No hacked servers, no cracked encryption. For months, a genuine certified email address sent requests for confidential data from hundreds of bank customers. The lesson isn't about certified email technology, but how organizations choose to trust it.
Speed has become one of the key indicators of digital transformation. Organizations are required to introduce new tools, automate processes , and develop operational solutions in ever-shorter timeframes. Acceleration is now considered a necessary requirement to remain competitive. Yet, just as they strive to become faster, many companies risk achieving the opposite effect. Let's find out why.
What happened
The news circulated quickly and was confirmed by Revolut: an unauthorized individual had sent requests for information from authentic certified email addresses of a government agency and for this reason the company considered them to be authentic requests from an authority.
According to reconstructions, the mailbox was a certified email address of the Reggio Calabria prefecture, which ended up under the control of criminals via an infostealer (malware that steals login credentials), and the requests were submitted in the name of the Postal Police.
Sensitive data of approximately 680 account holders , including identity documents, accounts, and bitcoin transactions, was handed over , and the fraud is believed to have continued for approximately five months before being discovered. The bank states that its systems and customer funds were not affected.
The Postal Police and the UK Data Protection Authority are investigating for unauthorised access and computer fraud.
No technical checks failed
This is precisely what makes the case instructive. The domain and the certification guaranteed by the provider passed all the checks. PEC did exactly what it was designed to do: guarantee that the message originated from that inbox. But PEC does not, and cannot, guarantee the identity of the sender or whether the content is legitimate. The authenticity of the channel is a technological problem, and PEC solves it. The legitimacy of the request is a process problem, and no channel can resolve it alone.
The signals were there, what was missing was a process to read them
In hindsight, there was no shortage of clues. The requests were signed by the Postal Police but originated from a prefecture's certified email address, whereas the Postal Police has its own certified email address.
Furthermore, the judicial authority decree that typically accompanies requests of this type appears to be missing. Each of these elements corresponds to a verifiable rule: who is the competent party, which channel they usually use to write, which attachments are required. Added to this is a data point observable over time: a sequence of requests spread over months.
There's a second detail. The requests continued until the bank decided to investigate further and contacted the Italian institution directly, which denied being the source.
The definitive control, therefore, existed: a human verification through an independent channel. The problem is that it arrived months later, on initiative and not by design.
Learn how to build, model, and govern business processes
From identity verification to consistency verification
Identifying who sent a message is no longer enough. We need to ask ourselves: is it normal for this person to ask us this question, in this way, at this time?
Responding requires cascading checks, and order matters:
- Deterministic rules, i.e. the process design: competence, expected channel, mandatory documentation.
- Statistics and anomaly detection on frequencies and volumes.
- Semantic similarity to communications already received.
- Content analysis with linguistic models, compared with the sender's history.
In effect, it's a process that uses AI agents that extend control beyond the reach of rules and can read the content and compare it with the history of the relationship (on volumes that no protocol office could ever manually examine in such a short time). This infrastructure must be Private AI, given the confidentiality of the information processed.
Where the person remains
In this model, the agent doesn't decide to release data. It extracts, classifies, assigns a risk level , and passes the file to a human along with the collected evidence. This allows for more sensitive requests, such as disclosing personal data to an authority, to be verified by the Human in the Loop before execution. And every step is tracked.
This is the concrete meaning of Human in the Loop: establishing by design who makes decisions, on what elements, and with what traceability. It's not about adding a human check "for security." This is what actually happened in the Revolut case, but five months too late.
The Jamio Solution
The Jamio solution for managing incoming communications (PEC/PEO) , already adopted by numerous organizations to structurally manage the acquisition and processing of communications, is enriched with a new player: an agent system natively integrated into the platform.
The system, based on a private architecture designed to preserve the confidentiality of information, analyses the received communications and their contents, automatically extracting the relevant information.
The information identified is integrated with the data and context already present in Jamio, allowing the system to interpret the message not as an isolated element, but within the context of the processes, information and relationships already managed by the platform.
Based on the elements thus collected, the agentic system proposes a classification of the message and provides the evaluator with useful information to support the evaluation and subsequent decisions.
In this case, Jamio could have detected that the behavior of a seemingly trustworthy sender was inconsistent with their historical profile. And that's exactly the signal that, in this case, no one picked up on for months.
