Cybersicherheit komplexer Systeme

Negative Trust Architectures (Ne-Trust)

The Agentur für Innovation in der Cybersicherheit GmbH (Cyberagentur) invites you to a virtual partnering event for the “Negative-Trust Architectures” (Ne-Trust) research program.

Tuesday, September 22, 2026, 2:00 p.m. to 5:00 p.m.

Registration is open through September 16, 2026, via this link.

Aim of the Partnering Event

Those interested in the new research program can obtain initial, in-depth information about its content at the upcoming partnering event. Furthermore, all participants will have the opportunity to present their areas of focus and thus network with potential partners to form consortia.

Agenda

  • Introduction to the Cyberagentur
  • Introduction to the Ne-Trust Program
  • Introduction to the Partners (2 minutes each)

Please send your presentation slides by September 18, 2026, at the latest to ne-trust@cyberagentur.de.

Introduction Slide

Registered participants can also download the slide here.

Netiquette

The digital space is intended to foster exchange and is based on a critical yet constructive—and above all, respectful—interaction with one another. We therefore strongly urge you to treat one another with respect.

Background

IT systems face a growing threat from internal actors, who often move undetected within systems, probe IT infrastructures, and cause damage. Insider threats take a wide variety of forms and include malicious, negligent, collusive, or compromised insider threats. The growing awareness of this attack vector is further fueled by the use of artificial intelligence (AI). These current and future challenges do not stop at the gates of government agencies, defense, and security authorities.

To be prepared to address threat scenarios like this, IT security paradigms are particularly important: They shape how IT systems are fundamentally designed, operated, and protected. “Zero Trust” is considered the most established example. Zero Trust principles are considered helpful for making application access more robust against various types of attacks and for increasing the resilience of an organization’s IT infrastructure. However, this approach has its limitations when it comes to defending against insider attacks. Key reference documents, including the NIST guideline SP 800-207, point to remaining gaps and unmet research needs.

Against this backdrop, there is a need to explore a more advanced and innovative paradigm for more effectively countering internal perpetrators, in part to make IT systems in public administration and among external and internal security actors even more resilient for the future.

Aim

The aim of Ne-Trust is therefore to enable demonstrably improved detection and more proactive defense against the growing and evolving insider threats to IT systems, thereby taking the concept beyond Zero Trust. The project aims to conduct technology-neutral and interdisciplinary research and develop independent Negative Trust paradigms as well as corresponding reference architectures for IT systems. The improved effectiveness against insider threats, as well as the technical implementation of such an architecture, will be investigated, measured, and demonstrated. Furthermore, the program aims to ensure that research projects also examine social impacts and legal aspects in the study of Negative-Trust architectures.

Disruptive Risk Research

The program is based on the novel concept of “Negative Trust,” which is related to Zero Trust but can be interpreted as a standalone term for a distinct paradigm. Initial attempts have been made to define the concept of Negative Trust, for example, in the context of deception technology. However, there has not yet been a scientific and interdisciplinary examination of the term with a view to developing it into an independent, further-refined IT security paradigm.

Ne-Trust addresses precisely this gap and opens the door to the first-ever scientific examination and development of negative-trust architectures. The Cyberagentur is thus creating space for innovative and disruptive research perspectives, thereby providing early impetus for cybersecurity paradigms and IT security architectures of and for the future.

This outlook for the future, along with the dramatic improvement in the defensive capabilities of IT systems and the comprehensive consideration of conceptual, technological, social, and legal issues, underscores both the ambitious and the risky nature of the research program.

Questions about the programme? Please write to us:

  1. Program team: Cybersecurity of complex systems
  2. E-Mail: Ne-Trust@cyberagentur.de

Newsletter

Your update on research, awarding and co.

Subscribe to our scientific newsletter. In this way, you can find out promptly which research projects we are currently awarding, when partnering events, symposia or ideas competitions are coming up and what’s new in research.