- The tool, based on LLM and neural networks, has been trained using data from Sofistic’s SOC, Cuatroochenta’s cybersecurity subsidiary, to accelerate incident response times
Cuatrtoochenta, through its Applied Innovation department and its cybersecurity subsidiary Sofistic, headquartered at Málaga TechPark, has developed an advanced AI model to classify cybersecurity alerts based on risk level. This development is part of a project with the National Cybersecurity Institute (INCIBE), an entity under Spain’s Ministry for Digital Transformation and Public Service, through the Secretary of State for Telecommunications and Digital Infrastructures. The solution combines cutting-edge deep learning and language processing technologies (LLM), and has demonstrated a 95% success rate in classifying alerts’ criticality, matching manual human analysis.
With this initiative, Cuatroochenta positions itself at the forefront of technological innovation, addressing the growing need in Spain and Europe for solutions that reduce dependence on external technology providers.
This model is part of the Strategic Initiative for Innovative Public Procurement (IECPI), under Spain’s Recovery, Transformation and Resilience Plan, funded by the Next Generation EU program. The new tool is powered and trained daily with a robust, anonymized dataset from Sofistic’s Security Operations Center (SOC), which operates across two continents and boasts 18 years of experience in Spain and Latin America, particularly in the banking and critical infrastructure sectors. The system analyzes incoming alerts, extracts meaning from unstructured data, identifies relevant correlations, and automates classification based on severity.
The solution prioritizes high-risk or critical alerts, enabling analysts to focus on the most urgent threats and significantly reducing response times. This was the main goal pursued by the Cuatroochenta and Sofistic team involved in the project:
- Jaume Barrios (Head of AI)
- Nicolás Betancourt (Data Scientist)
- Sergi Fuster (Data Scientist)
- Manuel Ginés (Head of R&D de Sofistic)
- Abel Herrero (SOC Team Leader)
Additionally, the team collaborated with the Temporal Knowledge Bases Group (TKBG) from Universitat Jaume I of Castelló, led by Professor Rafael Berlanga.
A solution to speed up cybersecurity incident response
For years, leading global cybersecurity software vendors have used AI-driven behavioral analysis systems to detect and respond to threats in real time, solutions that Sofistic, as a key partner, systematically employs. These existing tools already perform an initial screening when alerts reach the SOC.
Cuatroochenta’s new AI model aims to complement this process by further automating and accelerating alert classification and optimizing analysts’ workflows. The ultimate goal is for the system to suggest actions in response to alerts and to guide organizations through incident response.
“Our model is not meant to replace existing platforms, but rather to complement them. After alerts pass the initial filtering when they reach the SOC, our system classifies them in a way that simplifies and optimizes analysts’ work. Response time is critical in managing cybersecurity alerts to minimize potential impact,” explains Jaume Barrios, Cuatroochenta’s Head of AI and one of the model’s developers.
This model is part of the AI4CYBERSOC project, which Cuatroochenta is developing in partnership with INCIBE, aimed at implementing an intelligent alert management system. Leveraging machine learning and natural language processing, AI4CYBERSOC will be an innovative tool that integrates data from multiple sources to predict potential cyberattacks and assist organizations in investigating and responding to incidents.
The project showcases the added value that AI brings to cybersecurity solutions, not only in threat
detection and prevention but also in improving alert and incident management. Moreover, it helps optimize operations in the shortage of specialized technical profiles, particularly in the public sector.

