About the project
What LATTICE is
Lateral Adaptive Threat Triaging and Intelligence Collaborative Ecosystems
European cybersecurity suffers from dangerous fragmentation: organisations and Member States defend in isolation while attackers coordinate across borders. Hospitals discover ransomware days after neighbouring facilities faced identical threats; financial institutions miss sector-wide campaigns. The result is preventable breaches and billions in losses.
Collective defence makes everyone stronger — when one organisation detects an attack pattern, all can respond immediately. Yet barriers block collaboration: privacy regulation prevents cross-border data sharing, organisations cannot reveal vulnerabilities to competitors, and today's platforms demand either centralised control or manual coordination that takes hours when minutes matter.
LATTICE breaks these barriers with three innovations — federated consensus for distributed response without central authority, privacy-preserving computation that verifies threats while keeping detection methods secret, and digital twin networks that test dangerous responses safely before deployment — demonstrated through four operational pilots processing millions of security events from genuine threats.
Fact sheet
- Grant Agreement
- No 101308832
- Acronym
- LATTICE
- Call
- HORIZON-CL3-2025-02-CS-ECCC
- Topic
- HORIZON-CL3-2025-02-CS-ECCC-02
- Type of action
- Innovation Action (HORIZON-IA)
- Granting authority
- European Cybersecurity Competence Centre (ECCC)
- Start date
- 1 October 2026
- End date
- 30 September 2029
- Duration
- 36 months
- EU contribution
- €5 142 378.78 (lump sum)
- Coordinator
- Luxembourg Institute of Science and Technology
- Consortium
- 14 partners + 1 affiliated entity · 9 countries
- Total effort
- 569.37 person-months · 11 work packages
- Maturity path
- Technology readiness level (TRL) 4 → 7
Objectives
One primary objective, six measurable ways to get there
Primary objective
Transform European cybersecurity from fragmented silos to privacy-preserving collective defence at operational scale.
OBJ-1Operational-grade privacy-preserving threat correlation
Peer-to-peer secure multi-party computation at security-operations speed, targeting a 99.9% privacy guarantee verified through zero-knowledge proofs per NIST SP 800-226 — validated on 50+ federated nodes.
WP3 · WP8 · WP10OBJ-2Sub-15-minute federated crisis coordination
The Jury Protocol's graduated 60/75/90% thresholds against today's 12–24-hour baseline — a 48–96× improvement, with ≥90% consensus accuracy and Byzantine fault tolerance up to 33% malicious nodes.
WP4 · WP8 · WP10OBJ-3Democratised cyber-range access
A federated digital twin network at roughly a tenth of the €500K–€2M cost of dedicated ranges, cutting validation cycles from 6–8 weeks to 24–48 hours — with SME participation proven in the pilots.
WP5 · WP8 · WP10OBJ-4Automated NIS2 / CRA / CSA compliance
70% automation of NIS2 Article 23 incident reporting, validated with the Luxembourg NIS2 authority — with full audit trails and GDPR-compliant data handling throughout.
WP3 · WP10OBJ-5TRL 7 demonstrated across four pilots
Six months of sustained operation on real telemetry in every pilot, targeting ≥99.5% uptime and ≥85% practitioner satisfaction — independently assessed against ISO 16290.
WP8 · WP9 · WP10OBJ-6Open-source sustainability and EU-wide adoption
EUPL releases (alpha 2028, full platform 2029), 1,000+ downloads and 5+ external deployments targeted, standards contributions to ETSI and CEN-CENELEC, and a Digital Europe Programme transition pathway.
WP6 · WP11