Alessandro Del Ninno
Areas of practice
Cybersecurity
Specialized legal services on digital security.

Cybersecurity, Digital Operational Resilience and Product Security

Cybersecurity is no longer an exclusively technical responsibility. Service continuity, information protection, the security of digital products and the ability to prevent and manage incidents directly affect corporate governance, relationships with customers and suppliers, directors’ liability and the ability to operate in regulated markets.

Reliance on ICT infrastructures, cloud services, software, platforms and digital supply chains exposes organisations to closely interconnected operational, contractual, regulatory and reputational risks. A single incident may simultaneously trigger notification duties, business continuity procedures, liabilities towards customers and business partners, communications to affected individuals, regulatory intervention and measures concerning the safety and security of products placed on the market.

Attorney Alessandro del Ninno advises companies, corporate groups, regulated operators, technology providers and public-sector bodies on the design and implementation of cybersecurity governance, ICT risk management and digital operational resilience programmes.

The advice coordinates Directive (EU) 2022/2555 — the NIS 2 Directive — and Italian Legislative Decree No. 138 of 4 September 2024 with Regulation (EU) 2022/2554 — DORA — and Italian Legislative Decree No. 23 of 10 March 2025, the Cyber Resilience Act, the General Product Safety Regulation, the Italian cybersecurity framework, the National Cybersecurity Perimeter and the rules governing the resilience of critical entities. Where relevant, account is also taken of European cybersecurity certification schemes, personal data protection law, artificial intelligence regulation, product liability rules and other applicable sector-specific legislation.

The objective is not to produce standard-form documentation, but to establish a framework in which responsibilities, procedures, controls and contracts reflect the organisation’s actual operations and can be demonstrated to competent authorities, customers and business counterparties.

Governance, Regulatory Scope and Compliance Programmes

Assistance may begin with an assessment of the legal and regulatory frameworks that actually apply to the organisation. The analysis considers the business sector, the size of the undertaking, the services effectively provided, the role performed within the supply chain, membership of a corporate group, the nature of the customer base and the products or technologies placed on the market.

This assessment identifies the obligations arising under NIS 2, DORA, the Cyber Resilience Act, the Italian cybersecurity framework, product safety legislation and sector-specific rules, while clarifying whether the relevant regimes apply on a lex specialis, complementary or concurrent basis.

The assessment results in a matrix of applicable legislation, a framework of roles and responsibilities, a gap analysis and a compliance roadmap prioritised according to risk, deadlines and business impact.

Attorney Alessandro del Ninno also advises on the preparation and review of policies and procedures concerning security governance, asset management, identity and access management, business continuity, backups, vulnerability management, secure development, system maintenance, change management and supply-chain security.

The work is carried out in coordination with the CISO, CIO, DPO, Legal, Compliance, Risk Management, Internal Audit, Procurement and business functions. Legal and regulatory assessment remains distinct from technical decision-making, while ensuring that technical measures are consistent with the applicable obligations and properly documented.

NIS 2, Italian Legislative Decree No. 138/2024 and ACN Practice

Attorney Alessandro del Ninno advises organisations on determining whether they fall within the NIS framework, their classification as essential or important entities and the entire compliance process established by Italian Legislative Decree No. 138/2024 and the measures adopted by the Italian National Cybersecurity Agency — Agenzia per la cybersicurezza nazionale, or ACN.

The assistance includes registration and updating of information through the ACN platform, the designation of the point of contact and other relevant representatives, the review of communications received from the Agency and the management of requests for clarification or reconsideration.

A specific area of advice concerns the listing and categorisation of the organisation’s activities and services. The service includes identifying NIS activities and services, mapping them against the categories established by ACN, carrying out the relevant impact analysis and preparing the evidence required to support the classifications adopted.

Assistance also covers the identification of relevant NIS suppliers and the mapping of dependencies within the digital supply chain, coordinating the legal assessment with business impact analysis, vendor management and third-party risk management processes.

