Joint Lab for Cybersecurity

A first-response task force in case of security breaches and a training, consulting, and support service, with the aim of creating a virtuous circle between research and applications in the field of cybersecurity

Pisa, may 20th 26

Towards a new security governance: JL presented at GARR Conference 2026

link to the magazine

april 14th 26

Security status 2026 in FBK by JL

link to academy

In recent years, the evolution of IT infrastructures has forced to rethink cybersecurity.

At FBK, this challenge led in January 2025 to the creation of a Joint Lab for Cybersecurity, a joint initiative between the IT Service and the Center for Cybersecurity, strongly supported by the General Secretariat. This laboratory stems from the previous experience of the Living Lab between IT and CS, which allowed the experimentation and validation of advanced technologies for systems and data protection. Now, with an even more structured approach, the Joint Lab aims to strengthen digital security through applied research, development of innovative methodologies, and continuous training, supporting internal units and Services in identifying solutions to common problems through consolidated practices and training, stimulating awareness and knowledge sharing.

The initiative is part of the broader context of the 2024-2027 Mandate Plan, with the aim of transforming the Joint Lab into a territorial reference hub capable of supporting public and private entities in managing cybersecurity challenges, contributing to building a secure local digital ecosystem that respects privacy and contributes to national and European resilience, thus responding to the increasingly high standards required and the complexity of the challenges posed by new technological and application scenarios.

 

 

 

Furthermore, on 13 April 2025, the Foundation received notification of inclusion in the list of entities subject to the European Directive NIS2 (Network and Information Systems 2) n. 2022/2555, implemented by Italy through legislative decree n. 138 of 2024 (so-called "NIS2 Decree"), and entered into force on 10/16/24.

This legislation, which provides for the adoption of a common level of cybersecurity to strengthen the security of European critical infrastructure and digital services, has shifted the Joint Lab's priorities primarily towards compliance with the Directive, according to well-defined deadlines. These needs have seen the approval by the CdA and the related publication of Resolution 2025/12 of 17 July 2025, formally called Information Security Organization (OSI) in FBK which creates and defines the specific roles of CISO (Chief Information Security Officer in the person of Mirco Vivaldi) and CSRM (Cyber Security Risk Manager in the person of Matteo Rizzi), with the function of regulation, monitoring, vigilance, coordination and intervention in the prevention and management of incidents; this together with, among other entities, the Joint Lab for Cybersecurity, in technical support for the assessment of threats and vulnerabilities and in the provision of advice to the Centres for the definition of security by design projects and for awareness-raising and targeted training.

The activities carried out by the Joint Lab are also part of the broader context of the new Sustainability Plan 25-27 (Data and Digital Infrastructure Security Pillar (D)) with the aim of:

  • acting as a first response task force in the event of compromises;
  • developing annual plans outlining actions introduced to improve preventive defense capacity, reducing risks related to remote access to the Foundation's systems;
  • providing training programmes to improve and keep up-to-date staff skills in terms of security.

 

GARR Conf 20/05/26

LAUNCH EVENT 20/02/25