The Emilia Chamber of Commerce funds 50% (up to €10,000) of cloud, cybersecurity and digitalisation projects for SMEs in Parma, Piacenza and Reggio Emilia. Applications from 20 to 30 July, processed in chronological order: the dates, the supplier rule, the mandatory Selfi4.0 report and the comparison with the MIMIT voucher.
On Tuesday 14 July SQL Server 2016 receives the final security updates of its life: after that, every new vulnerability stays open forever. How to find hidden instances (the SQL Express installs inside business applications), apply the last patch everywhere and choose the path — upgrade, Azure SQL or ESU via Azure Arc.
A WireGuard-based overlay network connects users, servers and sites with direct encrypted tunnels, with no VPN concentrators exposed on the Internet. How it works, what the control plane really sees — keys, policies, topology — and why the decisive question is where it lives and which jurisdiction it answers to. With an honest comparison with Microsoft Entra Private Access.
The UniFi controller is the management plane of the entire network: where it lives determines who updates it, who backs it up and where its data ends up. The four options compared — on-site CloudKey, self-hosted, Official UniFi Hosting, managed hosting — with the criteria that matter: backups, updates, data residency.
On 14 July SQL Server 2016 leaves extended support: no more security patches. The three paths for SMEs — upgrading to SQL Server 2022, Azure SQL, Extended Security Updates via Azure Arc — plus the parallel Windows 10 chapter, with concrete steps to set up the transition.
Sign in to Windows with a FIDO2 key and a fingerprint, without a password, on Entra hybrid joined PCs managed by Intune, with SSO to on-premises resources via Entra Kerberos. Architecture, user experience (fingerprint only) and the real limits, from a real case.
What disaster recovery is, why it is not the same as backup, what a DR plan contains and how it is measured with RPO and RTO. The ransomware test and the role of the cloud, for SMEs.
From July 2026, Microsoft 365 Business mailboxes grow from 50 to 100 GB. But capacity is not retention: why email archiving is still needed for retention, immutability, legal hold and recovery — and why the archive stays at 50 GB on the Business plans.
A company handling health data on behalf of US clients is a Business Associate under HIPAA: a BAA is required, a US datacenter is not, and HIPAA certification does not exist. The mapping to ISO 27001, the HHS cloud guidance and the upcoming Security Rule update.
The largest Patch Tuesday ever: around 200 vulnerabilities fixed, 33 critical, six zero-days closed (including GreenPlasma, YellowKey and HTTP/2 Bomb). And if printing stopped working on Windows Server 2022, the culprit is hotpatch KB5087424. What to install, what to verify and what remains exposed.
Microsoft Entra Kerberos lets Azure Virtual Desktop and FSLogix profiles on Azure Files run without a domain controller: it is still Kerberos, but the tickets are issued by the cloud rather than by Active Directory. How it really works, hybrid vs cloud-only, and which companies it makes sense for.
Microsoft will disable NTLM by default. IAKerb and LocalKDC bring Kerberos to scenarios that used to fall back to NTLM: local accounts, domains with no line of sight to the KDC, heterogeneous environments with NAS and macOS. How it works, why it is a zero-trust matter and what to do today.
The Italian CSIRT reports systematic Qilin ransomware campaigns against Italian SMEs: access via VPN appliances without MFA, encryption of VMware ESXi hypervisors and backup neutralisation. The 5-step kill chain and the 5 countermeasures to defend your business.
End-to-end managed service or platform-only delivery on which the internal IT team operates autonomously: differences, five decision questions, the hybrid model and compliance coverage for NIS2 (art. 21 of Italian Legislative Decree 138/2024), ISO/IEC 27001:2022 A.8.13 / A.5.30 and DORA.
May 2026 unauthenticated RCEs in Cisco SD-WAN (CVE-2026-20182) and Fortinet (AL04/260513) expose the limits of the VPN model. What ZTNA is, how Microsoft Entra Private Access works, a 6-step migration path and NIS2 + ISO 27001:2022 coverage.
On 24 May 2026 Regulation (EU) 2016/679 turns ten. More than €6 billion in fines across Europe, €311 million in Italy spread over 538 cases: a story of continuous evolution. In many SMEs, however, privacy is still seen as a bureaucratic chore handled by non-specialist consultants. Balance, real cases, and convergence with NIS2 and ISO 27001.
ACN FAQs FRN.5–FRN.10 (18 May 2026) clarify intermediated supply (FRN.8) and intra-group suppliers (FRN.9). What to do by 31 May 2026 for the annual update of NIS entities on the ACN platform.
CVE-2026-42897, an XSS vulnerability in Outlook Web Access on Exchange Server 2016/2019/SE: active exploitation in the wild, no official patch and CISA KEV listing. What to do today and why Microsoft 365 closes the problem at its root.
ISO/IEC 27001:2022 is a solid foundation for NIS2 compliance but it is not sufficient. Seven operational gaps with Legislative Decree 138/2024, the entity vs supplier distinction with contractual cascade, personal liability of company top management and a three-horizon roadmap for those already certified.
EU Regulation 2024/2847: the CE mark comes to software, IoT and connected devices. ENISA vulnerability notification within 24h from 11 September 2026, full application from 11 December 2027. What changes for European SMEs that buy software.
SMTP relies on opportunistic StartTLS, which is vulnerable to downgrade attacks. MTA-STS (RFC 8461) and DANE (RFC 7672) make TLS mandatory between mail servers. Microsoft Exchange Online has rolled out outbound DANE. A practical rollout path for your organisation.
