The main Cyber Security risks in Public Administration

Table of Contents
ToggleCyberattacks on Public Administration
The Public Administration sector is one of the industries most affected by cyberattacks.
According to the latest Clusit 2026 Report (covering 2025), Italian Public Administration (the Gov/Mil/LE category in Clusit’s taxonomy) returned in 2025 to being the number-one target of domestic cybercrime, after two years in which other sectors had contested the lead.
Public Administration accounted for 28.4% of all incidents recorded in Italy in 2025, gaining 12 percentage points compared to 2024. In absolute terms, attacks on the sector rose from 37 (2024) to 107 (2025): a +290% increase, by far the sharpest growth among all the sectors monitored.
The leading attack technique is DDoS (Distributed Denial of Service), with a national total of 5,930 attacks recorded in 2025, up 26% from 2024 (4,720).
An alarming figure, one that underscores the growing need to adopt the right measures and strategies to defend against the numerous attacks threatening process integrity and driving the theft of personal data and sensitive information.
Types of cyberattacks targeting Public Administration
| Attack type | Typical consequences |
|---|---|
| DDoS | Unavailability of websites and portals, difficulty accessing services, reputational damage |
| Ransomware | Data encryption, halted processes, possible exfiltration and extortion |
| Phishing o compromissione di account | Unauthorized system access, fraud, internal spread of the attack |
| Data breach | Disclosure of personal data, risk of identity theft and penalties |
| Supply-chain attack | Simultaneous compromise of multiple entities through a shared vendor or platform |
| Wiper o sabotaggio | Data destruction and recovery difficulties, with potential systemic effects |
| Defacement e disinformazione | Alteration of institutional communications and loss of credibility |
What are the consequences of a cyberattack on Public Administration?
A cyberattack on a Public Administration body can cause disruption of essential services, loss or exposure of data, financial costs, legal liability, and loss of public trust.
The severity depends on the type of attack, the systems involved, and the entity’s ability to detect, contain, and recover from the incident.
Below are the main consequences:
Disruption of essential public services for citizens
Even a relatively short DDoS attack can block access to digital services. In the case of a ransomware attack, by contrast, downtime can stretch on considerably, with more severe effects stemming from data breaches.
Loss, Alteration, or disclosure of data
Public Administration bodies manage large volumes of sensitive data, including personal and tax records, health information, administrative and judicial documents, and digital credentials and identifiers.
A compromise can result in breaches of confidentiality, identity theft, fraud, extortion, and misuse of information. An attacker could also alter data or records, undermining the integrity of rankings, payments, authorizations, medical records, or administrative acts.
Operational slowdown or paralysis
An attack can significantly slow down operations due to the unavailability of internal applications or loss of access to files and databases.
The impact can spread to municipalities, regions, ministries, healthcare organizations, in-house companies, and ICT vendors, especially where shared dependencies or centralized infrastructure exist.
Direct and indirect financial costs
For a Public Administration body, financial damage isn’t limited to lost revenue: it can also take the form of delayed service delivery, extraordinary expenditure, and inefficient use of public resources.
Penalties and liability
In the event of a personal data breach, the entity may need to fulfill obligations under the GDPR, including:
- Assessing the incident and the risk to data subjects;
- Notifying the Data Protection Authority within the applicable deadlines;
- Informing data subjects when the risk is high;
- Documenting the event and the measures taken.
Administrative, disciplinary, contractual, or criminal liability may also arise, depending on the nature of the incident and any organizational shortcomings. For entities falling within the scope of NIS2 Directive or related national regulations, a significant incident may also trigger notification, management, and cooperation obligations with the competent authorities.
The SGBox Platform: italian technology for data protection in Compliance with GDPR and NIS2
The proprietary SGBox platform guarantees full protection of sensitive and personal data belonging to individuals and public institutions, in compliance with the GDPR and the NIS2 Directive.
SGBox integrates Log Management, SIEM, and SOAR capabilities within a modular, scalable architecture, available on the ACN-certified European Cloud.
The Log Management functionality enables secure data collection and retention, thanks to timestamping and encryption processes.
With SIEM, security events can be correlated and network security status monitored in real time, with the goal of proactively identifying threats.
The SOAR component introduces workflow automation capabilities for efficient incident management.