Government & public administration — sovereign by design
For governments and public administrations: sovereign, on-premise and evidence-backed — built first for the Italian PA (decree 138/2024, national cyber perimeter) and mapped to NIST 800-53, the UK CAF and the Gulf national frameworks.
The Italian transposition of NIS2 (decreto legislativo 138/2024, in force since 16 October 2024) brought thousands of public-administration bodies — central agencies, regions, large municipalities, healthcare authorities — into a regime of personal accountability for cybersecurity adequacy. ACN guidance combined with AgID requirements and the supply-chain provisions of the Perimetro di Sicurezza Nazionale Cibernetica create a procurement environment where SaaS security tooling is increasingly disqualified before evaluation. The 2025 wave of named attacks on Italian regional authorities and healthcare ATS / ASL bodies has made the topic board-level.
What is on the PA CISO's desk
Personal liability under decreto 138/2024
Top management is now personally accountable for "adequate, proportionate, effective" measures. The standard of proof is documentary evidence, not best-effort attestation.
AgID + ACN procurement requirements
Cloud-related procurement for PA requires qualification levels (QC1-QC4) with explicit data-locality and processor-control requirements. Many SaaS security tools cannot satisfy QC3+ for production telemetry.
Perimetro Nazionale Cibernetica supply chain
For PSN-included entities, every ICT product in production must pass the CVCN evaluation. Vendor-cloud dependencies dramatically expand the evaluation surface.
Ransomware against regional administrations
Multiple named Italian regional and ATS incidents through 2025-2026 have demonstrated that the assumption of "we are too small to be targeted" no longer holds for any PA body with funding or citizen data.
How Zero Hunt fits the Italian PA procurement
NIS2 evidence for ACN audits, from one signed record
Every detected finding and traffic event is auto-mapped to the controls of NIS2 (as transposed by decreto 138) and ISO 27001 where applicable; evidence for AgID and national cyber perimeter requirements is packaged from the same signed record, and the Trust Center exports signed bundles for ACN audits.
Continuous validation without the SaaS dependency
The appliance runs entirely on-prem. No vendor-cloud touch point on production telemetry. The 10-agent swarm and the AI Gym backtest corpus all live inside the perimeter.
Network-side detection on flat municipal estates
Most PA networks are flatter than the network diagram suggests. The AI Traffic engine catches the in-progress patterns (lateral movement, exfiltration, ransomware staging) that an endpoint-only stack misses on the unmanaged or partially-managed segments typical of regional / municipal estates.
Capability emphasis for the PA
- ▸Italian-language Trust Center export aligned with ACN expectations
- ▸No vendor-cloud touch points: Cloud-Italia QC3 / QC4 friendly
- ▸Documented chain-of-custody for personal-liability defensibility under decreto 138
- ▸OT/ICS detection for utility-adjacent PA bodies (regional water, transport)
- ▸Air-gap option for classified or defense-adjacent agencies
Who buys this in the PA
RSPI / CISO sponsoring; Direttore Generale signing because personal liability is now on the line under decreto 138; AgID-qualified procurement office validating against cloud-qualification requirements; consulting partner (system integrator or accredited reseller) on the procurement side. The conversation tends to be channel-led — see the partner program for accredited Italian PA integrators.
Frameworks mapped for this sector, worldwide
The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:
- Global / cross-industry
- NIST Cybersecurity Framework
- ISO/IEC 27001:2022
- CIS Critical Security Controls v8
- European Union
- NIS2 Directive
- United States
- NIST SP 800-53
- United Kingdom
- NCSC Cyber Assessment Framework
- Asia-Pacific
- Singapore Cybersecurity Act / PDPA
- Middle East
- Saudi NCA ECC / SAMA CSF
- UAE Information Assurance (NESA)
- Qatar NCSA framework
Why this sector runs its AI red team on-premise, on private AI →
Go deeper on the regulations
- Playbook · 12 minNIS2 penetration testing and vulnerability assessment requirements — what is mandatory and what is risk-based
A clause-by-clause guide to what NIS2, Implementing Regulation (EU) 2024/2690 and, for Italy, D.Lgs. 138/2024 and the ACN baseline measures require on vulnerability assessment and penetration testing, and the evidence that proves it.
- Playbook · 11 minOn-Premise & Air-Gapped Pentest Platforms: A Buyer's Guide
A procurement guide to on-premise and air-gapped platforms for automated and autonomous penetration testing: who needs them, which third-party rules make a vendor cloud hard to accept, and what on-premise should mean in the contract.
- Playbook · 10 minSaudi NCA ECC penetration testing requirements — controls 2-10 and 2-11 and the CSCC frequencies for critical systems
A control-by-control guide to vulnerability management and penetration testing in the Saudi NCA Essential Cybersecurity Controls (ECC-2:2024) and the Critical Systems Cybersecurity Controls: who must comply, how often, and what to document.
- Definition · 7 minDecreto Legislativo 138/2024 — the Italian NIS2 transposition
Decreto Legislativo 138 of 4 September 2024 is the Italian transposition of NIS2 (Directive (EU) 2022/2555). It identifies essential and important entities, defines technical and organizational measures, attaches personal liability to top management, and operationalizes ACN as the competent national authority and CSIRT Italia as the national CSIRT.
- Playbook · 8 minNIS2 Article 23 incident timeline — the practical playbook
A step-by-step operational reference for the NIS2 Article 23 incident reporting cadence: what to do in the first hour, by hour 24, by hour 72, and by month 1. Decision gates, evidence checklists, common failure modes.
- Definition · 6 minWhat is private AI in cybersecurity?
Private AI means the AI models that power a security tool run on infrastructure the organization controls — on-premise or in its own sovereign environment — so prompts, context and results never leave its perimeter and no third-party AI provider sits in the loop.
Want to see this against your environment?
A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.