POWRÓT DO BLOGA
CybersecurityAINIS2Incident ReportingEU Projects

Behind the Scenes of INCIDENTRON: Ending the Incident Reporting Nightmare (And Why AI Alone Won’t Save Your R&D Project)

2026-02-20// Grzegorz Strus
Behind the Scenes of INCIDENTRON: Ending the Incident Reporting Nightmare (And Why AI Alone Won’t Save Your R&D Project)

Most articles about emerging technologies read like perfect PR brochures: "Artificial Intelligence will revolutionize the market, the system will do everything itself, and we can all finally relax." The reality, however, is vastly different.

Behind every technological breakthrough lie months of tough negotiations, firefighting, rigorous requirements engineering, and hard project management. And, above all: the highly underrated art of saying "NO."

Imagine this scenario: you are the CISO at a critical infrastructure operator. Your organization has just fallen victim to a severe, cross-border cyberattack. But instead of focusing 100% of your SOC team's resources on containing the threat, a bureaucratic nightmare begins. You have to report the exact same incident multiple times, under different legal frameworks (NIS2, DORA, CER, GDPR, CRA), to various authorities across different countries, in entirely different formats and languages.

This "reporting marathon" is currently one of the biggest bottlenecks in the cybersecurity industry. And this is exactly the problem we are solving in a pan-European consortium by building the INCIDENTRON project. Serving as a Work Package Leader and PMO in this initiative, my role is to ensure that a high-level EU vision actually translates into a functional, secure, and deliverable product.

What Exactly is INCIDENTRON? Breaking Down the Silos

From a market perspective, INCIDENTRON is a massive, Digital Europe-funded project aimed at creating a modular, open-source framework and platform for automated incident reporting.

Our core promise to the market is based on one simple premise: One incident, one workflow for multiple regulations, instead of multiple disconnected workflows for a single event.

The system (developed in collaboration with partners like the VUB AI Lab) leverages Large Language Models (LLMs) to automatically assess breach parameters, structure data from MSSP systems, and generate ready-to-send reports tailored to specific legal frameworks. Furthermore, the platform natively integrates with threat intelligence sharing platforms (MISP) and Cyber Range training environments.

The active involvement of key European players, including ECSO (European Cyber Security Organisation), guarantees that we are not just building another piece of academic "shelfware," but a true market standard for the whole of Europe.

(You can read more about the project's foundation on the official Incidentron website and in the recent ECSO announcement).

From the PM's Trenches: How EU Innovation is Actually Delivered

While AI will eventually automate the reports, in international consortiums, not a single line of code gets written without iron-clad project management. Coordinating lawyers, researchers, and engineers from over a dozen countries is a political and technological minefield.

In complex R&D environments, the role of a Leader is not simply to "move tickets in Jira." You have to step into the shoes of a Strategy Architect and a Crisis Manager. What does this mean in practice, and what lessons can be drawn from the INCIDENTRON battlefield?

Scope Defense & Budget Protection

R&D projects are notorious for scope creep—a never-ending wishlist from stakeholders. When sudden pressure arises to implement unplanned, highly complex architectural changes or additional data integrations mid-development, simply saying "we don't want to do this" is never an option. My role is to translate the developers' technical constraints into the hard language of business risk, diplomatically blocking ad-hoc additions that could derail critical project milestones and burn through the budget.

The "Tech-to-Biz" Translator

Cybersecurity projects often cause a clash between legal experts (focused strictly on the letter of the law) and engineers (focused on the codebase). When the development team expresses justified frustration over seemingly illogical legal requirements, I take that raw, emotional feedback and convert it into constructive, diplomatic communication. You have to shield the IT team from consortium politics, giving them the breathing room they need to actually build.

Intellectual Property (IP) Strategy

INCIDENTRON is an Open Source project. In such collaborative environments, the lines can easily blur. The key is navigating between providing substantial, required input (e.g., delivering complex scenarios for the Cyber Range) and protecting your own commercial know-how. When questions about licensing arise, you need to know how to share value without giving away years of proprietary R&D for free.

Technical Product Ownership (Catching Bugs at the Source)

Architectural flaws are the most expensive to fix. A deep understanding of the cybersecurity domain allows us to catch gaps in requirements analysis very early on. For instance, when a logical issue emerged regarding MITRE ATT&CK matrix mapping (a single vs. multi-select conflict), we forced an architectural pivot before the developers wrote a single line of faulty code.

What Does This Mean for the Industry?

Ultimately, INCIDENTRON will lift a massive administrative burden off the shoulders of CISOs and SOC teams, allowing them to focus on actual incident response rather than paperwork. It will also revolutionize the work of MSSPs, who will be able to offer their clients automated compliance out-of-the-box.

However, the experience of managing such a complex ecosystem proves another crucial point. Even the most brilliant concept and the most advanced AI models will fail without ruthless scope management, conscious stakeholder alignment, and seamless translation between the worlds of Business, Law, and IT.

Technology never defends itself—it needs leadership that knows when to say a firm "NO" to ensure that real value is safely delivered at the end of the day.

How is your organization currently handling the preparation for NIS2 and cross-border incident reporting? Are you already feeling the administrative weight? Let's connect and share your thoughts in the comments!

Masz chaos w procesach?

Twoje narzędzia IT nie nadążają za wzrostem sprzedaży?
Umów się na bezpłatną konsultację.