Hackathons

- October 31st, 2025
- 10:00 - 13:00 (Local Time, Greece)
- JOIST Innovation Park, Larissa, Greece
Test. Refine. Advance SME's Cybersecurity.
The CyberSuite Hackathon brings together cybersecurity professionals, SMEs, developers, and innovators for a collaborative, hands-on experience focused on testing and improving real-world cybersecurity tools.
At the core of the event are the CyberSuite tools, designed to help SMEs across critical sectors like energy, transport, health, and agrifood address today’s complex security challenges. From protecting smart-home IoT data and railway monitoring systems to securing digital health services and SaaS platforms for sensitive data, CyberSuite equips organisations with robust capabilities for detection, response, compliance, and secure development.
Whether you’re here to improve your skills or to help shape tools built for operational environments, this hackathon offers a chance to contribute directly to cybersecurity innovation, guided by real needs, pragmatic use cases, and real impact.
We welcome:
Cybersecurity professionals
Tech developers and testers
SME representatives
Students and early-career technologists
Anyone passionate about secure digital innovation
What’s the Mission?
The CyberSuite Hackathon 2025 is more than a challenge: it’s a co-creation lab for validating, testing, and improving the CyberSuite tools. With real-world use cases and thematic challenges, you’ll get exclusive access to tools developed under an EU-funded DevSecOps framework aimed at empowering SMEs to tackle modern cyber threats.
Â
In this hackathon, you will:
Dive deep into tool testing and evaluation
Work on realistic cybersecurity challenges
Provide structured feedback
Connect with mentors and peers across Europe
Shape the tools that will power tomorrow’s cybersecurity landscape
Themes & Challenges
You’ll tackle curated, high-impact cybersecurity themes, such as:
Data Protection & Compliance (e.g. GDPR tools)
Cyber Hygiene & Phishing Prevention
Secure Digital Onboarding
Threat Monitoring & Incident Reporting
Each challenge comes with clear briefs, goals, and evaluation criteria. Your mission: test tools, identify gaps, and propose improvements.
Â
Why Join?
Refine Tools that Matter: Directly influence the tools shaping the SME cybersecurity ecosystem.
Grow Your Network: Meet and collaborate with developers, cybersecurity professionals, and EU innovation leaders.
Upskill through Practice: Gain valuable hands-on experience in DevSecOps, tool testing, and feedback methodologies.
Get Recognized: Make your mark through certificate recognition and potential future collaboration opportunities.
Hackathon Structure
Before the event, you’ll receive:
A comprehensive Welcome Pack
Credentials and access to the CyberSuite Sandbox
A CyberSuite Tools Guide and training materials (Online workshop during the week of October 20th–24th, date and time TBC)
Invitations to optional webinars and team networking sessions
Get familiar with the challenges, tools, and teammates to hit the ground running.
A full-day experience of:
Team collaboration (pre-formed or built on the spot)
Hands-on testing of CyberSuite tools
Real-time mentorship and support
Structured check-ins and feedback sharing
Final team presentations
All activity is centered around evaluating tools against realistic cybersecurity scenarios, with expert support and feedback loops throughout.
After the hackathon:
Receive your Certificate of Participation
Be featured on CyberSuite channels (for standout contributions)
Share feedback through surveys and reports
Get access to follow-up piloting opportunities
Stay connected with the CyberSuite innovation community
Cybersecurity Tools of the Hackathon
Purpose: Network analytics with probes for (near) real-time anomaly detection and Root Cause Analysis (RCA); supports new protocol analyses and provides rule/AI-based detections.
Target audience / sectors: SMEs and MEs that operate IP/IoT/Mobile networks, especially where rich network telemetry analysis and Network Detection and Response (NDR) and Network Behaviour Analysis (NBA) techniques can be used to detect and mitigate cyber attacks.
Why it’s valuable for participants: Hands-on experience with detection, rule tuning, protocol parsers, and RCA workflows; see how analytics improve incident understanding and management. Configuration of security services during the Planning phase and operation during the Monitoring phase.
How we’ll test it:
- Feed ACAS probes with controlled benign + attack traffic (e.g., from Pentesting/5greplay); verify alerts and RCA.
- Measure basics like detection latency and false positives, and evaluate usefulness of RCAÂ for automated or human decision-making.
Purpose: Non-invasive, WAF-plus protection for web apps & APIs; collects traffic from common proxies/servers, detects auth failures, injections, scanners/bots; can publish rule feeds (e.g., NGINX, ModSecurity) and notify SIEMs.
Target audience / sectors: SMEs with public-facing web apps/APIs; relevant across many sectors (e.g., portals, e-services, SaaS) including the project’s priority sectors.
Why it’s valuable for participants: Practical OWASP Top-10 style defenses, rules feed generation, and SIEM integration in the Test stage of DevSecOps.
How we’ll test it:
- Place Seer Box in front of a demo app; run curated OWASP-style attacks (auth brute force, XSS/SQLi, path traversal).
- Confirm detections, blocking, rules feed export/import, and alert delivery to a log aggregator/SIEM; review time-to-restore and coverage.
Purpose: Risk assessment platform with dynamic risk estimation. Kubernetes-centric security functions orchestration.
Target audience / sectors: DevOps teams in SMEs running containerized apps (SaaS, platforms) across targeted sectors (health, transport, energy, agrifood).
Why it’s valuable for participants: Experience risk scoring, policy validation, and automated mitigations applied to real workloads; bridges Build/Test/Operate.
