As we do every year, before the summer break, it is worth briefly summarising the most significant events of the past few months.
NIS2
The October 2026 deadline marks an important milestone to be met in full compliance, and this involves not only the adoption of the ACN’s basic security measures but, above all, the proper contractual arrangement of supplies with third parties. This aspect, which is often overlooked or given secondary importance, is in fact one of the key factors in ensuring efficient and robust services, both during normal operations and following a cyber incident.
Contractual adaptation is not merely a technical or legal exercise; it must be carried out in consultation with the relevant stakeholders. Contracts should specify the procedures for communication between the supplier and the client, as well as the procedures and timeframes for availability and intervention, which must be consistent with the type of system to be protected. Last but not least, recovery times must be in line with the service and organisational requirements.
Reviewing contracts provides an opportunity to improve them and make the relationship with suppliers more robust and fruitful, but it is also a crucial moment for reflection, enabling us to understand the priorities of systems and services, assess their importance and determine the relevant strategies to be implemented. This has been discussed in the following articles:
NIS2 – Requirements for supplier management
Data Centre
The significant media attention surrounding data centres has shifted the political debate from the local to the regional and national levels. Politicians, who are currently ill-prepared on this issue, will find themselves having to manage a trend of rapid growth which will have major implications for the local area and the climate. The ‘heat island’ effect, which, according to some studies, could cause a rise of up to five degrees in the vicinity of the facility, is causing concern amongst neighbouring local authorities, but this is not merely an environmental issue. The Lacchiarella case, like those of Zibido San Giacomo and Magenta, has highlighted a dangerous and unwelcome lack of communication between the public and political institutions: without citizens’ associations, many planning issues would not have come to light, and the State would not have been prompted to request further investigation and verification. There is, therefore, an apparent disconnect between the interests represented by the community and the political response coming from the local councils, and this is clearly demonstrated by the communications from the associations, as well as by a number of public videos showing confrontations between citizens and political authorities.
The risk is an uncoordinated proliferation of data centres which, according to some, is already underway and would see several data centres located just a few hundred metres apart as the crow flies. This has been discussed in the following articles:
Data centres: from the Lacchiarella case to technological development
Data centres: the case of Zibido San Giacomo
The ‘No Data Centres’ movement
Cybersecurity
The recent cyber-attacks targeting some of the country’s key IT infrastructure have once again highlighted a lack of commitment to compliance; this is not merely a technical or IT issue, but a legal and organisational one. Unfortunately, this problem cannot be countered by a firewall, a device, software or a service: it comes down to the simple application of principles of accountability which, evidently, remain stifled by organisational and profit-driven dynamics, to the detriment of citizens’ data and regulatory compliance. Until responsibility for the damage caused is properly attributed, it is unlikely that these aspects will be respected. This is also discussed in the following article:
Regarding the recent data breaches
Conclusions
Autumn will bring many changes, and it will be interesting to see‘if’ and‘how’ things will change after October. For the time being, as many articles point out, there is still time to adapt your infrastructure, but it is worth remembering that the work does not end at the end of October. Adopting a sound cybersecurity policy means working day in, day out on procedures, processes, infrastructure and services to keep data secure and compliant with current regulations. But it should. Have a great summer, everyone.