Ciardi (Acn): “More reports on cyber risk: notifications up by 310 per cent”
An interview with the deputy director of the National Cybersecurity Agency on the results for the first six months of 2026. The number of incidents has risen by 47 per cent as a result of the NIS 2 Directive, which introduced a mandatory reporting requirement
In the first half of 2026, the National Cybersecurity Agency handled 2,171 incidents, 47 per cent more than in the same period last year. However, this figure does not equate to a corresponding increase in cyberattacks against the state’s strategic infrastructure. It primarily reflects a rise in the number of reports and an improved ability to detect incidents, partly due to the implementation of NIS 2, the European regulation that introduced mandatory reporting requirements. This legislation ‘has strengthened our ability to detect incidents, broadening our visibility of cyber threats and improving our response capacity, to the extent that we issued 606 alerts and bulletins – a 275 per cent increase compared with the whole of 2025 – and over 12,000 communications, representing a 131 per cent increase on the same period last year”.
Nunzia Ciardi, deputy director of the Agency, takes stock in *Il Sole 24 Ore* of the first six months of activity of the body, which reports to the Prime Minister’s Office, focusing on the main trends highlighted in the *Operation Summary* due to be published today.
The number of incidents is rising. What about incident reports?
Let us make it clear from the outset that this increase should not be interpreted as a deterioration in the country’s cyber security landscape. We received 1,160 notifications: 953 came from entities subject to NIS 2, and of these, 690 were first-time notifications. They are, so to speak, newcomers to the notification process. A further 207 reports, on the other hand, were submitted on a voluntary basis. This represents a 310 per cent increase in notifications compared with 2025. It is the hidden issues coming to light, enabling us to understand and address these phenomena.
So they’ve also served notices on companies that weren’t under any obligation to do so?

