Cybersecurity is becoming increasingly central to the strategic agendas of countries as they seek to counter growing threats, exacerbated by digital transformation. The digitalization of Public Administration is essential for economic recovery and competitiveness, but it requires greater cybersecurity awareness. The Cybersecurity Area operates within this scenario with an integrated approach that combines research, technology scrutiny, technical and scientific support, development and training.
Among the main topics addressed by the Area is the security of next-generation networks and IoT devices, with results that have mainly strategic, methodological and operational implications. Particular attention is given to the protection of critical infrastructure, such as industrial control systems, to prevent attacks that could compromise essential services.
Another key strategic field is the interaction between AI and cybersecurity, both to protect AI-based systems and as a use in identifying anomaly detection and in automated incident response, including within complex cloud environments.
To address the threats posed by quantum computers, the Area explores the use of quantum-safe cryptography and crypto-agility, which are crucial for adapting to new cryptographic standards and ensuring a secure migration of public administration systems to the cloud. Additionally, the potential of quantum technologies for secure cryptographic keys distribution is analyzed.
Thanks to its expertise in evaluation and certification processes, the Area provides support within the National Cybersecurity Perimeter and ensures compliance with European regulations, including the NIS2 Directive and the Cyber Resilience Act. It also collaborates with laboratories and institutions to test hardware and software, contributing to the design and updating of platforms and laboratories at the National Evaluation and Certification Center (CVCN).
The Cybersecurity Area consists of four main functions:
- 5G and IoT Cybersecurity – focuses on 5G security assurance and risk assessment, including the IoT world, with an approach that integrates the analysis of national and European regulatory developments and the development of methodologies and platforms for security testing and risk assessment.
- Cloud and AI Cybersecurity – studies the interactions between artificial intelligence and cloud, analyzing solutions to protect data and mitigate risks associated with AI usage.
- Cryptography and Data Security – addresses scientific and technological aspects, security implications, economic and regulatory impacts related to the adoption of quantum technologies, with a focus on quantum-safe cryptography, crypto-agility and quantum key distribution.
- Technology Scrutiny – provides technical and scientific support to CVCN for verifying the security of ICT products, systems and services intended for use in national security-critical environments and supports OCSI assessments.