The fundamental stability of modern society—characterized by the reliable provision of electricity, potable water, and the integrity of aviation radar networks—is intrinsically dependent upon critical infrastructure (CI). While these systems were traditionally characterized by physical isolation, they have evolved into highly interconnected ecosystems underpinned by cloud computing, Internet of Things (IoT) sensors, and industrial control systems.
Although digital transformation significantly enhances operational efficiency, it concurrently introduces an expansive and vulnerable attack surface. Consequently, the protection of these assets has transitioned from a localized IT concern to a primary objective of national and continental security. In response, the European Union, through the Horizon Europe program, is implementing a comprehensive strategy that combines rigorous legislative mandates with significant investment in advanced technological initiatives, such as the CyberSecDome project [4].
The Evolving Threat to Critical Infrastructure
Contemporary critical infrastructure is characterized by a significant structural vulnerability: heterogeneity. Systems such as intelligent airports or energy grids typically utilize a complex integration of legacy mechanical hardware and sophisticated, internet-enabled artificial intelligence analytics.
State-sponsored actors and organized cyber-criminal organizations exploit this systemic fragmentation. Ransomware remains a significant threat to logistics centers, while advanced persistent threats (APTs) compromise firmware to exert unauthorized control over physical components. In the event of a breach, the consequences extend beyond data loss to include severe operational disruption and direct threats to public safety.
The Legislative Mandate: NIS2 and CER Directives
Recognizing these systemic vulnerabilities, the EU enacted two monumental regulatory frameworks to force critical infrastructure operators to baseline their defenses.
The NIS2 Directive (Network and Information Security)
Replacing its weaker predecessor, the NIS2 Directive significantly expands the scope of sectors classified as “essential” or “important” entities [5].
- Broader Reach: It captures energy, transport, banking, water, healthcare, and digital infrastructure under a unified, strict compliance umbrella.
- Personal Accountability: Corporate executives can be held personally liable for gross negligence in security oversight.
- Stringent Reporting: Entities must report significant cyber incidents to national authorities within 24 hours of awareness.
The CER Directive (Critical Entities Resilience)
While NIS2 focuses on digital and network security, the CER Directive acts as its physical counterpart. It ensures that entities are equally prepared against non-cyber threats such as natural disasters, supply chain blockages, or physical sabotage (e.g., pipeline attacks). Together, NIS2 and CER form a holistic, all-hazards approach to European resilience [6].
CyberSecDome: Next-Generation Defense in Action
Legislation tells operators what to protect, but pioneering research initiatives provide the technical blueprint for how to do it. Funded by the EU’s flagship Horizon Europe program, the CyberSecDomeproject is an innovative consortium designed to defend complex, fragmented digital infrastructures.
The core philosophy of CyberSecDome relies on four interconnected technical pillars [4]:
[ Physical Infrastructure ] ➔ Streams live data to
↓
[ Digital Twin Cyberrange ] ➔ Safe testing & behavior replication
↓
[ AI-Empowered Security Tools ] ➔ Predicts, detects, and pen-tests threats
↓
[ Immersive VR Interface ] ➔ Human-in-the-loop collaborative response
The Four Pillars of CyberSecDome
- Digital Twins & Cyberranges: CyberSecDome uses high-fidelity virtual mirrors to safely simulate attacks and test security patches without disrupting live infrastructure.
- AI-Empowered Security Modules: Localized AI monitors traffic to predict threats and uses automated penetration testing to proactively find systemic weaknesses.
- Immersive VR Interfaces: Replacing flat logs, a 3D VR environment allows distributed experts to collaboratively visualize and contain cyberattacks in real time.
- Privacy-Aware Knowledge Sharing: Federated AI learning enables global entities to share threat profiles instantly while protecting private user data.
