Citizens do not wait: public services have to work
Local authorities, publicly owned companies and public bodies run essential services and handle particularly sensitive data, under growing regulatory obligations — from the GDPR to NIS2, which brings the public sector within its scope. Xion IT Group works alongside the public sector with the practicality of a local partner and the structure of an enterprise supplier.
What we do for the public sector
- Security and NIS2 — assessment, technical measures, incident handling and documentation;
- GDPR in the public sector — records, impact assessments, supplier management and training (GDPR);
- Operational continuity — off-site backup, recovery plans and continuous monitoring;
- Workstation management and support — helpdesk for offices and public counters (XION MSP);
- Networks and infrastructure — design, cabling and management (networks);
- Process digitisation — document automation and custom software for internal workflows and citizen services;
- Staff training — security, privacy and digital tools (consulting and training).
Where to start
An introductory meeting to understand the body’s constraints, priorities and procurement arrangements. We bring references, a method and a clear plan of work, with the documentation the public sector requires.
Citizens at the centre, compliance as method
In the public sector, technology serves two masters at once: the citizen, who wants services that work, and the law, which imposes strict rules on data, security and transparency. For a public body, the GDPR and NIS2 are not abstract obligations: they are the frame inside which every project has to be conceived. Xion approaches public sector IT with that double view — solutions that genuinely improve the service to citizens and that are, at the same time, documented and compliant from the outset. The GAPOFF platform keeps track of the obligations, while the technical measures (access control, backup, segmentation, monitoring) are implemented on the real systems.
Digitising without leaving anyone behind
Digitising public processes — registry, approval workflows, citizen portals, removing paper — is an enormous opportunity for efficiency, but it has to be done with judgement: attention to accessibility, to data protection, and to the continuity of essential services during the transition. Our approach is gradual and concrete: start with the processes that have most impact on citizens and on internal operations, automate what is repetitive with custom software, and support the staff with training. Technology has to make the job simpler for the people doing it, not more complicated.
Retention is not the same as filing
This is the distinction that causes most problems in public bodies, because in everyday language the two words are synonyms and in administrative practice they are not.
Filing means putting a document somewhere it can be retrieved from. Compliant retention means guaranteeing over time that the document is authentic, intact, readable and findable — with signatures and timestamps proving its validity twenty years from now, when today’s formats and programs will no longer exist.
The practical consequence is that a backup, however well made, is not retention. They are two different things serving different purposes and both are needed. Confusing them is the mistake discovered late — at the moment a document has to be produced and its integrity cannot be demonstrated.
Transparency and confidentiality pull in opposite directions
A public body has to publish and protect at the same time, and the point of balance is not obvious. Publication obligations cover acts and data that must be accessible to anyone; data protection requires that no more is disclosed than necessary.
In day-to-day practice the most frequent risk is not failing to publish: it is publishing too much — attachments not redacted, lists containing data that should not have been there, documents indexed by search engines and then hard to remove. It is a process control rather than a technology problem, and it belongs before publication rather than after a complaint.
What we find in public bodies
- Workstations of very different ages, replaced when the budget allowed rather than when they needed replacing, with three generations of operating system on the same network.
- Access tied to the person rather than the role, which becomes a problem at every change of post.
- Documents living in shared folders without differentiated permissions, accessible to the whole organisation.
- Vertical systems supplied by different vendors that do not talk to each other, with data rekeyed by hand from one application to another.
- No documented restore test, which is also one of the points on which bodies are audited.
Where we work
Xion IT Group has its head office in Milan and offices in Lecco and Bergamo, and works with public bodies and publicly owned companies across Lombardy.