In recent times, the cybersecurity has become one global priority, causing growing concern also in Italy. It therefore arrives on the table of the Council of Ministers on Thursday Cybersecurity bill.
The legislation aims to establish a more defined regulatory framework for Artificial Intelligence and IT security, with the aim of introducing more severe sanctions to counter cyber attacks, in particular those linked to the breach of computer data.
La first draft provides for harsher penalties for hackers, with imprisonment of up to 10 years, fines for those who do not report cyber attacks, and then, sanctions for public administrations that do not comply with the indications, a more involved judiciary and finally, greater coordination between intelligence and Cybersecurity Agency (ACN).
Let's see in detail the key points contained in the draft bill.
Tougher penalties for hackers
The bill proposes a significant tougher penalties for hackers or for those who illegally access computer systems. The current sentence (from 1 to 5 years) would be doubled to a range between 2 and 10 years. Fines can reach up to twelve years of imprisonment in case of serious damage to the system. Concessions and penalty discounts are provided for hackers who "repent" and choose to collaborate with the authorities. Penalties could be reduced by half to two-thirds for those who actively contribute to preventing further criminal consequences by assisting law enforcement or judicial authorities in gathering evidence or recovering the proceeds of crime.
Narrow even for those who possess or provide malicious programs for computer systems they risk a maximum sentence of 2 years of imprisonment and A fine starting from 10.329 euros.
Obligation to report attacks
The obligation also arises report cyber attacks 24 within hours from their occurrence. Public administrations, including central, regional, municipal bodies, local health authorities and local public transport companies, will be required to promptly report cyber attacks from the moment they become aware of the incidents (article 8 of the bill).
Il lack of respect of this rule could trigger inspections by the Cybersecurity Agency. In case of persistent failure to notify, I am sanctions are foreseen pecuniary amounts ranging from 25.000 to 125.000 euros.
Likewise, sanctions will be applied to public administrations that do not comply with the Agency's indications regarding the vulnerabilities to which they are exposed. The reported actors must also designate a contact person for cybersecurity (Article 13).
More involved judiciary
Another innovation that will be introduced by the bill is a greater involvement of the judiciary in case of cyber attacks. A way to underline the importance given to legal protection in such situations.
Greater coordination between Intelligence and Acn
Finally, the cyber bill provides provisions for the operational coordination between security information services andNational Cybersecurity Agency (article 12).
Furthermore, it places the responsibility on the ACN enhance artificial intelligence through partnerships between the public and private sectors, using it "as a resource for strengthening national cybersecurity, also with the aim of promoting a ethical and correct use of systems based on this technology".
After tomorrow's meeting of the Council of Ministers, the text will go to Parliament for discussion and conversion.
Meanwhile, by October, the government will have to incorporate it into the national legislative system two European directives: the Apr 2, which introduces new data security obligations for companies, and the cerium, focused on the resilience of critical infrastructures.
