Current Affairs

Ciardi (Acn): “More reports on cyber risk: notifications up by 310 per cent”

An interview with the deputy director of the National Cybersecurity Agency on the results for the first six months of 2026. The number of incidents has risen by 47 per cent as a result of the NIS 2 Directive, which introduced a mandatory reporting requirement

Nunzia Ciardi, vice direttore generale Acn (Imagoeconomica)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

In the first half of 2026, the National Cybersecurity Agency handled 2,171 incidents, 47 per cent more than in the same period last year. However, this figure does not equate to a corresponding increase in cyberattacks against the state’s strategic infrastructure. It primarily reflects a rise in the number of reports and an improved ability to detect incidents, partly due to the implementation of NIS 2, the European regulation that introduced mandatory reporting requirements. This legislation ‘has strengthened our ability to detect incidents, broadening our visibility of cyber threats and improving our response capacity, to the extent that we issued 606 alerts and bulletins – a 275 per cent increase compared with the whole of 2025 – and over 12,000 communications, representing a 131 per cent increase on the same period last year”.

Nunzia Ciardi, deputy director of the Agency, takes stock in *Il Sole 24 Ore* of the first six months of activity of the body, which reports to the Prime Minister’s Office, focusing on the main trends highlighted in the *Operation Summary* due to be published today.

Loading...

The number of incidents is rising. What about incident reports? 

Let us make it clear from the outset that this increase should not be interpreted as a deterioration in the country’s cyber security landscape. We received 1,160 notifications: 953 came from entities subject to NIS 2, and of these, 690 were first-time notifications. They are, so to speak, newcomers to the notification process. A further 207 reports, on the other hand, were submitted on a voluntary basis. This represents a 310 per cent increase in notifications compared with 2025. It is the hidden issues coming to light, enabling us to understand and address these phenomena.

So they’ve also served notices on companies that weren’t under any obligation to do so?

Exactly. The companies that have done so voluntarily have chosen to report incidents to us precisely in order to seek support from the ACN. This is an important step forward – first and foremost, a cultural one. With the entry into force of NIS 2, the number of organisations that regard the Agency as a point of reference has increased.

What are the most common types of attack?

DDoS and ransomware – the former bring a service to a standstill by flooding it with traffic, whilst the latter lock or encrypt data and demand a ransom – remain the most common forms of attack, but both are on the decline. Without wishing to sound overly triumphant, the figures tell us that we are heading in the right direction. Over the six-month period, we recorded 181 ransomware incidents – 12 per cent fewer than the 206 recorded in the same period of 2025 – and 407 DDoS attacks, down by 32 per cent. This is a sign that defences are now more effective. The peak occurred in February, during the Milan-Cortina Olympics, due to the actions of activist groups often sponsored by states. However, only 6% of the incidents recorded that month resulted in a website being taken offline, and even then for no more than 15 minutes. The impact, therefore, was virtually nil.

Have IT systems been compromised?

They have fallen to 1,560 from 4,408 in the corresponding period of 2025, representing a decline of 64.6 per cent – which is no small matter.

Loading...

A general decline, then.

The trend in these indicators reflects the effectiveness of our alert system, despite the ever-increasing digital footprint. Reports are becoming increasingly widespread and timely, enabling us to identify and rectify vulnerabilities sooner. This leaves attackers with fewer opportunities. And the figures confirm this.

However, one weakness remains: all it takes is for an employee to click on the wrong link in an email to put the entire company – and perhaps even the supply chain – at risk?

It must be clear that, in every context, cyber security is a shared responsibility: the greatest share certainly lies with the institutions and those who deal with these issues professionally, but a share of the responsibility rests with each and every one of us.

Copyright reserved ©
  • Ivan Cimmarustigiornalista

    Luogo: Roma

    Lingue parlate: Italiano, inglese

    Argomenti: Sicurezza, giudiziaria, inchieste, giustizia tributaria

    Premi: Nel 2011 tra i vincitori del Premio Internazionale Antimafia Livatino-Saetta

Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti