ROME — Italy and Germany are moving to strengthen their defenses against hybrid threats, but their latest reforms point to two different approaches: Rome is building up the military’s cyber architecture, while Berlin is giving its intelligence services a more operational edge.
The difference is emerging as European governments reassess how institutions designed for clearer distinctions between peace and conflict should respond to cyberattacks, espionage, disinformation and influence operations that deliberately blur those lines.
Why it matters: The comparison is not simply about which country is moving faster. It highlights a broader European question: whether countering hybrid warfare requires stronger defensive structures, more offensive capabilities — or a combination of both.
- Italy’s government approved on Aug. 4 a broad bill strengthening the national defense apparatus in the cyber domain. The measure is now before Parliament.
- Germany, meanwhile, has moved ahead with a reform of its domestic and foreign intelligence services aimed at expanding their ability to actively counter hybrid operations.
- The two moves show Rome and Berlin responding to the same security environment while assigning different weight to military defense and intelligence capabilities.
The Italian view: That contrast is at the center of an analysis by Niccolò Petrelli, an intelligence and national security scholar, published by our sister website Formiche.net.
- Petrelli argues that Berlin’s intelligence reform appears more explicitly operational, while Italy’s bill remains primarily focused on reorganizing and strengthening the military side of cyber defense.
- The Italian measure formally establishes a “national cyber space of interest for the defense and military security of the State,” whose perimeter is defined and updated by the defense minister. It also elevates cyber to a strategic military domain alongside land, sea and air.
The reform reorganizes military intelligence through the Joint Cyber Intel Command– Reparto Informazioni e Sicurezza (COCI-RIS) and creates specialized cyber roles.
- Petrelli’s key distinction is about posture. In his reading, the German approach explicitly opens the door to active responses, while Italy remains more defensive and focused on containing hybrid threats in the military sphere.
But Italy’s reform goes beyond a reshuffle. That distinction comes with an important qualification.
- Alberto Pagani, also an intelligence and national security scholar, writing for Formiche.net, places the Italian measure within a broader effort to adapt a fragmented security architecture to threats that increasingly cut across institutional boundaries.
- Italy’s national security responsibilities are currently distributed among several actors: the DIS intelligence coordination department; foreign intelligence agency AISE and domestic agency AISI; the National Cybersecurity Agency (ACN); the Interior Ministry; and the Defense Ministry.
- That architecture was built around a clearer division between intelligence, policing, cybersecurity and military defense. Hybrid warfare makes those distinctions harder to sustain.
- A hostile influence operation, Pagani notes, can simultaneously affect domestic political debate, public trust and critical infrastructure while being accompanied by cyberattacks.
Between the lines: Seen from this perspective, the Italian reform is less about creating an offensive cyber instrument than about making the military component of the existing system more capable of operating inside that increasingly blurred environment.
- The bill turns the traditional military intelligence department into a joint Cyber Intel command, formally bringing conventional intelligence collection and the cyber domain closer together.
- It also creates a joint training center dedicated to combat and countering hybrid threats under the Chief of Defense Staff, bringing disinformation, electronic warfare and attacks on infrastructure into military training.
- A dedicated military cyber specialist career is also envisaged, alongside measures intended to support military technological research and accelerate the acquisition and testing of new systems.
- Pagani therefore reads the legislation as a “structural transition” for Italian defense rather than simply an administrative change.
Zoom out: Germany. Germany is taking a different route. The reform of the BND, Germany’s foreign intelligence service, and the BfV, its domestic intelligence service, is designed to move the agencies beyond a predominantly defensive model of information collection and analysis.
- As described in the analyses published by Formiche.net, the German framework expands the space for active measures against hostile hybrid activities.
- Among the envisaged capabilities are the possibility of accessing and manipulating data in cyber systems connected to hostile operations, disabling infrastructure and interrupting financial flows. The reform also broadens the potential use of spyware and artificial intelligence, as well as online surveillance and the retention of data collected through those activities.
- For Petrelli, this is the critical difference: Germany is moving toward a model that can include “strike-back,” sabotage and counter-hacking operations.
- Italy, by contrast, has so far chosen to strengthen its defensive architecture without a comparable redefinition of offensive powers.
The bigger picture: The Italian move looks less cautious when viewed against the longer trajectory of European allies.
- Pagani notes that France has been developing an integrated cyber-defense structure since the creation of Comcyber in 2016, later establishing a doctrine for military operations in the information sphere.
- The United Kingdom combines the non-kinetic and information activities of the 77th Brigade with the offensive cyber capabilities brought together in the National Cyber Force.
- Germany had already elevated its Cyber- und Informationsraum command in 2024, giving the cyber and information domain a more central place within the Bundeswehr.
The message for Italy: Rome is not designing its approach in isolation. It is trying to close a gap with allies that started adapting their military and intelligence structures earlier — while preserving an Italian institutional architecture in which defense, intelligence and civilian cybersecurity retain distinct responsibilities.
- That helps explain why Petrelli’s and Pagani’s readings are complementary. Petrelli identifies the limitation: Italy has not yet made the shift toward the more active posture now visible in Germany. Pagani identifies the significance of what Rome has done: formally bringing cyber, intelligence and hybrid threats deeper into military organization, training and career structures.
What we’re watching: The Italian bill still faces Parliament, making its final shape one of the immediate variables to watch. The larger question raised by the two analyses is what comes next.
- Petrelli argues that Italy should now consider whether the changing hybrid threat warrants “a less defensive and reactive posture” in national security and defense.
- Pagani, meanwhile, points to another challenge: ensuring that a stronger role for the Defense Ministry does not create overlaps with ACN and the intelligence agencies.
The bottom line: Germany’s answer to hybrid warfare is pushing intelligence toward more active disruption. Italy’s is strengthening the military cyber system and the institutional machinery around it.
- For Italian security analysts, the distinction matters — but so does the direction of travel. Rome is moving from treating cyber and hybrid threats largely as specialized functions toward embedding them more deeply in national defense.
- The next debate is whether that institutional upgrade will be enough, or whether Italy will eventually follow Berlin toward a more active posture.



