Editorial explainer on an institutional source: no single actormedium
The number rose 47%, the threat did not: reading Italy's cyber half-year properly
In the first half of 2026 CSIRT Italia handled 2,171 cyber events, 47% more than the 1,474 of the same period in 2025. It is the kind of figure that ends up in headlines next to the word "alarm". Italy's National Cybersecurity Agency, however, states in its own document that the growth does not measure a rise in the threat: it measures the widening of the observation perimeter brought by full implementation of NIS2. Confirming this are the numbers that fall in the same reporting: ransomware down to 181 cases (-12%), DDoS down to 407 events (-32%), events without confirmed impact down 6%. A half-year in which Italy saw more, not necessarily suffered more.
A rise that is not a worsening
There is a statistical trap that reappears whenever a country starts counting something seriously: the numbers go up, and everyone reads them as though the phenomenon had grown. It happened with reports of crimes that previously went unreported, with diagnoses of illnesses that previously went undiagnosed. Italy's cyber first half of 2026 is a textbook case.
CSIRT Italia, the technical-operational arm of ACN that receives the incident notifications required by law, handled 2,171 cyber events between January and June 2026, against 1,474 in the first half of 2025: a 47% rise. Of these, 1,072 were classified as incidents with confirmed impact.
The Agency's document is explicit about how that jump should be read. The growth is attributed chiefly to the more than one thousand notifications arriving as a result of NIS2, not to a real worsening. In its own words, the figure should not be interpreted as an increase in the threat or in the impacts suffered, but as the result of a greater capacity to intercept and handle phenomena that previously might not have surfaced with the same speed or granularity.
Who wrote to the CSIRT, and for the first time
The detail that tells the story best is not the total, it is the senders. The 1,160 notifications come from 890 entities, of which 690 reported for the first time.
Nearly eight in ten had never written before. Not because they had never had an incident — because they were not required to report it, or did not know they could, or did not know to whom. NIS2 widened the list of obliged entities and gave them an address. The rest is arithmetic.
The split between 953 mandatory and 207 voluntary notifications deserves an extra line. The first are compliance; the second are organisations that chose to disclose something nobody compelled them to disclose. In any reporting system, the voluntary share is the trust indicator: it tells you whether the authority is seen as a place you go to be helped or a place you go to be fined.
The numbers that fall
If the total really were the thermometer of the threat, then everything inside it should rise. It does not.
Ransomware falls to 181 cases, down 12%. DDoS falls to 407 events, down 32%. Events without confirmed impact number 1,099, broadly in line with the 1,164 of the first half of 2025, a 6% decline. The most affected sectors in the period were manufacturing, retail and technology.
Two specific facts give the half-year its shape. The highest peak of DDoS activity comes in February, coinciding with the Milan-Cortina 2026 Winter Olympics: an international event attracts demonstrative campaigns the way a streetlamp attracts insects, and this is known and expected. Between May and June, meanwhile, the trend is shaped by a resurgence of hacktivist DDoS campaigns — almost always without significant impact — and by incidents affecting IT service providers, whose effects propagated along the supply chain to organisations in different sectors.
That last point is the only genuine warning signal in the report, and it is not about totals: it is about the shape of incidents. An attack that hits a provider and propagates downstream produces a small number of events and a large number of affected organisations. It is precisely the kind of phenomenon that event-based statistics tend to under-represent.
What to take away
If you run an entity in scope for NIS2: you are probably among the 690. Notification is not a form to fear, it is the channel that turns that 47% into a useful figure rather than a black hole. An unreported incident is not an avoided incident, only an invisible one.
If you read headlines about Italian cybersecurity: distrust percentages without a denominator. When the measurement perimeter changes, comparing two years is like comparing two censuses taken with different borders. ACN says so in its own document — it is the piece of information most easily lost between report and news story.
If supply risk is your job: the part of the half-year that signals real change is the May-June note. The IT provider as a propagation point is not a scenario hypothesis, it is a line inside an official reporting for the first half of 2026.
A note on sourcing: the figures here come from ACN's Operational Summary for the first half of 2026 and the Agency's accompanying statement. ACN publishes monthly and half-yearly data as downloadable documents: where our summary and the original diverge, the original governs.