Table of Contents

PHACKS | Cybersecurity

As the EU’s European Cyber Competence Centre (ECCC), which sponsors the PHACKS project, has a special interest in using Sedicii’s ZKP technology platform to increase cybersecurity competence, particularly by increasing collaboration.  Some of the ECCC National Coordination Centres are expected to assist in encouraging active participation.  

Suggested requirements have so far included: 

  • Identifying requirements to match or validate sensitive data attributes between organisations that cannot normally be shared today.  This particularly includes attributes in existing taxonomies that support the five risk steps – Identify (risk), Protect, Detect, Respond, Recover.  This may also include attributes for anomaly detection, particularly for threats or vulnerabilities, as previously identified internationally for Collaborative Cyber Situational Awareness (CCSA).  This could include existing or new attributes in taxonomies such as STiX, TAXii and developments that have replaced IODEF. 
  • Related counter-fraud, access control and personnel security challenges, including for RBAC, geo-authentication (e.g. for Export Control requirements) and law enforcement agencies’ collaboration. 
  • KYB onboarding. This is the onboarding of a registered and compliant company as a relying party on the PHACKS platform.   What are the minimum regulatory compliance, operational, digital and cybersecurity requirements?  What sensitive data attributes exist that need to be verifiedsecurely?  
  • KYC: Customer onboarding KYC.  This is based on either Customer Due Diligence (CDD) or Enhanced Due Diligence (EDD), which includes digital contact data and device KYC, together with any additional requirements. In the EU, this also ought to comply with Strong Customer Authentication (SCA) in PSD2.  
  • KYC: Employee KYC.  All employees of regulated companies should go through EDD and have an AML background check.   SCA may be required in some cases also. 
  • Tax returns and refunds.  The requirements seem very similar to the financial sector requirements to validate tax returns and claims for refunds, to help defeat types of tax fraud.  This may also apply to Authorisation Push Payment Fraud (APPF).  
  • Monitoring. There is a requirement for continuous digital monitoring of different kinds.  The increasingly strong requirements for AML are likely to require yet more monitoring, which is the kind of problem that PHACKS is well positioned to address. 

Realising Value through PHACKS 

Data about cybersecurity vulnerabilities in products and general threats from groups of bad actors (e.g. ransomware methods) is routinely provided to, or shared by, cybersecurity and cyber defence organisations.  However, there is much less sharing of operational or intelligence data.  PHACKS can help to address this in a number of areas and with different communities, mainly in industry, but potentially with governments also.  Sedicii is building on its extensive experience in cybersecurity communities to build into PHACKS different kinds of attribute validation and anomaly detection features that individual organisations or communities of smaller communities can use to improve existing cyber situational awareness and cyber defence, both internally and collaboratively.   

PHACKS is particularly grateful for the assistance of the National Coordination Centres, and through them, with some of the leading CERTs, CSIRTs and ISACs across the EU.  

How to Participate in PHACKS

If you are inerested in getting involved, please visit our How to Participate page or Contact Us

Scroll to Top