SAVIOR

SAVIOR - AI-Supported Alert Validation for Industrial SOC Response - strengthens the Swedish industry’s ability to handle cybersecurity alerts in Security Operations Centers. By developing AI-supported prototype modules for alert validation and post-incident reporting, the project creates conditions for faster, more structured, and more scalable SOC response.

Facts
School: Tekniska Högskolan
Time: 2026-2028
Partners:
Dizparc Security Solutions, TD SYNNEX, Bufab, Sydved, Proton Group, and Carlsson & Möller
Financer: Vinnova / Advanced Digitalization
Researchers:
Erik Bergström, Associate Professor
Görkem Kilinc Soylu, Assistant Professor
Maria Riveiro, Professor
To be recruited, PostDoc
The project aims to develop AI-supported tools to help SOC analysts validate alerts that cannot be resolved solely through technical data. It focuses on the communication and decision-making steps, where analysts determine whether an alert is a real incident, expected activity, or a false positive.
Growing industrial cybersecurity challenge
The project addresses a growing challenge for Swedish industry: cyber incidents are no longer isolated technical events, but can affect production continuity, logistics, service delivery, safety, and trust across industrial value chains.
Security Operations Centers are central to managing these risks, but analysts often face large volumes of alerts and fragmented information. Many alerts require manual checking, customer contact, and contextual interpretation before a decision can be made. This creates a bottleneck in SOC operations and increases the risk of delayed or inconsistent responses.
Strengthened SOC alert validation
The project examines how alert validation can be supported through a combination of multi-source security data, customer-specific context, expert rules, machine learning, and structured feedback from previous cases. The goal is to reduce unnecessary manual communication and to support analysts in making faster, more consistent decisions.
SAVIOR will develop two interconnected prototype modules. One module supports human-in-the-loop alert validation and customer communication. The other supports post-incident analysis and reporting, including AI-supported draft reports for both incident and no-incident cases.
Increased resilience and reduced workload
The results will be useful to SOC operators, technology providers, industrial companies, and SMEs seeking more efficient, scalable ways to handle cybersecurity alerts. By improving alert validation and post-incident reporting, SAVIOR contributes to increased digital resilience, reduced analyst workload, better reuse of case knowledge, and stronger cybersecurity maturity in the Swedish industry.
Want to know more?
- Docent Datavetenskap
- Tekniska Högskolan
- erik.bergstrom@ju.se
- +46 36-550 2420