Cybersecurity 2026

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting

3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Operational resilience in the Italian financial sector is primarily governed by DORA, which applies directly and structures ICT risk management, incident report - ing, resilience testing and third-party oversight for a broad range of financial entities. Digital operational resilience is treated as a prudential issue and inte - grated into governance and risk management frame - works. Scope is functionally defined and captures entities by reference to regulated activities rather than legal form. ICT service providers located outside Italy become relevant where they support in-scope financial enti - ties, and supervisory focus centres on contractual enforceability, auditability and exit strategies. National authorities operationalise the framework through sec - toral supervision and reporting documentation. 3.2 ICT Service Provider Contractual Requirements DORA introduces a prescriptive contractual architec - ture designed to ensure that financial entities retain effective control over outsourced ICT services sup - porting critical or important functions. The definition of ICT service providers focuses on the nature and role of services within the regulated entity’s ICT environment. Contractual requirements address service descrip - tion, data location, security safeguards, incident noti - fication and co-operation duties. Rights of access, inspection and audit are central, as are mechanisms to control subcontracting and chain outsourcing. Exit strategies and portability arrangements are treated as core resilience elements, reflecting the need to pre - serve continuity and controllability. In practice, the contractual framework required by DORA interacts closely with broader outsourcing governance and internal control expectations. Finan - cial entities are expected to demonstrate not only the formal inclusion of mandatory clauses but also their operational effectiveness. This requires that contrac - tual rights of access, audit and information be sup -

ported by internal processes capable of exercising those rights in a meaningful way. Supervisory scru - tiny therefore extends beyond contractual drafting and focuses on whether oversight mechanisms operate in practice and are integrated into the entity’s risk and compliance functions. The emphasis on contractual control also reflects concerns relating to concentration risk and systemic dependency on a limited number of ICT service pro - viders. Governance arrangements increasingly require that entities map critical dependencies, assess substi - tutability, and document decision-making processes relating to provider selection and retention. Contrac - tual provisions addressing termination and transition are assessed in light of these considerations and are expected to align with internal contingency planning rather than operate as abstract legal safeguards. 3.3 Key Operational Resilience Obligations Key obligations encompass governance, ICT risk management, incident management and reporting, resilience testing and third-party risk management. Management bodies are responsible for the ICT risk framework and its integration into overall governance. ICT risk management covers identification, protection, detection, response and recovery. Incident management is structured as a regulated life cycle, and reporting duties require alignment between internal classification and regulatory thresholds. Test - ing obligations range from basic resilience assess - ments to advanced threat-led penetration testing, reflecting a maturity-based approach. 3.4 Operational Resilience Enforcement Enforcement operates through supervisory process - es assessing governance, controls and evidence of compliance. Measures include information requests, inspections, corrective actions and administrative sanctions. Even where critical ICT service providers fall under EU-level oversight, regulated entities remain the primary addressees of supervision. Supervisory practice in the area of operational resil - ience increasingly reflects an outcome-oriented approach. Authorities assess whether governance structures, internal controls and documentation

218 CHAMBERS.COM

Powered by