Skip to main content
BilgeQor
Back to industries

CTO, VP Engineering

Retail & Consumer Platforms

Italy Cyber Operational Context — H1 2025

Italy H1 2025 Cyber Operational Context — ACN / CSIRT Italia 1° Semestre Summary

Market context — not industry-specific evidence

The following data reflects cyber events and confirmed-impact incidents handled by Agenzia per la Cybersicurezza Nazionale (ACN) / CSIRT Italia and reported in the H1 2025 (1° semestre) operational summary published 4 August 2025. H1 figures are from this single semester publication and are presented as semester-level context only.

Italy — ACN / CSIRT Italia H1 2025 operational summary (1° semestre)H1 2025 (published 4 August 2025)

Cyber events recorded — H1 2025

H1 2025 — cyber events recorded
1,549
Unit
cyber events recorded by ACN / CSIRT Italia in H1 2025
Period
H1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summary

ACN / CSIRT Italia recorded 1,549 cyber events in H1 2025, as reported in the H1 semester operational summary.

Italy ACN / CSIRT Italia operational context from the H1 2025 semester summary only. Must not be summed with H2 figures to form an annual total. Not total Italian business incident prevalence and not industry-specific evidence.

Confirmed-impact incidents — H1 2025

H1 2025 — confirmed-impact incidents
346
Unit
confirmed-impact incidents in H1 2025
Period
H1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summary

ACN / CSIRT Italia handled 346 confirmed-impact incidents in H1 2025, as reported in the H1 semester operational summary.

Italy ACN / CSIRT Italia operational context from the H1 2025 semester summary only. Must not be summed with H2 figures to form an annual total. Not total Italian business incident prevalence and not industry-specific evidence.

Ransomware attacks — H1 2025

H1 2025 — ransomware attacks (91)
91
Unit
ransomware attacks in H1 2025
Period
H1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summary

ACN / CSIRT Italia reported 91 ransomware attacks in H1 2025. Source terminology uses "attacks" in the H1 operational summary.

H1 source uses the term "ransomware attacks". Must not be combined with H2 ransomware cases into an annual ransomware total. Subcategory within H1 confirmed-impact incident context. Not total Italian ransomware prevalence and not industry-specific evidence.

H1 cyber events — year-on-year increase vs H1 2024

H1 cyber events — year-on-year increase vs H1 2024
53%
Unit
percent increase in cyber events versus H1 2024
Period
H1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summary

Cyber events increased 53% in H1 2025 versus H1 2024.

Year-on-year change in recorded event counts between H1 2025 and H1 2024 only. Does not measure a per-business incident rate, is not comparable with H2 figures, and does not represent total Italian business incident trends.

Source: ACN / CSIRT Italia — Operational Summary 1° semestre 2025

Source: ACN / CSIRT Italia — Operational Summary 1° semestre 2025 (published 4 August 2025). Covers cyber events recorded and confirmed-impact incidents handled by CSIRT Italia in H1 2025. H1 and H2 are separate semester operational summaries from ACN / CSIRT Italia. Values must not be summed into an approved annual total. Values are ACN / CSIRT Italia operational context only. Values are not total Italian business incident prevalence, not hidden incident prevalence, not all-Italy attack prevalence, not industry-specific evidence, and not proof of compliance, certification, or security.

Methodology: Data covers cyber events recorded and confirmed-impact incidents handled by ACN / CSIRT Italia in H1 2025 (first semester). The 53% increase is a year-on-year change versus H1 2024 in recorded cyber event counts; it does not measure a per-business incident rate. The 91 ransomware attacks are a subcategory within the H1 confirmed-impact incident context; H1 source uses the wording "ransomware attacks". H1 and H2 values come from separate semester operational summaries; do not present H1 + H2 as an approved annual total. These figures are Italy ACN / CSIRT Italia H1 2025 operational reporting context only; they are not total Italian business incident prevalence, hidden incident prevalence, all-Italy attack prevalence, population-wide victimisation rate, industry-specific evidence, compliance achievement, certification, or proof of security.

Accessible data table
Verified Italy Agenzia per la Cybersicurezza Nazionale (ACN) / CSIRT Italia H1 2025 operational context from the 1° semestre operational summary data from ACN / CSIRT Italia — Operational Summary 1° semestre 2025, reporting period H1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting.
MetricValueSourceScopeReporting period
H1 2025 — cyber events recorded1,549 cyber events recorded by ACN / CSIRT Italia in H1 2025ACN / CSIRT Italia — Operational Summary 1° semestre 2025Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summaryH1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
H1 2025 — confirmed-impact incidents346 confirmed-impact incidents in H1 2025ACN / CSIRT Italia — Operational Summary 1° semestre 2025Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summaryH1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
H1 2025 — ransomware attacks (91)91 ransomware attacks in H1 2025ACN / CSIRT Italia — Operational Summary 1° semestre 2025Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summaryH1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting
H1 cyber events — year-on-year increase vs H1 202453% percent increase in cyber events versus H1 2024ACN / CSIRT Italia — Operational Summary 1° semestre 2025Italy ACN / CSIRT Italia H1 2025 operational context — 1° semestre summaryH1 2025 (January–June 2025) cyber event, confirmed-impact incident, ransomware attack, and year-on-year change context from ACN / CSIRT Italia operational reporting

Italy Cyber Operational Context — H2 2025

Italy H2 2025 Cyber Operational Context — ACN / CSIRT Italia 2° Semestre Summary

Market context — not industry-specific evidence

The following data reflects cyber events and confirmed-impact incidents handled by Agenzia per la Cybersicurezza Nazionale (ACN) / CSIRT Italia and reported in the H2 2025 (2° semestre) operational summary published 27 January 2026. H2 figures are from this single semester publication and are presented as semester-level context only.

Italy — ACN / CSIRT Italia H2 2025 operational summary (2° semestre)H2 2025 (published 27 January 2026)

Cyber events recorded — H2 2025

H2 2025 — cyber events recorded
1,253
Unit
cyber events recorded by ACN / CSIRT Italia in H2 2025
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

ACN / CSIRT Italia recorded 1,253 cyber events in H2 2025, as reported in the H2 semester operational summary.

Italy ACN / CSIRT Italia operational context from the H2 2025 semester summary only. Must not be summed with H1 figures to form an annual total. Not total Italian business incident prevalence and not industry-specific evidence.

Confirmed-impact incidents — H2 2025

H2 2025 — confirmed-impact incidents
304
Unit
confirmed-impact incidents in H2 2025
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

ACN / CSIRT Italia handled 304 confirmed-impact incidents in H2 2025, as reported in the H2 semester operational summary.

Italy ACN / CSIRT Italia operational context from the H2 2025 semester summary only. Must not be summed with H1 figures to form an annual total. Not total Italian business incident prevalence and not industry-specific evidence.

Ransomware cases — H2 2025

H2 2025 — ransomware cases (54)
54
Unit
ransomware cases in H2 2025
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

ACN / CSIRT Italia reported 54 ransomware cases in H2 2025. Source terminology uses "cases" in the H2 operational summary.

H2 source uses the term "ransomware cases". Must not be combined with H1 ransomware attacks into an annual ransomware total. Subcategory within H2 confirmed-impact incident context. Not total Italian ransomware prevalence and not industry-specific evidence.

H2 cyber events — year-on-year increase vs H2 2024

H2 cyber events — year-on-year increase vs H2 2024
30%
Unit
percent increase in cyber events versus H2 2024
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

Cyber events increased 30% in H2 2025 versus H2 2024.

Year-on-year change in recorded event counts between H2 2025 and H2 2024 only. Does not measure a per-business incident rate, is not comparable with H1 figures, and does not represent total Italian business incident trends.

H2 confirmed-impact incidents — year-on-year decrease vs H2 2024

H2 confirmed-impact incidents — year-on-year decrease vs H2 2024
25%
Unit
percent decrease in confirmed-impact incidents versus H2 2024
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

Confirmed-impact incidents decreased 25% in H2 2025 versus H2 2024.

Year-on-year change in confirmed-impact incident counts between H2 2025 and H2 2024 only. Does not measure a per-business incident rate, is not comparable with H1 figures, and does not represent total Italian business incident trends.

CSIRT Italia proactive communications — H2 2025

CSIRT Italia communications to subjects with systems at risk (over 5,000)
5,000
Unit
communications from CSIRT Italia to subjects with systems at risk in H2 2025 (over)
Period
H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
Scope
Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summary

CSIRT Italia sent over 5,000 communications to subjects with systems at risk in H2 2025.

Source uses approximate language ("over 5,000"). Refers to CSIRT Italia proactive communications to subjects with systems identified as at risk in H2 2025. Not a count of resolved incidents, not a count of protected organisations, and not proof of protection from cyber incidents.

Source: ACN / CSIRT Italia — Operational Summary 2° semestre 2025

Source: ACN / CSIRT Italia — Operational Summary 2° semestre 2025 (published 27 January 2026). Covers cyber events recorded and confirmed-impact incidents handled by CSIRT Italia in H2 2025. H1 and H2 are separate semester operational summaries from ACN / CSIRT Italia. Values must not be summed into an approved annual total. Values are ACN / CSIRT Italia operational context only. Values are not total Italian business incident prevalence, not hidden incident prevalence, not all-Italy attack prevalence, not industry-specific evidence, and not proof of compliance, certification, or security.

Methodology: Data covers cyber events recorded and confirmed-impact incidents handled by ACN / CSIRT Italia in H2 2025 (second semester). The 30% increase is a year-on-year change versus H2 2024 in recorded cyber event counts; the 25% decrease is a year-on-year change versus H2 2024 in confirmed-impact incidents; neither measures a per-business incident rate. The 54 ransomware cases (H2 source wording: "cases") are a subcategory within the H2 confirmed-impact incident context; H1 source uses the wording "ransomware attacks" — do not merge into a single annual ransomware total. The "over 5,000 communications" refers to CSIRT Italia proactive communications to subjects with systems at risk in H2 2025; this is not a count of resolved incidents, not a count of protected organisations, and must not be presented as proof of protection. H1 and H2 values come from separate semester operational summaries; do not present H1 + H2 as an approved annual total. These figures are Italy ACN / CSIRT Italia H2 2025 operational reporting context only; they are not total Italian business incident prevalence, hidden incident prevalence, all-Italy attack prevalence, population-wide victimisation rate, industry-specific evidence, compliance achievement, certification, or proof of security.

Accessible data table
Verified Italy Agenzia per la Cybersicurezza Nazionale (ACN) / CSIRT Italia H2 2025 operational context from the 2° semestre operational summary data from ACN / CSIRT Italia — Operational Summary 2° semestre 2025, reporting period H2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting.
MetricValueSourceScopeReporting period
H2 2025 — cyber events recorded1,253 cyber events recorded by ACN / CSIRT Italia in H2 2025ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
H2 2025 — confirmed-impact incidents304 confirmed-impact incidents in H2 2025ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
H2 2025 — ransomware cases (54)54 ransomware cases in H2 2025ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
H2 cyber events — year-on-year increase vs H2 202430% percent increase in cyber events versus H2 2024ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
H2 confirmed-impact incidents — year-on-year decrease vs H2 202425% percent decrease in confirmed-impact incidents versus H2 2024ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting
CSIRT Italia communications to subjects with systems at risk (over 5,000)5,000 communications from CSIRT Italia to subjects with systems at risk in H2 2025 (over)ACN / CSIRT Italia — Operational Summary 2° semestre 2025Italy ACN / CSIRT Italia H2 2025 operational context — 2° semestre summaryH2 2025 (July–December 2025) cyber event, confirmed-impact incident, ransomware case, year-on-year change, and proactive communication context from ACN / CSIRT Italia operational reporting

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Account Takeover
  • Data Breaches
  • Payment Fraud

Digital surfaces in scope

Loyalty AppsE-commerce SitesCustomer Portals

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.