Ransomware is one of the most frequent types of cyberattacks: it involves taking control of data and demanding payment to restore access (i.e., a ransom). This type of attack is evolving into a sophisticated form of extortion, leveraging cybercriminal organizations that provide infrastructure and services (i.e., ransomware-as-a-service) to exploit vulnerabilities in target entities (e.g., industries, public administrations, small and medium-sized enterprises, and critical infrastructures) [1].
This digital form of “protection racket”, which holds encrypted data hostage until the ransom is paid, differs from its physical counterpart by transcending geographic boundaries, enabling perpetrators to operate remotely and anonymously, thereby amplifying the reach and impact of their attacks.
Ransomware breaches thus represent a significant threat to small and medium-sized enterprises (SMEs), which often lack the robust cybersecurity infrastructure of larger companies, risking substantial financial loss, reputational damage, and even business closure.
The case of an Italian SME [2] that refused to pay the ransom—adhering to ethical and legal principles—exemplifies the potential impact of such an attack. While upholding these values and rules is a source of European pride, the inability to adequately defend them remains a vulnerability: the company was forced to halt all production activities and temporarily suspend its staff.
Therefore, intrusions by these cybercriminals not only threaten the economic sustainability and existence of the affected business but also negatively affect its broader network of stakeholders, including individuals and other companies.
In this context, the increasing sophistication and frequency of ransomware and cyberattacks underscore the urgent need for greater cybersecurity awareness and the adoption of proactive measures by SMEs. These organizations must implement a multilayered approach involving employees, organizational processes, and technologies to address well-known and exploited vulnerabilities, such as backup strategies, human error, data management, access control policies, and technological obsolescence [1][3][4].
Awareness and proactivity can be achieved through a robust and collaborative defense strategy. The creation of a shared and continuously evolving body of knowledge (BoK) dedicated to countering cyber threats is no longer just an advantage—it is a critical imperative to safeguard digital assets and ensure operational resilience. This BoK should serve as a dynamic compendium of attack methodologies, threat actor profiles, effective mitigation techniques, best practices for incident response, and lessons learned. A consolidated and shared knowledge base would be a valuable asset for significantly improving threat landscape understanding, identifying vulnerabilities, and developing more effective security controls.
Moreover, the inherent interconnectedness of cyber threats demands the smooth sharing of information with appropriate stakeholders. Cyberattacks rarely operate in isolation; threat actors often adopt similar tactics across multiple targets. A well-governed BoK would promote the timely and secure dissemination of actionable intelligence (e.g., emerging attack patterns and effective defensive strategies) to relevant entities, such as SMEs, government bodies, and security providers. This collaborative approach would strengthen collective defense, enabling organizations to anticipate and counter attacks based on community-shared experiences. The sharing of information, in compliance with appropriate legal and ethical frameworks, turns individual efforts into a coordinated and stronger defense, ultimately reducing the impact and prevalence of cyberattacks in the digital landscape. The BoK, therefore, stands as a cornerstone of a proactive and collaborative cybersecurity posture essential to addressing the complexity of today’s threat environment.
On the other hand, the collaborative creation of a shared BoK requires coordination through adequate support tools. Participants in this initiative should be able to share and grant access to a wide range of cyber threat intelligence (CTI), including emerging threats, attack vectors, tactics, techniques and procedures (TTPs) used by threat actors, and indicators of compromise (IOCs).
Such data sharing requires explicit consent, respecting the protection of personal data (privacy) in accordance with EU Regulation 2016/679 GDPR [5]. This consent mechanism, which governs data processing based on specific policies, enables the controlled and governed creation of collective knowledge, fostering trust and encouraging responsible intelligence sharing among participants.
The ReD Service, developed by CyberEthics Lab. [6], supports the collaborative sharing of CTI data among appropriate entities based on consent and smart contracts. While consent mechanisms ensure privacy and transparency, smart contracts on immutable ledgers (i.e., blockchain) securely contain the necessary information to automatically enable access and data sharing among stakeholders, ensuring integrity, availability, and confidentiality.
As a standalone module, the ReD Service can be integrated into existing or new platforms to add compliant data-sharing features, policy management, and consent handling. To better protect potentially personal, confidential, or sensitive data from policies and consents, the ReD Service uses a technique called pseudonymization. This process replaces identifiable information with unique and anonymised codes using a robust cryptographic method (i.e., SHA-2 family cryptographic hash functions). This design choice ensures that the ReD Service never stores personal data in smart contracts or on the blockchain, maintaining compliance with regulatory constraints (e.g., Articles 16 and 17 of the GDPR).
The ReD Service represents the core engine of the Smart Consent component (SMAC – “Smart contracts and icons for consent management in the context of an SSI approach”). This innovation was recognized by the European Commission’s Key Innovation Radar in 2024 [7] in the “Smart & Sustainable Society INNOVATION” category, contributing to Sustainable Development Goal 16: “Peace, Justice and Strong Institutions” [8].
CyberSocial Lab. and CyberEthics Lab. collaborate to test, optimize, and extend the ReD Service in the CyberNEMO [9] and INTERSOC [10] projects.
This work was supported by the CyberNEMO project (Grant Agreement No. 101168182), which has received funding from the European Union’s Horizon Europe research and innovation program, and by the INTERSOC project (Grant Agreement No. 101145853).
The opinions expressed in this document reflect only the author’s view and in no way reflect the European Commission’s opinions. The European Commission is not responsible for any use that may be made of the information it contains.
[1] ENISA Threat landscape 2024 – https://www.enisa.europa.eu/sites/default/files/2024-11/ENISA%20Threat%20Landscape%202024_0.pdf
[2] Alf Dafrè case – https://decripto.org/en/treviso-hacker-attack-on-alf-dafre-furniture-company-350-workers-end-up-on-lay-off/
[3] ISO/IEC 27001:2022 https://www.iso.org/standard/27001
[4] NIST Cybersecurity Framework (CSF) – https://www.nist.gov/cyberframework
[5] EU General Data Protection Regulation 2016/679 – https://eur-lex.europa.eu/eli/reg/2016/679/
[6] ReD in the CEL Portfolio – https://cyberethicslab.com/en/portafoglio/
[7] Smart Consent in the Innovation Radar – https://innovation-radar.ec.europa.eu/innovation/56307
[8] United Nations SDG no.16 – https://sdgs.un.org/goals/goal16
[9] CyberNEMO project – GA. no. 101168182 – https://cybersoclab.com/cybernemo-eng/
[10] INTERSOC project – G.A. no. 101145853 – https://cyberethicslab.com/en/intersoc/