Operational notes Security

Cyber incidents on the rise in Italy? No — we're finally seeing them

4 min read

Control room with multiple screens
The numbers are rising because we are finally measuring: good news dressed up as bad. Photo: U.S. National Guard (Flickr), CC BY 2.0.

In the early months of 2026, bulletins from the National Cybersecurity Agency (ACN, Agenzia per la Cybersicurezza Nazionale) recorded figures that look alarming if read too quickly: incidents up +60% in February on the previous month, +81% in March (313 incidents). The easy headline: “Italy under attack”. The right headline: we are finally seeing what we previously could not. The surge is largely an effect of NIS2, which made incident notification mandatory — and what gets measured, shows up. It is a distinction that completely changes what a company should do.

Reading the numbers correctly

ACN’s Operational Summary reports tell a clear story: strong growth in February–March, then a levelling off (April and May both down). The Agency itself attributes the March increase “mainly to the greater visibility” resulting from the implementation of NIS2 (Legislative Decree 138/2024): not necessarily more attacks, but more attacks notified. The sectors hit hardest in the period — telecommunications, healthcare, manufacturing — are exactly the ones where NIS2 widened the perimeter of obliged entities. The recurring threats: data exposure, compromised email accounts, breaches of expected service levels.

In other words: the rising number is not a thermometer for the threat, it is a thermometer for our ability to notice it. For years incidents happened just the same — they simply never ended up in any statistics.

The ACN warning that matters more than the numbers

There is one line in the commentary to the reports that matters more than any percentage: too many companies still treat cybersecurity as a notification obligation, not as risk governance. That is the mistake that defeats the whole point of the law: treating NIS2 as “who do I email within 72 hours” rather than “how do I avoid getting there in the first place”. Notification is the last link in a chain — and if it is the only one you have built, you will notify your disasters punctually.

We made this point already when explaining what NIS2 really requires: the visible obligation (notification) is the easy part; the hard part — and the useful one — is the ability to notice. The tight deadlines (early warning within 24 hours, notification within 72) are unreachable without continuous visibility: you cannot notify within a day an incident that takes a month to discover.

What the three hardest-hit sectors teach us

Telecommunications, healthcare and manufacturing are not at the top by chance: these are sectors with many connected systems, large volumes of sensitive data and critical operational continuity — and now, with NIS2, also the obligation to look inside them. For a company in these sectors, the question is not “will we be attacked?” but “if we are attacked tonight, how long will it take us to notice?”. The three top threats — exposed data, compromised email, degraded services — can only be caught if someone (or something) is watching the right signals in real time. This is the ground on which AI agents that read the data flows and alert the operator make the difference between a contained incident and one that ends up in the news.

What to do, beyond the headlines

  1. Stop reading the spikes as an alarm and read them as a mirror: they measure your visibility, not the threat. If you have no internal numbers of your own, you are in the unmeasured part.
  2. Build detection before notification: centralised logs, continuous monitoring, thresholds. Notification within 24 hours is a consequence, not a starting point.
  3. Treat cyber as a business risk, with an owner, a process and a periodic review — not as a mailbox pointed at ACN.
  4. Take stock of what you have: you cannot protect — or notify — what you do not know you have. It is the first step for NIS2, the Cyber Resilience Act and the AI Act, all at once.

Want to know how long it would take you to notice an incident — and what it takes to cut that time down? Half an hour with one of our experts for the first map.

Sources