Threat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mapping

Topic · Institutions

National cybersecurity

Who defends Italy in cyberspace, with what powers, and within which European framework.

criticalFeatured dossierThe heart of WordPress, run by someone who never logged in: the WP2Shell chainRead the dossier →

Dossiers in this section

4 dossiers

The topic in brief

The institutional perimeter

Italy's cybersecurity has a defined architecture. The National Cybersecurity Agency (ACN) is the national authority for cybersecurity: it coordinates strategy, the resilience of essential services, and relations across the public and private ecosystem. Within it operates CSIRT Italia, the national computer security incident response team, which receives reports, issues alerts and bulletins, and supports incident handling.

The European framework: NIS2

The national level plugs into the Union's. The NIS2 Directive (Directive EU 2022/2555) raised the common European bar: it widens scope to eighteen critical sectors, mandates risk-management measures and reporting of significant incidents, and introduces direct accountability of top management. Member States had to transpose it by 17 October 2024. Each State also adopts a national cybersecurity strategy.

Why it matters even if you're not a “critical entity”

NIS2's logic cascades: the obligations of essential operators flow down their supply chain. A company not directly regulated may still have to demonstrate security measures because it supplies one that is. Knowing the institutional perimeter isn't a formality: it defines who to contact during an incident and which obligations apply.

FAQ

Who is Italy's national cybersecurity authority?
The National Cybersecurity Agency (ACN), within which CSIRT Italia handles incident response.
What changes with NIS2?
It widens the covered sectors, introduces risk-management and reporting obligations, and makes top management accountable for compliance.