Cookie Consent by Free Privacy Policy Generator

NIS2: Phase Two Begins. Time for Italian Public Administrations to Strengthen Cybersecurity

Emerging Technologies

The National Cybersecurity Agency (ACN) has officially announced the launch of the second phase of the NIS (Network and Information Security) journey. The goal is to strengthen the cybersecurity posture of essential and digital service operators, in line with the European NIS2 Directive, transposed by Italy in January 2023. This phase involves a broader and deeper engagement of Public Administrations (PAs), which are now required to conduct a structured risk assessment and adopt minimum security measures, according to the standards set by ACN.

What changes in cybersecurity for the Public Sector?

With the implementation of NIS2, cybersecurity in public administrations is no longer an optional best practice—it becomes a regulatory obligation.

The new rules introduce several requirements, including:

  • Mandatory reporting of cyber incidents within 24 hours
  • Adoption of risk management policies
  • Implementation of business continuity plans

The focus thus shifts from merely protecting systems to the entire digital resilience cycle, which includes prevention, response, recovery, and security governance.

Why are assessments now so critical?

At this stage, it’s essential for PAs to equip themselves with effective tools to understand their exposure level and define intervention priorities. The first step is a thorough assessment that allows them to:

  • Map critical IT systems
  • Identify existing vulnerabilities
  • Evaluate compliance with required standards (ACN minimum measures, ISO/IEC 27001, CIS Controls, etc.)
  • Define a realistic and measurable action plan

Among the companies ready to support Public Administrations in this process is Italy&Partners, which—together with Yalla Security—offers services including assessments, gap analysis, roadmap development, and security governance support.

Cybersecurity Stats Speak Clearly

According to the Clusit Report 2024, 23% of serious cyberattacks in Italy in 2023 targeted the public sector—an 18% increase over the previous year. Ransomware accounted for 36% of these attacks, followed by phishing techniques and exploits of known but unpatched vulnerabilities.
The public sector’s exposure is worsened by limited resources and, in many cases, outdated and non-segmented infrastructure.

In this scenario, the NIS2 Directive is not just a legal requirement but a real opportunity to change course, modernize systems, and improve incident response capabilities.

Building a Shared Security Culture

Beyond technical measures, NIS2 also emphasizes training and awareness. Cybersecurity must be seen as a shared responsibility, not just the domain of IT departments.
Italy&Partners offers training courses and workshops for public sector staff, aiming to build a strong, cross-functional security culture.

Towards Compliance: How Italy&Partners Can Help

Within this framework, Italy&Partners, supported by Yalla Security, positions itself as a strategic partner for all Public Administrations seeking to initiate a structured path toward NIS2 compliance.

Cybersecurity services for the public sector include:

  • Cybersecurity Assessments & Risk Analysis
  • Assistance in meeting ACN minimum security requirements
  • Support in drafting policies and incident response plans
  • Awareness and training programs for both technical and non-technical staff

To request a preliminary evaluation of your IT system’s cyber maturity level, you can contact Italy&Partners at info@italyandpartners.com—a no-obligation first step to aligning your infrastructure with the new directives.