STEP SPA has officially adopted its Corporate Cybersecurity Policy, fully implementing EU Directive 2022/2555 “NIS2” and Legislative Decree 138/2024. The new Model, developed with support from Galli Data Service, aims to protect the company’s IT systems from internal and external threats, ensuring business continuity and regulatory compliance.
The policy applies to employees, suppliers, and collaborators, and includes technical, organizational, and training measures to strengthen digital resilience. Key objectives include incident prevention, risk management, and enhanced security at both national and European levels.
STEP is also committed to providing regular updates and periodic monitoring to continuously improve its Cybersecurity posture.