Contact DEC
Language: IT EN

Your partner for cybersecurity and operational continuity

We defend, test and keep running the infrastructure your business depends on every day: a SOC staffed around the clock, offensive testing, disaster recovery, and the compliance work European regulation now demands.

  • SOC staffed 24/7
  • Two data centres, one governance
  • PECB-certified expertise

Defence and resilience

Keeping attackers out, and restoring services quickly when an incident does occur.

Managed security and SOC

Round-the-clock monitoring of endpoints, networks and critical services, with threat intelligence, recurring vulnerability assessment and incident response. Industrial IT/OT environments included.

Business continuity

Risk analysis, business impact analysis and continuity plans written to be followed under pressure. Clear roles, failover procedures and regular exercises that test the plan before an incident does.

Disaster recovery as a service

Geo-redundant replication between the two data centres, automated backups and restores that are verified, not merely documented. RTO and RPO targets are set contractually for each service tier.

Secure hosting

Infrastructure designed around the requirements placed on essential and important entities: segmentation, risk management, logging, and support for incident notification duties.

Hybrid cloud

Architectures that hold on-premise and public cloud together without multiplying blind spots: clean integration, unified governance and consistent controls across every environment.

Compliance and governance

Alignment with NIS 2 and the Cyber Resilience Act: gap analysis, technical and organisational measures, staff training and support with ACN notifications. The engagement concludes with verifiable evidence that the required measures have been implemented effectively.

Offensive security

Identifying and remediating vulnerabilities before they can be exploited.

Penetration testing and vulnerability assessment

Controlled offensive testing across infrastructure, applications and networks. Every finding comes with proof, a real-world impact and a remediation priority — and the retest is included.

Red team and blue team

Realistic attack and defence exercises: the red team behaves like a real adversary while the blue team tries to spot and stop it. The result is a measurement of the time between intrusion and response.

SAST, DAST and code review

Static and dynamic code analysis, supplemented by manual review where specialist assessment is required. Integration into CI/CD pipelines allows issues to be identified before release.

Blockchain security

Smart contract audits, on-chain vulnerability analysis and security reviews of wallets, Web3 infrastructure and exchange platforms.

Our own solutions

Four solutions designed, implemented and managed directly by DEC for recurring security, training, document exchange and compliance requirements.

CyberShield

Managed security as a single service: continuous detection and response, emergency intervention when an incident hits, and business continuity. One point of contact to prevent, detect, respond and restore.

Explore the service

PhishGuard

Governed phishing and smishing simulations, targeted training and human-risk measurement. Authorised campaigns, department-level results and integration with directories, delivery systems and training platforms.

View the platform

SecureShare

End-to-end encrypted file transfer. Documents are encrypted on the sender's device, so the server holds ciphertext only and cannot read what is inside. Deployable on your own infrastructure, under your own brand if you prefer.

Review the features

Whistleblowing

The internal reporting channel that Legislative Decree 24/2023 makes mandatory, white-labelled: technical anonymity over Tor if needed, encrypted reports, statutory deadlines tracked. Under your own brand, on our infrastructure or on yours.

Explore the service

Ransomware negotiation and response

When an attack is already under way, clear and timely decisions are essential. Our role is to provide method, coordination and decision-making capability even in the most critical situations.

Advance preparation

Simulations, tabletop exercises and negotiation playbooks are prepared in advance. Roles, delegated authority and decision criteria are defined before an emergency occurs.

Negotiation management

Profiling the counterparty, weighing what they are asking for and setting the strategy. Every exchange is structured and logged, so control of the process stays with you.

Service restoration

Negotiation does not stand alone: it has to move in step with the technical response and the disaster recovery plan. The goal throughout is less downtime, less financial damage and less reputational damage.

Paying is never the starting point. Before any contact with the counterparty we check that a payment would not be barred by EU restrictive measures or other sanctions lists: moving funds to a sanctioned entity is a criminal offence, whatever the circumstances. We work alongside your lawyers, coordinate the report to the Polizia Postale and the notifications owed to ACN, and in most cases the objective remains recovering without paying.

DDoS attack simulation

A progressive methodology to identify perimeter vulnerabilities, verify that mitigation services meet their stated performance levels and SLAs, and reduce the risk of operational disruption.

Defence validation

Controlled simulations at increasing intensity, designed to surface misconfigurations and weak spots in your network protections.

Provider SLA validation

The performance levels stated by mitigation providers are validated through realistic, measurable test scenarios.

Response exercises

The team rehearses the actual procedures under pressure, so that when an attack does arrive nobody has to improvise.

