Rome. Over the course of 2024, the cyber threats affecting Italy have become more numerous, more sophisticated, and, above all, more targeted. This is the picture emerging from the first Cyber Security Report published by TIM and the Cyber Security Foundation, Italy's leading nonprofit foundation focused on cyber security.
An investigation that photographs the evolution of digital attacks in Italy, analyzing in particular two phenomena in strong growth: DDoS attacks and ransomware attacks.
DDoS attacks, which aim to block access to websites and online services by overloading them with simultaneous requests, increased 36% compared to the previous year. The average was 18 events per day, but it's not just the number that's impressive: nearly 4 in 10 attacks exceeded 20 Gbps in intensity, a level that makes both detection and defense more difficult.
There has also been an evolution in the methods of execution, with multiple attacks simultaneously hitting multiple points of the same organization (sites, networks, devices), making many of the traditional countermeasures inadequate.
It is significant to note how these attacks have increasingly affected the Public Administration, whose exposure has gone from 1% to 42% of the total in just one year, a sign of a change in strategy by malicious actors and an increasingly unstable geopolitical context.
Ransomware, the technique that consists of blocking or encrypting sensitive data and then asking for a ransom, also continues to represent a concrete threat. With 146 cases officially detected in 2024, Italy is the second most affected country in the European Union. The sectors that were targeted were especially the most vital for the economy: 58% of the attacks involved the world of services, while another 26% involved manufacturing.
One of the causes of the expansion of the phenomenon is the spread of the so-called Ransomware-as-a-Service: criminal groups that develop malicious software and make it available to other subjects, widening the audience of attackers also to those with less technical skills.
The report also devotes ample space to the new technologies that are changing the face of cybersecurity. Artificial intelligence, for example, is already a double-edged sword: on the one hand, it allows for a faster and more proactive defense thanks to the ability to detect anomalies and automate incident responses; on the other, it is used by attackers themselves to make phishing campaigns more credible, create manipulated content (such as deepfakes) or design more targeted and difficult-to-intercept attacks.
In parallel, the European regulatory context is also adapting: in 2024, new directives and regulations came into force, including NIS2, the Cyber Resilience Act and the Digital Operational Resilience Act (DORA), which impose higher standards for the security of digital infrastructures and also make small and medium-sized enterprises, which are often less equipped, more responsible.
The report was presented this morning at the Chamber of Deputies in the presence of institutions and numerous operators and experts in cyber and digital security.
"Our country - explained the director of the Operations Service of the National Cybersecurity Agency, Gianluca Galasso - is among the most affected in Europe. The attacks are becoming increasingly aggressive and ransomware is threatening the production sector in particular. In this scenario, cooperation with structured operators is essential. Initiatives such as the HyperSOC platform, developed according to defined requirements with the support of various private entities, aim precisely to share high-value technical data and risk indicators quickly and effectively".
For the director of the Postal and Communications Police, Ivano Gabrielli, "a systemic approach is needed. Cyber threats no longer concern only specialists. Citizens, companies, institutions contribute, each for their own responsibility, to the security of a domain in which fundamental rights are exercised. Along with technology, we need culture, training and shared responsibility".
"This report - underlined the founder and president of the Cyber Security Foundation, Marco Gabriele Proietti - is much more than a technical photograph: it is an invitation to change pace. The numbers tell a complex story that once again demonstrates how necessary it is to promote a culture of digital security that overcomes the emergency and becomes part of our daily lives.
The Cyber Security Foundation was born for this: to educate, raise awareness and create synergies and concrete connections between public and private, pooling experiences, skills and responsibilities. Data are not just tools of .
“As an infrastructure operator, Tim intercepts early signs of cyber attacks every day. This - said Eugenio Santagata, Chief Public Affairs, Security and International Business Officer of Tim - allows us to contribute with valuable data and analysis. The report was born from a need.
Speaking with them were, among others, the Honorable Alessandro Colucci, Secretary of the Presidency of the Chamber of Deputies and President of the Parliamentary Intergroup for Information and Technological Security, Matteo Macina, Operational Vice President of the Cyber Security Foundation, and Angelo Tofalo, Director of the Technical Scientific Committee of the Foundation.
"This report - Alessandro Colucci recalled - represents an important and valuable tool for the activity of the parliamentary intergroup that I chair: data, analysis and ideas that represent the basis on which to build an effective regulatory initiative. But it is also and above all a contribution and support to training and awareness on cyber security and cyber threats, which affect all segments of the population across the board.
It is only through an aware citizenship that we can successfully face the challenges posed by technology. Our task, as representatives of the institutions, is to ensure that families, businesses and citizens have adequate tools to defend themselves from the daily and increasingly insidious dangers of the digital domain”.
“As the document shows,” he concluded, “we are facing an escalation of cyber danger, in every form. This requires timely and systemic responses. Digital security is now a national priority.”
The analysis, built on data collected by Tim's Security Operation Center and integrated with the contribution of the Cyber Security Foundation, is available for download and is intended as a tool for knowledge and awareness, inviting people to consider cybersecurity not only as a technical issue, but as a strategic theme that closely concerns the economy, institutions and citizens.




The article makes you think about how cyber threats have increased in Italy. It is important that institutions and citizens are more aware of these issues to be able to react better in the future. We need a culture of security.