Hackathons

Test. Refine. Advance SME's Cybersecurity.

The CyberSuite Hackathon brings together cybersecurity professionals, SMEs, developers, and innovators for a collaborative, hands-on experience focused on testing and improving real-world cybersecurity tools.

At the core of the event are the CyberSuite tools, designed to help SMEs across critical sectors like energy, transport, health, and agrifood address today’s complex security challenges. From protecting smart-home IoT data and railway monitoring systems to securing digital health services and SaaS platforms for sensitive data, CyberSuite equips organisations with robust capabilities for detection, response, compliance, and secure development.

Whether you’re here to improve your skills or to help shape tools built for operational environments, this hackathon offers a chance to contribute directly to cybersecurity innovation, guided by real needs, pragmatic use cases, and real impact.

We welcome:

  • Cybersecurity professionals

  • Tech developers and testers

  • SME representatives

  • Students and early-career technologists

  • Anyone passionate about secure digital innovation

What’s the Mission?

The CyberSuite Hackathon 2025 is more than a challenge: it’s a co-creation lab for validating, testing, and improving the CyberSuite tools. With real-world use cases and thematic challenges, you’ll get exclusive access to tools developed under an EU-funded DevSecOps framework aimed at empowering SMEs to tackle modern cyber threats.

 

In this hackathon, you will:

  • Dive deep into tool testing and evaluation

  • Work on realistic cybersecurity challenges

  • Provide structured feedback

  • Connect with mentors and peers across Europe

  • Shape the tools that will power tomorrow’s cybersecurity landscape

Themes & Challenges

You’ll tackle curated, high-impact cybersecurity themes, such as:

  • Data Protection & Compliance (e.g. GDPR tools)

  • Cyber Hygiene & Phishing Prevention

  • Secure Digital Onboarding

  • Threat Monitoring & Incident Reporting

Each challenge comes with clear briefs, goals, and evaluation criteria. Your mission: test tools, identify gaps, and propose improvements.

 

Why Join?

  • Refine Tools that Matter: Directly influence the tools shaping the SME cybersecurity ecosystem.

  • Grow Your Network: Meet and collaborate with developers, cybersecurity professionals, and EU innovation leaders.

  • Upskill through Practice: Gain valuable hands-on experience in DevSecOps, tool testing, and feedback methodologies.

  • Get Recognized: Make your mark through certificate recognition and potential future collaboration opportunities.

Hackathon Structure

Pre-Hackathon Onboarding

Before the event, you’ll receive:

  • A comprehensive Welcome Pack

  • Credentials and access to the CyberSuite Sandbox

  • A CyberSuite Tools Guide and training materials (Online workshop during the week of October 20th–24th, date and time TBC)

  • Invitations to optional webinars and team networking sessions

Get familiar with the challenges, tools, and teammates to hit the ground running.

Hackathon Day

A full-day experience of:

  • Team collaboration (pre-formed or built on the spot)

  • Hands-on testing of CyberSuite tools

  • Real-time mentorship and support

  • Structured check-ins and feedback sharing

  • Final team presentations

All activity is centered around evaluating tools against realistic cybersecurity scenarios, with expert support and feedback loops throughout.

Post-Hackathon Recognition & Engagement

After the hackathon:

  • Receive your Certificate of Participation

  • Be featured on CyberSuite channels (for standout contributions)

  • Share feedback through surveys and reports

  • Get access to follow-up piloting opportunities

  • Stay connected with the CyberSuite innovation community

Cybersecurity Tools of the Hackathon

ACAS — Advanced Cybersecurity Analytics Service (by Montimage)

Purpose: Network analytics with probes for (near) real-time anomaly detection and Root Cause Analysis (RCA); supports new protocol analyses and provides rule/AI-based detections.

Target audience / sectors: SMEs and MEs that operate IP/IoT/Mobile networks, especially where rich network telemetry analysis and Network Detection and Response (NDR) and Network Behaviour Analysis (NBA) techniques can be used to detect and mitigate cyber attacks.

Why it’s valuable for participants: Hands-on experience with detection, rule tuning, protocol parsers, and RCA workflows; see how analytics improve incident understanding and management. Configuration of security services during the Planning phase and operation during the Monitoring phase.

