Cybersecurity
-

NIS2 and manufacturing: when an undertaking not listed by code enters the scope through REACH
Legislative Decree No 138 of 4 September 2024, which transposed Directive (EU) 2022/2555, the NIS2 Directive, has been in force since 16 October 2024 and requires the entities falling within its scope to register, or to update their registration, on the platform of the Italian National Cybersecurity Agency (ACN) from 1 January to 28 February…
-

A platform still without an address: the Cyber Resilience Act reporting obligation starts on 11 September
On 11 September 2026 manufacturers of products with digital elements will have to notify actively exploited vulnerabilities and severe incidents within twenty-four hours, as required by Article 14 of the Cyber Resilience Act. The channel through which they must comply, the single reporting platform run by ENISA, still has no public address, no dates for…
-

Frontier artificial intelligence reaches the board: a report due by 31 December
On 16 July 2026 the Official Journal of the European Union published a warning of the European Systemic Risk Board describing frontier artificial intelligence models as a source of systemic risk for the Union’s financial system. The following day the Bank of Italy and IVASS asked the boards of supervised intermediaries and of insurance undertakings…
-

Inspections without suspicion: ACN sets out how NIS 2 supervision works
On 11 August 2026 the Italian National Cybersecurity Agency added to its NIS frequently asked questions a section on monitoring, supervision and enforcement, made up of answers MVE.1 to MVE.5 and announced by the Agency on the same day. This is not new legislation and it adds no further obligations: it is the soft law…
-

Ten notifications and no more: the operating instructions for the Cyber Resilience Act platform
The reporting obligation under the Cyber Resilience Act applies from 11 September 2026 and runs through a single channel, the single reporting platform operated by ENISA. On 14 August the Agency updated the operating instructions for that platform and added a rule that did not appear in its July answers: a representative whose association with…
-

Twenty-four hours to report: what starts on 11 September under the Cyber Resilience Act
The Cyber Resilience Act applies in full from 11 December 2027, but not everything waits for that date. From 11 September 2026, six weeks from now, manufacturers of products with digital elements will have to notify actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware of them, through a single platform run…
-

Cyber accountability reaches the board, but the standards to prove it are still out to tender
On 14 July 2026 the Italian National Cybersecurity Agency (ACN) updated its FAQs on the obligations of the management bodies of NIS entities, clarifying that the approval of cybersecurity risk management measures cannot be delegated and that responsibility for the way that function is exercised stays with those who sit on the board. The day…
-

AI Security Specialist: attacks that resemble no other, and those who must stop them
Prompt injection, data poisoning, model evasion: Artificial Intelligence systems have an attack surface of their own, so specific that it has earned dedicated taxonomies from NIST, the OWASP project and MITRE. Guarding it is the craft of the AI Security Specialist, in a European market where security specialists are already in short supply, even before…
-

Mapping the risks of Artificial Intelligence: NIST, MIT, CSA and ENISA compared
Before managing AI risks you have to be able to name them. Four tools, all public and free, offer as many perspectives: NIST’s management framework, MIT’s taxonomic repository with over 1,700 catalogued risks, the Cloud Security Alliance’s controls matrix and ENISA’s cybersecurity framework. A reasoned map for those building AI governance. Anyone setting out to…
-

NIS 2, DORA and the Cyber Resilience Act: how to find your way when perimeters overlap
Three European acts, three regulatory logics, one goal: digital resilience. But for those who fall within several perimeters — from a bank to a software vendor — the question is concrete: which discipline prevails? The answer lies in the coordination clauses: Article 4 of NIS 2, the lex specialis of DORA and the complementarity of…