Organizations will continue to invest in perimeter protection, and rightly so. But the decision to trust is a process, and like any process, it must be designed, governed, and auditable. With agents reading and people deciding.
Organizations will continue to invest in perimeter protection, and rightly so. But the Revolut case shows that the critical point lies elsewhere: the moment when a decision is made to follow up on a request. That moment must be designed, governed, and made verifiable. With agents who read and propose, and people who decide. Because trust isn't certified. It's governed.
Learn how Jamio integrates AI and governance into communications management
Legally Valid Digital Copies: How Pròdeo Certifies the Dematerialization Process

In summary
Pròdeo SpA has been digitizing archives for the Public Administration for decades. Thanks to PròdeoDoc, a document solution built on the Jamio Openwork platform, Pròdeo manages the process certification, regulated by Annex 3 of the AgID Guidelines, in a single environment. Digital copies acquire evidentiary value, offices operate digitally, and the originals remain, protected, in the repository.
The context
Pròdeo SpA was founded in Bari in 1985 and has been providing document management services to the public administration for over forty years. Municipalities, provinces, healthcare providers, and regional authorities entrust it with the entire lifecycle of their archives: from outsourced storage to digitization, and finally, to the return of documents to the institution's information systems.
The most recent challenge concerns certified dematerialization projects , in which the digital copy is called upon to replace the original in administrative proceedings, assuming a evidentiary value recognized by the law. The regulatory framework is defined by art. 22, paragraph 1-bis, of the Digital Administration Code , which permits the creation of the image copy through process certification, and by Annex 3 of the AgID Guidelines , which establishes the requirements. In particular, the process is based on four essential requirements: the adoption of an ISO 9001 and ISO/IEC 27001 certified production cycle ; an initial verification , prior to the start of production; the assignment of a unique process code , recorded in the metadata of each copy; and a closing verification conducted on a sample basis , according to the UNI ISO 2859-1 standard .
The legal validity of copies thus created depends on the person certifying their conformity. If the certification comes from a notary or public official, the copies are deemed valid until challenged (Article 22, paragraph 2, CAD; Article 2700 of the Civil Code). If the certification comes from a private individual, such as the supplier who performed the digitization, the copies are presumed to be compliant until expressly disavowed (Article 22, paragraph 3, CAD; Article 2719 of the Civil Code).
The challenge
Public administrations have long been faced with a veritable overproduction of documents. Paper archives are growing, saturating space, and becoming progressively less accessible. Municipal technical offices, for example, provide eloquent evidence of this: building inspections, access to documents, and checks on the legal status of properties require the timely retrieval of even very old documents. These documents often lie in storage far from the offices, or on deteriorated media that further wear out with each consultation.
Process certification addresses the issue at its root by introducing strategic benefits for the institution: digital copies acquire legal significance and replace originals in proceedings: the office consults them in seconds, while the originals never leave the repository. Full comparison, which AgID itself defines as costly and sometimes impractical, gives way to random checks based on statistical data. This, however, presupposes two conditions: a supplier capable of managing the process using an archival method and a software platform capable of implementing all process phases, facilitating the activities of the contact persons, and tracking each step.
The solution
Pròdeo chose to build its PròdeoDoc solution on the Jamio platform based on specific requirements: a qualified ACN cloud service, accessible from any browser, flexible enough to be tailored to the specific needs of the process, as verified during tests conducted with its archivists. Each document can be acquired with the metadata required by Annex 5 of the AgID Guidelines and with its own SHA-256 fingerprint.
In accordance with the provisions of Annex 3, PròdeoDoc manages the certification in two control phases. In the Initial Verification (§ 2.3) a sample of the test batch is compared with the originals; the sample size and the acceptance and rejection numbers are determined by the system in application of UNI ISO 2859-1. In the event of a positive outcome of the verification, PròdeoDoc generates the process identification code and associates it with each practice produced from that moment on. In the Final Verification (§ 2.4), PròdeoDocoperates in batches: in the event of a positive outcome, it values, for all the practices in the batch, the metadata "Conformity of image copies on electronic media" and simultaneously produces the relevant report.
The results
The most significant measure of results emerges from a comparison between two generations of the same digitization service. The solution developed for municipal technical offices supports the digitization of private building practice archives: a first portion was processed using a traditional dematerialization process, while the remaining portion underwent certified dematerialization, currently underway, through PròdeoDoc.
