ITALY Trends and Developments Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
diploma from the School of Specialisation for the Legal Professions, which further refined her legal skills. She obtained a master’s degree in Cybersecurity Culture and Governance from the University of Catania, which deepened her knowledge of the sector. She is also actively involved in research activities, demonstrating her commitment to the advancement of cybersecurity and data protection.
ICT Legal Consulting ICTLC - ICT Legal Consulting Via Borgonuovo 12 20121 Milan Italy
Tel: +39 028 424 7194 Fax: +39 027 0051 2101 Email: info@ictlc.com Web: www.ictlc.com
Background The Italian cybersecurity landscape is currently char - acterised by a phase of regulatory consolidation in which the focus has progressively shifted from legisla - tive design to practical implementation and operation - al readiness. After several years marked by the adop - tion of new EU instruments and the reorganisation of national governance structures, market participants now face the challenge of translating principle-based requirements into sustainable compliance models. This transition has material implications for govern - ance, risk allocation and investment priorities across sectors. One of the most significant developments lies in the entry into force and operationalisation of the NIS2 framework at national level. While the underlying obligations are familiar in their risk-based logic, their scope and intensity have reshaped the compliance perimeter for many organisations that were previous - ly subject to lighter or sector-specific requirements. Entities newly classified as essential or important are required to formalise governance arrangements, clarify internal accountability and develop structured incident management capabilities that extend beyond ad hoc technical responses.
This phase of consolidation is also characterised by heightened regulatory engagement. Supervisory authorities increasingly focus on registration, scoping and preparedness, rather than on punitive enforce - ment. The emphasis is placed on whether organisa - tions have correctly identified their regulatory status, mapped applicable obligations and initiated remedia - tion plans capable of reaching maturity within reason - able timeframes. As a result, cybersecurity compli - ance is treated as a dynamic process rather than as a static checklist. At the same time, national security considerations continue to exert a strong influence on the regulatory environment. The coexistence of EU-driven frame - works and national security instruments requires organisations to manage overlapping obligations and to ensure that reporting, escalation and decision-mak - ing processes remain coherent. This interaction has become a defining feature of the Italian cybersecurity landscape and shapes how both public authorities and private operators approach resilience and risk management. This phase of implementation has also highlighted differences in preparedness across sectors. Larger
223 CHAMBERS.COM
Powered by FlippingBook