The framework
An AI-based SOC-as-a-Service, built for the clinical environment
Traditional SOC systems focus purely on the IT perspective and miss the context of healthcare. HEALTH-ER runs either as a complete SOCaaS or as a complementary layer over the tools a hospital already has, with patient-safety logic built into the security picture.
HEALTH-ER operates either as a complete SOC-as-a-Service or as a complementary security layer on top of the tools a hospital already runs. Four technical blocks feed the SOCaaS, and a set of preparedness and assessment services surrounds it.
Capability blocks
Four blocks feeding one platform
Situational awareness and orchestration together form the SOCaaS itself. Information exchange connects it outward to the sector. Capacity building addresses the factor that no platform can patch: people.
AI-based Situational Awareness & Prediction
Continuous analysis of system and user behaviour across hospital IT, medical devices and OT, turning raw telemetry into prioritised, explainable risk.
Components
Cyber risk assessment and prioritisation
Comprehensive risk assessment, proactive defence against emerging threats, and effective prioritisation and risk treatment, with customised long-term protection.
AI-based attack prediction for medical and IoT devices
Ad-hoc behavioural models trained per system deliver an estimated probability that a device is behaving incorrectly, which may be an early warning of an attack. Because the models learn normal operation rather than parse protocols, they are unaffected by the diversity of medical device architectures and data formats.
User and entity behaviour analytics (UEBA)
Machine learning builds a baseline of normal behaviour for users such as doctors, nurses and administrative staff, and for entities such as infusion pumps, EHR systems and IoT devices, then flags deviations such as unusual logins or unauthorised access to patient records. This matters in healthcare, where insider risk, compromised accounts and lateral movement bypass perimeter defences.
CTI-driven threat hunting
Rather than relying solely on automated alerts, analysts use intelligence-driven hypotheses to actively search for anomalies and stealthy mechanisms, informed by attacker tactics, techniques and procedures, indicators of compromise and emerging vulnerabilities.
Intelligent Orchestration, Automation & Response
Coordinated, partly automated response that keeps clinical services running, built on playbooks that can be shared between hospitals.
Components
Adaptive SOAR
The core component for active protection: a central provisioning layer that coordinates security operations and service delivery, evolving the SOCaaS into a unified cyber operations and service provisioning fabric able to analyse many different environments.
Incident response and business continuity playbooks
OASIS CACAOStandardised playbooks for the healthcare sector covering proactive actions triggered by predictive maintenance or attack prediction, and reactive actions to detected incidents, so that business processes are not disrupted.
Information Exchange
Turning one hospital’s lesson into the sector’s defence, and meeting the reporting duties that come with NIS2.
Components
EU-compliant reporting
NIS2, Cyber Solidarity ActStandardised reporting processes and templates that let healthcare providers notify incidents, vulnerabilities and breaches in a timely and secure manner, supporting cross-border cooperation and trust between hospitals, national authorities and EU institutions.
CTI sharing
STIX, TAXIIAggregating and analysing intelligence from consortium members and trusted sources such as ENISA, national CSIRTs and healthcare CERTs, so hospitals move from reactive to proactive defence.
Collaborative threat hunting
Intelligence-driven hypotheses and shared playbooks let security teams detect what automated defences miss, and transfer lessons learned from one institution across the EU healthcare ecosystem, reducing dwell time at scale.
Cyber Ranges, Knowledge & Capacity Building
The human factor: realistic exercises and role-specific training for clinical, technical and management staff.
Components
Cyber ranges
Realistic scenarios such as ransomware outbreaks or attacks on connected medical equipment help IT teams and clinical staff identify, respond and recover faster. Incident response and business continuity playbooks can also be rehearsed in these environments.
Education and training
From general cyber hygiene for healthcare professionals to advanced courses for security experts, plus material and guidelines on EU policies and regulations. Four full-day training sessions run at the pilot sites for pilot personnel.
Consulting services and mentoring
Matching the real problems faced by healthcare providers and SMEs with the right expertise, plus advisory services connecting authorities and policy makers with providers, researchers and industry. A dedicated helpdesk operates at HOPE premises.
Awareness and knowledge transfer
Activities that engage stakeholders across government, policy, academia, industry and civil society, promoting understanding of healthcare cybersecurity and generating demand for the technologies developed.
Preparedness and assessment
The services around the platform
Technology alone does not make a hospital resilient. These services wrap the SOCaaS and are available independently of it.
Cybersecurity maturity and risk assessment
Establish the baseline: digital maturity, existing tools and processes, security controls, staff awareness and regulatory compliance, across large hospitals, small providers and private clinics alike.
Penetration testing
Test the capacity to withstand cyber incidents while maintaining uninterrupted healthcare services, including resilience benchmarks and business continuity drills.
Compliance, policy and certification
Navigate NIS2, GDPR, the Medical Device Regulation, the Cybersecurity Act and the Cyber Resilience Act, with support for ISO/IEC 27001, 27701, 27799:2016 and 80001.
Supply-chain assessment
Methodologies for supply-chain risk assessment, vendor auditing and certification-based assurance, helping hospitals avoid long-term dependency on a limited number of providers.
Technical plans and roadmaps
Structured, practical roadmaps setting out the architecture, tools, processes and resources needed, tailored to the operational, financial and regulatory context of each provider.
Cost-benefit analysis
Capital and operational expenditure, return on investment, and avoided costs from reduced incidents, downtime and breaches, to build the business case for sustained investment.
Training and capacity building
Cyber-hygiene courses, cyber-range exercises, workshops and mentoring for technical, clinical and management personnel.
Threat intelligence and collaborative defence
Integration with trusted CTI sources, standards-based exchange and CTI-driven threat hunting to improve situational awareness across the sector.
Standards and regulation
Designed against the rules hospitals are actually held to
Compliance is not a separate workstream bolted on at the end. The framework's reporting, exchange formats and playbooks are built on the standards and regulations below.
- NIS2 DirectiveHealthcare designated a sector of high criticality; multi-stage incident reporting.
- GDPRProtection of patient data throughout the framework.
- Medical Device Regulation (MDR)Security of connected medical devices.
- Cyber Resilience Act (CRA)Product security requirements and certification pathways.
- Cybersecurity Act (CSA)EU certification schemes.
- Cyber Solidarity ActCyber reserve and early-warning system.
- European Health Data Space (EHDS)Secure infrastructure for health data exchange.
- OASIS CACAOStandardised, shareable incident-response playbooks.
- STIX / TAXIIStructured threat intelligence exchange.
- ISO/IEC 27001, 27701, 27799, 80001Information security and health informatics management.
Want to try this in your own environment?
The Open Pilot gives European healthcare providers access to the tools, services and methodologies described on this page.
