Il bill on cybersecurity is law. With 80 votes in favour, 3 against and 57 abstentions, the Senate definitively approved the text. The M5s, Pd, Italia Viva and Azione groups abstained, while the Greens and Left Alliance (Avs) voted against.
The cybersecurity bill represents a important step to strengthen the country's cybersecurity, considering that in 2023 the ACN managed 1.411 cyber attacks, with an increase of 29% compared to the previous year and the new danger arising from attacks enhanced by artificial intelligence. Tuttavia, critical issues remain related to lack of resources additions in the new law, which make the practical implementation of the measures difficult. Ivan Scalfarotto of Italia Viva criticized this deficiency, defining the bill as "little more than an elaboration of good intentions".
However, the Undersecretary of State with responsibility for security and cybersecurity was satisfied, Alfredo Mantovano, who expressed "appreciation for the definitive approval by the Senate of the government bill on cybersecurity: it is a text that has found enrichment and positive integration in the parliamentary process, thanks also to the amending contribution of the opposition. From today the entire national security system, and in particular the cyber one, which has become the main front for attacks by hostile state subjects, he finally comes equipped with more suitable operational toolsto reject them"
But let's now see the new law on cybersecurity in detail and what new features have been introduced.
What is the new cybersecurity law?
The new cybersecurity law is a legislative text that aims to enhance cybersecurity in Italy, especially against increasingly sophisticated and frequent cyber attacks. The law expand the “perimeter” of the subjects obliged to improve their defenses and introduces an alarm and collaboration procedure with theCyber Security Agency (Acn) for repairs. The legislation also defines the methods of intervention in the event of competing competences, such as between the ACN and the judicial police, and introduces new types of crime with more effective investigation tools.
The bill provides for thetougher penalties for cybercriminals and forces entities at risk, such as large municipalities, local health authorities and regional capitals, to adopt advanced cybersecurity systems and promptly report attacks. The fines for failure to notify an attack they go from simple warnings to significant fines.
The obiettivo of the new law on cybersecurity is twofold: on the one hand, intensify punitive measures against those responsible for cyber attacks, and on the other, promote a more robust and widespread cybersecurity culture.
Cybersecurity law: the key points
Tightening of penalties for computer crimes
One of the main novelties of the text is thetightening of penalties for computer crimes. This measure aims to dissuade illicit behaviour in the cyber field and to guarantee a more severe and adequate response to the damage caused. The changes made to the Criminal Code provide more severe penalties for crimes such as unauthorized access to computer systems, the dissemination and illegal installation of harmful software, and aggravated fraud: unauthorized access to computer systems will now lead to imprisonment ranging from 2 to 10 years, doubling the previous sentence which ranged from 1 to 5 years. Furthermore, those who possess or distribute malicious software may be punished with up to 2 years in prison and fines. The penalties for damaging public utility IT systems will be increased to up to six years in prison.
A new type of crime is also introduced, including thecyber extortion while the tools to investigate and verify such cyber crimes are strengthened.
Obligation to report accidents
Another great innovation of the law is theobligation for public administrations to report, within 24 hours, certain types of cyber incidents that impact networks. The reporting must be carried out at the National Cybersecurity Agency. The reporting obligation also concerns operators who carry out institutional or essential functions for the interests of the State, ensuring a timely and coordinated response to cyber threats. The Presidency of the Council, upon proposal of the Inter-Ministerial Committee for Cybersecurity, will define the scope of the reporting obligation of accidents, determining which public and private bodies will be required to fulfill this obligation.
Ad hoc structures in Public Administration
Public administrations will be required to equip themselves with structures dedicated to cybersecuritya single contact person for the ACN, in line with the European NIS2 Directive. The contact person will be responsible for managing and coordinating all activities relating to IT security within the administration. Additionally, a National Encryption Center will be established within the National Cybersecurity Agency, which will develop and implement advanced encryption technologies to protect sensitive communications and data.
The bill provides that for i public contracts relating to IT goods and services, especially those used to protect strategic national interests, will be defined specific cybersecurity requirements. A decree issued on the proposal of the ACN and the Inter-Ministerial Committee for the Security of the Republic will identify the essential cybersecurity elements to be taken into consideration in the procurement of IT goods and services.
Participation of anti-mafia and anti-terrorism and access to databases
All meetings of the Cybersecurity Unit (NCS) of the ACN, representatives of the ACN may also participate, in relation to specific issues of particular relevance National anti-mafia directorate e anti Terrorism and Bank of Italy. The measure guarantees a integrated and coordinated approach in the management of cyber threats, involving all the competent security authorities.
The legislation establishes precise rules foraccess to databases of public administrations by technical staff, providing rigorous authentication systems.
The human side: cooling off period for technicians and no more revolving doors in intelligence
The bill introduces a “cooling down” period for specialized technicians who move from the public to the private sector, in order to prevent potential conflicts of interest. Furthermore, ACN employees who have participated in specialization programs will not be able to take positions with private entities in cybersecurity for at least two years.
The regulatory text also includes provisions for stop the revolving doors in intelligence: the former managers of Dis, Aisi and Aise will not be able to work abroad or in companies subject to golden power for three years, unless authorized by the Prime Minister.
The resource node
The cybersecurity bill was criticized for the lack of financial allocations additional items needed for implement the measures effectively of cyber security. The proceeds from the sanctions, for example, will only be allocated to the National Cybersecurity Agency to improve its operations.
This has led some politicians to define the new law as “little more than a making good intentions“, underlining that without adequate resources it may not be effective in countering increasingly sophisticated cyber risks.
Will this law be enough to improve and make companies and public administrations more aware of the fight against cybercrime? The final passage of the cybersecurity bill is certainly a significant first step in strengthening the national defense against growing cyber threats. It remains to be seen whether these provisions will be sufficient to guarantee effective protection and to promote a culture of IT security spread across public and private entities. However, it will be necessary to invest more in an increasingly crucial sector to preserve the integrity of digital infrastructures and the security of sensitive data, facing future challenges with adequate resources and innovative strategies.
