Present across all three projects (CyberWiz, EnergyShield, SOCCRATES), consistently focused on identifying and modeling security weaknesses in critical systems.
FORESEETI AB
Swedish cybersecurity SME specializing in vulnerability assessment, attack graph modeling, and AI-driven threat prediction for critical infrastructures.
Their core work
FORESEETI AB is a Stockholm-based cybersecurity SME specializing in vulnerability assessment and threat modeling for critical infrastructures. They build tools and methods for analyzing attack paths, predicting cyber threats, and assessing business impact of security incidents. Their work spans industrial control systems (ICS/SCADA), energy infrastructure protection, and Security Operations Center (SOC) automation — helping organizations understand where they are most exposed before an attack happens.
What they specialise in
CyberWiz explicitly targeted ICS/IACS/SCADA security visualization; EnergyShield continued this into energy grid protection.
SOCCRATES project centered on attack defense graphs, business impact modelling, and AI-driven threat prediction for SOC/CSIRT teams.
EnergyShield (anomaly detection, DDoS mitigation, SIEM) and SOCCRATES (monitoring & response, course of action) both address real-time defense.
SOCCRATES introduced AI and machine learning into their portfolio for automated threat prediction and response recommendation.
How they've shifted over time
FORESEETI started in 2015 with a tight focus on visualization and vulnerability assessment for industrial control systems (ICS/SCADA), essentially helping operators see where their OT environments were at risk. By 2019, their scope expanded significantly — into cyber threat intelligence, attack graph modeling, AI-driven threat prediction, and SOC/CSIRT automation. The shift shows a clear move from static vulnerability scanning toward dynamic, intelligent security orchestration that covers the full detect-analyze-respond cycle.
FORESEETI is moving from infrastructure-specific vulnerability tools toward AI-powered, full-lifecycle cyber defense platforms — expect future work in automated security orchestration and predictive threat modeling.
How they like to work
FORESEETI operates exclusively as a project participant, never as coordinator — consistent with a specialist SME that contributes deep technical expertise rather than managing large consortia. With 30 unique partners across 17 countries from just 3 projects, they integrate well into large, diverse teams. Their repeat focus area across projects suggests they are brought in specifically for their vulnerability assessment and threat modeling capabilities.
Despite only three projects, FORESEETI has built a remarkably wide network of 30 partners across 17 countries, indicating participation in large pan-European security consortia. Their geographic reach spans well beyond the Nordic region into a broad European footprint.
What sets them apart
FORESEETI brings a rare combination: deep ICS/SCADA security knowledge from the industrial side, merged with modern AI-driven attack graph modeling and SOC automation from the IT security side. This OT-IT convergence capability is in high demand as energy grids, manufacturing plants, and other critical infrastructures digitize. For consortium builders, they offer a proven SME partner that delivers concrete security assessment tools rather than just research papers.
Highlights from their portfolio
- CyberWizTheir first H2020 project and largest single grant (EUR 854,875), establishing their position in critical infrastructure cybersecurity visualization.
- SOCCRATESRepresents their most advanced work — combining attack defense graphs with AI/ML for automated SOC and CSIRT response, marking a clear technology leap.
- EnergyShieldBridges their ICS expertise into the energy sector specifically, covering anomaly detection to DDoS mitigation for energy grid protection.