GreenShieldX: AI for a New Generation of Cybersecurity
The project submitted by Mashfrog under the STEP Campania program aims to transform cybersecurity innovation into a scalable, transparent, and industrialized SOC service offering.
In cybersecurity, speed is no longer enough. Detecting a potential threat within seconds has limited value if security analysts and decision-makers cannot understand why an event was classified as risky, what evidence led to that assessment, and what consequences the recommended response may have.
This is one of the key challenges in the transformation of Security Operations Centers, or SOCs: environments that process large volumes of alerts every day and must quickly to distinguish genuinely critical signals from operational noise. GreenShieldX was created in response to this need. The technology project, submitted by Mashfrog under the STEP Campania ERDF 2021–2027 program, aims to develop an AI-powered cybersecurity platform conceived not as an isolated set of algorithms, but as the foundation of a new, continuous, scalable, AI-native SOC service offering.
Critical Technologies and Specialized Expertise
GreenShieldX is being developed in a context in which cybersecurity, artificial intelligence, cloud infrastructure, and computing capacity have become central to Europe’s competitiveness and resilience. The project also represents an opportunity to consolidate specialized expertise, computing infrastructure, and applied research capabilities in Campania in the fields of AI and digital security.
Naples and the Campania Region can therefore further strengthen their role, as well as that of Southern Italy, as a hub for advanced technology initiatives capable of connecting research, industrial development, and new services for a market that increasingly demands resilience and reliability.
From Alert Management to Cognitive Defense
GreenShieldX is designed to integrate the different stages of incident management into a single environment: event ingestion, threat detection, prioritization, assessment of potential countermeasures, response support, and the production of evidence required for audit and reporting activities.
The Cognitive Threat Detection Engine envisioned by the project will correlate information from multiple sources, including logs, telemetry, affected assets, and operational context. The goal is not simply to generate more alerts, but to improve their quality, reduce false positives, and enable operators to focus on the events that genuinely require attention.
This capability is complemented by a defense orchestration system designed to assess different response strategies by balancing the probability of successful mitigation, speed of intervention, impact on business systems, and consumption of computing resources.
Explainable AI: Understanding Before Acting
One of GreenShieldX’s defining features is the role assigned to Explainable AI. In this context, explainability is not an optional feature or an additional layer of information applied after model processing. It is a necessary component for making artificial intelligence genuinely usable in cybersecurity operations.
The first principle is auditability. Every AI-supported assessment must be reconstructable through the evidence that led to it: observed signals, identified correlations, confidence level, affected assets, the version of the model used, and the rationale behind the recommended response. In this way, the decision can be reviewed before, during, and after an incident.
The second principle is human-in-the-loop decision-making. GreenShieldX is not designed to allow AI to autonomously make decisions that may affect business continuity, customers, or escalation processes. The system provides prioritization, context, evidence, and potential response options, while the analyst retains responsibility for the final decision and can approve, modify, or stop the recommended action.
The third principle is governance. Interactions among models, data, and operators must be traceable and aligned with established procedures, roles, and regulatory requirements. The framework envisioned by the project will generate different levels of explanation based on the needs of each user, from the technical detail required by SOC analysts to the decision-making perspective needed by CISOs, as well as the evidence required for compliance, audit, and reporting.
The goal is to combine the speed and analytical capabilities of artificial intelligence with the transparency, accountability, and human discretion required in critical operations.
A Collaborative Project for a Platform + Service Model
The project also benefits from the involvement of DICITA, the Department of Civil, Computer Science and Aeronautical Technologies Engineering at Roma Tre University, in the industrial research activities focused on two core components of the platform: the Cognitive Threat Detection Engine and Autonomous Defense Orchestration. This marks a renewed collaboration between Mashfrog and the Rome-based university.
The involvement of DIEF, the “Enzo Ferrari” Department of Engineering at the University of Modena and Reggio Emilia, is equally important. As part of Work Package 4, the department is responsible for designing, developing and validating, in a relevant environment, an advanced Explainable AI framework and decision-governance model capable of making the decisions generated by the detection module (WP2) and the autonomous orchestration module (WP3) interpretable, traceable and auditable, in line with the regulatory and accountability requirements of an industrializable SOC service.
For Mashfrog, GreenShieldX represents an important step in the industrialization of its expertise. The capabilities developed across cybersecurity, artificial intelligence, cloud, and system integration are brought together within a “platform + service” model designed to be replicable, continuously updated, and used on an ongoing basis.
The ambition is not to replace the expertise of cybersecurity analysts, but to enhance their ability to understand, decide, and act. It is in the balance between automation and human control, performance and sustainability, innovation and governance that Mashfrog, through GreenShieldX, has identified a potential path for the evolution of SOCs and cybersecurity services.