ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
Sectoral regulators retain supervisory and enforce - ment powers within their respective domains, and integrate cybersecurity and operational resilience requirements into existing regulatory frameworks. In regulated sectors, particularly financial services, cybersecurity obligations are assessed as part of broader governance and risk management evalua - tions. Supervisory scrutiny extends to ICT outsourcing arrangements, internal control systems and prepar - edness for cyber-incidents, reflecting the increasing convergence between cybersecurity regulation and prudential supervision. Investigative and enforcement powers vary depending on the applicable regime but generally include infor - mation requests, audits, inspections, binding correc - tive measures and administrative sanctions. In regimes oriented towards national security, supervisory tools also encompass enhanced scrutiny of strategic ICT procurement and supply-chain arrangements. The Italian regulatory landscape therefore requires entities to interact with multiple authorities in a co-ordinat - ed manner and to structure internal governance so that reporting, escalation and remediation processes remain coherent across different oversight models. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Cybersecurity obligations for essential or critical enti - ties in Italy arise from the intersection of the NIS2 implementation framework and the national cyber - security perimeter, supplemented by sector-specific provisions and supervisory practice. Under the NIS2- derived regime, entities fall within scope by reference to the sectors in which they operate and the relevance of the services they provide. The framework captures a broad spectrum of activities, including energy, trans - port, health, digital infrastructure and public adminis - tration, and applies to both public and private opera - tors. The national cybersecurity perimeter captures a dis - tinct category of entities whose networks, informa - tion systems and ICT services support essential State
functions and whose disruption may affect national security. Scope is determined by strategic relevance rather than by sector alone, with the result that the perimeter may extend to entities not otherwise sub - ject to sector-specific cybersecurity regulation. This approach reflects a focus on functional criticality and systemic impact. Digital infrastructure and managed service providers assume relevance under both regimes through differ - ent mechanisms. Under NIS2, certain digital services and infrastructures may be directly subject to obliga - tions. Under the national perimeter, managed services become relevant in so far as they form part of the critical service chain supporting protected functions. Interpretative challenges typically arise at the bounda - ries between digital services and general ICT enable - ment, and in the classification of cloud and managed service providers whose contractual positioning varies across sectors. In practice, scope determination is shaped by imple - menting measures, registration and notification processes, and institutional guidance. Supervisory assessment focuses on whether entities have correct - ly identified their regulatory exposure and document - ed the reasoning underlying classification decisions. Accurate scoping is therefore treated as a substantive compliance obligation rather than as a purely formal exercise. 2.2 Critical Infrastructure Cybersecurity Requirements Baseline cybersecurity requirements applicable to essential or critical entities in Italy are framed in risk-based terms and combine governance duties with technical and organisational controls. Under NIS2-derived frameworks, management bodies bear responsibility for approving and overseeing cyberse - curity risk management measures and for ensuring that adequate resources and accountability structures are in place. Cybersecurity is therefore embedded within corporate governance rather than delegated exclusively to technical functions. Technical and organisational measures are expect - ed to address asset identification, risk assessment, access control, monitoring, vulnerability management
216 CHAMBERS.COM
Powered by FlippingBook