The aSIEMmetry project has officially kicked off, marking the beginning of a European collaboration focused on strengthening Security Operations Centres through artificial intelligence, machine learning and advanced behavioural analysis.
The official kick-off meeting brought together the three consortium partners: project coordinator Expertware, Vrije Universiteit Brussel and the Romanian National Cyber Security Directorate. The meeting established a shared direction for the project and created the foundation for the research, technical development, validation and communication activities that will follow.
A shared mission for stronger Security Operations Centres
Security Operations Centres are responsible for monitoring increasingly complex digital environments. Analysts must process large volumes of alerts and telemetry while identifying incidents that may involve several users, devices, applications and infrastructure components.
Traditional SIEM technologies remain essential to this process, but SOC teams can still face difficulties caused by excessive alert volumes, inefficient prioritisation, delayed containment and shortages of specialised cybersecurity personnel.
aSIEMmetry aims to address these challenges by enhancing existing SIEM and SOC capabilities with self-hosted artificial intelligence. The project will focus on detecting behavioural changes, identifying emerging threats and helping analysts investigate security events more efficiently.
Developing two complementary AI models
A central objective of the project is the development and training of two complementary AI capabilities.
The first is a security-entropy multi-agent model designed to represent SIEM-monitored IT assets and evaluate changes in their behaviour. By analysing relationships between users, devices, applications, identities and network activity, the model will aim to identify significant deviations that may indicate a developing security incident.
The second component is a specialised LLM SOCagent. This model will be designed to assist analysts by organising security evidence, summarising activity, supporting event correlation and providing clearer context during investigations.
Together, these components are intended to form an AI-assisted cybersecurity capability that supports proactive anomaly detection and threat mitigation while keeping human analysts responsible for operational decisions.
Keeping sensitive security data under organisational control
Self-hosting is an important part of the aSIEMmetry approach. SOC telemetry may contain sensitive details about internal systems, users, vulnerabilities, configurations and active incidents.
Running the project’s AI components within approved infrastructure can provide organisations with greater control over how their data is processed, accessed and stored. It can also support environments in which operational or regulatory requirements restrict the use of external public AI services.
Combining complementary consortium expertise
Each consortium partner contributes a different perspective to the project.
Expertware coordinates the project and contributes cybersecurity-platform, implementation and system-integration expertise. Vrije Universiteit Brussel contributes academic research and artificial-intelligence capabilities. The Romanian National Cyber Security Directorate provides institutional and operational cybersecurity knowledge connected to national cyber resilience.
This combination will help ensure that the project’s results are technically advanced while remaining connected to real SOC requirements.
Aligning development with operational needs
Throughout the project, regular decision-making sessions will support coordination between the partners. The consortium also plans anthropological visits intended to provide a better understanding of how cybersecurity professionals work, which challenges they encounter and how AI-supported tools can fit into their existing processes.
This user-centred perspective will be important for ensuring that the developed models and methodologies are not limited to research prototypes. Their outputs must be understandable, explainable and useful to the analysts who will work with them.
The beginning of a three-year development journey
aSIEMmetry officially began on 1 January 2025 and will run until 31 December 2027. The project is funded by the European Cybersecurity Competence Centre under the Digital Europe Programme through Grant Agreement No. 101190232.
The kick-off meeting represents the first major milestone in this three-year journey. With the consortium aligned around a shared technical and operational vision, the next activities will focus on requirements, asset modelling, AI-pipeline development, model training, integration and validation.
Through collaboration between industry, academia and a national cybersecurity authority, aSIEMmetry aims to deliver scalable and reusable AI capabilities that strengthen SOC operations and contribute to a more resilient European cybersecurity ecosystem.