ACN Operational Summary, August 2026: turning national cyber threat data into NIS2 risk assessment input

ACN (Italy's National Cybersecurity Agency) published its new Operational Summary on 28 September 2026, with data and indicators on the cyber threat landscape in Italy for August 2026. Most organizations read it as news and file it away. Few actually use it as input for their NIS2 risk assessment (NIS2 is EU Directive 2022/2555 on the security of network and information systems) — and it's this second use, not the first, that this article is about.
What the ACN Operational Summary is, and why it matters now
ACN is Italy's National Competent Authority under Article 8(1) of the NIS2 directive, and the single point of contact for NIS matters; CSIRT Italia, which receives incident notifications from in-scope entities, operates within it. Legislative Decree 138/2024, Italy's NIS2 transposition law, formalizes this role and sets the obligations for essential and important entities. The Operational Summary is ACN's periodic publication on the national cyber threat landscape: recorded events, confirmed incidents, the most affected sectors and access vectors, plus results of the preventive monitoring carried out on public administration and company systems. This edition's data covers August 2026, compared against the previous month, with a monthly cadence. It matters now because many organizations are still consolidating their NIS2 compliance processes: a recurring, public data point is a chance to check, month after month, whether your reading of the risk is still current.
What this edition's data actually shows
In August 2026, ACN recorded 309 cyber events and 185 incidents, stable compared to July (188 incidents): a broadly unchanged landscape, not a sudden escalation. The most frequent threats remain data exposure, defacement and ransomware. The most affected sectors: manufacturing (ransomware), telecommunications (email account compromise) and technology (vulnerability exploitation); the most common access vectors are exploited vulnerabilities, compromised credentials, and phishing/spear phishing — all easy to mitigate with basic cyber hygiene controls (patching, credential management, awareness). The CVE Program monitoring also shows 12,719 new CVE records, up roughly 2,800 from July, of which 288 already have a public Proof of Concept — a detail that matters for patching priorities, since a PoC makes a vulnerability exploitable much faster. ACN's preventive monitoring flagged over 9,000 at-risk systems in public administrations and Italian companies, with 8,382 alert notifications sent.
Turning it into input for NIS2/ISO 27001 risk assessment
These numbers say nothing about your specific risk: no Operational Summary can replace a threat analysis calibrated to your organization. They are, however, a useful external benchmark for calibrating threat likelihood in your NIS2/ISO 27001 risk assessment: if your sector shows up among the most affected — manufacturing, telecommunications, technology, in this edition — that's a signal to weigh, not to ignore or overweight in isolation. The same goes for access vectors: if your risk register doesn't yet list exploited known vulnerabilities or compromised credentials among the likely causes of an incident, this data is a concrete reason to update it. The right way to use these figures is to cross-reference them with the risk register your organization already maintains for NIS2/ISO 27001 purposes — covered in detail in Anchoring your risk register to ACN data — not to read them as a standalone news item, disconnected from your risk management process.
The link with incident notification obligations toward ACN
Knowing the national threat landscape helps you classify an incident affecting you more accurately — for instance, spotting a ransomware pattern already common in your sector sooner, or framing a compromise attempt that started from a vulnerability with a public Proof of Concept, which typically spreads faster. But note: the Operational Summary neither states nor changes notification thresholds and timelines. Those remain set by Legislative Decree 138/2024 (Italy's NIS2 transposition law), Article 25: pre-notification to CSIRT Italia within 24 hours of becoming aware of a significant incident, notification within 72 hours with an initial assessment, final report within one month of the 72-hour notification. These are two distinct sources with different functions: one describes context, the other imposes precise obligations with fixed deadlines — and the distinction should hold in your internal communication toward management too, so a contextual data point isn't mistaken for a regulatory requirement.
What to do now
This publication's monthly cadence suggests a useful operating practice: set a recurring moment — monthly, tied to the release of each new Operational Summary — to review your risk register in light of the latest data, instead of updating it only around audits or incidents. A review cycle anchored to a recurring external publication is easier to institutionalize than one left to an individual's initiative.
Three questions to put this data to work instead of just reading it: does your sector appear among the most affected in this edition? Does your NIS2/ISO 27001 risk register already reference the latest ACN data, or is it stuck on an older snapshot? Could you tell today whether an event in your perimeter would meet the definition of a significant incident that triggers the notification clock?
If you're not sure whether you fall within the NIS2 perimeter, or which obligations apply to your organization, check it before the question comes from an audit or a real incident: Check if you fall within the NIS2 perimeter — NIS2 Gap Analysis.
Sources
- ACN — Operational Summary, dati e indicatori della minaccia cyber in Italia — pagina del 28 settembre 2026, numero di agosto 2026
- ACN — Operational Summary agosto 2026 (PDF)
- ACN — archivio degli Operational Summary