2025/20 Weekly Update from the EU ISAC for Cities & Regions: No call next week 25 July / ECCC Info Day – Funding opportunities, 2 September 2025, Berlin, Germany – European Union / Our (Almost) Daily Cyber Forecast on LinkedIn – Follow us / Invitation to Participate (and circulate) in ENISA’s NIS360 Sector Survey / Weekly [TLP:RED] / Barista moving to Mistral AI / Join our “I4C+ MISP” and “ISAC Baseline (IBAS)” projects / MCE Annual Conference Oct 9&10, 2025

2025/20 Weekly Update from the EU ISAC for Cities & Regions: No call next week 25 July / ECCC Info Day – Funding opportunities, 2 September 2025, Berlin, Germany – European Union / Our (Almost) Daily Cyber Forecast on LinkedIn – Follow us / Invitation to Participate (and circulate) in ENISA’s NIS360 Sector Survey / Weekly [TLP:RED] / Barista moving to Mistral AI / Join our “I4C+ MISP” and “ISAC Baseline (IBAS)” projects / MCE Annual Conference Oct 9&10, 2025

** Note there is no call next week 25 July **

** For Back Issues see https://isac4cities.eu/blog **

The City ISAC (I4C+) is an Information and Analysis Centre whose members are IT and cyber security decision makers exchanging knowledge to improve their cities and collective cyber resilience. I4C+ is a Special Interest Group (SIG) hosted by Major Cities Europe (MCE). Dr. Oliver Schwabe is a member of MCE and in his function Chair of the ISAC for Cities Plus (I4C+). He is the person in charge of this effort on behalf of MCE and the responsible contact person. I4C+ is recognized by the European Agency for Cybersecurity ENISA. See https://isac4cities.eu/.

Daily Cyber Forecast

Our GPT Barista is publishing an (almost) daily cyber forecast to our LinkedIn page at https://www.linkedin.com/company/eu-city-information-sharing-and-analysis-center-isac/.

Invitation to Participate (and circulate) in ENISA’s NIS360 Sector Survey

Over the past few months, our ENISA friends have been working on developing the NIS360 surveys — and they are happy to share that they are now ready to launch!

We would appreciate it if you could share the survey dedicated to public administrations with the members of ISAC4Cities.

The goal of the survey is to assess the cybersecurity maturity and criticality of sectors classified as essential or important under NIS2.

The input collected will directly inform the upcoming ENISA NIS360 Report, which will provide a comprehensive overview and comparison of sectors, highlighting where each sector stands. Through NIS360 surveys, ENISA aims to collect data on an annual basis to support companies and competent authorities in prioritising resources and strengthening cybersecurity practices over time.

You can access the survey via the following link: https://enablor.dk/auth/register/survey/8419079683a240e88266e257bf391b00?lang=en&enisa=true

We kindly invite you to complete the survey by September 15.

You can also find last year’s NIS360 report here: https://www.enisa.europa.eu/publications/enisa-nis360-2024.  However, this year, we aim to gather input from a broader range of entities in order to develop the most accurate and comprehensive picture of the sector possible.

If you have any questions, need further information, or are interested in continuing the dialogue and contributing your expertise to support our work, please do not hesitate to contact the ENISA team at NIS360@enisa.europa.eu <mailto:NIS360@enisa.europa.eu> .

Weekly [TLP:RED]

Please contact us directly for more information – these are summaries only and the “key” is in the actual stories shared privately. The stories are based on personal sensitive knowledge shared by peers in personal conversations under Chatham House Rules. This “stuff” may look obvious (?) – the magic lies between the lines and only becomes visible in a personal conversation. Full list at https://isac4cities.eu/tlpred.

This week´s thoughts are based on the scope of essential services your public administration subscribes to, operates, and manages, including what IT systems support their delivery.