Real-World Validation: The Athens International Airport (AIA) Scenarios
To prove its viability outside a purely theoretical laboratory setting, CyberSecDome is actively stress-tested and validated in high-stakes operational environments. One of the primary, reference scenarios for the project is coordinated by Athens International Airport (AIA). AIA represents a hyper-complex, dynamic cyber-physical ecosystem. A modern airport is not just a runway; it is an extremely complex and multi-stakeholder grid where airlines, ground handlers, retail shops, public networks, and automated industrial machinery intersect.
Overall, the year 2025 ended with Athens International Airport’s traffic reaching 34 million passengers (33.99), exceeding the 2024 levels by 6.7%. [1] For the year 2025, Athens International Airport’s number of flights amounted to 283,590, i.e. 5.7% above the respective 2024 levels. [2]
During May 2026, amidst the ongoing geopolitical crisis in the Middle East, the airport’s passenger traffic amounted to 3.22 million, above May 2025 by 3.7%, with both domestic and international air travel demand showing similar growth levels (at the level of 3.7%). [3] Overall, during the first five months of 2026, the airport’s passenger traffic totalled 12.23 million, exceeding the 2025 levels by 5.3%. Analytically, domestic and international passengers were above the 2025 levels by 6.0% and 5.0%, respectively. [3]
The Athens Intranational Airport is considered the 15th busiest airport in a list of the 100 busiest airports in Europe, ranked by total passengers per year. [7]
Despite operating within a highly dynamic and critical cyber-physical environment, Athens International Airport reported no major cybersecurity incidents during 2026. Apart from some DDoS attacks that were promptly detected and mitigated without operational consequences, airport services remained uninterrupted, providing a valuable real-world validation environment for CyberSecDome’sresilience and monitoring capabilities.
Example Scenario: Targeted Attacks on Call Center, Helpdesk and Public Announcement Infrastructures
In an aviation hub, the central call centers and information desks are vital to passenger safety, flight routing adjustments, and crisis communication.
- The Threat: Attackers leverage sophisticated, multi-pronged social engineering combined with VoIP/SIP exploitation to hijack or flood the airport’s call center and public announcements’ infrastructure, effectively blinding communication. In the CyberSecDome environment, this is simulated as a Denial-of-Service (DoS) attack targeting the Session Initiation Protocol (SIP). Attackers may employ various vectors, such as flooding SIP INVITE or REGISTER messages and sending malformed packets to crash the server. These methods are designed to exhaust server resources or bandwidth, potentially setting the Call Center out of service and disrupting critical communication services like voicemail and chat. To establish a baseline for these simulations, security features are often disabled or non-secure profiles are used within the lab setup.
- Operational Implications: This attack might effectively blind airport facilities communication, severely disrupting critical services such as passenger safety updates, flight routing adjustments, and crisis management. It might also render call centers and information desks inoperable, preventing the handling of legitimate passenger queries and operational coordination.
- The CyberSecDome Solution: The digital twin replicates the airport’s unified communication network architecture. As the CyberSecDome automated penetration-testing tools identify hidden backdoors, the AI security module learns to filter malicious signals from legitimate passenger queries or the Airport’s standard operational communications. Furthermore, SOC analysts may use the immersive VR metaverse to visually isolate the compromised communication nodes and reroute airport-wide data safely, keeping lines open during a simulated crisis.
Lessons Learned: This scenario underscores the necessity of moving beyond perimeter-based defenses to a zero-trust architecture for internal communications infrastructure. It demonstrates that VoIP/SIP vulnerabilities are not merely IT issues but operational risks that require real-time, AI-driven monitoring. Furthermore, it highlights the importance of rigorous stress testing against non-secure configurations to identify hidden backdoors before they can be exploited in a live environment. Finally, the integration of human-in-the-loop VR response protocols proves essential for reducing mean time to recovery (MTTR) during complex, multi-vector incidents.
Moving Forward: A Resilient Future
The future of critical infrastructure protection requires technology and policy to move in absolute lockstep. As the strict compliance deadlines of the NIS2 and CER directives force organizations to redesign their foundational governance, innovations like CyberSecDome give security analysts the concrete tools they need to actually win the fight. By fusing predictive AI, digital twins, immersive VR collaboration, and stringent compliance, Europe is proactively building an adaptable shield against the threat landscape of tomorrow.
