What if it happened to your firm tomorrow?

Fifteen professional firms with compromised databases, more than three thousand clients locked out of their own records, wage support schemes for staff. It happened in the Italian province of Trento in spring 2026, and in August the first reports arrived from neighbouring South Tyrol. This is not an IT story: it is a story about business continuity and professional liability.
What happened
Between late March and April 2026, a cyberattack compromised the databases used by at least fifteen professional firms in the province of Trento, across Rovereto, Tione, Campiglio and the Adige valley. The outcome: more than three thousand clients unable to reach their own records, accounts and tax filings inaccessible, firms shut down for weeks, some forced to apply for wage support for their staff. The daily l'Adigedevoted a full page to the case on 20 April, reporting a ransom demand in cryptocurrency in exchange for the decryption key, and the call from the Trento and Rovereto Chartered Accountants' Association for affected members to file a formal complaint.
In August the story continued one province over: the Bolzano Chartered Accountants' Association recorded the first reports of attempted cyber fraud in its territory and responded in a structured way — framework agreements for dedicated cyber risk policies, incident crisis management services, and a priority monitoring channel with the postal police, the financial police, police headquarters and the public prosecutor's office — for a membership of more than 800 professionals. «Traditional defence is no longer enough against a cybercrime industry that has become fully industrialised», said president Anna Paola De Angelis.
One caveat before going further, because the difference between a useful article and an alarmist one lies in the details. L'Adigedescribes a «Russian raid». Attributing ransomware to a country is a technically delicate exercise that rarely concludes within the first few weeks: criminal infrastructure is rented, groups operate as franchises, and the language of the code or the geolocation of addresses says little about who gave the orders. For anyone who has to protect a firm, in any case, the identity of the attacker is the least useful variable of all.
The detail that changes everything: «the databases used by»
There is a phrase in the reporting on the Trento case that deserves a second reading: the attack compromised the databases used by at least fifteen firms. Not fifteen firms breached one at a time. A single point of concentration — a centralised archive, a shared practice management system — and fifteen professionals down together. Local reporting points to frequent delays in updates by the software vendors as one of the causes.
That shifts the centre of gravity of the problem entirely. A firm can have an up-to-date antivirus, strong passwords and trained staff, and still end up paralysed because the paralysis came from its supplier. This is the attack model the Clusit 2026 Report identifies as dominant: in 2025 almost one serious incident in five worldwide hit «multiple targets» — campaigns striking indiscriminately across sectors and organisation sizes — and that category grew by 96% in a single year. Hitting one node to reach everything connected to it has become the rational strategy, and that is why the Trento case is not local news but a textbook lesson.
For anyone running a firm, the practical consequence is a question that rarely appears in contracts: what has whoever holds my data promised me, in writing?
With what recovery times, what obligations to notify me, and what evidence that backups are actually being tested.
Why a professional firm is a rational target
Attackers do not pick at random: they pick the point where the ratio between effort and leverage is best. A professional firm is exactly that point, for three reasons that compound.
A few terabytes hold accounts, payroll, company records, contracts, tax payments, powers of attorney, the health data contained in payslips, and login credentials to the tax portals of hundreds of businesses.
This is not an attack on fifteen organisations: it is an attack on three thousand businesses that cannot close their accounts, file a return, or pay their staff.
A firm with eight people carries the same confidentiality obligations as a bank, with an infinitesimal fraction of its defences.
This is not an impression: in its dedicated ransomware report, Italy's National Cybersecurity Agency (ACN) identifies small businesses as the primary victim category in the country, «often because of a limited disposition towards a culture of security».
What the data says (and what it does not)
The Clusit 2026 Report recorded 5,265 known serious incidents worldwide in 2025 (+49% on 2024), of which 507 in Italy (+42%): 9.6% of the global total, a share out of all proportion to the country's economic weight. Note the perimeter, however: Clusit counts only serious and known incidents. Fifteen provincial firms do not make that sample, and in the ACN's Operational Summaryfor March 2026 the ransomware claims against Italian entities recorded from open sources number twenty-four for the entire month, with 48% of victims classified as «lower criticality». The real phenomenon is larger than the measured one — and for a professional, that is the uncomfortable part: no statistic will come looking for them.
The Sophos State of Ransomware 2026 (2,158 affected organisations, 17 countries, Italy included) measures the aftermath instead:
- in 56% of attacks the criminals succeeded in encrypting data;
- the average recovery cost, excluding any ransom, is 1.7 million dollars, with a median of 375,000;
- 55% recovered within one week, but the average recovery time remains three weeks, and 14% take between one and three months;
- backup-based recovery rose back to 66% of cases where data was encrypted, while the share of those paying the ransom fell to 48%, the lowest in three years.
Here too the limit must be stated: the sample covers organisations from 100 to 5,000 employees. A ten-person firm does not face 1.7 million dollars in recovery costs — but it does not have an IT department either, and three weeks of downtime weigh on it infinitely more than on a company with a thousand employees.
One final and most operational figure: the two leading root causes in 2026 are malicious email (26%) and phishing (24%). Half of all incidents begin with a message opened by a person. Exploited technical vulnerabilities, which led the ranking in previous years, have fallen from 32% to 18%. That is worth remembering when you read that «artificial intelligence has raised the risk bar»: it is true that AI makes phishing more credible and cheaper to produce at scale — Clusit records a 75% rise in phishing and social engineering in 2025 — but the mechanics of the attack are the same as ever. A message, a credential, a badly configured remote access. The threat has become industrialised, not science-fictional.