  • Weekly [TLP:RED] for Publicly Elected Officials (Repeat # 32): Solicit the establishment of an Internet Exchange Points (IXPs) as the foundation for a high-performance and cyber resilient digital platform.
  • Weekly [TLP:RED] for Essential Services Managers (Repeat # 32): The more (subjectively) confident your citizens are regarding the cyber security of your services, the more likely it is they will adopt them. Be proactive to market cybersecurity!
  • Weekly [TLP:RED] for IT Leaders (Repeat # 32): All software should have a valid SOG-IS certificate and tenders should mandate it.

Ask Barista (GPT)

We have now launched a Barista pilot where colleagues get access to a custom designed ChatGPT app called “Barista” – I asked Barista who it is and it replied: “I’m Barista, your cybersecurity analyst assistant. I’m here to help security operations centre (SOC) teams, blue team defenders, and incident responders with things like: Log analysis (from Splunk, Sentinel, ELK, etc.), Writing detection rules (Sigma, KQL, SPL), Mapping alerts to MITRE ATT&CK, Remediation guidance (NIST, CIS, OWASP best practices), Threat hunting, system hardening, and incident response support, Automating security processes in hybrid and cloud environments”.

After extensive exploration we have decided to move our GPT solution from ChatGPT by OpenAI (US based) to “Le Chat” by Mistral AI (French / EU based) for data protection reasons (and wanting to use an EU based solution). Since we have been able to replicate our daily threat report in the free version of “Le Chat”, I have also cancelled the paid subscription to ChatGPT and will initially focus on the free version of “Le Chat”.

One key learning point has been that the greatest value of a GPT comes from being able to work with internal data of an organisation. Since members hesitate to upload internal data to a public GPT solution (even if the provider assures data protection), the “best” solution would be for them to install a GPT solution insider their own network (and then perhaps feed insights to an ISAC GPT solution hosted by one of our members -> like Paolo is working on for the MISP).

Another key learning point has been that ChatGPT can only automate tasks (i.e., email notifications) when combined with other paying services like Zapier. We will need to see what Mistral offers in this respect.

Finally, we have learned that while the GPT solutions can provide some very fast benefits, this requires extensive work in defining the queries – a skill our members in general do not seem to have.

Exploration continues and will keep you updated – the next sensible step would be copying our MISP approach and implementing Mistral AI inside the network of a member plus then beginning to open that up for others / helping others install their own and connect – all powerful activities but need funding.

For those administrations that joined the ChatGPT based version of Barista note that the Barista access expires middle of August – by then we should have the “Le Chat” version running

If you would like us to operate a query process for your GPT solutions (i.e., with internal data from your side) please do reach out.

I4C+ MISP

One public administration colleague now has our MISP running in their own network and we are working on pulling together the many:many NDA needed to begin using it – more once that NDA is finalised. Each administration can get its own confidential area and there is then the opportunity to share with other administrations and publish to the ENISA MISP. Let us know if you would like to join.

Summary

Hi everyone, friends from Belgium, Estonia, Ireland, and Italy joining this morning. Besides sharing holiday banter, we somehow got onto the track of discussing energy consumption in IT – actually I think it was triggered by a colleague sharing a story that their daughter is now avoiding streaming and GPT solutions due to their energy consumption. Lots of different viewpoints and approaches, while we agreed that the carbon footprint of suppliers should be included in any tenders. Also – take a look at https://www.computable.be/2024/02/22/vlaamse-overheid-bespaart-miljoenen-euros-aan-stroom-door-aanpassing-netwerk/ – a colleague administration reducing costs (and carbon footprint) by dynamically adjusting the IT assets powered. Overall, the challenge seems to be understanding the total impact of solutions across multiple services – optimizing one service may increase costs in other spaces as we know.

CTI sharing challenges was also explored with the general consensus that the sharing of IoCs is most helpful but that runs into major legal challenges in respect to stuff like vendor license agreements and administration policies – then again perhaps resolvable at a national level, but mission impossible when it comes to inter-national sharing -> maybe something for the EU to think about as a whole?