Implementation of cybersecurity risk-management measures and incident notification duties is assessed in light of the baseline specifications, determinations, taxonomies and guidance issued by ACN. For digital service providers subject to Commission Implementing Regulation (EU) 2024/2690, assistance also covers the application of the relevant European technical and methodological requirements and sector-specific criteria for determining whether an incident is significant.

The service is not confined to reviewing formal documentation. It also assesses whether policies and procedures correspond to actual operational practices, identifies the evidence that must be retained and prepares the organisation for supervisory and enforcement activities.

Responsibilities of Corporate Bodies and Organisation of the Cybersecurity Function

The NIS framework and DORA assign direct responsibilities to management bodies for approving, overseeing and monitoring cybersecurity and ICT risk-management measures.

Attorney Alessandro del Ninno advises on the design of the governance model, the allocation of powers and responsibilities and the coordination between the board of directors, senior management, CISO, CIO, DPO, Risk Management, Compliance, Internal Audit and operational functions.

The service includes drafting board resolutions, delegations of authority, powers of attorney, committee charters, escalation procedures and reporting arrangements. The content and frequency of reporting are defined so that corporate bodies receive clear and appropriate information on risks, incidents, vulnerabilities, critical suppliers, testing outcomes and the status of compliance programmes.

Particular attention is paid to documenting decisions, assessing whether sufficient resources have been allocated and providing training to directors and senior management. The objective is to ensure that management involvement is substantive rather than merely formal and that decisions can be reconstructed and justified during inspections, enforcement proceedings or litigation.

Incident Response, Notifications and Crisis Management

Managing a cyber incident requires coordinated technical, legal and organisational decisions. The organisation must reconstruct what occurred, preserve evidence, classify the event, assess its impact and promptly determine which communications must be made to authorities, customers, affected individuals and contractual counterparties.

Attorney Alessandro del Ninno advises on the preparation and review of incident response plans, escalation matrices, classification criteria and internal reporting flows. The service includes defining the crisis team and organising legal analysis and communications in compliance with legal professional privilege and the rules governing the confidentiality of communications with legal counsel.

For NIS entities, assistance covers the qualification of significant incidents and the management of notifications to CSIRT Italia in accordance with the applicable deadlines, taxonomies and procedures.

Where an incident affects personal data, financial entities, products with digital elements, entities falling within the National Cybersecurity Perimeter or public bodies subject to Italian Law No. 90/2024, the different reporting obligations are coordinated to avoid inconsistent communications or fragmented assessments.

Assistance may also be provided while the incident is ongoing and may include coordination with forensic advisers, insurers, technology providers, corporate bodies and competent authorities. The final incident report, remediation plan and documentation supporting the decisions taken are also prepared, including any decision not to submit a particular notification.

The service also includes the design of exercises, simulations and tabletop exercises intended to assess the organisation’s ability to make timely decisions and activate the correct escalation levels.

Supply Chain, ICT Suppliers and Cybersecurity Contracts

Organisational resilience increasingly depends on cloud providers, software developers, outsourcers, managed service providers, managed security service providers, systems integrators and subcontractors.

Attorney Alessandro del Ninno advises on the design of supplier selection, classification and monitoring processes, the preparation of due diligence questionnaires and the assessment of the technical, organisational and contractual safeguards offered.

The analysis considers the criticality of the service, the systems and data accessible to the supplier, infrastructure locations, technological dependencies, the use of subcontractors, concentration risks and the consequences that disruption or compromise could have for the organisation.

Contracts are drafted or reviewed with particular regard to security measures, applicable standards, cooperation duties, access to information, audit rights, testing, vulnerability management, incident notification, business continuity, disaster recovery, portability and exit strategies.

Particular attention is paid to subcontracting chains, conditions governing the replacement of subcontractors, the location from which services are provided and situations in which the customer must obtain information or contractual rights from the supplier in order to comply with its own regulatory obligations.

