Cybersecurity is increasingly a factor of industrial competitiveness. AI accelerates the number and speed of digital threats, but does not increase companies’ ability to defend themselves. In particular, small and medium-sized enterprises continue to represent the weakest link in the cybersecurity chain. All the data from the Cyber Index SME Report 2025 promoted by Generali and Confindustria, with the support of Polimi, Osservatori.net and ACN.
THE NUMBERS OF THE CYBER INDEX SME 2025
The good news on the national cybersecurity front is that SME maturity has increased by 3 points, rising from 52 to 55. The bad news is that Italian small and medium-sized enterprises have not yet reached a passing grade. In 2025, the volume of “mature” SMEs surpassed that of beginners. The biggest increase compared to 2024 was recorded in the strategic approach. The level of internal responsibility for cybersecurity increased by 10 percentage points, reaching 86% of SMEs. Two out of three allocate funds for the purchase of cybersecurity solutions and services. The problem is that there is an ongoing race between market evolution and companies, according to Alessandro Piva, Director of the Cybersecurity & Data Protection Observatory at Politecnico di Milano.
“13% of Italian SMEs consider cyber attacks a risk. 11% of SMEs consider the issue of non-EU suppliers of particular interest. 81% of SMEs are part of sensitive supply chains,” he said, emphasizing that there is still a large gap between small and medium-sized enterprises, which stop at an average score of 53.
ITALY INCREASINGLY TARGETED BY CYBER ATTACKS
Italy is one of the main targets of cyber attacks and SMEs are particularly exposed, stressed Fausto Bianchi, president of Piccola Industria: 1 in 4 has received at least one cyber attack in the last 4 years. Therefore, risk management is proving increasingly fundamental to ensure investments and industrial competitiveness. “In 2025, cyber attacks increased by 42% compared to 2024. In particular, in the military and law enforcement sectors they increased by 300%,” said Bianchi.
The acceleration of technologies has increased exposure to risks. For this reason, digital security has become a matter of operational continuity for companies, according to Massimo Monacelli, General Manager of Generali Italia. “Cybersecurity today is also essential to access public and private contracts,” said Monacelli.
HOW TO BUILD AN ITALIAN DIGITAL SOVEREIGNTY
The key to building Italian digital sovereignty is governance. A mapping is needed to understand where to reduce cyber risk and choose priorities, according to Pietro Labriola, Delegate of the President of Confindustria for Digital Transition. “Our Government first of all included a solution in the PSN that provides hyperscale technologies limited by risk level. In fact, the encryption key is in the hands of the consortium; therefore, the US authority cannot access the data. In April, the EU will try to define rules to limit digital sovereignty, today the complexity of the rules makes everything complicated to solve. We are working on a board to understand what end-to-end sovereignty is: from the chipset, to the people managing the cloud, to contracts. You cannot be sovereign over chips,” said Labriola.
“Megalide is one of the supercomputing machines functional to an AI development ecosystem involving SMEs. The goal is to achieve technology transfer that would help us find those forms of technological autonomy that reduce dependence on non-EU tech,” emphasized Bruno Frattesi, Director General of the National Cybersecurity Agency.
WHY THE CLOUD IS CENTRAL
The issue of cloud service penetration is a central element because it increases the overall risk, not only cyber, for national sovereignty, according to Pietro Labriola, Delegate of the President of Confindustria for Digital Transition. “The world has changed compared to when there were rules valid for everyone. The cloud introduces another dimension. We think data are stored in Italy, but the software used complies with American laws, which say that at any time the US can access information for security reasons. We woke up from the dream of being the Continent that colonized the world, now we are the colonized,” said Labriola.
In particular, local providers capable of supporting SMEs end to end throughout risk and business management are needed, according to Remo Marini, Group Chief Security Officer, Generali.
AI FOR CYBER DEFENSE
Today AI allows planning and conducting devastating cyber attacks in a few hours. However, existing tools are not yet effective in terms of threat identification and counterattack, stressed Remo Marini, Group Chief Security Officer of Generali: “In Iran AI was used to coordinate and manage the attack strategy against Iran. Artificial intelligence is the fifth domain of warfare.”
Meanwhile, the Italian AI market has reached 1.8 billion euros, +50% in one year. “Small entities, however, remain on the sidelines, with adoption stuck at 7%, compared to 11% of medium-sized and about 70% of large companies,” emphasized Bianchi.
However, AI remains an abstraction without infrastructure, explains Frattesi, pointing out that today it mainly concerns the production processes of large companies. “Without governance guarantees, operators risk the explosion of the value chain,” he warned.
HOW TO MOVE FROM RISK AWARENESS TO ACTION
Our production system is more aware but we are below the passing level, admitted Barbara Lucini, Head of Country Sustainability & Social Responsibility at Generali Italia, emphasizing that “often companies do not know how to translate risk knowledge into operational solutions.”




