SICUREZZA DEI SISTEMI INFORMATICI DI ANGELO NICOLOSI* GLI attacchi informatici alle PMI italiane sono in forte crescita. Secondo il Rapporto Clusit 2024, gli attacchi DDoS (consistono nel tempestare di richieste un sito fino a renderlo inaccessibile) rappresentano il 36% del totale degli incidenti, segnando un aumento del 1486% rispetto all’anno precedente. Gli attacchi tramite sfruttamento di vulnerabilità costituiscono il 18% e quelli di phishing e social engineering l’8%. La sicurezza informatica è, quindi, una delle aree di rischio emergenti più critiche per le PMI. Non c’è previsione su dove, come e quando l’incidente informatico si possa verificare, né che impatto possa avere sull’azienda. Rimedi certi e alternativi, se si è connessi, non ne esistono. Pensare di stipulare una copertura assicurativa potrebbe sembrare la soluzione al problema. Sì, è vero, un’idonea “Polizza Cyber” può mitigare le conseguenze del danno, ma rimane il fatto che quando si ricorre alla garanzia ormai la criticità è in atto o è già avvenuta, ragion per cui occorre prevenire implementando una serie di prassi, piani e procedure per proteggere dati, sistemi e informazioni che ormai costituiscono il nucleo del patrimonio aziendale. È necessario precisare che non tutti i settori di attività CYBER attacks on Italian SMEs are growing rapidly. According to the Clusit Report 2024, DDoS attacks (consisting in storming a site with requests until it becomes inaccessible) account for 36% of the total number of incidents, marking an increase of 1486% over the previous year. Attacks through exploitation of vulnerabilities account for 18% and phishing and social engineering attacks for 8%. Cyber security is therefore one of the most critical emerging risk areas for SMEs. There is no predicting where, how and when a cyber incident may occur, nor what impact it may have on the business. Certain and alternative remedies, if you are connected, do not exist. Thinking about taking out insurance cover might seem to be the solution to the problem. Yes, it is true, a suitable ‘Cyber Policy’ can mitigate the consequences of the damage, but the fact remains that by the time the cover is taken out, the criticality is already in place or has already occurred, which is why prevention is needed by implementing a series of practices, plans and 52 RISCHIO informatico e POLIZZE assicurative Cyber RISK and INSURANCE policies LA SICUREZZA INFORMATICA È UNA DELLE AREE DI RISCHIO EMERGENTI PER LE PMI. SENZA UN’ATTIVITÀ DI PROTEZIONE DI DATI, SISTEMI E INFORMAZIONI NON È POSSIBILE ATTIVARE UNA POLIZZA Cyber security is one of the emerging risk areas for SMEs. Without protecting data, systems and information, it is not possible to activate a insurance policy
RkJQdWJsaXNoZXIy NDUyNTU=