The institutionalization of the CSIRT Contact Point, as provided for by ACN Determination no. 333017/2025, consolidates a robust cyber governance structure. The CSIRT Contact Point serves as the technical and operational link between the NIS entity (essential or important) and CSIRT Italia. Integrating this figure into the response team is fundamental to building effective resilience against cyber incidents.
Incident response team: roles and operations
The CSIRT Contact Point acts as a central node in the Incident Response Team (IRT), ensuring continuous multidisciplinary coordination between various company departments:
- IT Department and System Administrators: They manage networks, systems, and applications. They support the isolation of compromised systems, apply emergency patches, and handle service restoration. They collaborate with the CSIRT Contact Point to collect logs and Indicators of Compromise (IoCs) necessary for notification.
- Security Operations Center (SOC): If present, it monitors events and reports potential incidents. The CSIRT Contact Point technically validates these reports to determine whether the event is a significant incident according to Art. 25 of the NIS2 Decree.
- Legal Function and DPO: They assess notification obligations, minimum content requirements for CSIRT Italia and other authorities, including the management of cybersecurity clauses in ICT contracts. Legal support is also necessary for notifications to the Data Protection Authority in the event of a personal data breach.
- Corporate Communication: Manages communication toward customers, users, and the media during significant incidents, preventing panic and misinformation, while aligning regularly with the CSIRT Contact Point.
- Management and Administrative Bodies: They approve incident management plans and security policies. The CSIRT Contact Point reports to decision-making bodies regarding impacts and critical issues to facilitate timely choices on operational continuity.
Operational delegation and legal liability
The designation of the CSIRT Contact Point represents an operational and functional delegation. The Contact Point is the executor of notification obligations and serves as the technical interface with authorities. However, the ultimate responsibility regarding non-compliance with NIS2 obligations remains with the administrative and management bodies according to Art. 23 of Legislative Decree 138/2024. They must provide adequate resources and support, ensuring that the decision-making chain is effective and rapid to guarantee the timeliness of notifications (within 24 or 72 hours). In the event of a breach of obligations, liability and administrative pecuniary sanctions fall exclusively on company leadership.
Practical tools for resilience
- Playbooks: ACN recommends adopting specific playbooks for each type of attack (e.g., ransomware, DDoS, spear-phishing). Each phase of the response is associated with precise activities and roles, reducing dependence on individual people and facilitating management even in the absence of dedicated figures.
- Table-top exercises: Simulations of significant incidents that allow for testing the functionality of the chain of command and internal communication channels. These exercises also help non-technical IRT members understand emergency procedures and the information requests of CSIRT Italia.
- Reference standards: The incident management process must be consistent with the National Cybersecurity Framework, NIST SP 800-61r3, and CAD Guidelines, structured into the phases of preparation, detection, response, recovery, and improvement.
Summary
The CSIRT Contact Point plays an operational role within a structured and multidisciplinary Incident Response Team, in an ecosystem governed by clear responsibilities and practical tools. The model outlined by the NIS2 Decree requires adequate resources, formalized procedures, and fluid governance to ensure a resilient and compliant response to regulations.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
