A cyber attack during holidays is not a harder technical problem than one in March, it is a harder decision-making problem. The systems fail in the same way, the forensics follow the same method, and the regulatory clocks run at the same speed. What changes is that the people named in the incident response plan are unreachable, the supplier that caused the incident is running on a skeleton crew, and whoever happens to be at the desk usually believes they have no authority to act.
Data Protection & Cybersecurity
Here you can read some articles on Italian and international privacy, cybersecurity and data protection issues drafted by either Giulio Coraggio or the other authors of GamingTechLaw.
AI sentiment analysis in the workplace raises critical questions under both the GDPR and the AI Act, as confirmed by a recent warning issued by the Italian Data Protection Authority against Myndoor S.r.l., a company offering a stress-detection plug-in for Slack and Teams corporate chats.
The new framework on NIS2 categorization in Italy introduces significant compliance obligations for entities falling within the scope of the Italian NIS2 regime. The purpose of the categorization exercise is to enable ACN to determine which additional cybersecurity measures will apply depending on the services provided by the relevant entity.