A real 2026 case: an IT vendor asks for a permanent VPN into a client network to manage a phone system. The right answer is not technical, it is risk governance. What NIS2, GDPR and ISO 27001 say about the IT supply chain, and why it matters for accountants, lawyers and SMEs well beyond NIS2 entities.
At the Clusit event of 29 April 2026 ACN clarified categorisation of activities, non-fungible suppliers, the 24-hour window starting from evidence and the responsibility of management bodies. NIS2 enters the phase of real risk governance.
Microsoft’s KB5082063 April 2026 update sends domain controllers into LSASS reboot loops and triggers unexpected BitLocker recovery prompts on Windows Server 2016/2019/2022/2025. Symptoms, mitigations and operational checklist.
Italy’s CSIRT reports a surge in attacks on SCADA, IoT and industrial systems exposed via VNC on the Internet. Weak encryption, brute force, hacktivism. Mitigations and Zero Trust checklist for SMEs.
Italy’s ACN determination 155238/2026 introduces 10 macro-areas and 4 relevance categories for NIS2 entities. Mandatory submission on the ACN platform from 1 May to 30 June 2026.
How much does a business server really cost? The 5 line items that drive real TCO: hardware (only 30-40%), electricity, IT staff time (20-25%), licensing, maintenance. When cloud rental really wins.
May 7, 2026 is World Password Day. Passkeys supported by M365, Google, Apple and GitHub, SMS/TOTP MFA no longer enough, NIST PQC standards since 2024. Three concrete actions for your business in 2026.
The US CLOUD Act allows extraterritorial access to data hosted by American providers, even in Europe. What changes with Schrems II, the Data Privacy Framework and EU Data Boundary.
Italy’s CSIRT has reported an OAuth campaign against Microsoft 365 that bypasses MFA. Consent Phishing and Device Code Grant: mechanism, risks and practical Entra ID countermeasures.
Digitally signed documents without a timestamp stop being verifiable when the certificate expires. Why publishing them online is risky and how to correctly apply CAdES-T for PA supplies.
From 14 April 2026, the Active Directory KDC no longer issues Kerberos RC4 tickets. Legacy service accounts, NAS with keytabs and non-Windows devices may stop authenticating. How to check and migrate to AES.
Italy’s CSIRT has confirmed 13 Akira ransomware incidents against Italian SMEs in early 2026. Unpatched perimeter firewalls and SSL VPN gateways remain the main vector. What to do today.
Ten-year civil obligations, electronic invoicing, GDPR, NIS2 and Italian PEC: in 2026 corporate email must be retained in an immutable, signed and searchable way. Mailbox backup is no longer enough.
The Italian National Cybersecurity Agency (ACN) has awarded the QC1 qualification to ATWS Email Security Gateway (SA-7582) and ATWS Secure Backup for Microsoft 365 (SA-7583). Valid for 36 months.
Software vendors with sysadmin access, overlapping backup tools, no governance. The database server in SMEs is the most critical and least controlled system. How to regain control.
CVE-2026-3098 in Smart Slider 3 exposes 500,000 WordPress sites. But the problem is not the individual plugin: it’s the architecture itself. Why static sites on cloud infrastructure are the alternative.
Over 90% of cyber attacks begin with an email. How an email security gateway with Libraesva protects business mailboxes from phishing, BEC and malware.
80% of breaches start with compromised credentials. MFA, Conditional Access and Zero Trust: how to protect digital identities and comply with NIS2 and DORA.
Over 85% of malware uses DNS to communicate with C2 servers. How Azure DNS Security Policy protects enterprise DNS resolution: filtering, DNSSEC, monitoring and NIS2 compliance.
NIS2 requires a CSIRT contact point and strict incident notification timelines. For SMEs without a dedicated team, an outsourced CSIRT is the solution to achieve compliance without building internal capabilities.
OEMs increasingly require TISAX compliance from their suppliers. For automotive supply chain companies in Piacenza and Emilia-Romagna, getting prepared is a competitive priority.
+49% cyber incidents in 2025. Italy accounts for 9.6% of global attacks with 507 serious incidents. Manufacturing +79%, healthcare +19%. Key findings and what they mean for SMEs.
60% of SMEs that lose their data close within 6 months. The 5 most common mistakes, the 3-2-1-1-0 rule and how to truly protect your business with tested, resilient backups.
The free cybersecurity self-assessment at nist.atws.app is now available in three languages: Italian, English and German. Same 106 questions based on NIST CSF 2.0, with a fully localised interface and report.
The Zscaler report on 1,750 IT leaders and the WEF confirm: corporate security strategies are still too inward-focused. The new perimeter is user identity.
MIMIT voucher, NIS2 deadlines and Exchange 2016 end of support: three concrete reasons to migrate email and files to Microsoft 365 in 2026. A practical guide for SMEs.
Average score 55/100, only 16% of SMEs classified as mature, and 1 in 4 hit by a breach in the past three years. Key findings from the third Cyber Index PMI report.
ATWS has applied to register as a supplier for the MIMIT 2026 voucher programme. Non-repayable grants up to €20,000 for cloud and cybersecurity services for SMEs and professionals.
Our free self-assessment tool based on the NIST CSF 2.0 framework is now available. 106 questions, instant report and analysis of your organisation’s security posture.
ACN qualification request submitted for the SaaS backup service for Microsoft 365. Protection of Exchange, SharePoint, OneDrive and Teams with encrypted EU storage.
ACN qualification request submitted for the email security gateway. Filtering, antispam, antivirus and configurable policies on European cloud infrastructure.
ATWS Secure Workspace is ACN-qualified and listed in the Cloud Catalogue for the Italian Public Administration. Secure SaaS desktop with MFA and EU-only data.