SEA Vision has been officially classified as an “important entity” under Italy’s Legislative Decree 138/2024, which transposes the European NIS2 directive. This designation requires us to implement solid technical and organizational cybersecurity measures to increase resilience and comply with the new regulatory baseline.
The company has met the initial regulatory deadlines regarding information sharing with the National Cybersecurity Agency by defining responsibilities, completing gap analysis, training plan and updating its cybersecurity incident management procedure.
SEA Vision has launched a certification roadmap for ISO 27001:2022 and IEC 62443‑4‑1, with the goal of achieving both certifications by October 2026, in line with NIS2 deadlines.
Ludwig Feuerbach once said, “We are what we eat".
But in today’s digital world — especially in 2026 — a more accurate version would be:
"We are the data we generate".
For individuals, losing control of personal data means identity theft, financial fraud and emotional distress.
For organizations the impact is exponentially greater:
And the more data you manage, the higher the stakes.
So the real question pharma software companies should ask is no longer:
“Could we be hacked?”
but rather:
“Do we truly understand the risks surrounding our data and are we prepared to manage them?”
To address the growing threat landscape, the EU introduced Directive 2022/2555 (NIS2) — the most comprehensive cybersecurity legislation implemented in Europe to date.
Effective at EU level since January 17, 2023, NIS2’s objectives are to:
Italy transposed the directive with:
ACN is responsible for compliance, requirements and enforcement.
NIS2 expands its perimeter significantly:
Pharma stakeholders, including software providers supporting pharmaceutical processes, are fully included.
This means pharma software companies are officially recognized as essential or important entities.
NIS2 is not a checklist. It’s a strategic shift in how organizations manage cyber risk.
Companies must implement robust frameworks and controls, including:
Significant incidents must be reported to ACN within 24 hours, followed by ongoing updates. This demands real‑time monitoring capabilities.
Organizations must be able to:
Cybersecurity is not only a technical issue — it is a cultural one.
NIS2 mandates:
In the healthcare sector, the data speaks for itself: in Q1 2025, nearly one‑third of all security incidents were linked to hacktivism.
Main attack techniques included:
This trend highlights how healthcare and pharma remain primary targets due to the criticality — and value — of the data they manage.
In pharma, cybersecurity is no longer just a requirement: it’s a responsibility. Frameworks like NIS2, IEC 62443 and ISO/IEC 27001 set the foundation for true operational resilience, but the real value comes from actively embracing them.