Your partner for cybersecurity and operational continuity
We defend, test and keep running the infrastructure your business depends on every day: a SOC staffed around the clock, offensive testing, disaster recovery, and the compliance work European regulation now demands.
- SOC staffed 24/7
- Two data centres, one governance
- PECB-certified expertise
Defence and resilience
Keeping attackers out, and restoring services quickly when an incident does occur.
Managed security and SOC
Round-the-clock monitoring of endpoints, networks and critical services, with threat intelligence, recurring vulnerability assessment and incident response. Industrial IT/OT environments included.
Business continuity
Risk analysis, business impact analysis and continuity plans written to be followed under pressure. Clear roles, failover procedures and regular exercises that test the plan before an incident does.
Disaster recovery as a service
Geo-redundant replication between the two data centres, automated backups and restores that are verified, not merely documented. RTO and RPO targets are set contractually for each service tier.
Secure hosting
Infrastructure designed around the requirements placed on essential and important entities: segmentation, risk management, logging, and support for incident notification duties.
Hybrid cloud
Architectures that hold on-premise and public cloud together without multiplying blind spots: clean integration, unified governance and consistent controls across every environment.
Compliance and governance
Alignment with NIS 2 and the Cyber Resilience Act: gap analysis, technical and organisational measures, staff training and support with ACN notifications. The engagement concludes with verifiable evidence that the required measures have been implemented effectively.
Offensive security
Identifying and remediating vulnerabilities before they can be exploited.
Penetration testing and vulnerability assessment
Controlled offensive testing across infrastructure, applications and networks. Every finding comes with proof, a real-world impact and a remediation priority — and the retest is included.
Red team and blue team
Realistic attack and defence exercises: the red team behaves like a real adversary while the blue team tries to spot and stop it. The result is a measurement of the time between intrusion and response.
SAST, DAST and code review
Static and dynamic code analysis, supplemented by manual review where specialist assessment is required. Integration into CI/CD pipelines allows issues to be identified before release.
Blockchain security
Smart contract audits, on-chain vulnerability analysis and security reviews of wallets, Web3 infrastructure and exchange platforms.
Our own solutions
Four solutions designed, implemented and managed directly by DEC for recurring security, training, document exchange and compliance requirements.
CyberShield
Managed security as a single service: continuous detection and response, emergency intervention when an incident hits, and business continuity. One point of contact to prevent, detect, respond and restore.
PhishGuard
Governed phishing and smishing simulations, targeted training and human-risk measurement. Authorised campaigns, department-level results and integration with directories, delivery systems and training platforms.
SecureShare
End-to-end encrypted file transfer. Documents are encrypted on the sender's device, so the server holds ciphertext only and cannot read what is inside. Deployable on your own infrastructure, under your own brand if you prefer.
Whistleblowing
The internal reporting channel that Legislative Decree 24/2023 makes mandatory, white-labelled: technical anonymity over Tor if needed, encrypted reports, statutory deadlines tracked. Under your own brand, on our infrastructure or on yours.
Ransomware negotiation and response
When an attack is already under way, clear and timely decisions are essential. Our role is to provide method, coordination and decision-making capability even in the most critical situations.
Advance preparation
Simulations, tabletop exercises and negotiation playbooks are prepared in advance. Roles, delegated authority and decision criteria are defined before an emergency occurs.
Negotiation management
Profiling the counterparty, weighing what they are asking for and setting the strategy. Every exchange is structured and logged, so control of the process stays with you.
Service restoration
Negotiation does not stand alone: it has to move in step with the technical response and the disaster recovery plan. The goal throughout is less downtime, less financial damage and less reputational damage.
Paying is never the starting point. Before any contact with the counterparty we check that a payment would not be barred by EU restrictive measures or other sanctions lists: moving funds to a sanctioned entity is a criminal offence, whatever the circumstances. We work alongside your lawyers, coordinate the report to the Polizia Postale and the notifications owed to ACN, and in most cases the objective remains recovering without paying.
DDoS attack simulation
A progressive methodology to identify perimeter vulnerabilities, verify that mitigation services meet their stated performance levels and SLAs, and reduce the risk of operational disruption.
Defence validation
Controlled simulations at increasing intensity, designed to surface misconfigurations and weak spots in your network protections.
