Navigation and cybersecurity: new circular to increase security
Compliance with the NIS2 Directive and new standards for ships and ports. Cybersecurity will be fully integrated into Security Management Systems starting November 1, 2026.

The Ministry of Infrastructure and Transport is reshaping its national maritime security priorities, placing emphasis on the increasingly concrete threat of cyber risk. With the publication of the Circular "Navigation Security, General Series No. 177/2025" on December 16, the General Command of the Port Authorities and the NIS Authority for the Transport Sector defined the new binding regulatory framework. The measure applies to ships flying the Italian flag, ISM management companies, and port facilities, requiring an update of digital defense measures consistent with IMO guidelines and harmonized with the European framework of the NIS2 Directive, implemented in Italy with Legislative Decree 138/2024.
The convergence of information and operational technologies has made modern naval vessels and port terminals dependent on interconnected systems such as ECDI, AIS, and remote access interfaces. While this evolution has optimized logistical efficiency, it has also increased the surface area exposed to attacks that, by compromising Computer-Based Systems, could threaten not only operational continuity, but also the very safety of navigation and environmental integrity. Hence the need for regulatory intervention.
Circular 177/2025 thus marks the transition from a voluntary to a structural and mandatory approach. The focus of the measure is on the need for companies to organically integrate cyber risk management into their Safety Management Systems and security plans. It's no longer simply a matter of installing technological barriers, but of formalizing corporate procedures that cover the entire threat lifecycle: from intrusion prevention and detection to response planning and post-incident recovery strategies to ensure the resilience of critical systems, such as propulsion, steering, power generation, and load management.
In this context, human capital is a fundamental pillar, which is why the Ministry has established that technological upgrades must go hand in hand with a qualified training program for all key personnel, from crews to Company and Port Facility Security Officers, and even IT/OT technicians. This training must also be constantly updated to enable them to recognize the most sophisticated attack techniques and respond promptly.
The legislator pushes forward to future technological frontiers, including provisions regarding autonomous systems and integrated ship-shore services, anticipating the vulnerabilities of a rapidly automating sector. Furthermore, emergency management is integrated with the notification requirements set forth in the NIS2 regulation, requiring operators to promptly report significant incidents to the Italian National Cybersecurity Research Institute (CSIRT), thus strengthening cooperation between the maritime sector and national cyber defense.
As jointly emphasized by the General Command and the NIS Authority, cybersecurity is becoming an essential component of overall maritime security. To allow operators to adapt to these high standards, the new provisions have been set to enter into force on November 1, 2026.
SUBSCRIBE TO FREE SUPER YACHT 24 NEWSLETTER
SUPER YACHT 24 IS ALSO ON WHATSAPP: JUST CLICK HERE TO SUBSCRIBE TO THE CHANNEL AND ALWAYS BE UPDATED




