On 8 October 2026 Italy's Ministry of Foreign Affairs (the Farnesina) said its website was under cyberattack. The ministry said its security systems mitigated the attack with no service disruption, and that cyber experts were checking Italian embassy and consulate sites worldwide. Euronews reported that Italian news agencies believed the pro-Russian group NoName057(16) was behind a distributed denial-of-service (DDoS) attack. The ministry has not confirmed that attribution, as far as the coverage we reviewed shows.
This is not a shutdown order. That is why it is useful. It shows what a state does when someone else threatens availability, and the answer looks very different from what governments do when they choose to cut access themselves.
Two kinds of outage
An attacker-caused outage and a government-ordered shutdown can look identical to a user: the page does not load. Legally and morally they are opposites. A DDoS is an attack on a service, and the state's duty is to restore availability, find the perpetrators and deter them. A shutdown is the state removing availability from lawful users, often at the moment they most need information.
The contrast is live this week. On 9 October India's Ministry of Home Affairs ordered mobile internet suspended within a 4-km radius of a central Delhi crossing from 10 pm on 9 October to 10 pm on 10 October, ahead of a planned protest. According to MediaNama, the notice was marked "top secret", stated no grounds and did not explain the radius. The area is roughly 2.5 times that of an order issued on 2 October. These are the features that make shutdowns hard to defend: opacity, scope creep and no stated justification.
They are also common. The #KeepItOn coalition documented at least 296 shutdowns in 54 countries in 2024, including 84 in India. Italy does not appear in that coverage.
The strongest case for emergency powers
The best argument for broad emergency powers deserves a fair hearing. In a real crisis, such as a cascading attack on critical infrastructure, officials may need to isolate networks, throttle traffic or take systems offline quickly, and statutory authority avoids improvisation under pressure. A government that cannot act decisively may fail the people it is meant to protect.
But that argument supports targeted, technical, defender-side powers. It does not support cutting a population's access to communications. The Farnesina episode shows the difference.
What Italy's framework actually provides
Italy's main instrument is the national cybersecurity perimeter, created by Decree-Law 105/2019, converted by Law 133 of 18 November 2019. It covers public and private entities whose essential functions depend on networks and IT systems. Those entities must keep inventories of their systems and report them to the national cybersecurity agency (ACN). They must follow minimum security measures, including incident handling and supply-chain requirements. Buyers of ICT products for covered systems must notify a national evaluation and certification centre, which can test them and set conditions. Non-compliance carries administrative fines generally between €200,000 and €1.8 million.
None of that is a switch-off power. The perimeter is an obligations regime: it makes the defended systems more resilient and makes failures visible to a competent authority. That is proportionate regulation in the sense we favour, with duties on those who run critical systems, backed by a specialist agency, and no authority to deprive the public of connectivity.
The EU layer works the same way. The NIS2 Directive (Directive (EU) 2022/2555) replaced the original NIS Directive, covers 18 sectors including public administration and digital infrastructure, and required entities to notify national authorities of significant incidents. Member States had to transpose it by 17 October 2024. The Italian perimeter decree itself now links its incident reporting to Italy's NIS2 implementing decree. The architecture rests on preparation, reporting and shared situational awareness.
Attribution is the proportionate response
The Farnesina's second response is political. Foreign Minister Antonio Tajani said Italy would work with Romania and other member states to propose, at upcoming EU meetings, that those responsible for cyberattacks, including ones against Italian institutions, be "designated." Euronews notes that this does not specifically mention sanctions. Whether designation becomes sanctions is a decision for the EU, and nothing in the sources we reviewed says it will.
This is the right instinct. Naming and penalising attackers raises the cost of attacking and targets the actor responsible. A government that answers an availability attack by restricting its own citizens' internet access punishes the wrong party.
Policy lessons
First, a mitigated DDoS is a success story for resilience investment. Tajani credited capabilities strengthened "in recent months" for the absence of disruption. The lesson is to fund detection, redundancy and incident response, not to expand emergency powers.
Second, any emergency power over connectivity should carry the safeguards India's order lacks: a published legal basis, stated grounds, a defined and necessary geographic and time scope, and independent review. Ideally, such powers should be reserved for narrow technical isolation, never general suspension of service.
Third, caution about the facts matters. This was one reported DDoS, mitigated within hours, against a website. It is not evidence of a crisis that justifies new powers, and the attribution remains unconfirmed.
Italy's approach, imposing duties on operators, building a central agency and pursuing attackers diplomatically, is a model for how democracies can defend availability without sacrificing the open internet. Others should copy it before reaching for the off switch.