Attorney Alessandro del Ninno designed and delivered a specialist executive workshop on the implementation of the NIS 2 Directive and its Italian implementing legislation, addressed to General Counsel, Legal Directors, Compliance Officers, Company Secretaries, Risk Managers, Governance professionals and Cybersecurity executives. The programme examined cybersecurity not merely as a technical discipline but as a core element of corporate governance and enterprise risk management, highlighting the central role of boards of directors in overseeing, documenting and continuously supervising cyber resilience strategies.
Adopting a highly practical and business-oriented approach, the workshop demonstrated how the obligations arising under the NIS 2 framework, Italian Legislative Decree No. 138/2024 and the implementing measures issued by the Italian National Cybersecurity Agency (ACN) can be translated into an effective governance model capable of withstanding regulatory scrutiny. Participants were provided with practical methodologies for building structured, documented and auditable compliance programmes, with particular emphasis on board resolutions, governance structures, allocation of responsibilities, designation of key NIS roles and the establishment of effective reporting lines between operational functions and senior management.
The programme explored the principal areas of organisational compliance required by the new regulatory framework, including the identification of the NIS scope, classification of critical activities and services, appointment of the NIS point of contact and CSIRT representatives, and the ongoing reporting obligations towards the Italian National Cybersecurity Agency. Particular attention was devoted to supply chain governance and third-party risk management, examining the identification of critical suppliers, contractual implications, Business Impact Analysis (BIA), procurement governance and the management of cybersecurity risks arising throughout the supply chain.
The final part of the workshop focused on the implementation roadmap for compliance with the cybersecurity measures introduced by NIS 2, covering incident management procedures, cyber incident reporting, internal governance policies, audit programmes, documentation requirements and the preservation of evidence required by supervisory authorities. Through practical case studies and real-world implementation scenarios, the workshop provided participants with a comprehensive framework for embedding cybersecurity within corporate governance systems, enabling organisations to transform regulatory obligations into an effective enterprise cyber risk management model that strengthens operational resilience while enhancing board accountability and strategic oversight.