The International Monetary Fund (IMF) has urged Italy to update its national cybersecurity strategy for the financial sector, recommending that insurance and pension fund supervisors be formally incorporated.
In its report, Italy: Financial Sector Assessment Program, the IMF acknowledged that Italy’s cyber resilience framework is relatively mature but continues to evolve in response to regulatory developments and heightened risks.
The report also highlighted that authorities currently collaborate effectively on incident response and intelligence sharing, supported by on-site and off-site inspections, thematic reviews, and advanced testing aligned with international standards.
It also noted Italy’s supervisory capacity has been strengthened through dedicated units, recruitment of information technology (IT) experts, and advanced training, alongside active participation in domestic and international cyber crisis simulations.
Despite these areas of success in Italy's cybersecurity sector, the IMF identified three key priorities for improvement that it said should be implemented within one to two years.
The first priority is to update the sector-wide cyber strategy to reflect the EU’s Digital Operational Resilience Act (DORA) and formally integrate insurance and pension fund supervisors.
Additionally, the IMF advised strengthening governance and independence of cyber risk oversight across financial entities, including by appointing senior cybersecurity officers, such as chief information security officers.
The final priority is to expand simulations and cyber stress tests to encompass payment disruptions, supply chain attacks, and cross-sector scenarios involving energy and telecommunications infrastructures, while ensuring effective board-level involvement in sector-wide exercises.
The recommendations apply to Banca d'Italia, the National Commission for Companies and the Stock Exchange (CONSOB), the Pension Fund Supervisory Commission (COVIP), and the Institute for the Supervision of Insurance (IVASS).
“A rapidly evolving landscape of artificial intelligence-enabled cyber threats, digitalisation, and third‑party reliance calls for further strengthening of cyber resilience,” the IMF stated.
“Implementation of the EU DORA provides an opportunity to strengthen cyber governance, supervisory capacity, and board‑level accountability, while expanding system‑wide cyber stress testing, particularly for critical third-party disruptions, and applying enforcement where deficiencies are identified.”