Conclusions
摘要
In just over a decade, Italy has undergone a profound transformation, characterized by the implementation of three significant institutional reforms that have shaped the national stance on cybersecurity. The Italian cybersecurity policy framework has evolved through various phases, reflecting a dynamic interplay among different actors and stakeholders. Starting with the "Monti Decree" of 2013, which placed cybersecurity under the direct responsibility of the President of the Council of Ministers, the need for a revision of existing policies became evident due to their shortcomings. This Decree introduced the first form of Italian architectural governance for cybersecurity. However, despite efforts to enhance the country’s cybersecurity framework, several major deficiencies soon emerged. These included, among others, overlaps between competent authorities, dispersion of responsibilities, lack of transparency in decision-making, a diversity of involved actors, and the absence of a specific budget to achieve strategic objectives. These issues, compounded by European and NATO initiatives, highlighted the necessity for reform. The "Renzi Directive" of 2015 and the subsequent "Gentiloni Decree" of 2017 sought to address these issues by reorganizing the national architecture. The second reform improved the distribution of responsibilities and decision-making processes while also incorporating European-derived recommendations and regulations. Nonetheless, fundamental questions regarding governance efficiency and the effectiveness of implemented policies persisted. One such question was whether intelligence services were the appropriate public administration apparatus for managing cybersecurity, given that transparency and direct interactions among stakeholders are crucial aspects. The approval of the National Cybersecurity Perimeter (PSNC) not only marked a strategic turning point in Italian cybersecurity legislation but also intensified these questions. Specifically, decision-makers began to ask: can intelligence services, which are inherently secretive, effectively manage cybersecurity where information sharing is critical? In response to this question, Italy decided in 2021 to evolve the policy framework by approving a third reform. This reform revolutionized national cybersecurity governance and led to the creation of the National Cybersecurity Agency. The change reframed cybersecurity as not merely a domain reserved for intelligence services, defense, or law enforcement but as a critical element for ensuring the political, social, economic, and industrial resilience of the nation. However, several important questions still remain. For example, will centralizing both oversight and coordination functions within a single Agency be effective and efficient governance system in the long term? What are the Agency’s actual capabilities in dealing with the expanding threat landscape presented by artificial intelligence (AI) and disruptive technologies like quantum computing? How well can it intervene across the entire national territory? What is the most effective model for involving private actors, who are increasingly burdened by stringent regulatory requirements? Furthermore, what best practices could be adopted in Italy? If these questions are not systematically addressed, they risk undermining the stability of the entire national ecosystem. This chapter aims not to merely summarize previous discussions, but to highlight the challenges, risks, and opportunities that Italy must address in the near future.