We facilitate innovation

in the Italian financial system in terms of Cyber Risk and Cyber Resilience.

Go immediately to:

About us

CERTFin – CERT Finanziario Italiano is a public-private cooperative initiative aimed at increasing the cyber risk management capacity of financial operators and the cyber resilience of the Italian financial sector through operational and strategic support activities for prevention, preparation and response to cyber attacks and security incidents.

CERTFin performs its activities in line with the national strategy and with other country-wide institutional initiatives relating to cybersecurity and the protection of critical infrastructure, helping to further develop the national and international network of institutional partners and experts.

Per poter visualizzare il contenuto è necessario aggiornare le preferenze cookie, prestando il consenso ai servizi di categoria "Miglioramento dell'esperienza".
Modifica preferenze cookie

Objectives

Il CERTFin promuove la collaborazione tra gli operatori del settore finanziario e le istituzioni con l'obiettivo di rafforzare la resilienza del sistema finanziario italiano nei confronti delle minacce cyber e dei fenomeni fraudolenti. In particolare, il CERTFin si propone di:

  • rappresentare un punto di riferimento e di coordinamento per la cybersecurity del settore finanziario italiano;
  • favorire la cooperazione tra operatori, istituzioni e organismi nazionali e internazionali;
  • promuovere la condivisione tempestiva di informazioni su minacce, vulnerabilità, incidenti e lezioni apprese;
  • sviluppare analisi e approfondimenti sul panorama delle minacce e sul loro potenziale impatto sul settore;
  • supportare la gestione degli incidenti cyber e delle situazioni di crisi a rilevanza sistemica;
  • contribuire alla definizione e diffusione di metodologie, pratiche e strumenti per la gestione del rischio cyber;
  • accrescere la consapevolezza e la cultura della sicurezza attraverso iniziative di formazione, sensibilizzazione e confronto tra pari;
  • promuovere la collaborazione internazionale e la partecipazione alle principali iniziative europee e globali in materia di cybersecurity finanziaria.
  • Create a Single Point of Contact (PoC) for the financial sector
  • Promote public-private and intersectoral cooperation
  • Foster the exchange of information on incidents, cyber threats, vulnerabilities, and lessons learned
  • Study specific cyber events and assess their impact on the system
  • Support incident response and the crisis management process (CODISE)
  • Establish guidelines, methodologies, practices and tools to manage cyber risk
  • Promote awareness and security culture (training / education)
  • Develop international cooperation

Governance and organisation

CERTFin, jointly led by the Bank of Italy and ABI (Italian Banking Association) is operated by ABI Lab under the guidance of a Strategic Committee whose task is to set out policies and lines of development, and a Steering Committee, in charge of defining and overseeing the operational and economic management. Within the Strategic Committee, the insurance sector is represented by IVASS and ANIA, while Consob speaks for the financial sector.

Diagramma con due livelli: un triangolo blu in alto con la scritta 'Livello Strategico' e sotto la scritta 'Livello Tattico/Operativo'.
Organigramma del Comitato Strategico e Direttivo CERTFin con loghi IVASS, Ania, Banca d'Italia, Consob e ABI, e schema di condivisione informazioni tra SOC Banca, Assicurazione e Operatore finanziario tramite il Modello campus e ABI Lab come direzione operativa.

Strategic Committee

Steering Committee

defines the operational management of services offered to members and provides the Strategic Committee with an overall view of unfolding events, their impact on the industry and of the effective measures to be taken both collectively and by individual banks.

Operational Management

coordinates operational activities and the development of CERTFin.

Virtual Team

some CERTFin members contribute their own resources to the institution's activities through participation in the virtual team under the decentralised "campus" organisational model, which provides:

  • central coordination by Operations Management
  • the virtual team’s contribution to the activities

Certifications

Authorized to use CERT.
TF-CSIRT. Trusted Introducer

RFC 2350

This document contains a description of CERTFin, its functions and contact information, using the format provided by RFC 2350