Evolution of Italy’s National Cybersecurity Governance
摘要
This chapter examines the evolution of the Italian national cybersecurity governance over a period of more than a decade 2013–2024. The chapters highlights the critical reforms and strategic shifts that have significantly shaped the Italian approach in this field. The content chronologically traces how in the first period (2013–2020) Italy’s Intelligence services have been central in redefining cybersecurity measures in response to a series of internal adjustments, and external pressures, notably from the European Union and NATO. This period encapsulates, for instance, the strategic deployment of Italy’s cybersecurity national framework, beginning with the foundational 2013 architecture, which emphasized primordial structure implemented to mitigate cyber threats. Initial efforts in 2013 laid the groundwork for an integrated national cybersecurity architecture which was assessed in 2015 and refined in 2017 to address emerging complexities and inefficiencies. The second period (2019–2021) analyzed in this chapter discusses the new Italian approach to cybersecurity, which shifted towards a more centralized governance model. Indeed, in 2021 a “revolutionary” governance reform was approved, leading to the creation of the National Cybersecurity Agency. The chapter explores the operational and governance adjustments across three national architectures, detailing the specific roles and responsibilities assigned to various governmental bodies. It also critically analyzes the impact of these reforms on the overall efficiency and effectiveness of the national cybersecurity policy, identifying both strengths and weaknesses in each architecture.