How we’ll test it:

  • Feed ACAS probes with controlled benign + attack traffic (e.g., from Pentesting/5greplay); verify alerts and RCA.
  • Measure basics like detection latency and false positives, and evaluate usefulness of RCA  for automated or human decision-making.
Seer Box — Web Application Security Manager (by Puribus One)

Purpose: Non-invasive, WAF-plus protection for web apps & APIs; collects traffic from common proxies/servers, detects auth failures, injections, scanners/bots; can publish rule feeds (e.g., NGINX, ModSecurity) and notify SIEMs.

Target audience / sectors: SMEs with public-facing web apps/APIs; relevant across many sectors (e.g., portals, e-services, SaaS) including the project’s priority sectors.

Why it’s valuable for participants: Practical OWASP Top-10 style defenses, rules feed generation, and SIEM integration in the Test stage of DevSecOps.

How we’ll test it:

  • Place Seer Box in front of a demo app; run curated OWASP-style attacks (auth brute force, XSS/SQLi, path traversal).
  • Confirm detections, blocking, rules feed export/import, and alert delivery to a log aggregator/SIEM; review time-to-restore and coverage.
PUZZLE — Kubernetes-centric Risk Assessment & Security Orchestration (by UBITECH)

Purpose: Risk assessment platform with dynamic risk estimation. Kubernetes-centric security functions orchestration.

Target audience / sectors: DevOps teams in SMEs running containerized apps (SaaS, platforms) across targeted sectors (health, transport, energy, agrifood).

Why it’s valuable for participants: Experience risk scoring, policy validation, and automated mitigations applied to real workloads; bridges Build/Test/Operate.

How we’ll test it:

  • Assess risks, learn about threats, vulnerabilities and mitigations that effectively reduce risk.
  • Enforce protection rules on an application deployed on K8s, view results and trigger mitigations when test findings arise.
SASTer — Static Application Security Testing (by InQbit)

Purpose: SASTer provides static code analysis to identify vulnerabilities at the source level. Users can easily create projects, upload code, run automated analyses, and retrieve actionable results.

Target audience / sectors: Developers in small and medium-sized enterprises (SMEs) across all sectors who are building and maintaining software applications.

Why it’s valuable for participants: SASTer empowers development teams by delivering immediate feedback on coding issues during the Build phase. This enables faster remediation, reduces security risks early in the lifecycle, and directly supports secure development KPIs and developer personas.

How we’ll test it:

  • Create a project within SASTer.
  •  Upload source code and initiate the automated analysis.
  • Review results displayed on the interactive dashboard, highlighting detected vulnerabilities.
  • Download comprehensive reports for further offline review and remediation planning.
Pentesting Tool (5greplay) — Traffic Capture/Replay and Fuzz/Scalability Testing Tool (by Montimage)

Purpose: Traffic capture/replay and fuzz/scalability testing to stress systems and validate defenses.

Target audience / sectors: QA/security engineers and SMEs that need network traffic with and without injected attacks/anomalies to validate the robustness of network elements and protection techniques.
Why it’s valuable for participants: Generates realistic adversarial traffic for the Test phase; helps validate ACAS/Seer Box detection and system resiliency.

How we’ll test it:

  • Replay malicious/edge traffic into demo services protected by ACAS/Seer Box; confirm which scenarios are detected/blocked.
  • Evaluate the improved ease for configuration (sources/targets), repeatability and coverage.
MAESTRO — Deployment & Orchestration Framework (by UBITECH)

Purpose: Unified deployment/orchestration for apps and security functions (policy-based scaling, monitoring hooks), easing secure rollouts.

Target audience / sectors: Teams that must deploy apps and attach security services (across the project’s sectors).

Why it’s valuable for participants: See how orchestrated deployment with embedded checks speeds Deploy/Operate while maintaining security baselines.

