Le Italian SMEs do not reach the sufficiency mark of cyber risk management, according to the Cyber Index PMI 2024. The report, presented in Confindustria, has detected a average score of 52 out of 100, far from the sufficient threshold set at 60 points. Despite an improvement compared to 2023 (+1%), Italian small and medium-sized enterprises continue to show significant gaps in awareness and implementation of protective measures. In particular, SMEs struggle to develop a strategic approach and correctly identify risks.
Cybersecurity: the picture of Italian SMEs
The Cyber Index PMI, created by Generali e Confindustria with the support ofCybersecurity & Data Protection Observatory of the Polytechnic University of Milan and in collaboration with theNational Cybersecurity Agency, measures the preparation of small and medium-sized Italian companies on cyber risks. The results reveal that, although there is a growing attention towards cybersecurity, many Italian companies are still poorly structured in dealing with cyber threats.
Italian SMEs obtain a score of 54 out of 100 for thestrategic approach to cybersecurity, but the data remains insufficient, indicating the lack of formal corporate policies, targeted investments and clearly defined responsibilities. ability to identify risks gets the lowest score: 45 out of 100, a sign that many companies do not adequately recognize threats. Only theimplementation area is more developed, with a score of 57 out of 100, indicating that SMEs are more reactive but not yet fully prepared.
Maturity levels of Italian SMEs
Il Cyber Index PMI 2024 divides Italian small and medium-sized enterprises into four groups based on their maturity in cyber risk management:
- 15% of SMEs are defined as “mature“: has a strategic approach, is aware of the risks and implements concrete actions to protect its resources.
- 29% of SMEs are “aware“: understands the risks, but has limited resources to act effectively.
- 38% of SMEs are “informed“: has a superficial understanding of the risks, but the approach is still disorganized.
- 18% of SMEs are “beginner“: has a low awareness of IT risks and does not adopt adequate protection measures.
The international context and emerging challenges
From 2018 to 2023, the cyber attacks serious cyber threats globally have increased by 79%. New technologies, such as artificial intelligence and GenAI, are amplifying cyber threats, creating an even more complex environment. Furthermore, the European Union's NIS2 directive, which aims to improve cybersecurity at a continental level, represents an opportunity to further raise awareness among Italian SMEs.
Comments
Angelo Camilli, vice president for Credit, Finance and Taxation of Confindustria, underlined: "Cybersecurity is a fundamental pillar for the resilience and growth of our economic system. Strengthening digital security means protecting the future of our companies and the entire production system, creating a safer and more competitive ecosystem. Confindustria works to support this process, through initiatives such as the Cyber Index PMI and constant dialogue with the institutions".
Pietro labriola, delegate of the president of Confindustria for the Digital Transition, added: "Cybersecurity is a challenge that concerns businesses, institutions and citizens. In a context of increasingly sophisticated threats, it is essential that the country adopts a strategic approach that promotes the culture of cybersecurity. Confindustria has always been committed to supporting companies, facilitating access to resources and skills and promoting the changes necessary to make our country grow. We must therefore invest in secure technologies, increase skills and build a system of public-private collaboration that allows our companies, especially SMEs, to protect themselves effectively".
