Insights

News and Insights

Practical guides, analysis and updates on cloud, cybersecurity and IT for businesses. Search by topic or keyword.

·

Digital Innovation Grant 2026 (PI26): 50% non-repayable funding for SMEs in Emilia

The Emilia Chamber of Commerce funds 50% (up to €10,000) of cloud, cybersecurity and digitalisation projects for SMEs in Parma, Piacenza and Reggio Emilia. Applications from 20 to 30 July, processed in chronological order: the dates, the supplier rule, the mandatory Selfi4.0 report and the comparison with the MIMIT voucher.

Read the article
·

SQL Server 2016: the last patches ever arrive on 14 July. This week’s checklist

On Tuesday 14 July SQL Server 2016 receives the final security updates of its life: after that, every new vulnerability stays open forever. How to find hidden instances (the SQL Express installs inside business applications), apply the last patch everywhere and choose the path — upgrade, Azure SQL or ESU via Azure Arc.

Read the article
·

WireGuard overlay network: replace the corporate VPN without exposing anything

A WireGuard-based overlay network connects users, servers and sites with direct encrypted tunnels, with no VPN concentrators exposed on the Internet. How it works, what the control plane really sees — keys, policies, topology — and why the decisive question is where it lives and which jurisdiction it answers to. With an honest comparison with Microsoft Entra Private Access.

Read the article
·

Where to host the UniFi controller: self-hosted, CloudKey, official hosting or managed

The UniFi controller is the management plane of the entire network: where it lives determines who updates it, who backs it up and where its data ends up. The four options compared — on-site CloudKey, self-hosted, Official UniFi Hosting, managed hosting — with the criteria that matter: backups, updates, data residency.

Read the article
·

SQL Server 2016: support ends on 14 July 2026 — ESU, Azure Arc and how to migrate

On 14 July SQL Server 2016 leaves extended support: no more security patches. The three paths for SMEs — upgrading to SQL Server 2022, Azure SQL, Extended Security Updates via Azure Arc — plus the parallel Windows 10 chapter, with concrete steps to set up the transition.

Read the article
·

Passwordless Windows login with FIDO2: how to do it on hybrid PCs managed by Intune

Sign in to Windows with a FIDO2 key and a fingerprint, without a password, on Entra hybrid joined PCs managed by Intune, with SSO to on-premises resources via Entra Kerberos. Architecture, user experience (fingerprint only) and the real limits, from a real case.

Read the article
·

Exchange Online moves to 100 GB: do you still need email archiving?

From July 2026, Microsoft 365 Business mailboxes grow from 50 to 100 GB. But capacity is not retention: why email archiving is still needed for retention, immutability, legal hold and recovery — and why the archive stays at 50 GB on the Business plans.

Read the article
·

HIPAA for Italian companies serving US clients: what it actually takes

A company handling health data on behalf of US clients is a Business Associate under HIPAA: a BAA is required, a US datacenter is not, and HIPAA certification does not exist. The mapping to ISO 27001, the HHS cloud guidance and the upcoming Security Rule update.

Read the article
·

June 2026 Patch Tuesday: 200 vulnerabilities, six zero-days and the KB5087424 printing bug

The largest Patch Tuesday ever: around 200 vulnerabilities fixed, 33 critical, six zero-days closed (including GreenPlasma, YellowKey and HTTP/2 Bomb). And if printing stopped working on Windows Server 2022, the culprit is hotpatch KB5087424. What to install, what to verify and what remains exposed.

Read the article
·

Azure Virtual Desktop without Active Directory: how it works and when it makes sense

Microsoft Entra Kerberos lets Azure Virtual Desktop and FSLogix profiles on Azure Files run without a domain controller: it is still Kerberos, but the tickets are issued by the cloud rather than by Active Directory. How it really works, hybrid vs cloud-only, and which companies it makes sense for.

Read the article
·

Goodbye NTLM: Kerberos everywhere with IAKerb, LocalKDC and what to do now

Microsoft will disable NTLM by default. IAKerb and LocalKDC bring Kerberos to scenarios that used to fall back to NTLM: local accounts, domains with no line of sight to the KDC, heterogeneous environments with NAS and macOS. How it works, why it is a zero-trust matter and what to do today.

Read the article
·

Qilin ransomware: how it attacks Italian SMEs and how to defend against it

The Italian CSIRT reports systematic Qilin ransomware campaigns against Italian SMEs: access via VPN appliances without MFA, encryption of VMware ESXi hypervisors and backup neutralisation. The 5-step kill chain and the 5 countermeasures to defend your business.

Read the article
·

Managed backup vs. backup platform: how internal IT should choose

End-to-end managed service or platform-only delivery on which the internal IT team operates autonomously: differences, five decision questions, the hybrid model and compliance coverage for NIS2 (art. 21 of Italian Legislative Decree 138/2024), ISO/IEC 27001:2022 A.8.13 / A.5.30 and DORA.

