Industry News for Business Leaders
Artificial IntelligenceCybersecurityFeatured

Cybelia: What Is This French Program for AI-Augmented Soc Operators in Industry?

Cybelia: What Is This French Program for AI-Augmented Soc Operators in Industry?
We spoke with Réda Yaich and Alexandre Balondrade about Cybelia programme, its objectives, and what it will change for SOC operators. (Courtesy of Airbus Protect)

Cybelia is a French R&D program dedicated to “augmented cybersecurity” for industry. It was launched by IRT SystemX as part of France 2030. The four-year program brings together around a dozen industrial players, including Airbus Protect and RTE. The idea is to create SOC operators augmented by AI. At a time when cyberattacks are multiplying in France (tax authorities, La Poste, etc.), we spoke with Alexandre Balondrade from Airbus Protect, and Réda Yaich from IRT SystemX. With them, we take a look at the program’s objectives.

They were both at the IGPSC Congress in Biarritz at the end of August, to present the ongoing Cybelia program. (An event of which DirectIndustry was a partner). Cybelia is not intended to replace cyber experts with AI. It aims to augment their capabilities, particularly when they have to monitor complex industrial systems and respond to incidents.

At the origin of this initiative is the SystemX Technological Research Institute. This French non-profit scientific cooperation foundation wqs created 15 years ago to help industrial companies adapt research to concrete issues.

Among the program’s partners is Airbus Protect. We spoke with Alexandre Balondrade, SOC Manager at Airbus Protect and Réda Yaich, Head of Cybersecurity, Safety and Digital Trust at IRT SystemX, to find out more about this program, its objectives, and what it will change for SOC operators.

Could you introduce us to the Cybelia program? Where does this project come from and what are its objectives?

Reda Yaich: “The idea at the beginning was to question industrial companies such as Thales, Naval Group, Airbus, SNCF, Safran, in short, the leaders of the French economy, in light of this new cyber context, to understand their priorities. We held workshops over several months and together defined a roadmap in agreement with the key cybersecurity stakeholders, notably ANSSI, the French National Agency for Information Security, the Cyber Campus and the national coordinator of the cyber strategy within the SGPI (General Secretariat for Investment). And this roadmap was broken down into three themes.”

What are these three themes, in a few words?

Reda Yaich: “The first theme is augmenting humans. It is about augmenting all cybersecurity players, from the design of solutions through to supervision. We are targeting, among others, augmented cyber operators.

The second topic is embedded cyber autonomy. That is how do we develop cybersecurity capabilities to embed them in vehicles, drones, satellites, trains and aircraft. We are aware that relying on humans is not always a possible strategy. For example because of network or accessibility issues. Sometimes it is difficult to get information back to a human so that the human can make a decision and enable the embedded system to react. So the idea is to add embeddability and trust to embedded decision-making systems so that we can both detect attacks and respond autonomously.

The third topic is the supply chain. We can clearly see that attacks exploit the value-chain vector. So this area focuses on trusted collaboration between organizations and on compliance with the Cyber Resilience Act and how we can collectively protect ourselves against coordinated attacks between several players.”

Where does this roadmap stand today?

Reda Yaich: “The first use case, that of the augmented cyber operator, is the priority we started with very early on. RTE, Airbus Protect and SystemX are leading it. The other two are still in the development stage and should begin in the coming months. Each use case should last four years. And for the first one, we are roughly halfway through.”

Read also

And concretely, what have you developed so far?

Reda Yaich: “We developed the approach and methodology that were presented at the IGPSC Congress. The challenge was to understand the impact of AI on the cyber operator’s job and to provide an approach that covers technology, procedures and people.

We do not want to add another layer of technology because we are aware that there is already an abundance of it. Operators already handle a fairly extensive arsenal of tools. The idea is to rationalize the tools and add the right dose of AI, both in the workflow, in the procedure and internal processes, and at the right moment. Because we are talking about people who work 24 hours a day, 7 days a week. AI can make sense at a certain time of day, when faced with a particular attack. Just as it may not make sense for attacks that are more under control. The use of AI dynamically is what is quite innovative about this project.”

The industrial partners you mention are not just any companies. They are large French companies, in rather critical sectors, aerospace, defence, etc., which are heavily targeted by cyber attackers. Is Cybelia primarily aimed at these sectors, or is it intended to be applied to all critical systems?

