Cybersecurity & NIS2

We assist businesses and organisations with cybersecurity obligations and incident management, from defining the applicable regulatory scope to incident response and defence in the event of an attack.

Security is neither solely a technical nor solely a legal matter. We cover both sides — regulatory obligations and incident response — working with the Firm’s technology partners and drawing on digital forensics expertise.

What we do

  • NIS2 scope — classification as an essential or important entity and registration on the ACN platform.
  • Risk management measures — technical and organisational safeguards, training obligations, and liability of management bodies.
  • Incident notification — procedures, deadlines, and liaison with the ACN.
  • DORA for the financial sector — digital operational resilience and oversight of ICT providers.
  • Supply chain and ICT contracts — security clauses, management of critical providers, and audits.
  • Incident response and cybercrime — crisis management, liaison with authorities and the Italian Data Protection Authority, defence, and protection of victims.
  • NIS2 — Directive (EU) 2022/2555, Legislative Decree 138/2024. Extends cybersecurity obligations to a broad range of entities classified as “essential” and “important”. Registration on the ACN platform has been required since late 2024; substantive obligations become operational in 2026, with ACN inspections expected from the autumn.
  • Law 90/2024 — cybersecurity and cybercrime. Strengthens notification obligations (24 hours for public authorities), increases penalties for cyber offences, and affects 231 Models. It complements Legislative Decree 138/2024.
  • DORA — Regulation (EU) 2022/2554. Since January 2025, requires financial entities to manage ICT risk, conduct resilience testing, and oversee critical third-party providers.
  • Cyber Resilience Act — Regulation (EU) 2024/2847. Introduces security requirements for products with digital elements; the main obligations are expected to apply from 2027.
  • National Cybersecurity Perimeter — Decree-Law 105/2019. Enhanced regime for entities included within the perimeter, coordinated with NIS2.
  • Authorities — ACN. The National Cybersecurity Agency (Agenzia per la Cybersicurezza Nazionale) is the competent authority for NIS2 and Law 90/2024.

How we work

For us, cybersecurity is built around two inseparable stages: compliance, which comes before an incident, and response, which follows it. It is in the way an incident is handled that the strength of the work done beforehand is ultimately put to the test.

Would you like to be contacted?


Contact information