ITALY Trends and Developments Contributed by: Giuseppe Fornari, Enrico Di Fiorino, Emanuele Angiuli and Lorena Morrone, Fornari e Associati Studio Legale
National Cybersecurity Perimeter The legislative cybersecurity perimeter has been rein - forced in Italy and Europe in recent years. Two main laws have been introduced to that end. Law No 90/2024, focused specifically on cybercrimes, strengthened the national framework on cybersecu - rity, introducing a set of provisions aimed at ensur - ing enhanced protection against cyber-attacks and facilitating an efficient response to these emergen - cies. Section 16 of the Law specifically intervened on the Italian Criminal Code and Section 17 of the Law specifically intervened on the Italian Code of Criminal Procedure, introducing new crimes (such as cyber- extortion) and changes to procedural rules that help prosecutors in the investigations phase. Legislative Decree No 138/2024 transposed the NIS2 Directive (EU 2022/2555) into the Italian legal system, by embodying its principles and rules in the following ways. • National cybersecurity strategy: member states are required to adopt a national cybersecurity strategy and maintain an updated list of essential service operators, ensuring that these entities comply with the Directive’s requirements. • Scope of application: in addition to the sec - tors already covered by the NIS1 Directive (such as energy, transport, healthcare, finance, water resource management and digital infrastructure), the NIS2 Directive introduces – (a) new sectors subject to cybersecurity obliga - tions, classified as either “highly critical” or “critical”; (b) new categories of entities, classified as “es - sential” or “important”, based on their signifi - cance within the sector or the type of services they provide; and (c) the need for medium and large entities in criti - cal sectors to adopt adequate cybersecurity risk management measures and report signifi - cant incidents to national competent authorities (ie, incidents that may cause major disruptions or damage). • Supervisory measures: the NIS2 Directive intro - duces stricter oversight mechanisms and a more severe sanctioning regime, aiming to strengthen
The first includes: computer fraud (Section 640-ter of the Italian Criminal Code), unauthorised access to computer or telematics systems (Section 615-ter of the Italian Criminal Code), or the new offence of cyber- extortion (Section 629 (3) of the Italian Criminal Code). The second category, as already mentioned, repre - sents common crimes committed through the use of new technologies. The use of technology not only affects the way in which the crime is carried out but also makes the work of investigative bodies even more complex, as they find themselves having to investi - gate criminal phenomena that are difficult to decipher. By way of example, the offences of money laundering and self-laundering (Sections 648-bis and 648-ter.1 of the Italian Criminal Code, respectively) become so- called cyber-laundering if committed in the context of cyberspace. This is the case, for instance, in the transfer of money to current accounts opened at cred - it institutions based in offshore states or the use of so-called smart cards (ie, cards that can be reloaded and therefore used without a specific current account being opened). Another relevant phenomenon that increasingly inter - sects with money-laundering cases concerns the use of virtual currencies (or cryptocurrencies). The essen - tial characteristics of the cryptocurrency system are as follows: • decentralisation of negotiations – decisions are entrusted not to a bank or other regulatory body but to individual users, whose actions are imple - mented through the so-called blockchain; • rapid circulation on the internet; and • anonymity of market operators – the blockchain system actually makes it possible to trace trans - actions carried out on the network, but does not reveal the identity of those involved. The anonymity of virtual currencies, which can facili - tate criminal activities, continues to raise concerns, as emphasised in the EU’s Fifth Anti-Money Laundering Directive. To address these risks, national Financial Intelligence Units (FIUs) should be granted the ability to access information on cryptocurrency addresses.
228 CHAMBERS.COM
Powered by FlippingBook