Cybersecurity 2026

ITALY Trends and Developments Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting

organisations and regulated entities have generally approached the new requirements through structured programmes supported by external advisers and inter - nal project teams. Smaller operators, including entities newly captured by the extended scope of cybersecu - rity regulation, have encountered greater challenges in interpreting obligations and allocating resources. This divergence has contributed to a more heterogeneous compliance landscape and has reinforced the role of guidance and supervisory clarification in supporting consistent application of the rules. In addition, regulatory consolidation has influenced internal investment decisions. Cybersecurity budgets are increasingly justified in terms of regulatory expo - sure and risk mitigation rather than purely technical enhancement. This has supported greater alignment between compliance, risk management and strategic planning functions, but has also required organisa - tions to prioritise initiatives and to balance short-term remediation efforts with longer-term resilience objec - tives. Governance and Responsibilities A notable trend in the Italian market concerns the increasing centrality of governance and senior man - agement accountability in cybersecurity compliance. Regulatory frameworks applicable in 2026 consist - ently frame cybersecurity as a matter for boards and top management, rather than as an issue confined to IT or security departments. This shift has practi - cal consequences for organisational structures and decision-making processes. Senior management is expected to demonstrate informed oversight of cybersecurity risks and to inte - grate cyber considerations into broader enterprise risk management. In practice, this has led to a reas - sessment of internal reporting lines, the formalisation of roles and responsibilities, and the involvement of legal and compliance functions in cybersecurity gov - ernance. The emphasis is placed on documentation, traceability of decisions and the ability to evidence that cybersecurity risks are identified, assessed and addressed at appropriate organisational levels. This governance-driven approach also affects how organisations engage with regulators. Supervisory

dialogue increasingly revolves around governance arrangements, internal controls and the effectiveness of oversight mechanisms. Technical measures are assessed within the broader context of organisational maturity and risk awareness, rather than in isolation. As a result, entities that invest in governance frame - works and cross-functional co-ordination tend to be better positioned in supervisory interactions. The growing importance of accountability has also influenced market expectations. Boards and senior executives increasingly view cybersecurity as a stra - tegic risk capable of affecting reputation, operational continuity and value creation. This perception sup - ports greater investment in resilience and fosters a cultural shift in which cybersecurity is embedded in business planning and operational strategy. The growing emphasis on accountability has led to a reassessment of how cybersecurity responsibilities are distributed within organisations. In many cases, formal governance structures have been updated to ensure that cybersecurity risks are discussed at board or executive level with sufficient regularity and depth. This has included the introduction of formal report - ing cycles, risk dashboards and escalation criteria designed to support informed decision-making. From a practical perspective, this governance evolu - tion has also affected interactions with external stake - holders. Investors, business partners and customers increasingly expect transparency regarding cyberse - curity posture and incident management capabilities. As a result, governance arrangements are not only assessed through a regulatory lens but also influence commercial relationships and reputational positioning. Incident Management Incident management remains a central area of focus in the Italian cybersecurity landscape, particularly in light of expanded reporting obligations and increasing supervisory scrutiny. Regulatory regimes applicable in 2026 emphasise timely communication, accuracy of information and co-ordination between technical response and legal assessment. Organisations are expected to move beyond reactive notification and to adopt structured incident governance frameworks.

224 CHAMBERS.COM

Powered by