Provider SLA validation
The performance levels stated by mitigation providers are validated through realistic, measurable test scenarios.
Response exercises
The team rehearses the actual procedures under pressure, so that when an attack does arrive nobody has to improvise.
Nothing starts without written authorisation. A test of this kind is run only against systems the company owns or holds a mandate for, and only once formally authorised by someone entitled to grant it. Before we begin we agree the scope, the time windows, the thresholds and the criteria for stopping immediately, and we notify the hosting providers, carriers and mitigation services involved: without their consent a realistic test is indistinguishable from an attack, and carries the same legal consequences.
The European regulatory deadlines
NIS 2 and the Cyber Resilience Act are already in force. This is the state of the deadlines, including the ones still open.
NIS 2 Directive
Entry into force
Legislative Decree 138/2024 comes into force, and organisations have to start working out whether it applies to them.
ACN registration
The registration window on the ACN platform for essential and important entities.
Notification of inclusion
ACN confirms inclusion in the NIS 2 lists, and the compliance clock starts from that moment.
Incident notification becomes binding
The deadline for having working incident-notification procedures in place has passed: nine months from the ACN notification.
Full compliance
The final deadline — eighteen months — to have the risk-management measures fully implemented.
Cyber Resilience Act — Regulation (EU) 2024/2847
Mandatory cybersecurity requirements for products with digital elements placed on the European market.
Entry into force
The Regulation comes into force and the transition period opens for manufacturers, importers and distributors.
Conformity assessment bodies
The provisions on notifying conformity assessment bodies start to apply.
Reporting obligations
The duty to report actively exploited vulnerabilities and severe security incidents takes effect (Art. 14).
Full application
The essential requirements apply in full: security by design, vulnerability handling, conformity assessment and CE marking.
Two data centres for infrastructure resilience
Resilience is not an address on a map. It is a design decision.
Effective redundancy
Two physically separate data centres, in Milan and Gorizia. No single point of failure, and far less exposure to anything that takes out one location.
Continuity under stress
Replication between the two sites, controlled failover and regularly verified procedures. The effectiveness of a continuity plan depends on periodic validation through operational testing.
Risk kept in check
Separated infrastructure, a single governance model and centralised monitoring: two sites to defend, but one place from which to oversee them both.
Identity and working method
Global expertise, kept close to the people who rely on it.
What we set out to do
DEC works across Italy and Europe on a distributed infrastructure model, bringing cybersecurity, business continuity and disaster recovery together under a single chain of responsibility.
Our goal is not to occupy a territory, but to give the organisations we defend infrastructure that is reliable, scalable and compliant, and the means to prove it.
The experience we have built up on strategic infrastructure is applied with an engineering mindset: governance, control and continuous operation, around the clock.
DEC is an independent company, wholly Italian-owned: no investment fund and no group based outside the European Union holds a stake in it. There is no foreign parent that could dispose of our infrastructure or of the data you entrust to us, and the data centres we operate from are in Italy, under Italian and European law.
For essential and important entities, the supply chain falls within the risk assessment NIS 2 requires: who controls a supplier, and the jurisdiction it answers to, belongs in that assessment.
Dal 2017
Defending critical infrastructure
24/7
SOC in operation
100% Italian
Ownership and control, with no foreign funds
Our principles
- Independence: wholly Italian-owned, no non-EU investors, decisions taken in Italy
- Pragmatism: current technologies selected according to the objectives and specific requirements of each project
- Reliability: contractual SLAs, clearly defined responsibilities and directly accessible contacts
- Proximity: a local presence combined with expertise developed through international projects
- Compliance: certified expertise in NIS 2 and EU regulation, as a PECB Authorized Partner
Contact
Whether the requirement concerns an incident under way, an assessment, a continuity plan or a compliance programme, the initial discussion establishes priorities and scope. We will assess the context provided and propose the most appropriate approach.
We reply within one business day. If you would rather write or call us directly, here is where to find us:
- Via Lanzone, 31 — 20123 Milan (Italy)
- Corso Verdi, 22 — 34170 Gorizia (Italy)
- Unit G, Oldenway Business Park — Ballybrit, Galway H91 E65V (Ireland)