National Cybersecurity Agency

Italia is protecting itself against ‘zero-day’ cyber vulnerabilities by turning to ethical hackers

The National Cybersecurity Agency has adopted a new policy to identify and resolve, in a timely manner, vulnerabilities that are not yet publicly known

Adobe Stock

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

Reporting, analysis and management of ‘zero-day’ cyber vulnerabilities, i.e. those not yet publicly known. These are the cornerstones of the new National Policy on Coordinated Vulnerability Disclosure (CVD) adopted by the National Cybersecurity Agency (ACN) in agreement with the Ministry of Justice. The CVD policy was provided for in a legislative decree dating from 2024, which transposed the European NIS 2 Cybersecurity Directive.

The CVD policy

The aim of the CVD policy is to introduce a structured process that facilitates the timely identification and resolution of potential vulnerabilities, thereby staying one step ahead of criminal or malicious actors who might seek to disclose and exploit such information.

Loading...

ACN Director-General Andrea Quacivi explains that, under the new provisions, CSIRT Italia – the Computer Security Incident Response Team, an operational arm of the Cybersecurity Agency – once it has received the notification, ‘will immediately undertake the technical analysis to identify, in consultation with the manufacturer or the provider of the service or product affected by the vulnerability, the solution – usually a “patch” – to be implemented as soon as possible to resolve that specific threat’.

The role of the digital community

For the CVD policy to be effective, it therefore requires the collaboration of those who, through research and analysis, identify potential vulnerabilities in ICT services and products. It is therefore essential to harness the contribution of the digital community and, in particular, that of security researchers and ethical hackers – that is, cybersecurity experts who test the digital systems of companies or public bodies to identify their weaknesses before they are exploited by malicious actors.

‘Zero-day’ vulnerabilities can, in fact, pose a major risk. As they remain unknown until they are identified and addressed, there are often no solutions available to limit the damage until it is already too late. If malicious actors are the first to discover them, there is a risk that they will be exploited to carry out cyber-attacks that could have serious repercussions for the security of those using the affected products or services.

Reports

The system established by the Cybersecurity Agency to protect the country from ‘zero-day’ vulnerabilities is therefore based on a coordinated disclosure process designed to enable the manufacturer or supplier to take action as quickly as possible, including through the release of security updates or patches.

The aim is to minimise the risk to users before information relating to the vulnerability is made public. The ACN states that reports must be made in accordance with the law and may be submitted via an online platform that will be made available on the Agency’s website.

The parties involved

The CVD policy primarily involves three parties. Firstly, the reporter – that is, the natural or legal person who identifies a potential ‘zero-day’ vulnerability and reports it to the CSIRT, providing the technical information required for its analysis. Reports may also be made anonymously, upon request.

At this point, the CSIRT itself steps in: it receives and analyses the report, coordinates communications between the parties concerned and, together with the manufacturer or supplier, supports the assessment, mitigation and resolution of the vulnerability.

Loading...

Finally, at the third level of the system is the manufacturer or supplier, who works with the Computer Security Incident Response Team to analyse the vulnerability, identify mitigation measures and ensure that the necessary updates are developed and distributed within the agreed timeframe.

Quacivi emphasises that, by adopting this policy, the ACN ‘consolidates a model of collaboration between institutions, security researchers and industry professionals, aimed at promptly identifying vulnerabilities, facilitating their resolution and reducing the risk that they may be exploited for malicious purposes, thereby contributing to the overall strengthening of the resilience of the national digital ecosystem’.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti