← All industries
Industry deep dive

Government & public administration — sovereign by design

For governments and public administrations: sovereign, on-premise and evidence-backed — built first for the Italian PA (decree 138/2024, national cyber perimeter) and mapped to NIST 800-53, the UK CAF and the Gulf national frameworks.

The Italian transposition of NIS2 (decreto legislativo 138/2024, in force since 16 October 2024) brought thousands of public-administration bodies — central agencies, regions, large municipalities, healthcare authorities — into a regime of personal accountability for cybersecurity adequacy. ACN guidance combined with AgID requirements and the supply-chain provisions of the Perimetro di Sicurezza Nazionale Cibernetica create a procurement environment where SaaS security tooling is increasingly disqualified before evaluation. The 2025 wave of named attacks on Italian regional authorities and healthcare ATS / ASL bodies has made the topic board-level.

What is on the PA CISO's desk

Personal liability under decreto 138/2024

Top management is now personally accountable for "adequate, proportionate, effective" measures. The standard of proof is documentary evidence, not best-effort attestation.

AgID + ACN procurement requirements

Cloud-related procurement for PA requires qualification levels (QC1-QC4) with explicit data-locality and processor-control requirements. Many SaaS security tools cannot satisfy QC3+ for production telemetry.

Perimetro Nazionale Cibernetica supply chain

For PSN-included entities, every ICT product in production must pass the CVCN evaluation. Vendor-cloud dependencies dramatically expand the evaluation surface.

Ransomware against regional administrations

Multiple named Italian regional and ATS incidents through 2025-2026 have demonstrated that the assumption of "we are too small to be targeted" no longer holds for any PA body with funding or citizen data.

How Zero Hunt fits the Italian PA procurement

Pillar 3 — Automatic Compliance

NIS2 evidence for ACN audits, from one signed record

Every detected finding and traffic event is auto-mapped to the controls of NIS2 (as transposed by decreto 138) and ISO 27001 where applicable; evidence for AgID and national cyber perimeter requirements is packaged from the same signed record, and the Trust Center exports signed bundles for ACN audits.

Pillar 1 — Generative Pentest

Continuous validation without the SaaS dependency

The appliance runs entirely on-prem. No vendor-cloud touch point on production telemetry. The 10-agent swarm and the AI Gym backtest corpus all live inside the perimeter.

Pillar 2 — AI Traffic Analysis

Network-side detection on flat municipal estates

Most PA networks are flatter than the network diagram suggests. The AI Traffic engine catches the in-progress patterns (lateral movement, exfiltration, ransomware staging) that an endpoint-only stack misses on the unmanaged or partially-managed segments typical of regional / municipal estates.

Capability emphasis for the PA

  • ▸Italian-language Trust Center export aligned with ACN expectations
  • ▸No vendor-cloud touch points: Cloud-Italia QC3 / QC4 friendly
  • ▸Documented chain-of-custody for personal-liability defensibility under decreto 138
  • ▸OT/ICS detection for utility-adjacent PA bodies (regional water, transport)
  • ▸Air-gap option for classified or defense-adjacent agencies

Who buys this in the PA

RSPI / CISO sponsoring; Direttore Generale signing because personal liability is now on the line under decreto 138; AgID-qualified procurement office validating against cloud-qualification requirements; consulting partner (system integrator or accredited reseller) on the procurement side. The conversation tends to be channel-led — see the partner program for accredited Italian PA integrators.

Frameworks mapped for this sector, worldwide

The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:

Global / cross-industry
  • NIST Cybersecurity Framework
  • ISO/IEC 27001:2022
  • CIS Critical Security Controls v8
European Union
  • NIS2 Directive
United States
  • NIST SP 800-53
United Kingdom
  • NCSC Cyber Assessment Framework
Asia-Pacific
  • Singapore Cybersecurity Act / PDPA
Middle East
  • Saudi NCA ECC / SAMA CSF
  • UAE Information Assurance (NESA)
  • Qatar NCSA framework

Why this sector runs its AI red team on-premise, on private AI →

Go deeper on the regulations

Want to see this against your environment?

A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.