logo_header
  • Topics
  • Research & Analysis
  • Features & Opinion
  • Webinars & Podcasts
  • Videos
  • Dtw
Proof Of Concept | Autonomous networks, Digital twin

Combining cyber awareness and digital twins for autonomous operations

This Catalyst shows how CSPs can strengthen cyber resilience by combining a semantic digital twin with AI-driven cyber awareness. The result is faster threat triage, clearer service impact analysis, and autonomous, closed-loop mitigation across the network.

Ailis Claassen
09 Aug 2026
Combining cyber awareness and digital twins for autonomous operations

Combining cyber awareness and digital twins for autonomous operations

Telecom operators are under growing pressure to manage increasingly complex cyber risks across fixed and mobile networks, cloud-native environments, APIs, edge computing, IoT ecosystems and AI-enabled services. These risks span a wide range of assets, software platforms and network technologies, each with their own vulnerabilities and operational dependencies. Threat actors increasingly see telecom infrastructure as critical national infrastructure, while security operations teams are often forced to work from fragmented data and high volumes of alerts. At the same time, network operations teams may not have enough cyber-risk context to understand whether a vulnerability, configuration drift or security incident could affect services, customers or compliance obligations.

The Catalyst project, Cyber twin: Cyber-aware ontology for AIOps, addresses this gap through Cyber Twin, a cyber-aware semantic digital twin designed for AIOps. Showcased at DTW Ignite 2026, the project brought together Telia Company, Vodafone GmbH, Capgemini, NumoData and Trend Micro EMEA Ltd to demonstrate how a unified knowledge graph can connect telecom topology, service relationships and cybersecurity intelligence. The project was named winner of the Outstanding Catalyst – Rising star award at DTW Ignite 2026.

The challenge of cyber-aware operations

Current NOC and SOC environments remain heavily siloed. Security tools such as XDR, SIEM and vulnerability management platforms can detect suspicious activity, but they often lack real-time awareness of network topology, service chains, configuration data, resource dependencies and customer impact. Operations teams, meanwhile, may see alarms, performance degradation or service incidents without understanding the related cyber risk. This makes it harder to correlate cyber alerts with network assets and services, prioritize action by blast radius, and reduce false positives.

These problems are becoming more urgent as European operators must also comply with regulatory requirements such as NIS2 and DORA, both of which demand stronger visibility, risk analysis, and resilience across operational environments. Operators need more than alerting tools. They need cyber-aware systems that understand the network, assess risk in context, and act autonomously when required.

A semantic digital twin for cyber resilience

Cyber Twin acts as a contextual intelligence layer between operational and security systems, creating a single source of truth for network, service and cyber-risk data. Its semantic digital twin combines a knowledge graph and ontology covering telecom assets, services, relationships, software releases, security configurations and known vulnerabilities. The model can represent a broad range of telecom and IT assets, including mobile and fixed network infrastructure, cloud environments, enterprise IT systems, IoT assets, applications and network devices, enabling vulnerability analysis across heterogeneous operational environments. This enables graph-based analytics, contextual enrichment, relationship inference, service impact analysis, root cause analysis, predictive analysis and change impact simulation.

The solution connects data sources including CMDB inventory, NMS telemetry, events and alarms, XDR and SIEM feeds, CVEs, end-of-life and end-of-support information, vulnerability management tools, security posture management and ITSM ticketing. An agentic layer using GraphRAG, MCP and LLM capabilities allows the twin to interpret alerts, identify impacted services and customers, score incident priority, recommend actions and enrich tickets before they reach an analyst queue. In the demonstrated workflow, the first seven steps of incident enrichment and prioritization run automatically, while final execution uses a hybrid approach with human approval for actions that require sign-off.

The project also demonstrated agentic vulnerability management and network security posture management. In the vulnerability use case, Cyber Twin detects vulnerabilities, analyzes context, prioritizes upgrades and generates resolution recommendations. In the posture management use case, it supports configuration data collection, AI-driven network discovery, drift detection, compliance validation, cyber-risk identification, alarm and performance correlation, impact prediction, remediation planning and continuous learning.

Turning insight into autonomous action

The innovative part of the solution lies in combining three elements that are often treated separately: a semantic telecom ontology, cybersecurity intelligence and agentic execution. The twin does not simply visualize data. It gives AI-driven systems the context needed to understand which services and customers are exposed, how a threat could propagate, and which response would reduce risk without creating unnecessary operational disruption.

That context is essential because a cyber issue may first appear as a network symptom, a service degradation or a policy deviation. By linking cyber alerts with topology, dependencies, service impact and operational data, Cyber Twin supports faster triage, clearer prioritization and more effective remediation. Marton Sabli, Head of Architecture, IT Production and Cybersecurity, said the project reflects a wider shift in operating models: “In a world where telecom networks are transforming and automation is accelerating, security can no longer be isolated, manual or reactive. With our Catalyst solution Cyber Twin, we bring security at the centerof autonomous operations, delivering safer, smarter and more resilient networks.”

Measuring success

Success is measured through improvements in operational efficiency, cyber resilience and automation. The project aims to reduce investigation time and operational effort, improve data quality, reduce alert noise, increase AI effectiveness and accelerate response to cyber-related service degradations. The team’s materials indicate a target of reducing mean time to detect and mean time to repair cybersecurity threats by 50% to 70%, while accelerating operators’ journey toward cyber-resilient autonomous network operations by 50%.

For CSPs, the expected business benefits include greater customer trust, lower operational costs, improved resilience and streamlined compliance with evolving requirements such as NIS2 and DORA. For the wider industry, the project supports the adoption of secure autonomous networks and helps operators manage increasingly complex 5G and cloud-native environments as critical national infrastructure.

TM Forum assets used

The Catalyst aligns with TM Forum’s Digital Twin for Decision Intelligence framework, including IG1307 DT4DI, by using a digital twin, data fabric, AI and analytics, decision intelligence, APIs, UI and northbound integration concepts as part of the solution architecture. It also supports the broader Autonomous Networks journey by applying closed-loop, context-aware automation to security operations. TM Forum Open APIs are used to support integration and closed-loop mitigation across operational workflows.

Why it matters

This Catalyst matters because it tackles a structural weakness in telecom operations: the separation of cybersecurity and network assurance. By introducing a cyber-aware digital twin, the project helps operators move beyond isolated alerting toward a shared operational view of network, service and cyber risk. That is increasingly important as cyber threats directly affect service quality, customer trust, regulatory exposure and the resilience of critical national infrastructure.

For CSPs, the value is not just faster threat handling. It is the ability to create a more self-defending, context-aware operational environment in which security becomes a core component of AIOps and autonomous networks. Cyber Twin offers a practical path toward safer, smarter and more resilient telecom operations.