The assistance also addresses liability, indemnities, service levels, insurance coverage and remedies applicable in the event of an incident, service unavailability, data loss or breach of security obligations.

DORA and Digital Operational Resilience in the Financial Sector

Attorney Alessandro del Ninno advises financial entities on the application of Regulation (EU) 2022/2554 — DORA — and Italian Legislative Decree No. 23 of 10 March 2025, coordinating those rules with sector-specific legislation and the regulatory and implementing technical standards adopted at European level.

For financial entities that also fall within the NIS scope, the relationship between the two regimes is assessed at the outset. DORA constitutes a sector-specific Union legal act in relation to the matters it regulates, while NIS requirements may remain relevant for areas or entities not covered by the special financial-sector framework.

Assistance covers the ICT risk-management framework, the responsibilities of the management body, the classification and reporting of ICT-related incidents, the digital operational resilience testing programme and, where applicable, threat-led penetration testing.

A central area of the practice concerns ICT third-party risk. The service includes identifying critical or important functions, conducting due diligence, assessing concentration risks, negotiating contracts, managing audit and access rights, developing exit strategies and reviewing subcontracting chains in accordance with European Level 2 measures, including Commission Delegated Regulation (EU) 2025/532.

Attorney Alessandro del Ninno also assists in preparing and maintaining the register of information concerning contractual arrangements for the use of ICT services, reviewing data quality, the correct classification of services and consistency with the underlying contractual documentation.

ICT providers are not all directly subject to the full DORA framework. For ordinary ICT providers, advice primarily concerns contractual obligations, requests made by financial entities and the provider’s position within the subcontracting chain. For ICT third-party service providers designated as critical, assistance may also cover the European oversight framework and dealings with the competent Lead Overseer and other relevant authorities.

Cyber Resilience Act and Security of Products with Digital Elements

Regulation (EU) 2024/2847 — the Cyber Resilience Act — introduces horizontal cybersecurity requirements for hardware and software products with digital elements made available on the Union market.

Attorney Alessandro del Ninno advises manufacturers, importers, distributors, authorised representatives, developers and open-source software stewards on determining whether the Regulation applies and on identifying their role in relation to the relevant product.

The service includes cybersecurity risk assessment, security by design, vulnerability management, security updates, determination of the support period and preparation of technical documentation and information for users.

Assistance also covers product classification, including in light of the technical descriptions established by Commission Implementing Regulation (EU) 2025/2392, selection of the appropriate conformity assessment procedure, the EU declaration of conformity, CE marking and dealings with notified bodies and market surveillance authorities.

A specific area of advice concerns vulnerability handling throughout the product lifecycle: software component inventories, procedures for receiving and processing vulnerability reports, coordinated vulnerability disclosure, remediation, security updates, dependency management and retention of supporting evidence.

The practice also addresses remote data processing solutions, the integration of open-source components, the legal position of open-source software stewards and the interaction between the Cyber Resilience Act and other applicable EU legislation.

Assistance includes preparation for the reporting duties concerning actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements, applicable from 11 September 2026, as well as the related Single Reporting Platform. Compliance programmes are also structured in preparation for the application of the main body of CRA obligations from 11 December 2027.

GPSR, General Product Safety and Liability for Digital Products

Regulation (EU) 2023/988 on general product safety applies to consumer products and operates as a complementary framework alongside sector-specific Union harmonisation legislation.

The first stage of the assistance is to determine which aspects and risks are already governed by the Cyber Resilience Act or other sector-specific legislation and which remain subject to the general requirements of the GPSR.

Where relevant, product safety assessments consider risks arising from digital functionalities, cybersecurity vulnerabilities, interconnections with other products and evolving, learning, predictive or artificial-intelligence-based features capable of affecting the physical safety of the product.

Attorney Alessandro del Ninno advises manufacturers, importers, distributors, e-commerce operators and providers of online marketplaces on the establishment of product risk assessment, traceability and post-market monitoring processes.

