Attorney Alessandro del Ninno delivered a specialist workshop for Paradigma on the implementation of the NIS 2 framework and its impact on corporate governance, organisational structures and cyber risk management processes. The session offered a legally rigorous yet highly practical analysis of the new regulatory landscape, emphasising that cybersecurity can no longer be treated as a matter reserved for technical functions alone, but must be embedded within the company’s governance, compliance, risk management and internal control systems.
The workshop examined the scope of the NIS 2 regime, the distinction between essential and important entities and, above all, the responsibilities imposed on management bodies under Italian Legislative Decree No. 138/2024. A central part of the programme focused on the decisions that must be brought before the board of directors, including formal acknowledgement of the organisation’s inclusion within the NIS perimeter, approval of the governance model, appointment and oversight of key roles, adoption of the compliance roadmap, supervision of cyber risk management measures, training of board members and employees, establishment of reporting lines and periodic monitoring of implementation.
Considerable attention was devoted to the design of an effective NIS operating model and to the proper allocation of responsibilities among management and executive bodies, the point of contact, its deputy, the CSIRT liaison, the secretariat and designated operators. Attorney Alessandro del Ninno explained how Legal, Compliance, IT, Cybersecurity, Risk, Procurement, HR and Internal Audit should be coordinated in order to establish a clear, traceable and board-oriented responsibility matrix.
The session also addressed the principal obligations towards the Italian National Cybersecurity Agency, with particular focus on the continuous updating of corporate information, the listing and categorisation of activities and services, the attribution of relevance categories and the preservation of evidence supporting the assessments carried out. The workshop illustrated how these obligations form the documentary and organisational foundation for future compliance with cybersecurity measures and for a defensible relationship with the supervisory authority.
Particular emphasis was placed on supply chain governance and the management of NIS-relevant suppliers. The programme examined the criteria for identifying relevant suppliers, the information to be reported to the Agency, the use of CPV codes, the distinction between fungible and non-fungible ICT supplies and the most common practical scenarios, including resellers and intermediaries, subcontractors, intra-group suppliers, foreign providers and cases in which the formal contracting party differs from the actual service provider. The analysis highlighted the practical implications for procurement, contractual governance, Business Impact Analysis, operational continuity, supply chain security and third-party risk management.
The final part of the workshop focused on preparation for the cybersecurity and incident notification obligations arising under the NIS 2 regime. This included assessing the organisation’s current level of readiness, updating internal policies and procedures, defining escalation and incident communication workflows, ensuring timely involvement of the board and preparing the documentary evidence required in the event of regulatory inspections. The session provided participants with a practical roadmap for translating NIS 2 requirements into a structured, auditable and fully integrated cyber governance framework.