility, smart alerting, and deep forensics across cloud, on-prem, and hybrid environments

  • Continuous Vulnerability Management to identify, prioritize, and remediate risk across all assets

  • Live Cyber Threat Intelligence integrated directly into your workflows, with global insights and attacker profiling

  • AI-Powered Threat Detection that learns from your environment, explains alerts in plain language, and suggests next steps

  • Built-in Compliance Readiness for NIS2, GDPR, ISO 27001, and more, with automated reporting and audit tools

Whether you're managing a lean SOC or a full-scale enterprise security team, this platform gives you the tools to detect faster, respond smarter, and stay ahead of evolving threats — all without the complexity.

Experience enterprise-grade protection, streamlined workflows, and total control.

Your 90-day head start begins now.

Unlock Your 3-Month Free Trial