
The questionnaire is intended specifically for:
- CIOs and information systems managers;
- system administrators;
- CISOs and cyber managers;
- DPOs and regulatory compliance officers;
- CTOs;
- Policy makers;
- third parties who manage digital security on behalf of clients;
- top decision-makers in smaller organizations.
What's new in the OAD 2026 Questionnaire
The questionnaire, available only in Italian, online, and anonymous, with predefined answers to choose from, has been significantly reduced and simplified compared to previous years, both in terms of questions and answers, with the aim of broadening the audience as much as possible.
- It now contains a total of 51 questions (approximately one-third of the number of questions in previous editions), divided into eight sections, 28 of which, those on existing security measures, are optional.
- A new graphic design allows for responsive use of the questionnaire on mobile devices with smaller screens than those used on PCs.
- Further customization of the software has been implemented to allow for logical checks on the answers provided, thus helping respondents avoid making errors in multiple-choice questions, such as selecting one or more answers in addition to "I don't know."
- For those who also complete the optional section on security measures, a macro-assessment of the digital security level of their information system will be produced at the end, along with a personalized, downloadable and printable summary highlighting the main critical issues identified based on the responses provided.
The structure of the OAD 2026 online questionnaire
The OAD 2026 online questionnaire is in Italian, with predefined answers to choose from. It comprises a total of 51 questions divided into 8 sections, 31 of which, those on existing security measures, are optional.
Sections 1, 4, 5, and 6 contain hidden "questions" that perform calculations based on the selected answers to assess the overall security level of the information system being addressed.
The OAD 2026 questionnaire is structured into the following sections (number of questions per section is shown in brackets):
S1 - Brief information about the respondent's company/organization (4)
S2 - Digital attacks of any kind on the information system detected throughout 2025 (4)
S3 - Most feared attacks in the near future (3)
S4 - Macro-characteristics of the information system to which the respondent refers (10)
S5 - Technical measures in place for the digital security of the entire information system
1 - Inventory of the IS's ICT resources and basic architecture of digital security tools (3)
2 - Access and account protection (2)
3 - Patches, anti-malware, antivirus, EDR, endpoint protection (3)
4 - Networks, firewalls, remote access (2)
5 - Backup and business continuity (4)
6 - Digital security monitoring and log management (2)
7 - Vulnerability and incident management (2)
S6 - Main organizational measures for digital security (13)
S7 - Role of the respondent (1)
S10 - Calculations (not visible) and final real-time presentation of the macro-assessment of the SI security level to those who complete the responses, including those in Sections 5 and 6.
Completing the entire questionnaire, including the optional sections, automatically provides a macro-assessment of the digital security level that emerges from the responses provided, along with a list of the selected responses that are most critical and impactful on this assessment.
Completing the questionnaire also entitles you to all three AICA "gifts"