Nothing starts without written authorisation. A test of this kind is run only against systems the company owns or holds a mandate for, and only once formally authorised by someone entitled to grant it. Before we begin we agree the scope, the time windows, the thresholds and the criteria for stopping immediately, and we notify the hosting providers, carriers and mitigation services involved: without their consent a realistic test is indistinguishable from an attack, and carries the same legal consequences.

The European regulatory deadlines

NIS 2 and the Cyber Resilience Act are already in force. This is the state of the deadlines, including the ones still open.

days

left until the deadline for fully implementing the risk-management measures required by the NIS 2 Directive. The registration and incident-notification deadlines have already passed.

NIS 2 Directive

October 2024 Done

Entry into force

Legislative Decree 138/2024 comes into force, and organisations have to start working out whether it applies to them.

January – February 2025 Done

ACN registration

The registration window on the ACN platform for essential and important entities.

April 2025 Done

Notification of inclusion

ACN confirms inclusion in the NIS 2 lists, and the compliance clock starts from that moment.

January 2026 Done

Incident notification becomes binding

The deadline for having working incident-notification procedures in place has passed: nine months from the ACN notification.

October 2026 Next

Full compliance

The final deadline — eighteen months — to have the risk-management measures fully implemented.

Cyber Resilience Act — Regulation (EU) 2024/2847

Mandatory cybersecurity requirements for products with digital elements placed on the European market.

10 December 2024 Done

Entry into force

The Regulation comes into force and the transition period opens for manufacturers, importers and distributors.

11 June 2026 Done

Conformity assessment bodies

The provisions on notifying conformity assessment bodies start to apply.

11 September 2026 Next

Reporting obligations

The duty to report actively exploited vulnerabilities and severe security incidents takes effect (Art. 14).

11 December 2027

Full application

The essential requirements apply in full: security by design, vulnerability handling, conformity assessment and CE marking.

Two data centres for infrastructure resilience

Resilience is not an address on a map. It is a design decision.

Effective redundancy

Two physically separate data centres, in Milan and Gorizia. No single point of failure, and far less exposure to anything that takes out one location.

Continuity under stress

Replication between the two sites, controlled failover and regularly verified procedures. The effectiveness of a continuity plan depends on periodic validation through operational testing.

Risk kept in check

Separated infrastructure, a single governance model and centralised monitoring: two sites to defend, but one place from which to oversee them both.

< 10 ms
Latency between the two data centres
99,99%
Availability target set per service tier
3
Carrier-neutral providers

Identity and working method

Global expertise, kept close to the people who rely on it.

What we set out to do

DEC works across Italy and Europe on a distributed infrastructure model, bringing cybersecurity, business continuity and disaster recovery together under a single chain of responsibility.

Our goal is not to occupy a territory, but to give the organisations we defend infrastructure that is reliable, scalable and compliant, and the means to prove it.

The experience we have built up on strategic infrastructure is applied with an engineering mindset: governance, control and continuous operation, around the clock.

DEC is an independent company, wholly Italian-owned: no investment fund and no group based outside the European Union holds a stake in it. There is no foreign parent that could dispose of our infrastructure or of the data you entrust to us, and the data centres we operate from are in Italy, under Italian and European law.

For essential and important entities, the supply chain falls within the risk assessment NIS 2 requires: who controls a supplier, and the jurisdiction it answers to, belongs in that assessment.

Dal 2017

Defending critical infrastructure

24/7

SOC in operation

100% Italian

Ownership and control, with no foreign funds

Our principles

  • Independence: wholly Italian-owned, no non-EU investors, decisions taken in Italy
  • Pragmatism: current technologies selected according to the objectives and specific requirements of each project
  • Reliability: contractual SLAs, clearly defined responsibilities and directly accessible contacts
  • Proximity: a local presence combined with expertise developed through international projects
  • Compliance: certified expertise in NIS 2 and EU regulation, as a PECB Authorized Partner

Contact

Whether the requirement concerns an incident under way, an assessment, a continuity plan or a compliance programme, the initial discussion establishes priorities and scope. We will assess the context provided and propose the most appropriate approach.

We reply within one business day. If you would rather write or call us directly, here is where to find us:

  • Via Lanzone, 31 — 20123 Milan (Italy)
  • Corso Verdi, 22 — 34170 Gorizia (Italy)
  • Unit G, Oldenway Business Park — Ballybrit, Galway H91 E65V (Ireland)

The information provided is used solely to respond to your enquiry. The processing arrangements are described in our privacy policy.