Salta al contenuto
Fortgale · Cyber Governance & Defence Fortgale · Cyber Governance & Defence
SOC gestito 24·7·365
24·7·365 · SOC europeo
→
Managed Detection & Response
Detection in minuti
→
Cyber Threat Intelligence
Intelligence proprietaria
→
Cybersecurity Advisory
Postura NIS2 · DORA
→
Vedi tutti i servizi →
Specialistici
  • Protezione Identità · ITDR
  • Zero Trust
  • Phishing Aziendale
  • Phishing AiTM · Interceptor
  • Tracking C2
  • OT Security
  • Protezione Ransomware
  • Feed di Intelligence
MDR per piattaforma
  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • SentinelOne Singularity
  • Elastic Security
  • Cortex · Palo Alto
  • Darktrace
  • Splunk
  • Sumo Logic
  • Trend Micro
  • Vectra AI
  • Managed Detection & Response
  • Cyber Threat Intelligence
  • Identity · ITDR
  • Anti-phishing aziendale
  • Cybersecurity Advisory
  • Difesa ransomware
  • SOC gestito 24·7·365
  • Managed Detection & Response
  • Tracking C2
  • Zero Trust journey
  • Cyber per CdA · governance
  • Cybersecurity Advisory · board-ready
  • Cyber Threat Intelligence
  • Managed Detection & Response
  • Cyber per PMI · pacchetti chiavi in mano
  • SOC gestito 24·7·365
  • Managed Detection & Response
  • Difesa ransomware
  • Anti-phishing aziendale
  • Managed Detection & Response
  • Cyber Threat Intelligence
  • Identity · ITDR
  • Phishing AiTM · Interceptor
  • OT Security
  • Cybersecurity Advisory
  • Cyber Threat Intelligence
  • Identity · ITDR
  • Phishing AiTM · Interceptor
  • Feed di Intelligence
  • Cybersecurity Advisory · vCISO
  • Tracking C2
  • Incident Response · 24/7 hotline
  • SOC · contenimento immediato
  • MDR · contenimento in ~11 min
  • Difesa ransomware
  • Identity · ITDR
  • Tracking C2
  • Zero Trust journey
  • Phishing AiTM · Interceptor
  • OT Security
  • Cyber Threat Intelligence
  • Feed di Intelligence
  • Anti-phishing aziendale
  • Cybersecurity Advisory · tabletop
  • Advisory · postura NIS2
  • SOC · supporto continuo
  • DORA · settore finanziario
  • MDR per resilienza ICT
  • Advisory · DORA readiness
  • CTI · scenario testing
  • SOC · supporto notifica 24h
  • MDR · evidenze incidente
  • OT Security
  • Industria & Manifatturiero
  • Advisory · gap analysis OT
  • Cybersecurity Industria · pillar
  • OT Security · ICS/SCADA/PLC
  • MDR per manifatturiero
  • Cybersecurity per banche · DORA
  • MDR per resilienza ICT
  • CTI · attori finanziari
  • Cybersecurity Sanità · NIS2 + GDPR
  • MDR per continuità clinica
  • Aerospazio & Difesa · APT state-sponsored
  • CTI · APT contro l’Italia
  • MDR per supply chain difesa
  • Cyber per PMI · pacchetti chiavi in mano
  • SOC gestito 24·7·365
  • MDR Italia
Clients Advisory Blog
Société
  • Chi siamo Storia, sede, posizionamento
Contact & présence
  • Contatti Sales · stampa · HR · privacy
  • Eventi Speaker · partner · presenza
IT · EN · DE · FR
Servizi core Tutti i serviziSOC gestito 24·7·365Managed Detection & ResponseCyber Threat IntelligenceCybersecurity Advisory
Specialistici
Identità
Protezione Identità · ITDRZero Trust
Phishing
Phishing AziendalePhishing AiTM · Interceptor
Network & OT
Tracking C2OT Security
Sistemi & Intel
Protezione RansomwareFeed di Intelligence
MDR per piattaforma Microsoft Defender XDRCrowdStrike FalconSentinelOne SingularityElastic SecurityCortex · Palo AltoDarktraceSplunkSumo LogicTrend MicroVectra AI
Soluzioni · per ruolo
CISO · CIO · CTO
Managed Detection & ResponseCyber Threat IntelligenceIdentity · ITDRAnti-phishing aziendaleCybersecurity Advisory
IT Manager · SOC team
Difesa ransomwareSOC gestito 24·7·365Managed Detection & ResponseTracking C2Zero Trust journey
Proprietà · CdA
Cyber per CdA · governanceCybersecurity Advisory · board-readyCyber Threat IntelligenceManaged Detection & Response
Soluzioni · per dimensione
PMI
Cyber per PMI · pacchetti chiavi in manoSOC gestito 24·7·365Managed Detection & ResponseDifesa ransomwareAnti-phishing aziendale
Enterprise
Managed Detection & ResponseCyber Threat IntelligenceIdentity · ITDRPhishing AiTM · InterceptorOT SecurityCybersecurity Advisory
Corporate · gruppi
Cyber Threat IntelligenceIdentity · ITDRPhishing AiTM · InterceptorFeed di IntelligenceCybersecurity Advisory · vCISOTracking C2
Soluzioni · per urgenza
Sotto attacco ora
Incident Response · 24/7 hotlineSOC · contenimento immediatoMDR · contenimento in ~11 minDifesa ransomware
Rischio strutturale
Identity · ITDRTracking C2Zero Trust journeyPhishing AiTM · InterceptorOT Security
Prevenzione proattiva
Cyber Threat IntelligenceFeed di IntelligenceAnti-phishing aziendaleCybersecurity Advisory · tabletop
Soluzioni · per normativa
NIS2
Advisory · postura NIS2SOC · supporto continuo
DORA · Banche e Finanza
DORA · settore finanziarioMDR per resilienza ICTAdvisory · DORA readinessCTI · scenario testing
ACN · CSIRT Italia
SOC · supporto notifica 24hMDR · evidenze incidente
OT · NIS2 industriale
OT SecurityIndustria & ManifatturieroAdvisory · gap analysis OT
Soluzioni · per settore
Industria & Manifatturiero
Cybersecurity Industria · pillarOT Security · ICS/SCADA/PLCMDR per manifatturiero
Banche & Finanza
Cybersecurity per banche · DORAMDR per resilienza ICTCTI · attori finanziari
Sanità & Healthcare
Cybersecurity Sanità · NIS2 + GDPRMDR per continuità clinica
Aerospazio & Difesa
Aerospazio & Difesa · APT state-sponsoredCTI · APT contro l’ItaliaMDR per supply chain difesa
PMI & Mid-market
Cyber per PMI · pacchetti chiavi in manoSOC gestito 24·7·365MDR Italia
Clienti · Advisory · Blog Clienti Advisory · Threat Intelligence Blog & ricerca
Azienda Chi siamo ContattiEventi
IT · EN · DE · FR
Legal document · GDPR Art. 13 · EU Reg. 2016/679

