Shadowserver Critical Community Infrastructure Cyber Resilience Project

August 5, 2026

The Shadowserver Critical Community Infrastructure (CCI) Project is designed to improve the cybersecurity posture of essential public-serving organizations across Central and Eastern Europe (CEE), with a special focus on Ukraine. The initiative focuses on strengthening resilience in sectors that underpin daily community life, but often lack access to affordable, high-quality cybersecurity support. The initial countries of focus, aside from Ukraine, are Moldova, Romania, and selected countries of the Balkan region: Albania, Bosnia and Herzegovina, Kosovo, and Serbia. Subsequently, we plan to expand to other countries in the region.

Project Scope

We use the term “Critical Community Infrastructure” – by this we mean educational, environmental and local services organizations such as kindergartens, schools, universities, libraries, youth clubs, parks, housing, and community centers; cultural and creative organizations such as theaters, museums, and local newspapers; health, sport, and care organizations such as sports clubs, refuges, care homes, non-governmental health services such as hospitals and clinics; non-profit organizations (NGOs); and also essential local utilities related to, for example, waste management or transport, as well as many others.

While these organizations are fundamental to public well-being, they are frequently constrained by limited resources, fragmented visibility into cyber threats, and a lack of cybersecurity expertise. Additionally, they are often not the focus of cybersecurity initiatives and are sometimes hard to reach for cybersecurity organizations and experts. Often, even if notified of security problems, they are unable to respond effectively.

The Shadowserver CEE CCI Project addresses these gaps by delivering free Cyber Threat Intelligence (CTI), training, and hands-on support to these underserved public good organizations, wrapped in a new framework that is intended to convey information in the easiest and most friction-free manner possible.

The CEE CCI Project is possible thanks to the support of Google.org.

Project Overview

The project is designed around four core activities that work together to strengthen cybersecurity across CCIs in the CEE countries:

1) Enabling underserved public interest organizations to better understand and respond to emerging threats affecting their internet-facing systems, as well as any resulting compromise – achieved by providing free access to actionable and, most importantly, understandable CTI.

2) Strengthening the defensive capability of underserved organizations by helping them to build the practical skills and operational awareness needed to use threat intelligence effectively on a day-to-day basis.

3) Ensuring continuous improvements in cybersecurity maturity, so that participating organizations can move beyond short-term fixes and develop more sustainable security practices throughout the project

4) Enhancing regional cyber resilience through training and implementation assistance, helping organizations across Central and Eastern Europe translate CTI and guidance into real-world defensive improvements.

How the Project Works

At its technical core, the project focuses on identifying the types of technologies, systems, and internet-facing infrastructure commonly used by CEE CCI organizations across focus sectors (NGOs, healthcare, education, waste/transport management, etc.). This mapping helps establish a clearer understanding of each organization’s digital environment and potential exposure.

The resulting data is processed into structured, actionable intelligence and shared with relevant stakeholders, including network owners, national Computer Security Incident Response Teams (nCSIRTs), and authorized partners, to support remediation and risk reduction. An important part of the project is establishing relationships with stakeholders in the affected sectors, national governments, and the development of communications plans.

The project is based on non-intrusive Internet-wide scanning designed to identify exposed systems already visible on the public Internet, data from honeypot sensors (that detect attempted reconnaissance and exploitation), and data from cyber threat disruption operations (such as sinkholing of the technical command and control (C2) infrastructure used by attackers). It does not involve exploitation of vulnerabilities or unauthorized access.

Since its launch in November 2025, the three-year project has completed its first phase, during which we analyzed data from more than 2,000 CEE CCI organizations with over 11,000 associated IP addresses and 22,157 hostnames. All findings are shared responsibly and selectively with appropriate recipients to support remediation. Data handling and compliance requirements remain an important consideration, particularly when working with healthcare, government, and critical infrastructure sectors.

What the Project Provides

  1. Free, tailored, and actionable CTI on exposures, vulnerabilities, or compromises

Participating organizations receive daily CTI data feeds designed to help identify and respond to emerging threats directly affecting their infrastructure. These data feeds support visibility into exposed services, vulnerable systems, and configuration weaknesses observed in internet-facing environments, and, in some cases, compromised assets as well. This enables organizations to proactively reduce their attack surface and strengthen their security posture by addressing identified issues when needed.

  1. Situational cybersecurity awareness

The project enhances national and regional awareness of the cybersecurity resilience and defensive posture of underserved CCI organizations. It supports not only the organizations themselves but also sector associations, Information Sharing and Analysis Centers (ISACs), nCSIRTs, regional bodies, and policymakers. It also allows Shadowserver to monitor the performance of different sectors and assess whether the project has resulted in measurable improvements in cybersecurity resilience.

  1. Training and cybersecurity capacity building

The project includes practical training and guidance focused on improving the operational use of CTI, especially by organizations who may have little experience in using such data. By enhancing the knowledge and skills of cybersecurity personnel, the program supports the integration of CTI into operational workflows, enabling organizations to:

  • Interpret and prioritize threat intelligence data
  • Translate findings into remediation actions
  • Improve internal security workflows
  • Build sustainable cybersecurity practices over time

Reach out to us!

Organizations interested in learning more about our CEE CCI Project, or exploring opportunities to participate, are encouraged to contact The Shadowserver Foundation.

Our dedicated team is available to provide additional information about the project, eligibility criteria, and the support available to participating organizations. We welcome inquiries from CCI organizations, sectoral partners, and national cybersecurity stakeholders interested in strengthening cybersecurity resilience across their communities.

You can do so by sending an email to cee-cci-project @ shadowserver.org

Recent Articles