Security Summit Streaming Edition 2021 ended last week.

Organized by Clusit, the Italian Association for Information Security, and Astrea, an agency specializing in the organization of events in the field of Information Security, Security Summit is the event dedicated to promoting the culture of Cyber Security in Italy.

The November edition focused on current events: between data and analysis of new threats, the Clusit experts also explored the new role of the Intelligence and Defense of the Country System, with some of the protagonists of the political and security world that accompanied the birth of the National Cyber Security Agency.

In particular, during the plenary session on the first day of November 9, 2021, the Clusit Report on ICT Security in Italy in its October 2021 Edition was presented with our data on cyber attacks.

In the first half of 2021, we analyzed 1,053 cyber attacks, 24% more than in the same period of 2020, for a monthly average of 170 serious attacks (it was 156 in 2020).

Attacks carried out for Cybercrime purposes increased by 21%, which today represent 88% of the total.

Attacks related to Information Warfare are also growing (+ 18%), the so-called “information war”, while those related to Cyber Espionage activities apparently decrease (-36.7%), after the extraordinary peak of 2020 mainly due to espionage related to the development of vaccines and treatments for Covid-19.

Among the victims, the “Government” category represents 16% of the total and is confirmed in first place, as in the previous semester, while in second place we find Health, (13% of total attacks).

Attacks on the Transportation / Storage (+ 108.7%), Professional, Scientific, Technical (+ 85.2%), News & Multimedia (+ 65.2%), Wholesale / Retail (+61, 3%), Manufacturing (+ 46.9%), Energy / Utilities (+ 46.2%), Government (+ 39.2%), Arts / Entertainment (+ 36.8%), Healthcare (+18.8 %).

Attacks towards the “Multiple Targets” category decreased (-23.4%), which makes us understand the change of strategy by the attackers who at this point prefer targeted attacks and towards well-identified targets.

In the first half of 2021, attacks on European-based realities increase significantly: a quarter of the attacks are in fact directed towards this area (+ 9% compared to 2020).

The percentages of victims in the American area (almost half of the classified attacks) and those belonging to Asian organizations remain substantially unchanged.

On the other hand, serious attacks on targets with offices distributed in different countries decrease in percentage (16% in the first half of 2021, compared to 24% in 2020), which, once again, makes us understand how much attackers prefer to target more defined targets.

Malware is the most used technique, accounting for 43% of the total (up 10.5% over the previous year).

Unknown techniques (“Unknown” category) are in second place (+ 13.9%), surpassing the “Vulnerability” category, which is growing worryingly (+ 41.4%), and “Phishing / Social Engineering”, which is slightly down (-13%).

In essence, attackers can still rely on the effectiveness of Malware, produced industrially at decreasing costs, and on the exploitation of vulnerabilities, to hit two thirds of their targets (59% of the cases analyzed).

Furthermore, in the first half of 2021 attacks with very important and critical effects are 74% of the total (they were 49% in 2020), while 22% have a significant impact and only 4% low.

Basically, from the trends highlighted in the first 6 months of this year, it is evident that cyber attacks are constantly increasing, both in terms of frequency, criticality and impacts.

The situation can be defined as a global emergency: the losses due to damages caused by Cybercrime amounted to $6 trillion in 2021 and now account for a significant percentage of world GDP.

We hope that the new investments for the digital transition will represent an opportunity for Italy to catch up and fill its gaps also in the Cyber Security field, to lead to a significant reduction of the surface of the country’s attack.

Otherwise, the risk is to introduce new but insecure technology, with the result of worsening the Italian situation overall.

ECSM (European Cyber Security Month) is an initiative coordinated by Enisa (European Union Agency for Information Security) and the European Commission, with the aim of promoting Cyber Security through events and initiatives to raise awareness.

The campaign takes place every year in October and is supported by EU Member States and hundreds of European partners.

Since its first edition in 2012, the European Cyber Security Month has promoted its activities by adopting the slogan “Information Security is a shared responsibility”.

The EU Cyber Security Agency coordinates the organization of the ECSM campaign each year by acting as a “hub” for all Member States, EU institutions and participating organizations.

The 2021 edition is strongly influenced by the Covid-19 pandemic, which although it helped to spread the use of digital, on the other hand had put system security to a severe test.

The main objective is always to ensure that EU end users and organizations receive correct information about Cyber Security in order to understand risks and main threats.

#ThinkB4UClick (think before clicking) is therefore the main theme of this year’s campaign, in its 2 forms:

  • First aid, guidelines on what to do if you fall victim to a cyber attack
  • Be cyber-safe at home

Even this year the European Cyber Security Month will be supported in Italy by Clusit (Italian Association for Cyber Security) together with various organizations, universities and research centers.


You can find the list of initiatives promoted by the association for the ECSM2021 campaign in CLUSIT website.

As a member of the Clusit Scientific Committee, our CEO Sofia Scozzari is one of the Italian Partners for the ECSM2021 and she will participate with a series of events and initiatives.

To join the campaign, you can add an activity on the Cyber Security Month website or by sending it to Clusit.

You can also support the campaign online on Twitter or Facebook with references to @CyberSecMonth, #CyberSecMonth, #ThinkB4UClick

