B5545 - Sem.Cybersecurity: Technology, Regulation and Practice

Academic Year 2025/2026

Learning outcomes

The seminar aims to provide an overview of the legal, ethical, and technical aspects of cybersecurity from a multidisciplinary perspective, taking into account the growing attention to the subject not only as a technical issue but also as a regulatory and political one.

From a teaching methodology standpoint, the seminar seeks to integrate more traditional/theoretical learning with a more practical approach, in order to develop cross-disciplinary skills through so-called learning by doing. All topics covered during the seminar will, in fact, be operationalized through the analysis of case studies — including hypothetical ones — that illustrate legal frameworks (e.g., regarding the notification of a cybersecurity incident) or technical aspects (e.g., the threat and vulnerability landscape) from an applied perspective.

By the end of the seminar, students will have acquired basic knowledge of the main threats and attack techniques, as well as relevant technical and organizational cybersecurity measures and standards; a solid understanding of the regulatory framework at both EU and national levels; and the ability to critically assess the trade-offs sometimes required by cybersecurity objectives in relation to fundamental rights (e.g., respect for private and family life and the right to the protection of personal data).

Course contents

The main objective of the seminar is to enable students to address the complex and multidisciplinary normative issues arising in the emerging field of cybersecurity law.

The course will focus on the technical aspects related to cybersecurity (e.g., involved actors, threats, and technical measures), the EU and national cybersecurity legislative frameworks, as well as some underlying ethical issues (e.g., the relationship between cybersecurity and fundamental rights, both in terms of complementarity and clash), within an integrated perspective.

Course Outline:

  1. Threat Landscape and Key Actors

  2. Computer Security, Information Security, Cybersecurity: Concepts and Technical/Organizational Security Measures

  3. Cybersecurity in EU Law: From Telecommunications Frameworks to the European Commission’s Cybersecurity Strategies

  4. Service Security: The NIS Directive(s)

  5. The EU Cybersecurity Certification Framework: The Cybersecurity Act

  6. Product Security: The Cyber Resilience Act

  7. Information Security: GDPR, ePrivacy Directive, Data Governance Act, Data Act

  8. National Regulatory Framework – Part 1: The National Cybersecurity Perimeter and the National Cybersecurity Authority

  9. National Regulatory Framework – Part 2: The National Cybersecurity Perimeter and the National Cybersecurity Authority

  10. Cybersecurity vs. Fundamental Rights? The Encryption Debate

  11. Cybersecurity and Artificial Intelligence

  12. Towards a Fundamental Right to Cybersecurity?

Readings/Bibliography

To support the study of the topics presented during the seminar, it is recommended to supplement the slides used in class with the chapter from the new textbook on Diritto del digitale entitled "Il Diritto della Cybersicurezza: il quadro normativo"

As optional reading, relevant academic articles related to the topic discussed will be suggested during the lessons.

Teaching methods

From a teaching methodology perspective, the seminar aims to combine more traditional/theoretical learning with a practical approach, in order to develop cross-cutting skills through so-called learning by doing. All topics covered during the seminar will be operationalized through the analysis of case studies — including hypothetical ones — that illustrate legal frameworks (e.g., cybersecurity incident notification) or technical aspects (e.g., threat and vulnerability landscape) also from an applied standpoint.

Assessment methods

For attending students, the exam will consist of a written paper exploring a topic of the student’s choice, selected from a list of subjects briefly presented at the beginning of the seminar and further explored during the lessons. The paper must be submitted to the professor seven days prior to the selected exam session for discussion.

For non-attending students, the exam will consist of an oral exam on the topics covered during the seminar (section: Course cntents). Course materials are available on the platform 'Virtuale'.

The final assessment will be on a pass/fail basis.

Teaching tools

Lectures will be accompanied by slide presentations.

Students with learning disorders and/or temporary or permanent disabilities: please contact the office responsible (https://site.unibo.it/studenti-con-disabilita-e-dsa/en/for-students) as soon as possible so that they can propose acceptable adjustments. The request for adaptation must be submitted in advance (15 days before the exam date) to the lecturer, who will assess the appropriateness of the adjustments, taking into account the teaching objectives.

Office hours

See the website of Pier Giorgio Chiara