The transition to the new model determines a significant evolution on at least three levels.
- The processing unit. In the previous model, the reference unit was the file, acquired as a single block; now, the unit becomes the single document, complete with its own metadata, its own fingerprint, and the relevant verification result. The office can thus directly identify and retrieve the document of interest without having to consult the entire file.
- The effectiveness of copies. In the previous era of dematerialization, digital copies essentially served a consultation function, not being produced as part of a certification process and therefore not exhibitable in place of the paper copy; today, however, image copies have evidentiary value and can be fully used in place of the original.
- The basis of the controls. In the previous model, the verification was carried out on the basis of a sample agreed between the supplier and the contracting authority; in the new process, the size of the sample and the acceptance and rejection criteria are determined according to UNI ISO 2859-1, the parameters of which derive from a technical standard and not from a negotiated agreement.
The result is an archive in which each copy is traceable to the process, batch, and verification that concerned it, making the entire journey from the analog original to the digital copy traceable.
Next steps
Process certification, by its very nature, is not tied to a specific document type: what changes from one area to another are the preliminary archival analysis and the set of metadata.
Pròdeo is already planning to extend the model to new document sets encompassing numerous potential recipient entities: municipalities, provinces, healthcare agencies, and regional authorities, which maintain large document sets, consulted daily and currently stored on paper. For these administrations, process certification opens the possibility of addressing dematerialization through a secure, regulatory-compliant process, monitored at every stage, gradually transforming the archive from a repository to be safeguarded into a working tool.
It is precisely from this perspective that Jamio takes on a strategic role: its ability to model processes, data, documents, and rules allows Pròdeo to maintain a common technological framework while simultaneously adapting it to the archival and operational characteristics of the different document series. The model can thus evolve and find application in new contexts without having to redesign the entire technological solution each time.
"The model doesn't depend on the type of document. What we did for building permits applies to any series a public administration consults every day." Piero Cosoli, COO of Pròdeo
Cloud & Cybersecurity Vouchers: Half the cost paid by MIMIT. Pre-filling begins October 20, 2026.

A non-repayable grant of up to €20,000, awarded in chronological order of application, subject to the purchase of software or hardware solutions exclusively from suppliers authorized by Mimit itself: Openwork is among them. What does the measure entail for those considering adopting Jamio?.
In many SMEs, the most important processes (orders, requests, paperwork, certified communications) still exist in emails, Excel spreadsheets, and personal memos. They work as long as the people who manage them work. But when someone is absent, problems begin, and as volumes grow, errors increase, and management becomes increasingly difficult.
The problem is well known, but the right time to address it is always lacking: a more urgent priority, a budget already allocated, a project that can wait. The real risk, however, is that this constant postponement will result in a loss of market competitiveness.
A measure that can help you make a decision is therefore welcome: the Ministry of Business and Made in Italy (MIMIT) is funding the adoption of cloud and cybersecurity by small and medium-sized businesses and self-employed workers. Applications can be pre-filled from 12:00 PM on October 20th and submitted from 12:00 PM on November 10th, 2026, to 12:00 PM on January 20th, 2027, unless funds are exhausted earlier.
MIMIT's new Cloud & Cybersecurity Voucher offers €150 million for the digital transition of SMEs and professionals. Pay attention to the geographic distribution: €71 million is earmarked exclusively for Southern Italy (Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardinia, and Sicily). The incentive covers 50% of eligible expenses for the purchase of cloud and cyber solutions. The maximum bonus available is €20,000 (refundable with an investment of at least €40,000) . The service is available on a first-come, first-served basis: preparing the documentation in advance will make a difference.
Who can access
SMEs of any legal form, registered in the Business Registry and active, as well as self-employed workers and professionals with VAT numbers operating throughout the country, are eligible to apply. When applying, the applicant must:
• have a connectivity contract with a minimum download speed of 30 Mbps;
• have a digital identity (SPID, CNS, or CIE), an active certified email (PEC), and a digital signature;
• if required by law, have taken out natural disaster insurance. The relevant declaration is a condition for admissibility of the application.
The grant falls under the de minimis regime.
