Proteggiamo il tuo ambiente digitale da qualsiasi attacco informatico. Sfrutta tutte le potenzialità della piattaforma SGBox!

Gallery

Contatti

Via Melchiorre Gioia, 168 - 20125 Milano

info@sgbox.it

+39 02 60830172

Cyber News Knowledge Base

The main Cyber Security risks in Public Administration

Cyber Security in Public Administration

Cyberattacks on Public Administration

The Public Administration sector is one of the industries most affected by cyberattacks.

According to the latest Clusit 2026 Report (covering 2025), Italian Public Administration (the Gov/Mil/LE category in Clusit’s taxonomy) returned in 2025 to being the number-one target of domestic cybercrime, after two years in which other sectors had contested the lead.

Public Administration accounted for 28.4% of all incidents recorded in Italy in 2025, gaining 12 percentage points compared to 2024. In absolute terms, attacks on the sector rose from 37 (2024) to 107 (2025): a +290% increase, by far the sharpest growth among all the sectors monitored.

The leading attack technique is DDoS (Distributed Denial of Service), with a national total of 5,930 attacks recorded in 2025, up 26% from 2024 (4,720).

An alarming figure, one that underscores the growing need to adopt the right measures and strategies to defend against the numerous attacks threatening process integrity and driving the theft of personal data and sensitive information.

Types of cyberattacks targeting Public Administration

Attack typeTypical consequences
DDoSUnavailability of websites and portals, difficulty accessing services, reputational damage
RansomwareData encryption, halted processes, possible exfiltration and extortion
Phishing o compromissione di accountUnauthorized system access, fraud, internal spread of the attack
Data breachDisclosure of personal data, risk of identity theft and penalties
Supply-chain attackSimultaneous compromise of multiple entities through a shared vendor or platform
Wiper o sabotaggioData destruction and recovery difficulties, with potential systemic effects
Defacement e disinformazioneAlteration of institutional communications and loss of credibility

What are the consequences of a cyberattack on Public Administration?

A cyberattack on a Public Administration body can cause disruption of essential services, loss or exposure of data, financial costs, legal liability, and loss of public trust.

The severity depends on the type of attack, the systems involved, and the entity’s ability to detect, contain, and recover from the incident.

Below are the main consequences:

Disruption of essential public services for citizens

Even a relatively short DDoS attack can block access to digital services. In the case of a ransomware attack, by contrast, downtime can stretch on considerably, with more severe effects stemming from data breaches.

Loss, Alteration, or disclosure of data

Public Administration bodies manage large volumes of sensitive data, including personal and tax records, health information, administrative and judicial documents, and digital credentials and identifiers.

A compromise can result in breaches of confidentiality, identity theft, fraud, extortion, and misuse of information. An attacker could also alter data or records, undermining the integrity of rankings, payments, authorizations, medical records, or administrative acts.

Operational slowdown or paralysis

An attack can significantly slow down operations due to the unavailability of internal applications or loss of access to files and databases.

The impact can spread to municipalities, regions, ministries, healthcare organizations, in-house companies, and ICT vendors, especially where shared dependencies or centralized infrastructure exist.

Direct and indirect financial costs

For a Public Administration body, financial damage isn’t limited to lost revenue: it can also take the form of delayed service delivery, extraordinary expenditure, and inefficient use of public resources.

Penalties and liability

In the event of a personal data breach, the entity may need to fulfill obligations under the GDPR, including:

  • Assessing the incident and the risk to data subjects;
  • Notifying the Data Protection Authority within the applicable deadlines;
  • Informing data subjects when the risk is high;
  • Documenting the event and the measures taken.

Administrative, disciplinary, contractual, or criminal liability may also arise, depending on the nature of the incident and any organizational shortcomings. For entities falling within the scope of NIS2 Directive or related national regulations, a significant incident may also trigger notification, management, and cooperation obligations with the competent authorities.

The SGBox Platform: italian technology for data protection in Compliance with GDPR and NIS2

The proprietary SGBox platform guarantees full protection of sensitive and personal data belonging to individuals and public institutions, in compliance with the GDPR and the NIS2 Directive.

SGBox integrates Log Management, SIEM, and SOAR capabilities within a modular, scalable architecture, available on the ACN-certified European Cloud.

The Log Management functionality enables secure data collection and retention, thanks to timestamping and encryption processes.

With SIEM, security events can be correlated and network security status monitored in real time, with the goal of proactively identifying threats.

The SOAR component introduces workflow automation capabilities for efficient incident management.

Discover the advantages of SGBox for Public Administration >>

Leave a comment

Your email address will not be published. Required fields are marked *