The point that gets missed: this is not an IT problem
When the archives lock up, the question is not «who fixes my server». It is these:
- Clients are calling. What do we tell them, and who tells them?
- Tax deadlines do not move because a firm has been attacked. Who reports the delay, to whom, and with what documentary evidence?
- The encrypted data contains third parties' personal data: clients' employees, directors, dependent family members. Who are the controllers, and on whom does the notification duty fall?
On that last point it pays to be precise, because it is where liability is generated. Depending on the activity, a firm may act as an autonomous controller — where it determines purposes and means in fulfilment of professional and statutory obligations — or as a processor under Article 28 GDPR, typically when running payroll on behalf of a client company, as the Italian DPA indicated as early as a 2019 note on labour consultants. The difference is not academic: it changes who notifies the supervisory authority within the 72 hours required by Article 33, who informs data subjects under Article 34, and what the appointment contract requires the firm to do — and how fast — towards the client. A firm that discovers it is a processor while its archives are encrypted has already lost the first two days.
One recurring confusion should be deflated, though: the duty to notify the national CSIRT within hours applies to entities inside the NIS2 scope or the National Cybersecurity Perimeter, not to the average professional firm. NIS2 still reaches firms indirectly, however, through contracts: clients that are in scope must govern the security of their own supply chain, and will start demanding requirements, questionnaires and clauses from their advisers. Those unable to answer will lose business before they ever risk a fine.
On insurance, and on the ransom
The Bolzano association's response — insurance agreements and a direct channel to the authorities — is concrete and sensible. It deserves one clarification no broker will offer, though: a cyber policy transfers financial risk; it does not restore data. It does not bring the practice management system back online, does not rebuild the audit trail, does not extinguish the notification to the supervisory authority, and does not answer the client calling to ask whether their return is safe. It is a tool for economic mitigation that belongs after organisational measures, not in their place. And it must be read carefully: almost all cyber policies condition payout on minimum requirements — backups, multi-factor authentication, patching — that are verified when the claim is settled, not when it is underwritten. A policy signed on the back of an optimistically completed questionnaire is a cost, not a cover.
On the ransom, the reasoning is simpler. Paying is an operation with an uncertain outcome that funds the criminal market and extinguishes no obligation: it does not cancel the notification to the authority, does not recover exfiltrated data — it merely makes it less published, on a criminal's word — and rebuilds nothing. ACN and law enforcement advise against payment and encourage reporting, which is exactly the route the Trento association pointed its members towards. The Sophos figure cited above — 66% recovering from backups against 48% paying ransoms — tells you which lever actually works. And it is a lever built beforehand.
Seven questions to answer beforehand
Security in a professional firm does not begin with an antivirus. It begins with seven written answers that fit in a few pages and cost far less than three weeks of downtime.
- How long can I stay down? The maximum tolerable downtime (RTO) and the maximum amount of work I can afford to redo (RPO). If they are not numbers, they are opinions.
- Are the backups really backups? Offline or immutable copies, outside the domain, and — above all — a restore tested at least once a year. An untested backup is a file, not a guarantee.
- Who are my critical suppliers, and what have they promised me in writing? The practice management system, the shared archive, the IT consultant, the backup service. With what recovery times and what duties to inform me. This is the question the Trento case makes impossible to postpone.
- Do I have multi-factor authentication on everything facing the internet? Email, VPN, cloud software, tax portals. Half of all incidents start with a message and a credential.
- Do I have a map of who is controller and who is processor? With Article 28 contracts signed and client notification timelines defined before the emergency, not during it.
- Do I have a communication plan? A list of clients to notify by priority, a channel other than the firm's own email (if that is encrypted too, how do we communicate?), and a text already drafted.
- Do the people in the firm know how to recognise and report? Not «they did the training»: they know who to write to at 7pm on a Friday when something looks wrong, knowing that nobody will scold them for a false alarm.
The right question
The reporting on the Trento case describes firms that rebuilt their archives by hand. It is an image worth more than any statistic: professionals retyping work that a tested restore would have handed back in half a day.
Protecting a professional firm does not mean protecting computers and data. It means protecting the ability to fulfil the engagement: clients' deadlines, the trust built over twenty years, the salaries of the people who work there. The question to ask is not «what does security cost».
It is: for how many days can my firm stay down before the damage becomes irreversible? If the answer is not a number, that is where the work starts.
Sources
- Paolo Fisichella, «Attacco hacker, 3mila clienti coinvolti», l'Adige, 20 April 2026, p. 10 (print edition).
- «Cyberattacco in Trentino: oltre 3.000 clienti bloccati e studi in ginocchio», MB Time, 23 April 2026
- «Cyberattacchi agli studi dei commercialisti: a Bolzano polizze e aiuti», Nordest24, 13 August 2026
- Clusit, Rapporto Clusit 2026 — press data, 11 March 2026
- Sophos, The State of Ransomware 2026 (Vanson Bourne, Q1 2026, n=2,158)
- ACN, Ransomware — characteristics, preparedness and response
- ACN, Operational Summary, March 2026
- Regulation (EU) 2016/679 (GDPR), Arts. 28, 32, 33 and 34 — EUR-Lex