It is therefore in addition to other de minimis aid received in the last three years, up to a limit of €300,000. Therefore, the investment's financial capacity must be verified in advance, otherwise it will be excluded. Entities in liquidation or undergoing insolvency proceedings, as well as businesses in sectors excluded by European legislation, such as primary agricultural production and fisheries, are ineligible to apply.
The role of Openwork
To access the voucher, expenses are eligible only if incurred with official MIMIT suppliers (Decree 29/07/2026). Openwork is an authorized partner with its Jamio openwork platform, qualified in the SaaS category for managing productivity, workflow, and Artificial Intelligence features.
Inclusion in the ministerial list certifies the security standards that Jamio has always guaranteed: ISO 9001, ISO/IEC 27001 (with extensions 27017 and 27018), and ACN qualification.
The call covers 5 macro-categories of digital investment:
• Hardware and Software for IT security.
• Cloud infrastructure services and SaaS solutions (such as Jamio).
• Technical Support: Professional configuration, monitoring, and ongoing support services are eligible up to 30% of the plan, only if related to the purchased products.
• Exclusions: Pure training activities or consulting without technological implementation are not eligible.
The purchase method must be indicated immediately on the application and cannot be changed:
• Direct Purchase: Expenses to be incurred and paid within 12 months of the grant.
• Subscription (Minimum 24 months): Contract to be signed within 30 days of the grant.
Contracts, deposits, and invoices do not need to be submitted before submitting the application. Simply filling out the application form on the portal does not entitle you to spend.
The grant is paid as a reimbursement for expenses actually paid, in a maximum of two installments:
1. First deposit: Requested after at least 50% of the expenses have been paid (and no earlier than three months after the grant).
2. Final balance: Upon completion and reporting of the entire investment plan.
The next steps for those intending to seize the opportunity:
Before October 20th, the opening date for the pre-filling process, interested companies will be able to verify the requirements, define their spending plan, and collect offers from registered suppliers with their identification codes.
Since the application process is conducted in the order in which it is submitted, the pre-filling procedure allows you to submit your application as soon as the application office opens on November 10th.
Sources:
Ministerial Decree of July 18, 2025: https://www.mimit.gov.it/it/normativa/decreti-ministeriali/decreto-ministeriale-18-luglio-2025-disciplina-degli-interventi-di-sostegno-alla-domanda-di-servizi-di-cloud-computing-e-cyber-security
Directorial Decree of July 29: https://www.mimit.gov.it/it/normativa/decreti-direttoriali/decreto-direttoriale-29-luglio-2026-voucher-cloud-computing-cybersecurity-definizione-elenco-dei-soggetti-abilitati-alla-fornitura-dei-servizi-e-prodotti-agevolabili
Directorial Decree of August 4: https://www.mimit.gov.it/it/normativa/decreti-direttoriali/decreto-direttoriale-4-agosto-2026-voucher-cloud-cybersecurity-termini-e-modalita-di-presentazione-delle-domande-di-agevolazione
Information: https://www.mimit.gov.it/it/incentivi/sostegno-alla-domanda-di-servizi-di-cloud-computing-e-cyber-security
List of eligible suppliers: https://vcc-elencofornitori.npi.invitalia.it
Jamio Ouverture 6.0: Discover the new front end together in a webinar

With Jamio Ouverture 6.0 , the new major release of the platform, Jamio On Stage NEXT has been released , the new front end that introduces a renewed way of interacting with Jamio solutions and, above all, enables new possibilities in the design and use of applications .
To help users and partners discover these new features, we've organized a live webinar where we'll demonstrate how to best use the new interface and leverage its features in your daily work.
Starting from a Jamio solution, we will see how to navigate the new interface, how to organize and customize your workspace and we will delve into, through practical examples, some of the main features made available by Jamio On Stage NEXT.
The webinar will also be an opportunity to broaden our focus on the new features introduced with Jamio Ouverture 6.0 and the new integration possibilities with the Microsoft ecosystem, from document collaboration with Microsoft 365 to the new Microsoft Power BI connector for bringing dashboards, KPIs, and process data analysis directly into the Jamio experience.
It won't be a simple overview of the features, but a live demonstration to quickly familiarize yourself with the new environment and understand how Jamio On Stage NEXT represents the starting point for the platform's future evolutions.
Online appointment
Tuesday, October 27, 2026
, 3:30 PM
Live Online Webinar
Participation is free.
You will soon receive an email with all the information and the link to register for the webinar.