Cybersecurity

Cybersecurity and data protection are fundamental to maintaining the trust of citizens, businesses and institutions. In this context, CDP adopts an integrated approach to cybersecurity aimed at protecting its information assets, ensuring business continuity and strengthening the organisation's resilience against constantly evolving threats.


Our Approach

Security is an integral part of CDP's activities and reflects its principles of responsibility, transparency and commitment to creating public value. The organisation continuously invests in technologies, processes and specialist expertise to adequately manage risks and respond effectively to incidents. The objective is to safeguard information, protect strategic assets and ensure the secure management of the resources entrusted to it by citizens.

CDP's security model

Governance and security culture

Systems and data protection

Fraud prevention and people protection

Governance and security culture

Security is managed through a structured governance framework with clearly defined responsibilities, control processes and continuous monitoring. A strong security culture is promoted through mandatory training programmes, awareness initiatives and simulation exercises designed to strengthen cyber risk awareness at every level of the organisation. Particular attention is also paid to supply chain security and the assessment of business partners.

Systems and data protection

CDP adopts a multi-layered defence model to protect its digital infrastructure and data.

Continuous threat monitoring

Continuous monitoring enables the timely identification of security events and their effective management, contributing to the integrity and availability of systems while ensuring operational continuity.

Information protection

Information is protected through a structured set of technical and organizational measures, defined in accordance with cybersecurity best practices. These measures include access control, data classification, and the adoption of the Security by Design approach, which integrates security principles into the design and development of systems and processes from the outset.

Regular assurance activities

Regular reviews, including those conducted with the involvement of independent third parties, make it possible to assess the effectiveness of the measures in place and continuously strengthen the organisation's overall security posture.

Fraud prevention and protection of individuals

CDP promotes a structured framework for preventing and combating cyber fraud, aimed at protecting its assets, operational processes and institutional reputation. This approach combines technological detection tools, monitoring of digital channels and awareness initiatives. Security is also a direct commitment to citizens: CDP encourages safe online behaviour and advises users always to verify the authenticity of communications received by relying exclusively on official channels. Through alerts, educational content and regular updates, CDP helps strengthen people's ability to recognise fraud attempts and other digital threats.

Intiative

CDP contributes to promoting a culture of cybersecurity through information, awareness and training initiatives aimed at businesses, stakeholders and young talent. These activities foster greater awareness of cybersecurity, digital risk prevention and fraud prevention while encouraging the sharing of expertise and best practices in support of Italy's national system.