The service covers information to be provided in distance sales, the handling of complaints and accidents, notifications through the Safety Business Gateway, corrective actions, product withdrawals and recalls, and dealings with market surveillance authorities.

Cybersecurity is therefore coordinated with general product safety and product liability rules, preventing a software vulnerability capable of causing personal injury or property damage from being treated as a purely technical issue.

Italian Cybersecurity Framework, Critical Entities and European Certification

The practice covers the application of Italian Law No. 90 of 28 June 2024 and the guidance issued by ACN to strengthen the resilience of the organisations concerned.

The service includes identifying applicable obligations, designating the cybersecurity representative, reviewing organisational and technical measures and managing incident reports and notifications in accordance with the incident taxonomy adopted by ACN in 2026.

For organisations included within the National Cybersecurity Perimeter, assistance concerns the coordination of the Perimeter framework with NIS obligations, procurement procedures, incident reporting and the review of ICT goods, systems and services intended for essential state functions or services.

For entities subject to Italian Legislative Decree No. 134 of 4 September 2024, cybersecurity requirements are coordinated with the framework governing the resilience of critical entities, integrating operational continuity, physical security, essential dependencies and crisis management.

Attorney Alessandro del Ninno also advises companies on European cybersecurity certification schemes established under the Cybersecurity Act, including the EUCC scheme, assessing their relevance for regulatory compliance, contractual requirements, commercial positioning or market access.

For operators involved in European preparedness and response mechanisms, assistance may also cover the instruments established by the Cyber Solidarity Act, including exercises, incident response services and participation in European mechanisms addressing significant or large-scale cybersecurity incidents.

Audits, Due Diligence, Regulatory Proceedings, Litigation and Training

Attorney Alessandro del Ninno advises companies on the planning and conduct of legal and regulatory cybersecurity audits, including audits carried out in coordination with vulnerability assessments, penetration testing, red teaming and other technical reviews.

The legal work concerns defining the scope of the audit, obtaining the necessary authorisations, protecting information, managing the results, qualifying identified deficiencies and documenting corrective actions.

In acquisitions, investments, financing transactions, outsourcing arrangements and technology partnerships, due diligence may cover cybersecurity programmes, historical incidents, suppliers, digital products, contracts and the target’s current compliance position.

The analysis identifies regulatory liabilities, critical dependencies, remediation requirements and risks to be addressed in pricing, representations and warranties, conditions precedent and post-completion integration plans.

The practice also covers dealings and proceedings before ACN, CSIRT Italia, the competent financial supervisory authorities, the Italian Data Protection Authority and market surveillance authorities. Assistance includes responses to information requests, inspections, alleged infringements, corrective proceedings and administrative enforcement actions.

Litigation services include disputes with ICT suppliers, customers and commercial partners, liability arising from incidents or service outages, breach of contractual security obligations, damages claims, trade secret protection and disputes concerning product security.

Following a cyberattack, support may extend to evidence preservation, the preparation of criminal complaints, dealings with prosecuting and judicial authorities and coordination of criminal-law issues with administrative, contractual and corporate liabilities.

Attorney Alessandro del Ninno also designs training programmes for boards of directors, senior management, General Counsel, CISOs, CIOs, DPOs, Compliance, Risk Management, Procurement, HR, Internal Audit and operational functions. Training is based on the organisation’s actual processes and uses practical scenarios to address incident management, directors’ responsibilities, supply-chain security, ICT contracts, product security and dealings with competent authorities.

Advice may also be provided on an ongoing basis, assisting clients in assessing new services and suppliers, updating documentation, managing regulatory deadlines, carrying out exercises and monitoring developments in legislation and regulatory practice.

The overall objective is to provide companies with a single specialist legal point of reference capable of coordinating governance, technology, contracts, product security, incident management and relations with competent authorities, intervening before a technical vulnerability develops into an operational, regulatory or reputational crisis.