Privacy Policy

Notice on the processing of personal data provided to users of the fortgale.com site pursuant to Art. 13 of EU Regulation 2016/679 (GDPR) and applicable EU member state implementations.

Controller Fortgale S.r.l. · Last updated 5 May 2026 · Version 2.0
Index
  1. General information
  2. Browsing data
  3. Contacts, forms and bookings
  4. Newsletter and information materials
  5. Incident Response reports
  6. Cookies
  7. Recipients and transfers
  8. Rights of the data subject
  9. Security measures
  10. Document updates

This document is drafted in accordance with the principles of EU Regulation 2016/679 (GDPR) on personal data protection in order to allow users of the fortgale.com site (hereinafter the "Site") to understand Fortgale's privacy policy, how their personal information is processed and — if necessary — to provide express, free, specific and unambiguous consent.

The processing carried out by Fortgale S.r.l. (hereinafter "Fortgale") is based on the principles of lawfulness, fairness, transparency, purpose limitation, storage limitation, data minimisation, accuracy, integrity and confidentiality, as well as the principle of accountability under Art. 5 GDPR.

Specific technical and organisational measures are adopted to prevent data loss, unlawful or incorrect use and unauthorised access. Fortgale is ISO/IEC 27001 certified for the information security management system.

01 General information

Users (hereinafter "Data Subjects", ex Art. 4.1 GDPR) are informed of the following general profiles, valid for all processing scopes.

1.1 Data Controller

The Data Controller is the undersigned company, in the person of its legal representative:

  • Fortgale S.r.l.
  • Registered office: Via San Damiano 2, 20122 Milan (MI), Italy
  • VAT / Tax ID: IT10684000962
  • Phone: +39 02 3659 8955
  • Privacy email: privacy@fortgale.com
  • PEC email: fortgale@pec.it

1.2 Data Protection Officer (DPO)

For requests regarding personal data processing it is possible to contact the Fortgale privacy contact at privacy@fortgale.com. The appointment of a formal DPO, where required, will be communicated in this section.