Alexandre Balondrade: “The first task was precisely to ask each of the industrial companies what the current issues were in their SOCs. And we quickly realized that many of the issues overlap. The first is that, with digitalization and hyperconnectivity, we have more and more security tools, more and more security alerts. Analysts can no longer process the flow and volume of alerts. Whatever the type of attack, whatever the industry, we have the same issue in all SOCs. We have dashboards everywhere, screens everywhere and alerts everywhere.

We decided to bring all these pain points together, to decide which ones to address quickly and then move forward project by project, from collection to the end of the incident. An AI or AI agents will help the operator, initially by retrieving all the context, such as retrieving IPs. This will save the operator a lot of time and enable them to carry out their mission successfully. So whatever the industry, the conclusions of Cybelia will be transferable.

Where it becomes quite complicated, and that is why we needed SystemX, is with regard to reaction and automatic action. This is where the boundary between humans and AI is quite significant.”

Precisely, one of the program’s challenges is moving from an AI that assists the operator to agentic AI capable of chaining certain actions or taking initiatives. Where do we draw the line between augmenting humans and losing control? In other words, in a critical system, how do we concretely define what can be entrusted to AI and what must absolutely remain under human control? What is the threshold?

Alexandre Balondrade: “I think it is difficult to talk about a threshold or limit in cybersecurity because it is a world that is evolving enormously. Our rules, our processes and our tools evolve all the time. So, by default, this slider will change. It depends enormously on the context, the client and the infrastructure. If we have a very closed infrastructure, for example in the military, we will be able to push the slider further and further because we have perfect knowledge of the sector.”

But is there still some kind of red line?

Reda Yaich: “One of the major challenges of the Cybelia program is to define what we call the autonomy envelope. That is in what situation we can consider that an AI-based system can have autonomy. And the analogy with aviation is interesting. It took years for an aircraft to have a high-quality autopilot that we could trust. At the beginning, I think pilots did not fully trust it. Now, they dare to turn their backs on the cockpit and enjoy a meal during the flight. This is what we are starting to do. There may be failures, there will be feedback, but the idea is to be able to characterize the conditions both in relation to the operator’s situation and in relation to the threat or the overall configuration. Because the team may be understaffed, or there may be other incidents happening in parallel, and in that case, sometimes we can afford to take the risk of fully delegating certain low-impact decisions to an AI.

Of course, if we are in a critical infrastructure such as a nuclear power plant where the action is truly critical, we may not allow AI to act. Our message is to augment humans, but for them to always remain in control. That means that the human is both aware of this delegation and remains in control.

To put it simply, there are situations that are rather green, where the system is able to reassure the operator by saying, ‘I know how to handle this 100%.’ There are situations that are rather red, where the system says, ‘I don’t yet have the information to be able to handle this automatically.’ And there is a bit of grey between the two where the human and AI will have to learn to work together.”

But how can we guarantee that, in the event of a bad decision or unexpected behavior by the AI, it will always be possible to understand what happened and identify responsibilities?

Reda Yaich: “One of the advantages of agentic AI is that everything is tracked. We will be able to map the decision trajectory, which tool was called, and what result was obtained. In my view, this is important for understanding what happened and potentially learning from its mistakes.

The second thing, particularly in the context of Alexandre’s activities, is explainability. From the outset, we worked on AI explainability. We did not want to use black boxes or proprietary tools over which we have no control. Explainability makes it possible precisely to understand what happened so that we can potentially remedy this type of issue.”

And so, what does this change concretely for the operator?

Alexandre Balondrade: “At each stage of the workflow, there is a pain point and the agents are there to help the operator at each of these stages to retrieve the maximum amount of information very quickly in order to make their decision. We are talking about a significant volume, as I said, there are a lot of alerts. How to prioritize these alerts is the whole challenge. Sometimes, too, the databases that retrieve information from a system are not up to date, or we do not necessarily have access to them and need to make access requests. If we have agents that can retrieve all this, we remove a large part of the uncertainty and also make the investigation faster for analysts.”

Reda Yaich: “There is another dimension that is key for me, which is operator fatigue. These people have a complicated job, with a high level of frustration because they know very well that they will miss certain things despite the time invested. Uncertainty is very significant because we have different types of attacks, different ways of investigating and finding information, and different remediation options. This creates a very complex decision tree for a human to grasp, and AI will be able to limit this complexity and propose concrete options to the operator.”

