International Fraud and Asset Tracing 2026

ITALY Trends and Developments Contributed by: Giuseppe Fornari, Enrico Di Fiorino, Emanuele Angiuli and Lorena Morrone, Fornari e Associati Studio Legale

mutual trust and cybersecurity capabilites across the EU. • Liability of senior management: the Directive establishes senior management liability for non- compliance with cybersecurity risk management measures, thereby encouraging corporate govern - ance bodies to actively and continuously engage in cybersecurity-related decision-making. • Cybersecurity response networks: the Directive establishes a network of computer security inci - dent response teams (CSIRTs), tasked with sharing information on cyber-threats and managing cyber- incidents. Furthermore, it creates the European Cyber Crisis Liaison Organisation Network (EU- CyCLONe) to facilitate the exchange of information among member states and EU institutions in the event of large-scale cyber-incidents and crises. Alongside national laws, the EU DORA Regulation (EU 2022/2554) became applicable in Italy on 17 Janu - ary 2025, forcing financial institutions and critical ICT providers to manage cyber-risk, reporting and test - ing in accordance with stricter standards than those provided by NIS2. Corporate Vicarious Liability (Legislative Decree No 231/2001) Law No 90/2024 has added a new crime to the list of offences triggering company liability: “cyber-extor - tion” (Section 629 (3) of the Italian Criminal Code). The crime of cyber-extortion punishes “anyone who, through the conduct described in Sections 615-ter (”Unauthorized access to a computer or telematic system”), 617-quater (“Unlawful interception, obstruc - tion or disruption of computer or telematic commu - nications”), 617-sexies (“Forgery, alteration, or sup - pression of the content of computer or telematic communications”), 635-bis (“Damage to information, data and computer programs”), 635-quater (“Dam - age to computer or telematic systems”) and 635-quin - quies (“Damage to computer or telematic systems of public interest”), or through the threat of committing such acts, forces another person to act or refrain from acting, obtaining an unjust profit for themselves or others to the detriment of the victim”.

The legislature, through the introduction of the crime of cyber-extortion among the offences triggering the liability of a company, aims to counter the concern - ing phenomenon of ransomware, a type of virus that blocks user access to files and demands a sum of money, usually in cryptocurrencies, to make them accessible again. Entities convicted of cyber-extortion are subject to disqualifying sanctions, including the possibility of being banned from conducting business for a period of no less than two years. This provision underscores the legislature’s focus on preventing these crimes, which pose an increasing threat to businesses, par - ticularly those operating in the critical digital infra - structure sector. Indeed, according to data from the latest National Cybercrime Centre for the Protection of Critical Infrastructure ( Centro Nazionale Anticrimine Informatico per la Protezione delle Infrastrutture Crit- iche or CNAIPIC), these attacks accounted for 34% of “serious attacks”. Decree Law No 92/2024 (as amended and converted by Law No 112/2024) has added a new crime to the list of offences triggering corporate liability: “misap - propriation of money or movable property” in cases involving damage to the financial interests of the EU (Section 314-bis (2) of the Italian Criminal Code). The crime of “misappropriation of money or movable property” punishes “a public official or a person in charge of a public service who, by virtue of their office or service, has possession or availability of money or other movable property belonging to others and allocates it to a use different from that prescribed by specific legal provisions or acts having the force of law, leaving no margin for discretion, and who inten - tionally obtains an unfair financial advantage for them - selves or others or causes unjust damage to others” (paragraph 1). The penalty is increased “when the act affects the financial interests of the European Union and the unfair financial advantage or unjust damages exceed EUR100,000” (paragraph 2). The crime of “misappropriation of money or movable property” falls under offences triggering corporate lia -

229 CHAMBERS.COM

Powered by