In Italy Law No. 90 of 28 June 2024 («Provisions on Strengthening National Cybersecurity and on Cybercrime») recently intervened in the system of cyber offences. Despite the media emphasis on this reform - presented as a «crackdown» on cybercrime and soon followed by Law No. 132 of 23 September 2025 («Provisions and Delegations to the Government Concerning Artificial Intelligence ») - its substantive impact is relatively limited, primarily involving general increases in penalties and targeted adjustments. For example, a new offence (Article 629, paragraph 3) was introduced to address the spread of ransomware cyber-attacks, the practical effectiveness of which will depend on future case law. Additionally, Article 615-quinquies of the Criminal Code was repealed and relocated among property offences (Article 635-quater.1), with the addition of two new aggravating circumstances. Similarly, Article 640, criminalizing fraud, was supplemented by paragraph 2-ter, applicable when the offence is committed remotely using information or telematic tools designed to obscure identification. It is evident that the need for criminal protection of cybersecurity does not arise from an artificially constructed necessity but reflects the requirement «to secure a shared condition within the information society»
Cybersecurity and Criminal Law. Towards the protection of a new generation legal assets, between past, present, and future perspectives
R. Flor
2026-01-01
Abstract
In Italy Law No. 90 of 28 June 2024 («Provisions on Strengthening National Cybersecurity and on Cybercrime») recently intervened in the system of cyber offences. Despite the media emphasis on this reform - presented as a «crackdown» on cybercrime and soon followed by Law No. 132 of 23 September 2025 («Provisions and Delegations to the Government Concerning Artificial Intelligence ») - its substantive impact is relatively limited, primarily involving general increases in penalties and targeted adjustments. For example, a new offence (Article 629, paragraph 3) was introduced to address the spread of ransomware cyber-attacks, the practical effectiveness of which will depend on future case law. Additionally, Article 615-quinquies of the Criminal Code was repealed and relocated among property offences (Article 635-quater.1), with the addition of two new aggravating circumstances. Similarly, Article 640, criminalizing fraud, was supplemented by paragraph 2-ter, applicable when the offence is committed remotely using information or telematic tools designed to obscure identification. It is evident that the need for criminal protection of cybersecurity does not arise from an artificially constructed necessity but reflects the requirement «to secure a shared condition within the information society»I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



