Italia is protecting itself against ‘zero-day’ cyber vulnerabilities by turning to ethical hackers
The National Cybersecurity Agency has adopted a new policy to identify and resolve, in a timely manner, vulnerabilities that are not yet publicly known
Reporting, analysis and management of ‘zero-day’ cyber vulnerabilities, i.e. those not yet publicly known. These are the cornerstones of the new National Policy on Coordinated Vulnerability Disclosure (CVD) adopted by the National Cybersecurity Agency (ACN) in agreement with the Ministry of Justice. The CVD policy was provided for in a legislative decree dating from 2024, which transposed the European NIS 2 Cybersecurity Directive.
The CVD policy
The aim of the CVD policy is to introduce a structured process that facilitates the timely identification and resolution of potential vulnerabilities, thereby staying one step ahead of criminal or malicious actors who might seek to disclose and exploit such information.
ACN Director-General Andrea Quacivi explains that, under the new provisions, CSIRT Italia – the Computer Security Incident Response Team, an operational arm of the Cybersecurity Agency – once it has received the notification, ‘will immediately undertake the technical analysis to identify, in consultation with the manufacturer or the provider of the service or product affected by the vulnerability, the solution – usually a “patch” – to be implemented as soon as possible to resolve that specific threat’.
The role of the digital community
For the CVD policy to be effective, it therefore requires the collaboration of those who, through research and analysis, identify potential vulnerabilities in ICT services and products. It is therefore essential to harness the contribution of the digital community and, in particular, that of security researchers and ethical hackers – that is, cybersecurity experts who test the digital systems of companies or public bodies to identify their weaknesses before they are exploited by malicious actors.
‘Zero-day’ vulnerabilities can, in fact, pose a major risk. As they remain unknown until they are identified and addressed, there are often no solutions available to limit the damage until it is already too late. If malicious actors are the first to discover them, there is a risk that they will be exploited to carry out cyber-attacks that could have serious repercussions for the security of those using the affected products or services.