How we’ll test it:

  • Use MAESTRO to design a sample service.
  • Deploy the service and protect it with a CyberSuite control (e.g., PUZZLE agent/Seer Box connector).
  • Observe deployment time and monitoring visibility.
GEIGER Tools — Cybersecurity Awareness, Planning and Education Tools (by cyberGEIGER)

Purpose: Cyberthreat awareness, cybersecurity planning, and AI-based coaching for the implementation of cybersecurity measures and incident response

Target audience / sectors: Non-expert small business users/managers across sectors wanting to maintain a practical security posture.

Why it’s valuable for participants: Low-threshold way to plan and implement small but high-impact security tasks, supporting continuous improvement. Useful in the context of SecDevOps Operate and Monitor.

How we’ll test it:

  • Let the SME set up their GEIGER App instance, be briefed about top threats, select and plan recommended actions, and engage in initiating the plan. Evaluation: user feedback form.
  • Let the SME review a suspected incident (e.g. a suspected Phishing mail), resolve the incident (if applicable), and increase their security posture with respect to the incident’s type. Evaluation: user feedback form.
KARTOS — External Attack Surface & Digital Risk Protection (by Enthec)

Purpose: SaaS threat-intel platform emulating attacker reconnaissance to surface DNS issues, network exposure, data leaks/credentials, CMS status, IP reputation, CVEs, email security config; alerts & reports.

Target audience / sectors: SMEs across sectors (license and feature set tailored for SME budgets/needs).

Why it’s valuable for participants: Fast awareness of exposed risks beyond the perimeter; supports Plan/Monitor posture and compliance readiness.

How we’ll test it:

  • Run a domain assessment for the demo company; review findings (DNS/CMS/leaks/IP reputation).
  • Validate remediation suggestions and generate an executive report; observe alerting & false-positive behaviour against its KPIs.
Anti-Phishing Game (by Montimage)

Purpose: Immersive, hands-on phishing awareness game (easily installable, supports anonymous/subscribed players, provides different difficulty levels).

Target audience / sectors: All SME personnel; high relevance where email/social engineering risk is elevated.

Why it’s valuable for participants: Immediate and measurable improvements in skill and awareness for hackathon participants. Awareness KPIs appear for the different use cases.

How we’ll test it: Baseline short quiz → game session → post-quiz; measure awareness increase

CyberSuite Dashboard and CyberSuite Marketplace

As part of the hackathon, participants will also have the opportunity to explore two central components of the CyberSuite platform: the CyberSuite Dashboard and the CyberSuite Marketplace. The Dashboard brings together in real time the key metrics and KPIs from all integrated tools, offering a single interface for monitoring, visualization, and situational awareness. It enables participants to see how outputs from tools such as Seer Box, ACAS, and KARTOS translate into actionable insights and decision support. Complementing this, the Marketplace serves as the main entry point to the CyberSuite ecosystem, allowing participants to browse available services, access tool profiles, initiate trials or subscriptions, and understand the added value of each solution. Together, these two components provide the functional backbone of CyberSuite, helping participants assess both the effectiveness of the tools and the ease with which SMEs can adopt them.

Hackathon Agenda

10:00 – 10:20
Welcome & Opening Remarks
  • Welcome by organisers

  • Overview of the CyberSuite project and hackathon objectives

  • Introduction to the agenda & practical information 

  • Icebreaker: Short introductions from participants

10:20 – 10:45
CyberSuite Academy
  • Presentation of the CyberSuite Academy – online training and resources available to participants 
10:45 – 11:15
Participant Onboarding
  • Brief recap of tools and testing scenarios (building on the pre-hackathon workshop)

  • Formation of groups/assignment of tasks

11:15 – 11:30
Short Break & Networking
11:30 – 12:30
Hands-On Tool Testing
  • Teams explore assigned CyberSuite tools in guided scenarios

  • Tool owners and mentors provide real-time support

  • Participants document findings, usability issues, and improvement ideas

12:30 – 12:50
Feedback Sharing & Group Reflections
  • Each team briefly shares their insights (strengths, gaps, improvement ideas) 
  • Open discussion with tool owners and organisers 
12:50 – 13:00
Wrap-Up & Next Steps
  • Summary of key outcomes
  • Explanation of post-hackathon follow-up
  • Closing remarks & group photo 
Scroll to Top