National Cybersecurity
Strategy
ing narratives in adherence to specific ideologies or political motivations. No organization, even if technologically equipped and procedurally prepared, can come to completely eradicate the threats emanating from
cyberspace.
This reality must be addressed by acting according to an approach that includes the adoption of risk prevention and mitigation measures aimed at enhancing the resilience of digital infrastructures. The latter not only
include networks, systems and data, but also, and above all, users – be they institutional actors, private
companies or citizens – whose awareness must be raised through a widespread cybersecurity culture. If
today, in fact, there is a widespread perception of the risks related to physical security, for which every individual carries out, in their daily lives, actions aimed at protecting themselves and their assets, the same
cannot be said for the digital dimension, which risks are not yet fully understood.
This aspect, combined with the increasingly wide availability – at relatively low costs – of offensive tools, the
increased level of cyber-attacks complexity, the technical difficulty of attributing them to a certain actor, as
well as the possibility of cybersecurity vulnerabilities in IT products and solutions, has registered an overall
number of hostile actions in constant increase.
The recent attack trends provide evidence of economic and reputational damages to businesses, blocking of
energy infrastructure operations, malfunctions of information systems used by hospitals and healthcare
companies, dissemination of personal data aimed at discrediting public figures, journalists and political activists, to the point of sometimes endangering their safety.
Four essential considerations arise from this scenario:
1.
one of the duties of the State is the definition of adequate cybersecurity strategies aimed at planning, coordinating and implementing measures meant to make the Country safe and resilient even in the digital
domain, while ensuring citizens' trust in the possibility of exploiting its competitive advantages, in full protection of fundamental rights and freedoms;
2.
cybersecurity, which has become a matter of strategic importance, must be the foundation of the Country's
digitalization process, as an essential element of digital transformation, also with a view to achieving strategic national autonomy in the sector;
3.
cybersecurity must then be perceived not as a cost, but as an investment and an enabling factor for the
development of the national economy and industry, to increase the competitiveness of the Country at a
global level;
4.
cultural advance at every level of society, towards a "security-oriented" approach, must go in parallel with
ensuring the security of infrastructures, systems and information from a technical point of view, as an indispensable element in protecting our value and democratic system.
Being aware of what mentioned above and of the speed and breadth of technological change that require
persevering in the work of regulatory and strategic adaptation, starting from 2013, a lot has been done by
our Country in the field of cybersecurity. Over time, in fact, a series of measures have been adopted substantially aimed both at acquiring, developing and strengthening the necessary national cyber capabilities, and at
05