1.3 Definitions

  • Personal data — any information relating to an identified or identifiable natural person (Art. 4.1 GDPR).
  • Processing — any operation applied to personal data (collection, recording, storage, etc.; Art. 4.2 GDPR).
  • Data Subject — the natural person whose personal data is being processed.
  • Controller — Fortgale S.r.l., which determines the purposes and means of processing.
  • External processor — suppliers that process data on Fortgale's behalf (e.g. IT providers, hosting, M365).

02 Browsing data

The information systems and software procedures responsible for the operation of the Site acquire, in the normal course of operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This is information that is not collected to be associated with identified data subjects but that, by its very nature, could — through processing and association with data held by third parties — allow users to be identified.

This category of data includes:

  • IP addresses or domain names of the devices used to connect to the Site;
  • URI addresses of requested resources, time of request, HTTP method used;
  • size of the file obtained in response, response status code;
  • parameters relating to the operating system, browser and IT environment of the user.

2.1 Purpose and legal basis

This data is processed for the sole purpose of obtaining anonymous statistical information on the use of the Site, monitoring its correct operation and ensuring its security. The legal basis is the legitimate interest of the Controller (Art. 6.1.f GDPR) in technical maintenance and defence against attempted abuse or intrusion. The data may be used for the establishment of liability in the event of hypothetical computer crimes against the Site.

2.2 Retention period

Browsing logs are kept for a maximum period of 6 (six) months, save for any extensions related to investigation activities or the exercise of rights in court.

2.3 Provision

Browsing data is collected automatically and its provision is implicit in the use of Internet protocols; specific consent is not required, as it is data collected for the legitimate interest in security and technical maintenance of the Site.

03 Contacts, forms and bookings

The optional, explicit and voluntary sending of email to the addresses indicated on the Site (e.g. info@fortgale.com, privacy@fortgale.com) and/or the completion of contact and appointment booking forms (Microsoft Outlook Bookings) entails the acquisition of the Data Subject's address and any other personal data contained in the communication, in order to respond to requests and/or schedule the meeting.

3.1 Types of data collected

By way of example, the following personal data may be collected:

  • name and surname;
  • email address (typically business);
  • phone number (optional);
  • company name, role and sector of activity (to qualify the request);
  • free content of the message;
  • date and time of the appointment (Bookings).

3.2 Purpose and legal basis

The data is processed for the purpose of managing and responding to the request received and for the execution of pre-contractual measures at the Data Subject's request (Art. 6.1.b GDPR). For requests without contractual purpose (e.g. simple informational questions) the legal basis is the consent of the Data Subject (Art. 6.1.a GDPR), expressed by sending the communication voluntarily.

3.3 Retention period

Data is kept for the time strictly necessary to handle the request and — in the event of an established commercial relationship — for the duration of the contract and for the subsequent 10 years for the purposes of fulfilling tax, accounting and civil law obligations.

3.4 Provision

Provision is optional; however, failure to provide the data marked as mandatory may entail the impossibility of evaluating and following up on the Data Subject's request.

04 Newsletter and information materials

Should the user decide to subscribe to information communications or download gated content (whitepapers, threat intelligence reports, runbooks), Fortgale processes name, email and — if requested — role and company for:

  • sending the requested content;
  • sending periodic communications on Fortgale research, events and news.

The legal basis is the consent of the Data Subject (Art. 6.1.a GDPR), provided via double opt-in. Consent is freely revocable at any time via the unsubscribe link present in every communication or by writing to privacy@fortgale.com.

Data is kept until consent is revoked, after which it is deleted or anonymised within 30 days.

05 Incident Response reports

In the event of a cyber incident report via the 24/7 hotline or the dedicated emergency forms, personal data and data relating to information systems, logs, technical artefacts and — possibly — data of third parties involved in the incident may be acquired.

The legal basis is the execution of pre-contractual measures and the provision of the requested service (Art. 6.1.b GDPR) and, where applicable, the legitimate interest of both parties in gestion dincidents (Art. 6.1.f GDPR). In cases where Fortgale processes customers' personal data on their behalf, it acts as external data processor (Art. 28 GDPR) on the basis of a specific DPA (Data Processing Agreement).

