Cybersecurity 2026

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting

demonstrate an effective capacity to manage ICT risk under stress conditions. This assessment is not limited to formal compliance with regulatory require - ments but extends to the consistency between poli - cies, operational procedures and actual incident-han - dling experience. Deficiencies identified in one area, such as third-party oversight or incident escalation, may therefore have broader implications for the overall supervisory assessment of the entity. Enforcement action in this context serves both correc - tive and preventative functions. Corrective measures address identified weaknesses and require remedia - tion within defined timelines, while preventative meas - ures aim to reduce the likelihood of future disruptions by strengthening governance and control frameworks. The supervisory dialogue accompanying these meas - ures contributes to shaping market practice and clari - fies regulatory expectations regarding acceptable resilience standards. 3.5 International Data Transfers International data transfers intersect operational resil - ience where outsourcing and ICT services involve cross-border processing and remote access. Govern - ance therefore requires transparency regarding data locations and enforceability of access and audit rights across jurisdictions. Data protection transfer rules interact with resilience obligations by requiring that availability, integrity and recoverability remain assured notwithstanding third-country risks. 3.6 Threat-Led Penetration Testing Threat-led penetration testing forms part of the advanced testing framework under DORA and evalu - ates resilience against realistic adversarial scenarios. Testing is grounded in threat intelligence and inte - grated into governance so that findings translate into measurable improvements.

ulatory evolution reflects the recognition that digital products and services constitute critical components of economic and social infrastructures, and that weak - nesses embedded at design stage may propagate across sectors and jurisdictions. Within this context, the Cyber Resilience Act establishes a comprehensive framework of essential cybersecurity requirements for products with digital elements, and introduces securi - ty-by-design and security-by-default as legal obliga - tions tied to market access. The scope of cyber-resilience legislation extends beyond traditional ICT products and encompasses a wide range of connected devices, software compo - nents and digital services that rely on network con - nectivity or remote update capabilities. Manufactur - ers, importers and distributors are required to ensure that products placed on the market meet baseline cybersecurity standards throughout their life cycle. Cyber-resilience is therefore treated not merely as a feature of organisational processes but as an intrinsic characteristic of products and services that may affect downstream users and critical environments. This product-focused regime complements organisa - tional cybersecurity frameworks by addressing risks at source and by reducing systemic exposure to vulner - abilities that may otherwise be inherited by operators. In the Italian context, cyber-resilience legislation inter - acts with procurement practices, particularly in critical sectors and public administration, where compliance with security requirements increasingly functions as a prerequisite for market participation. The result - ing regulatory landscape connects product security, supply-chain governance and operational resilience within a unified risk management logic. The product-focused nature of cyber-resilience leg - islation alters the traditional allocation of cyberse - curity responsibilities by extending legal obligations upstream in the supply chain. Security considerations therefore influence design choices, component selec - tion and update mechanisms from an early stage. This shift has practical implications for contractual relation - ships between manufacturers and downstream opera - tors, as compliance with cybersecurity requirements becomes a shared concern that affects liability alloca -

4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

Cyber-resilience in Italy is increasingly shaped by hori - zontal EU product security regulation that addresses cybersecurity vulnerabilities as systemic supply-chain risks rather than as isolated technical flaws. This reg -

219 CHAMBERS.COM

Powered by