ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
ICT Legal Consulting ICTLC - ICT Legal Consulting Via Borgonuovo 12 20121 Milan Italy
Tel: +39 028 424 7194 Fax: +39 027 0051 2101 Email: info@ictlc.com Web: www.ictlc.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Cybersecurity regulation in Italy is structured around an integrated governance model in which national security considerations, the continuity of essential services and the harmonisation objectives of EU law converge. Cybersecurity is treated as a systemic con - dition for institutional stability, economic resilience and trust in digital transformation, rather than as a purely technical or sector-specific matter. This con - ceptual framework informs both strategic planning and legislative intervention, and underlies the gradual consolidation of cybersecurity as a core component of organisational governance. At the strategic level, Italy addresses cybersecurity through a national framework that connects prevention, preparedness, resilience and co-ordinated response. The National Cybersecurity Strategy 2022–2026 articulates cyber - security as a public interest of systemic relevance and situates digital security within a broader vision of national resilience. Within this vision, public authori - ties, private operators, and research and industrial actors are regarded as participants in a shared secu - rity ecosystem, rather than as isolated recipients of regulatory obligations. From a legislative perspective, the Italian approach rests on the coexistence of two complementary regu - latory axes. One axis is oriented towards the protec - tion of national security and strategic State interests, and addresses cybersecurity as a matter of sover -
eignty and resilience. The other axis reflects the EU internal market approach, which treats cybersecurity as a horizontal requirement for the reliable provision of essential and important services across sectors. These axes operate cumulatively, and their interac - tion determines both the scope and the intensity of compliance duties. The national cybersecurity perimeter represents the most visible expression of the security-oriented axis. It identifies networks, information systems and ICT services that support essential State functions and links cybersecurity obligations to strategic risk, sup - ply-chain control and centralised incident awareness. In parallel, the implementation of the NIS2 framework embodies the market-oriented axis and introduces a governance-driven model in which cybersecurity is embedded in management accountability and organi - sational decision-making. The regulatory intent is to ensure that cyber-risk is internalised within corporate governance structures and addressed through con - tinuous oversight rather than episodic compliance. Overall, the Italian cybersecurity strategy reflects a transition from reactive and fragmented measures to an integrated resilience model. Regulatory expecta - tions focus on the capacity of organisations to antici - pate risks, preserve operational continuity and engage constructively with public authorities through struc - tured reporting and co-operation mechanisms. Cyber - security is therefore framed as an ongoing governance obligation that permeates organisational structures, contractual relationships and operational processes.
214 CHAMBERS.COM
Powered by FlippingBook