Read the article
·

ZTNA: how to replace the corporate VPN with Zero Trust Network Access

May 2026 unauthenticated RCEs in Cisco SD-WAN (CVE-2026-20182) and Fortinet (AL04/260513) expose the limits of the VPN model. What ZTNA is, how Microsoft Entra Private Access works, a 6-step migration path and NIS2 + ISO 27001:2022 coverage.

Read the article
·

Ten years of GDPR: a balance sheet for Italian SMEs and the road ahead with NIS2 and the AI Act

On 24 May 2026 Regulation (EU) 2016/679 turns ten. More than €6 billion in fines across Europe, €311 million in Italy spread over 538 cases: a story of continuous evolution. In many SMEs, however, privacy is still seen as a bureaucratic chore handled by non-specialist consultants. Balance, real cases, and convergence with NIS2 and ISO 27001.

Read the article
·

ISO 27001 and NIS2: is certification enough for compliance?

ISO/IEC 27001:2022 is a solid foundation for NIS2 compliance but it is not sufficient. Seven operational gaps with Legislative Decree 138/2024, the entity vs supplier distinction with contractual cascade, personal liability of company top management and a three-horizon roadmap for those already certified.

Read the article
·

Cyber Resilience Act: how to prepare for CE marking of software by 2027

EU Regulation 2024/2847: the CE mark comes to software, IoT and connected devices. ENISA vulnerability notification within 24h from 11 September 2026, full application from 11 December 2027. What changes for European SMEs that buy software.

Read the article
·

NIS2: ACN clarifications from the Clusit event of 29 April 2026

At the Clusit event of 29 April 2026 ACN clarified categorisation of activities, non-fungible suppliers, the 24-hour window starting from evidence and the responsibility of management bodies. NIS2 enters the phase of real risk governance.

Read the article
·

Buy or rent a server: how to calculate the real TCO

How much does a business server really cost? The 5 line items that drive real TCO: hardware (only 30-40%), electricity, IT staff time (20-25%), licensing, maintenance. When cloud rental really wins.

Read the article
·

US CLOUD Act and data sovereignty: why choose European datacentres

The US CLOUD Act allows extraterritorial access to data hosted by American providers, even in Europe. What changes with Schrems II, the Data Privacy Framework and EU Data Boundary.

Read the article
·

OAuth Consent Phishing on Microsoft 365: how it bypasses MFA

Italy’s CSIRT has reported an OAuth campaign against Microsoft 365 that bypasses MFA. Consent Phishing and Device Code Grant: mechanism, risks and practical Entra ID countermeasures.

Read the article
·

Email archiving: why legal retention is no longer optional

Ten-year civil obligations, electronic invoicing, GDPR, NIS2 and Italian PEC: in 2026 corporate email must be retained in an immutable, signed and searchable way. Mailbox backup is no longer enough.

Read the article
·

Corporate database server: who has the keys to your data?

Software vendors with sysadmin access, overlapping backup tools, no governance. The database server in SMEs is the most critical and least controlled system. How to regain control.

Read the article
·

WordPress vulnerability: the problem is the architecture, not the plugin

CVE-2026-3098 in Smart Slider 3 exposes 500,000 WordPress sites. But the problem is not the individual plugin: it’s the architecture itself. Why static sites on cloud infrastructure are the alternative.

Read the article
·

DNS Security: Protecting Enterprise DNS Resolution with Azure

Over 85% of malware uses DNS to communicate with C2 servers. How Azure DNS Security Policy protects enterprise DNS resolution: filtering, DNSSEC, monitoring and NIS2 compliance.

Read the article
·

NIST Assessment now available in Italian, English and German

The free cybersecurity self-assessment at nist.atws.app is now available in three languages: Italian, English and German. Same 106 questions based on NIST CSF 2.0, with a fully localised interface and report.

Read the article
·

How to choose an IT company in Piacenza

Certifications, vendor independence, cloud and cybersecurity expertise: concrete criteria for evaluating an IT partner in Piacenza.

Read the article
·

Cybersecurity, AI and cloud: weekly news roundup

Trivy compromised twice in a month, NVIDIA reaches 1 million GPUs in AI factories, Tycoon 2FA dismantled and AWS-Google launch multicloud networking.

Read the article
·

Why 2026 is the right time to migrate to Microsoft 365

MIMIT voucher, NIS2 deadlines and Exchange 2016 end of support: three concrete reasons to migrate email and files to Microsoft 365 in 2026. A practical guide for SMEs.

Read the article
·

Cyber Index PMI 2026: the cyber maturity of Italian SMEs

Average score 55/100, only 16% of SMEs classified as mature, and 1 in 4 hit by a breach in the past three years. Key findings from the third Cyber Index PMI report.

Read the article
·

MIMIT Cloud and Cybersecurity Voucher 2026

ATWS has applied to register as a supplier for the MIMIT 2026 voucher programme. Non-repayable grants up to €20,000 for cloud and cybersecurity services for SMEs and professionals.

Read the article