This article is supported by the European Union funded project CyberSecDome under Grant Agreement No. 101120779. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Commission. Neither the European Union nor the European Commission can be held responsible for them.
[1] Athens International Airport | Stay up to date with the latest airport facts and figures, Passengers Traffic 2025,
https://media.aia.gr/assets/aiaportal/media/root/corporate/statistics/passengers-traffic-new/passenger-traffic-december-2025_final_en.pdf (Accessed, 2026.06.01)
[2] Athens International Airport | Stay up to date with the latest airport facts and figures, Passengers Traffic 2026,
https://media.aia.gr/assets/aiaportal/media/root/corporate/statistics/passengers-traffic-new/passenger-traffic-may-2026-en.pdf, (Accessed, 2026.06.01)
[3] Athens International Airport | Stay up to date with the latest airport facts and figures, Flights 2026,
https://media.aia.gr/assets/aiaportal/media/root/corporate/statistics/flights/flights-may-2026-en.pdf, (Accessed, 2026.06.01)
[4] CyberSecDome, https://cybersecdome.eu, (Accessed, 2026.06.01)
[5] EUR-Lex | Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (Text with EEA relevance),
https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng, (Accessed, 2026.06.01)
[6] EUR-Lex | Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (Text with EEA relevance), https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng, (Accessed, 2026.06.01)
[7] Wikipedia, List of the busiest airports in Europe,
https://en.wikipedia.org/wiki/List_of_the_busiest_airports_in_Europe, (Accessed, 2026.06)
Nikos Papagiannopoulos
NikosPapagiannopoulos (MSc, MBA, PMP, CISSP, CISA, ISO 27001 LA)is the Head of Digital Innovation of Athens International Airport (AIA), leading the airport’s digital transformation and innovation strategy. With extensive experience in cybersecurity, IT governance, digital technologies, and innovation management, he oversees the development and deployment of advanced digital solutions, AI applications, operational digital twins, and smart airport initiatives. Nikos has also led numerous European research and innovation projects under Horizon Europe, SESAR, Digital Europe, and CEF programs, promoting collaboration between airports, industry partners, startups, and academia to advance the future of aviation.
Christos Koziaris
ChristosKoziaris (MBA, MSc, CRISC, CDPSE, COBIT, Certified DPO)is an IT Engineer, with postgraduate studies in Business Administration (University of Economics) and Security and Risk Management (Leicester, UK).He is certified in Information Systems Risk Management (CRISC), Systems Privacy Planning (CDPSE), IT Resource Management based on the COBIT framework, by ISACA, Data Protection Officer (DPO) from TUV Austria.
He has been working since 1987 in the field of IT (16 years at Vodafone) in IT administrative positions, management of invoicing systems and risk management. He has significant experience in e-business, in the development and management of applications and hardware, in the integration of systems, in project and budget management, in the improvement of processes and control mechanisms, etc.
Finally, he has participated in regulatory compliance programs (SOX, ISOs, BCP, Information Security, Quality Management, GDPR, etc.) in private companies and public organizations. He has served as a member of the Board of Directors of ISACA in Greece (2016-2021).
He works as a business consultant and lecturer, focusing on data security and compliance with GDPR 2016/679, NIS, AI Act, etc., andteaches at the American College of Greece Informatics, Systems Security and Management Information Systems.Works also as a consultant for AIA in the CyberSecDome Project.
Nikolaos Velimachitis
NikolaosVelimachitisis a Senior Cyber Security Engineer and Information Security Officer with expertise in cybersecurity governance, risk management, and critical infrastructure protection. His professional career includes security architecture, information security compliance, identity and access management, cloud security, and cyber resilience. He has contributed to the evaluation and implementation of cybersecurity controls across complex enterprise environments and participates inEuropean and international cybersecurity initiatives. His work focuses on enhancing organizational security posture and supporting secure digital transformation.


Leave a Reply