Cybersecurity of Complex Systems

When Threats Lurk in the IT System

Ne-Trust is researching new defenses against insider threats

Ne-Trust is focusing on insider threats: At the virtual partnering event on September 22, 2026, the Cyberagentur will bring together potential partners to explore new negative-trust architectures.
Ne-Trust is focusing on insider threats: At the virtual partnering event on September 22, 2026, the Cyberagentur will bring together potential partners to explore new negative-trust architectures.

On September 22, 2026, the Agentur für Innovation in der Cybersicherheit GmbH (Cyberagentur) will host a virtual event to bring together potential research partners for the planned research program “Negative-Trust Architectures” (Ne-Trust). Ne-Trust aims to develop new approaches to detect insider threats in IT systems earlier and defend against them more proactively than established zero-trust concepts allow. At the partnering event, companies, startups, universities, and research institutions will gain insights into the research objectives and have the opportunity to network for joint interdisciplinary projects.

Threats to IT systems do not arise solely from external attacks. Internal perpetrators often already have legitimate access rights and can therefore move around within IT infrastructures relatively unnoticed. They can probe systems, misuse information, or cause damage. Insider threats can arise from malicious intent, negligence, or collusion. Compromised user accounts can also allow attackers to assume the role of a seemingly legitimate insider.

Through the planned research program “Negative-Trust Architectures” (Ne-Trust), the Agentur für Innovation in der Cybersicherheit GmbH (Cyberagentur) aims to investigate how such threats can be detected more reliably and countered more effectively.

On Tuesday, September 22, 2026, from 2:00 p.m. to 5:00 p.m., the Cyberagentur will host a virtual partnering event on this topic. It is aimed at companies, startups, universities, and research institutions that focus on IT security architectures, cyber defense, or related technical, social, and legal issues.

When Legitimate Access Becomes a Security Risk

Established security concepts such as Zero Trust are fundamentally based on the assumption that no access should be automatically trusted. Identities and authorizations are continuously verified, access rights are restricted, and IT systems are more heavily segmented. These principles can significantly increase the resilience of digital infrastructures.

However, insider threats present particular challenges. Individuals or compromised accounts may already have valid permissions and thus initially appear to be in compliance with the rules. Even key reference works such as the NIST guideline SP 800-207 point to remaining gaps and the need for further research.

In addition, artificial intelligence is changing the threat landscape. AI-powered methods can automate attacks, make deceptions more convincing, and exploit vulnerabilities in a more targeted manner. Such developments also affect IT systems in government, defense, and law enforcement agencies.

Negative Trust as an Independent Research Approach

Ne-Trust addresses these limitations of existing security concepts. Adopting a technology-neutral and interdisciplinary approach, the project aims to investigate and develop independent Negative Trust paradigms as well as corresponding reference architectures for IT systems. The goal is not merely to exercise greater control over access. Rather, the research aims to explore how systems can detect suspicious behavior within their own structures and respond to it more proactively.

The effectiveness of such approaches against various forms of insider threats will be investigated, quantified, and demonstrated through technical implementations. In addition to technical issues, social implications and legal frameworks will also be taken into account.

Negative Trust is not yet a scientifically established IT security paradigm. Initial conceptual approaches exist, for example, in the area of so-called deception technology. This technology specifically employs elements of deception to detect attackers, monitor their behavior, or divert them away from critical system areas. However, a comprehensive scientific and interdisciplinary examination of Negative Trust as an independent security paradigm has yet to take place.

Ne-Trust aims to address this research gap. “This research program introduces the concept of ‘negative trust’ into academic discourse for the first time in this context,” explains Felix Dotzauer, program director and research officer in the Department of Cybersecurity for Complex Systems. “This will enable the early exploration of new approaches to IT security architectures that address insider threats more effectively, rethink the defensive capabilities of IT systems, and go beyond today’s protection concepts.”

Partnering Event Brings Together Diverse Expertise

The program’s broad scope requires diverse perspectives. The Partnering Event is therefore designed to connect potential research partners and support the formation of interdisciplinary consortia.

Following a presentation on the Cyberagentur and the Ne-Trust research program, participants will have the opportunity to present their areas of expertise in brief, two-minute presentations. This will help highlight areas of expertise, identify points of overlap, and lay the groundwork for potential partnerships in future research projects.

Registration for the partnering event is open through September 16, 2026, via the following link. Participants who would like to give a presentation during the event should send their presentation slides to ne-trust@cyberagentur.de by September 18, 2026, at the latest.

Newsletter

Your update on research, awarding and co.

Subscribe to our scientific newsletter. In this way, you can find out promptly which research projects we are currently awarding, when partnering events, symposia or ideas competitions are coming up and what’s new in research.