Data is kept for the duration of the contractual relationship and for the subsequent 10 years in line with documentation obligations required by NIS2 transposition and with civil law statutes of limitations.

06 Cookies

The Site uses technical cookies necessary for operation and, with the consent of the Data Subject, analytics cookies and marketing cookies. For details on types, purposes, providers and duration please refer to the dedicated Cookie Policy.

Preferences management. You can change cookie preferences at any time from the banner that appears on first access or by clicking the Cookie preferences link present at the bottom of every page.

07 Data recipients and extra-EU transfers

Personal data is processed by authorised internal personnel duly instructed (Art. 29 GDPR). It may also be processed by external data processors providing technical services to Fortgale, in particular:

  • Microsoft Ireland Operations Ltd — Microsoft 365 (email, OneDrive, Teams) and Outlook Bookings. Data residency: European Union.
  • Hosting / CDN providers — EU-based IaaS providers for the Site's staging and production environments. Data residency: European Union. The detailed list of providers is available on request under NDA.
  • Google Ireland Limited — limited to loading Google Fonts used for the Site's typography.
  • LinkedIn Ireland Unlimited Company — only if marketing consent is active, for the LinkedIn Insight Tag pixel.
  • Mailing providers — EU-based newsletter sending systems, identified in the Cookie Policy when activated.
  • Legal, tax and audit consultants — only if necessary for the fulfilment of legal obligations.
  • Judicial authorities and law enforcement — exclusively in the presence of legitimate requests provided for by law.

Extra-EU transfers. Fortgale prefers suppliers with Résidence des données UE. Where processing implies a transfer to third countries (e.g. United States for Google Fonts), the transfer takes place exclusively on the basis of suitable safeguards under Art. 44-49 GDPR — primarily Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914) and, where applicable, adequacy decisions (e.g. EU-US Data Privacy Framework).

Personal data is not disseminated and is not subject to automated decision-making processes that produce legal effects on the Data Subject (Art. 22 GDPR).

08 Rights of the Data Subject

The Data Subject has the right to exercise at any time the following rights provided for by Articles 15-22 GDPR:

  • Access to one's personal data (Art. 15);
  • Rectification of inaccurate or incomplete data (Art. 16);
  • Erasure ("right to be forgotten", Art. 17);
  • Restriction of processing (Art. 18);
  • Portability of data in structured and readable format (Art. 20);
  • Object to processing based on legitimate interest (Art. 21);
  • Not be subject to automated decisions and profiling (Art. 22);
  • Withdraw consent previously given, without prejudice to the lawfulness of processing based on consent given before withdrawal (Art. 7.3).

To exercise their rights, simply write to privacy@fortgale.com indicating in the subject "GDPR · rights exercise" and specifying the request. Fortgale responds within 30 days of receipt, extendable by another 60 in case of particular complexity (Art. 12.3 GDPR).

In the event of no response or unsatisfactory response, the Data Subject has the right to lodge a complaint with the Supervisory Authority — the relevant national Data Protection Authority for their EU member state — pursuant to Art. 77 GDPR and Art. 13.2.d, as well as to protect their rights in court.

09 Security measures

Fortgale adopts technical and organisational measures appropriate to the risk (Art. 32 GDPR) to ensure confidentiality, integrity, availability and resilience of processing systems and services. In particular:

  • encryption of data in transit (TLS 1.3) and at rest;
  • role-based access control, multi-factor authentication on critical systems;
  • centralised logging and 24-hour monitoring by the Fortgale SOC;
  • redundant backups and tested disaster recovery procedures;
  • vulnerability management and periodic penetration testing processes;
  • continuous training of personnel authorised to process;
  • ISO/IEC 27001 certification for the information security management system;
  • complementary ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (health & safety) certifications.

10 Document updates

This notice is subject to periodic review to align it with regulatory, technical and process developments. Any updates will be published on this page with indication of the date of last revision and version.

Last updated: 5 May 2026 · Version: 2.0

Questions? Write to privacy@fortgale.com — we respond within 5 jour ouvrés.
Fortgale · Cyber Governance & Defence

Présence de défense cyber européenne · MDR + SOC + Cyber Threat Intelligence depuis 2017.

