ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
and incident handling. Business continuity and dis - aster recovery arrangements form an integral part of this framework, particularly where service availability and integrity are critical to public interests. Emphasis is placed on demonstrable control and on the ability to adapt measures to evolving threat environments. Supply-chain security constitutes a central compo - nent of compliance. Entities are expected to identify and manage risks arising from relationships with sup - pliers and service providers, including managed ICT services and cloud infrastructures. Due diligence, contractual safeguards and ongoing oversight are required to ensure that outsourcing arrangements do not undermine resilience or controllability. Where the national cybersecurity perimeter applies, requirements acquire a national security dimension. Implementing measures specify notification catego - ries and security obligations, and allow for technical determinations and phased implementation. Compli - ance therefore requires continuous alignment with supervisory acts and updated taxonomies rather than a one-off implementation of static controls. 2.3 Incident Response and Notification Obligations Incident response and notification obligations in Italy depend on the applicable regime and on the classifi - cation of both the entity and the incident. Under NIS2- derived frameworks, notification duties are structured around staged communication with the competent authority. Initial notifications provide early situational awareness, while subsequent updates address tech - nical analysis, impact assessment and remediation measures. Notifications generally cover the nature of the incident, its suspected cause, operational effects and mitigation steps. Parallel notification obligations arise where incidents affect personal data, financial stability or national security. Under data protection law, personal data breaches are notified to the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, subject to a risk-based thresh - old. Communication to affected individuals occurs where a high risk to rights and freedoms is identified. These obligations frequently intersect with cybersecu -
rity reporting requirements and require co-ordinated handling. In the financial sector, DORA introduces harmonised reporting duties for major ICT-related incidents, and requires alignment between internal incident classi - fication and regulatory materiality thresholds. Under the national cybersecurity perimeter, incident notifica - tion supports national situational awareness and crisis co-ordination, and is linked to predefined categories reflecting strategic impact. The coexistence of regimes requires a disciplined approach to incident governance. Mature compli - ance frameworks integrate technical response, legal assessment and regulatory communication into a sin - gle process that supports timely notification, progres - sive updates and post-incident analysis. 2.4 State Responsibilities and Obligations State responsibilities for national cyber-resilience in Italy operate through strategic direction, co-ordination of incident response, and development of common capabilities. National policy frames public-private co- operation and information sharing as structural com - ponents of cyber defence and resilience. The Agency for National Cybersecurity acts as the principal institutional vehicle for these responsibili - ties, supporting prevention activities, facilitating threat intelligence exchange and operating the national Computer Security Incident Response Team (CSIRT). The State also promotes qualification and assurance mechanisms for technologies used in critical environ - ments, and issues guidance and technical determina - tions that shape operational practice. Public-private co-operation is realised through struc - tured information exchanges, reporting frameworks and sectoral interaction, enabling authorities to develop situational awareness and disseminate alerts. These responsibilities interact with EU co-operation mechanisms under NIS2, which integrate national authorities into a networked European response archi - tecture and reinforce the need for coherent national procedures.
217 CHAMBERS.COM
Powered by FlippingBook