So the operator becomes more of a supervisor of an automated system and spends less time investigating problems and attacks. Is that ultimately the objective?

Reda Yaich: “Attackers, particularly with AI, are becoming increasingly ingenious and launching increasingly sophisticated and complex attacks. I think AI will be able to assist a human in copilot mode to search, investigate and discover new attacker operating methods, and I think that will be their new role. The operator will be an orchestrator of agents, with a range of agents at their service, which will allow them to devote their time to high-value-added activities in terms of thinking and problem-solving. AI will also make it possible to compensate for a lack of resources because SOCs have around ten people; we cannot have a SOC with 1,000 people! With the objective of reducing the delays between detection time, assessment time, investigation time and response. And that is a real challenge. We saw this with the hack of the French Tax Authority. There are more and more attacks that we do not discover. Most of the time, it is the attackers who reveal the attacks by announcing their haul!

Read also

Could Cybelia also be a solution for our public institutions?

Reda Yaich: “Yes, I think these public-sector players can benefit from it. There are many organizations that do not have a SOC operator. And there, for example, we will be able to have a small autonomous SOC. In the medium to long term, automation and agentic AI will be able to multiply the cyber capabilities of these organizations.”

So could we ultimately democratize cyber protection?

Reda Yaich: “In my view, agentic AI will make it possible to better concentrate human-resource needs, to gain operational efficiency by automating as many things as possible that create friction. At the end of Cybelia, there will be a body of knowledge handed down to the community, with guides, knowledge sharing and workflow automation tools that companies will be able to download, configure and reuse. Small organizations will benefit from a level of detection quality comparable to that of an Airbus or an RTE. The advantage of automation is that not everything has to run on a GPU, so we can do things on a good server. I think this is also quite an important message of hope.”

What are the biggest challenges in regards to cybersecurity? Or the points to watch carefully?

Reda Yaich: “The major challenge is imagining the impact on humans in terms of skills. What skills will we need to have in the future for the SOC? We are already imagining a conductor capable of choreographing all these agents, but also of opening the hood to configure them. For me, that is a real challenge.

The security of these technologies is also a risk issue. We are talking about technologies that sometimes have a maturity level based on only a few weeks of hindsight. For example, a few months ago, MCP protocols did not exist. That is why, rather than a ‘buy it’ approach, we are more on a ‘make it’ approach. We are not taking off-the-shelf solutions; we are creating automation processes with open-source solutions and accessible technologies because we want to make sure that we have control over everything we use, both in terms of the technology’s sustainability and its soundness.

Another major theme, obviously, is how to maintain control. How to avoid moving towards full automation. Because we are aware that AI will not be able to manage everything. We must not have false hopes. We are at a point of hype around agentic AI. At some point, these will become mature technologies with agents or completely autonomous agent systems to manage very simple situations. And I think that at that point, they will become part of conventional automation. But investigating complex cases, and above all decision-making and the responsibility associated with decision-making, that is what we will need to master in the end. Cutting off a flow, shutting down systems, restarting them, blocking IPs. We are talking about complex cyber-physical systems, with an impact on human life. Delegating the ability to react to AI is a major challenge. And so, we are currently experimenting with technical, technological and scientific feasibility. But at some point we will also have to rein in our enthusiasm regarding what is feasible and what is also acceptable to society.”

What about you, Alexandre, same question?

Alexandre Balondrade: “One of the most important points to watch will be the explainability of all these agents. It is good to provide information, whether context or recommendations, to the user, but if we do not know where it comes from and what percentage of truth lies behind it, it will be difficult to make a decision. And the second point is indeed the security of these agents. All it takes now is to take control of one of these agents to be able to block things. So even attackers will also be able to use agents to attack systems.”

And an AI-human duo?

Reda Yaich: “This is what we call the handover. It is the idea of creating a duo between an AI and a human. This means that the human must know how to trust and delegate things to an AI, but potentially the AI must also, at some point, call upon the human again. But we should also avoid this becoming a cognitive burden. And that is one of the challenges. That is why the human dimension is at the center of the concern. Augmenting humans is not just about adding technology. Augmenting humans means understanding the best way to make a human work with an AI.”

Advertisement
Advertisement
Advertisement
Advertisement
Advertisement