How we’ll test it:
- Assess risks, learn about threats, vulnerabilities and mitigations that effectively reduce risk.
- Enforce protection rules on an application deployed on K8s, view results and trigger mitigations when test findings arise.
Purpose: SASTer provides static code analysis to identify vulnerabilities at the source level. Users can easily create projects, upload code, run automated analyses, and retrieve actionable results.
Target audience / sectors: Developers in small and medium-sized enterprises (SMEs) across all sectors who are building and maintaining software applications.
Why it’s valuable for participants: SASTer empowers development teams by delivering immediate feedback on coding issues during the Build phase. This enables faster remediation, reduces security risks early in the lifecycle, and directly supports secure development KPIs and developer personas.
How we’ll test it:
- Create a project within SASTer.
- Â Upload source code and initiate the automated analysis.
- Review results displayed on the interactive dashboard, highlighting detected vulnerabilities.
- Download comprehensive reports for further offline review and remediation planning.
Purpose: Traffic capture/replay and fuzz/scalability testing to stress systems and validate defenses.
Target audience / sectors: QA/security engineers and SMEs that need network traffic with and without injected attacks/anomalies to validate the robustness of network elements and protection techniques.
Why it’s valuable for participants: Generates realistic adversarial traffic for the Test phase; helps validate ACAS/Seer Box detection and system resiliency.
How we’ll test it:
- Replay malicious/edge traffic into demo services protected by ACAS/Seer Box; confirm which scenarios are detected/blocked.
- Evaluate the improved ease for configuration (sources/targets), repeatability and coverage.
Purpose: Unified deployment/orchestration for apps and security functions (policy-based scaling, monitoring hooks), easing secure rollouts.
Target audience / sectors: Teams that must deploy apps and attach security services (across the project’s sectors).
Why it’s valuable for participants: See how orchestrated deployment with embedded checks speeds Deploy/Operate while maintaining security baselines.
How we’ll test it:
- Use MAESTRO to design a sample service.
- Deploy the service and protect it with a CyberSuite control (e.g., PUZZLE agent/Seer Box connector).
- Observe deployment time and monitoring visibility.
Purpose: Cyberthreat awareness, cybersecurity planning, and AI-based coaching for the implementation of cybersecurity measures and incident response
Target audience / sectors: Non-expert small business users/managers across sectors wanting to maintain a practical security posture.
Why it’s valuable for participants: Low-threshold way to plan and implement small but high-impact security tasks, supporting continuous improvement. Useful in the context of SecDevOps Operate and Monitor.
How we’ll test it:
- Let the SME set up their GEIGER App instance, be briefed about top threats, select and plan recommended actions, and engage in initiating the plan. Evaluation: user feedback form.
- Let the SME review a suspected incident (e.g. a suspected Phishing mail), resolve the incident (if applicable), and increase their security posture with respect to the incident’s type. Evaluation: user feedback form.
Purpose: SaaS threat-intel platform emulating attacker reconnaissance to surface DNS issues, network exposure, data leaks/credentials, CMS status, IP reputation, CVEs, email security config; alerts & reports.
Target audience / sectors: SMEs across sectors (license and feature set tailored for SME budgets/needs).
Why it’s valuable for participants: Fast awareness of exposed risks beyond the perimeter; supports Plan/Monitor posture and compliance readiness.
How we’ll test it:
- Run a domain assessment for the demo company; review findings (DNS/CMS/leaks/IP reputation).
- Validate remediation suggestions and generate an executive report; observe alerting & false-positive behaviour against its KPIs.
Purpose: Immersive, hands-on phishing awareness game (easily installable, supports anonymous/subscribed players, provides different difficulty levels).
Target audience / sectors: All SME personnel; high relevance where email/social engineering risk is elevated.
Why it’s valuable for participants: Immediate and measurable improvements in skill and awareness for hackathon participants. Awareness KPIs appear for the different use cases.
How we’ll test it: Baseline short quiz → game session → post-quiz; measure awareness increase
As part of the hackathon, participants will also have the opportunity to explore two central components of the CyberSuite platform: the CyberSuite Dashboard and the CyberSuite Marketplace. The Dashboard brings together in real time the key metrics and KPIs from all integrated tools, offering a single interface for monitoring, visualization, and situational awareness. It enables participants to see how outputs from tools such as Seer Box, ACAS, and KARTOS translate into actionable insights and decision support. Complementing this, the Marketplace serves as the main entry point to the CyberSuite ecosystem, allowing participants to browse available services, access tool profiles, initiate trials or subscriptions, and understand the added value of each solution. Together, these two components provide the functional backbone of CyberSuite, helping participants assess both the effectiveness of the tools and the ease with which SMEs can adopt them.
Hackathon Agenda
Welcome by organisers
Overview of the CyberSuite project and hackathon objectives
Introduction to the agenda & practical informationÂ
Icebreaker: Short introductions from participants
- Presentation of the CyberSuite Academy – online training and resources available to participantsÂ
Brief recap of tools and testing scenarios (building on the pre-hackathon workshop)
Formation of groups/assignment of tasks
Teams explore assigned CyberSuite tools in guided scenarios
Tool owners and mentors provide real-time support
Participants document findings, usability issues, and improvement ideas
- Each team briefly shares their insights (strengths, gaps, improvement ideas)Â
- Open discussion with tool owners and organisersÂ
- Summary of key outcomes
- Explanation of post-hackathon follow-up
- Closing remarks & group photoÂ