Cybersecurity 2026

ITALY Trends and Developments Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting

One of the key developments concerns the align - ment of internal incident classification with regula - tory thresholds. Multiple regimes may apply to the same event, including cybersecurity, data protection and sector-specific rules. Market practice increas - ingly reflects the need for integrated assessment pro - cesses capable of determining, in a coherent man - ner, whether notification obligations arise and which authorities must be informed. Fragmented or sequen - tial approaches have shown their limits and are viewed unfavourably by supervisors. Supervisory authorities place particular emphasis on early engagement and on the quality of information provided. Initial notifications are expected to support situational awareness, while subsequent communica - tions refine technical understanding and remediation measures. This approach incentivises organisations to invest in internal co-ordination and to prepare escala - tion procedures that operate effectively under pres - sure. From a market perspective, incident management capabilities have become a differentiating factor. Organisations with mature response frameworks, tested communication channels and documented decision-making processes are better positioned to manage regulatory interactions and to mitigate repu - tational impact. This trend reinforces the perception of cybersecurity as a governance and operational resil - ience issue rather than as a purely technical challenge. Another relevant development concerns the growing importance of post-incident analysis and remedia - tion. Supervisory authorities and market participants increasingly focus on lessons learned and on the abil - ity of organisations to demonstrate that incidents lead to tangible improvements in controls and processes. This expectation reinforces the need for structured incident reviews and for governance mechanisms capable of translating technical findings into organi -

and consistent manner. This has elevated the role of legal and communications functions in incident- response planning and has underscored the reputa - tional dimension of cybersecurity incidents. A further defining trend in the Italian cybersecurity context concerns the increasing sophistication and diversification of cyber-threats. Organisations across sectors report a shift from opportunistic attacks towards more targeted and persistent campaigns, often characterised by a combination of technical exploitation, social engineering and supply-chain compromise. This evolution has heightened aware - ness of the need for continuous monitoring and adap - tive defence strategies rather than reliance on static security controls. The growing reliance on cloud services, remote access solutions and interconnected digital ecosystems has expanded attack surfaces and increased dependency on third-party technologies. As a result, cybersecurity risk is no longer confined within organisational bound - aries but extends across complex networks of provid - ers and partners. This has practical implications for risk assessment, incident response and contractual governance, as vulnerabilities originating outside the organisation may have direct operational and regula - tory consequences. Artificial intelligence and automation technologies also play an ambivalent role in this evolving land - scape. On the one hand, they support more effec - tive detection, analysis and response capabilities. On the other hand, they are increasingly leveraged by threat actors to scale attacks and evade traditional controls. Market practice reflects growing attention to the security implications of technological innovation and to the need for governance frameworks capable of addressing both opportunities and risks associated with advanced digital tools. Supply-chain security has emerged as one of the most significant trends shaping cybersecurity strategies in Italy. Regulatory frameworks applicable in 2026 con - sistently emphasise the management of risks arising from outsourcing and reliance on ICT service provid - ers. This focus reflects the recognition that systemic

sational change. Other Key Trends

The handling of communications has also gained prominence. Organisations are required to manage communications with regulators, affected stakehold - ers and, where applicable, the public, in a coherent

225 CHAMBERS.COM

Powered by