PSI - Issue 84

Guerino Liberatore et al. / Procedia Structural Integrity 84 (2026) 702–708

704

operational model supported by a self-assessment checklist. This tool is designed to assist administrations in monitoring their internal coordination and readiness levels, ensuring that the transition from legislative theory to

operational practice is both measurable and continuous. 2. Security and Critical Infrastructure: an essential bond

The concept of security, etymologically derived from the Latin securitas - signifying a state free from care or anxiety - has undergone a profound transformation in modern institutional and corporate contexts. Historically, the term was broadly applied, but contemporary scholarly and operational frameworks necessitate a clear scientific demarcation between "safety" and "security". While safety pertains to protection against accidental events, environmental hazards, and non-intentional failures, security has emerged as a distinct discipline focused on safeguarding individuals, physical assets, and intangible data from deliberate and malicious acts, such as terrorism, sabotage, organized crime, and cyber-attacks (Jore, 2019). In the current landscape of national and international stability, security is no longer viewed merely as a reactive function but as a proactive component of systemic risk management. This shift is particularly evident in sectors of high strategic sensitivity, such as civil aviation, where the post-9/11 era has demanded a significant economic and structural effort to adapt security measures. For these infrastructures, the implementation of a Security Management System (SeMS) is crucial to supervise risk identification and the optimization of control measures. Critical infrastructures are defined by their systemic relevance: their disruption or destruction would entail significant cross sectoral impacts, jeopardizing public health, economic prosperity, and the continuous functioning of the State. Consequently, the operational declination of security within Critical Infrastructure (CI) management requires advanced risk assessment techniques to prevent incorrect risk quantification, which could severely compromise the overall security level (Tamasi and Demichela, 2011). This necessitates integrated planning tools designed to address both physical and cyber vulnerabilities. Within corporate risk taxonomies, "security risk" is often classified as a potential risk that demands a dedicated organizational function. This function is responsible for developing integrated security plans that protect the entity’s assets while ensuring compliance with national and European regulatory corpora, such as the CER Directive (European Union, 2022) and the Italian Legislative Decree 134/2024 (Italy, 2024). In this context, the resilience of critical entities is not merely a technical requirement but a fundamental pillar of national security, necessitating a shift from isolated protection strategies to a holistic paradigm of systemic resilience. 3. The regulatory framework: from protection to resilience The legislative landscape concerning the protection of Critical Infrastructure (CI) has undergone a significant evolution, shifting from a fragmented and sector-specific approach to a holistic paradigm of resilience. Historically, the European framework was anchored by Directive 2008/114/EC (Council of the European Union, 2008), which focused exclusively on the energy and transport sectors. This initial step, while fundamental, was limited by its narrow scope and an emphasis on physical protection rather than operational continuity. In Italy, this period was characterized by a reactive and non-coordinated regulatory effort, with measures often adopted in response to specific emergencies rather than as part of a systemic strategy. A decisive turning point was reached with the introduction of Directive (EU) 2022/2557 (European Union, 2022), known as the CER (Critical Entities Resilience) Directive. This new regulatory pillar expands the scope of application to eleven essential sectors - including health, water, space, and digital infrastructure - and moves beyond the concept of "protection" to embrace "resilience". The Directive mandates that Member States identify critical entities based on the significance of the services they provide and requires these entities to conduct comprehensive risk assessments. This approach acknowledges that in an increasingly interconnected society, the disruption of a single node can trigger cascading effects across borders and sectors (Ruiten et al., 2016). The national transposition of this framework was completed through Italian Legislative Decree 134/2024 (Italy, 2024), which marks a structural "change of pace" for the Italian system. The Decree establishes a sophisticated governance pyramid, centralizing strategic coordination within the Presidency of the Council of Ministers while assigning operational responsibilities to Sectoral Competent Authorities (ACS). Furthermore, the Decree emphasizes the role of Regions as vital nodes for territorial prevention and response, leveraging their deep knowledge of local

Made with FlippingBook flipbook maker