We also discussed a new e-identity / e-wallet solution being deployed in one of our member countries coupled with the many challenges these are facing from a security perspective. All countries struggling to safely provide e-services in the identity space (i.e., to support elections or health services) – biometrics are unfortunately no longer a robust solution due to the advancement of computing power and AI capabilities.

On a final note, and reflecting on the changes we are making to Barista, we all agreed that it is the public administrations that struggle most to not only fund needed security solutions, but also to build/maintain the internal competence to operate these. This is where we began reflecting on the role of the EU in making actual affordable services funded by the EU available to public administrations – outsourcing all of this to commercial third-parties cannot be the solution especially when we think about the global political challenges happening.

Cheers, 

Oliver

In the News
  • Major Cities of Europe, in collaboration with the City of Issy-les-Moulineaux, is pleased to announce the joint 2025 conference under the theme of “Piloting Disruptive Innovation in Cities and Regions”, which will be hosted at the UGC Congress Centre from October 9 to 10. Integrated into the Greater Paris Metropolis, Issy-les-Moulineaux is one of the most innovative cities in France and has long been recognized as a leader in digital innovation, circular economy, and environmental footprint reduction. The event is co-organized with Issy Media, the public company responsible for communication and innovation in Issy-les-Moulineaux. The conference will be conducted in English and French, with simultaneous translation available. See www.majorcities.eu for more details.
  • ECCC Info Day – Funding opportunities, 2 September 2025, Berlin, Germany – European Union
  ISAC Services (Member Funded)

We have published our services at Services Offered – EU ISAC for Cities (isac4cities.eu). Please do review and consider reaching out to include such in your activities and budgets.

Note that emerging new services are related to managing the MISP platform (and onboarding) plus Barista.

ISAC Baseline (IBAS) Project

The IBAS project continues and remember this sits on the Enablor platform serving a wider community. Enablor is currently supporting 3931 organisations with 4158 users and 10978 logins last year – a thriving community!

The ISAC benchmark platform offers a unique opportunity for public administrations to benchmark themselves against not only regulative requirements but also other local governments around Europe. Benchmarking data from European municipalities are now available in the ISAC Baseline Program providing participants with insight into how similar organizations perform and comply with legislation. Assessing the organization’s security level gives insight data on compliance with both legislation as well as automated mappings to security frameworks such as ISO 27001-2, CIS 18 and NIST CSF. The enablor platform can be used within your own organization and is a shortcut to collaborating with similar European organizations. If you are a region, you can also “sponsor” membership for your cities to create regional bench-learning groups. If you are a nation, then you can sponsor membership for your regions and cities as well of course.

Key value proposition? In the many discussions leading up to the launch, we see that the key value of participating is (a) access to a massive amount of detailed “real stories” on successful implementations across the NIS2 spectrum, and (b) significantly reduced efforts for reporting. If needed, we can also provide administrative support for transferring existing data into the enablor platform.

 

Please remember you can reach the whole group via city-isac-i4c-tlpwhite@majorcities.eu. A dedicated group for those cities signing the NDAs is available separately.

Also note our LinkedIn organisational page at https://www.linkedin.com/company/eu-city-information-sharing-and-analysis-center-isac/ and our discussion group at https://www.linkedin.com/groups/12773643/.  Do follow us / join.

Join our weekly Friday morning coffee chats from 9am-10am CET – feel free to come in your pyjamas. Let me know if you are missing an invite and I will send.

Thank you for the support, your City ISAC I4C+ Team.

Cheers and ever onwards

Oliver

Innovating our Future… Together

Chair City ISAC I4C+ / Dr. Oliver Schwabe.

Email: oliver.schwabe@isac4cities.eu Mobile: +49 (0) 1709053671. Web: https://i4c.isacs.eu/ & https://www.majorcities.eu/isac-for-cities-plus/  

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert