Digital Europe Programme · ECCC · CyberHEALTH

Cyber-resilient hospitals across the Adriatic region.

ShieldHealthAdria strengthens the cybersecurity readiness and resilience of public hospitals in Slovenia and Croatia — building a tested, NIS2-aligned model that healthcare providers across Europe can replicate.

Start
1 June 2026
Duration
24 months
Grant
No. 101299590
Coordinator
Telekom Slovenije
11
Pilot hospitals assessed, equipped & validated
1K+
Healthcare staff trained across IT, clinical & admin roles
10K+
Stakeholders reached through dissemination
30%
Target reduction in average incident-response time
13
Consortium partners across Slovenia & Croatia
About the project

Healthcare is one of Europe's most targeted sectors. We're changing the odds.

Since the pandemic, hospitals have faced relentless ransomware, phishing and data-breach campaigns. Telemedicine, remote diagnostics and connected medical devices — from imaging systems and infusion pumps to wearable monitors — have widened the attack surface, while many institutions still lack dedicated security teams, structured response plans and regular staff training.

ShieldHealthAdria answers with a complete, replicable framework: technical, organisational and regulatory assessments across a representative cluster of hospitals; validated pilot deployments in 11 hospitals (5 in Slovenia, 6 in Croatia) spanning tertiary, regional, municipal, paediatric, oncological and psychiatric care; training for over 1,000 healthcare professionals; and a replication toolkit for the whole EU.

The consortium pairs two leading EU-based cybersecurity providers — Telekom Slovenije and Combis — with 11 hospitals and key policy stakeholders, aligned with NIS2, GDPR and the EU Action Plan on the cybersecurity of hospitals and healthcare providers.

  1. 01

    Prevent

    Baseline maturity and compliance assessments, self-assessment guidelines and prioritised gap-reduction plans aligned with NIS2, GDPR and national legislation.

  2. 02

    Detect

    Endpoint monitoring, network detection, deception and early breach detection deployed and validated in live hospital environments.

  3. 03

    Respond & recover

    Structured incident-response procedures, simulations and continuous monitoring that keep care running under pressure.

  4. 04

    Sustain & scale

    A trained workforce, governance dashboards and a replication toolkit that carries the model to healthcare providers across Europe.

Work plan

Six work packages, one coherent flow.

From baseline assessment to EU-wide replication: each work package feeds the next, with management and communication running across the full 24 months.

WP1Lead · Telekom Slovenije

Management & Coordination

Project governance, technical coordination, quality assurance, ethics and risk management, and the KPI monitoring framework that keeps all activities on track.

M1M24
WP2Lead · Combis

Baseline Assessment & Requirements

Cybersecurity and compliance audits of the 11 pilot hospitals: maturity assessment, stakeholder needs analysis, NIS2/GDPR control mapping and a consolidated requirements & maturity model.

M1M8
WP3Lead · Telekom Slovenije

Technology Selection & Pilot Design

State-of-the-art review of EU cybersecurity solutions, the technology stack and deployment architecture, hospital-specific pilot blueprints and testing plans.

M3M15
WP4Lead · Combis

Pilot Deployment & Validation

Full-scale deployment of the selected solutions across all pilot sites, incident-response simulations, continuous monitoring and final validation with replication evidence.

M3M24
WP5Lead · Combis

Capacity Building & Awareness

Role-based training curricula, e-learning, tabletop exercises and hospital-wide awareness campaigns for more than 1,000 healthcare professionals.

M4M24
WP6Lead · Telekom Slovenije

Communication & Stakeholder Engagement

Dissemination and exploitation planning, the project's visual identity and website, stakeholder engagement and the EU-wide replication toolkit.

M1M24