Siège opérationnel Via San Damiano 2, 20122 Milano (MI)
+39 02 3659 8955
info@fortgale.com
24/7 · Urgence Êtes-vous attaqué ? Hotline Incident Response · réponse immédiate
Solutions
MDR
  • Milano
  • Brianza · Monza
  • Lugano · Ticino
  • Roma
  • Lazio
  • Emilia Romagna
  • Veneto
  • Piemonte
Anti-ransomware
  • Milano
  • Lugano · Ticino
  • Roma
  • Lazio
  • Emilia Romagna
  • Veneto
  • Piemonte
Anti-phishing
  • Milano
  • Roma
  • Lazio
  • Emilia Romagna
  • Veneto
  • Piemonte
Conformité
  • NIS2 · panoramica
  • NIS2 · notifica incidente
  • CSIRT Italia · cos’è e cosa fa
  • CSIRT · guida operativa
  • Trust Center
Ressources & mentions légales
  • Blog & recherche ↗
  • Événements
  • Qui sommes-nous
  • Politique de confidentialité
  • Politique des cookies
  • Préférences des cookies
Fortgale S.r.l. · P.IVA 10684000962 · © 2026
Prendre rendez-vous →
Outlook Bookings · Fortgale

Prendre rendez-vous

Chargement du calendrier…
Réponse · 1 jour ouvré

Échangez avec nos analystes.

Aucune séquence de nurturing, aucune réponse automatique. Un de nos analystes vous rappelle sous un jour ouvré.

Délai de réponse : < 1 jour ouvré. Nous traitons les données conformément au RGPD.

Ce site est protégé par reCAPTCHA et la Politique de confidentialité et les Conditions d'utilisation de Google s'appliquent.

📇 Tous les canaux de contact Sales · IR 24·7 · Confidentialité · Presse · RH · Partenaires →
Document · Fortgale

Aperçu PDF

Chargement du PDF…
Demande · Report Threat Intelligence Fortgale

Demander le Report

—

Le Report complet (executive summary · IoC opérationnels · runbook technique) est confidentiel. Envoyez-nous deux informations et un de nos analystes vous recontacte avec l'accès et un bref briefing technique.

Délai de réponse : < 1 jour ouvré · NDA mutuel inclus.

Ce site est protégé par reCAPTCHA et la Politique de confidentialité et les Conditions d'utilisation de Google s'appliquent.

Voir une attaque réelle

Threat Actor Behaviour · simulation Découvrez comment Fortgale le bloque →
IR · 24·7·365

Êtes-vous attaqué ?

Réponse en 30 minutes, confinement en 1 à 4 heures. Même si vous n'êtes pas client Fortgale.

+39 02 3659 8955 Appelez maintenant · disponible 24h/24 →
ou remplissez le formulaire

Nous vous rappelons sous 30 minutes. Nous traitons les données conformément au RGPD.

Ce site est protégé par reCAPTCHA et la Politique de confidentialité et les Conditions d'utilisation de Google s'appliquent.

📋 Procédure complète Incident Response Que faire dans les 60 premières minutes · timeline · échéances NIS2 →
Privacy first · RGPD · résidence des données UE

Nous utilisons des cookies techniques nécessaires au fonctionnement du site et, avec votre consentement, des cookies analytiques et marketing pour mesurer le trafic et personnaliser les contenus. Vous pouvez accepter tous les cookies, les refuser ou personnaliser vos préférences. Pour en savoir plus, consultez la Politique des cookies et la Politique de confidentialité.

Préférences des cookies · Fortgale

Gérer vos préférences

Choisissez quels cookies autoriser. Les cookies techniques sont indispensables au fonctionnement du site et ne peuvent pas être désactivés. Pour les autres, le consentement est toujours libre, spécifique et révocable à tout moment.

Techniques Toujours actifs

Nécessaires au fonctionnement du site (session, sécurité, préférences cookies). La base juridique est l'intérêt légitime du responsable de traitement (Art. 6.1.f RGPD). Sans ces cookies le site ne fonctionne pas correctement.

Analytiques Nous mesurons ce qui fonctionne

Cookies statistiques agrégés pour comprendre comment les utilisateurs naviguent sur le site (pages vues, durée de session, source de trafic). Fournisseurs EU-friendly ou anonymisés. Base juridique : consentement (Art. 6.1.a RGPD).

Marketing Personnalisation et remarketing

Cookies tiers (LinkedIn Insight Tag, éventuels pixels de campagne) pour mesurer l'efficacité des campagnes publicitaires et afficher des contenus pertinents. Base juridique : consentement (Art. 6.1.a RGPD). Désactivés par défaut.

Vous pouvez modifier ces choix à tout moment depuis la page Politique des cookies ou en cliquant sur le lien Préférences des cookies dans le pied de page.