A quiet shift in ICT contracting is turning penalty clauses into part of cyber-risk governance, but only when they are tied to clear obligations, critical suppliers, and the digital supply chain.
Italy’s NIS2 transposition is pushing cyber responsibility beyond geography and toward the real chain of systems, suppliers, and operational control.