Fort Cyber: Only 27% of Romanian companies can respond to a cyber attack

George Marinescu
English Section / 10 septembrie

Fort Cyber: Only 27% of Romanian companies can respond to a cyber attack

Versiunea în limba română

Companies in our country invest in antivirus, firewall, multifactor authentication and backup solutions, but many of them continue to confuse technology acquisition with real cybersecurity, only 27% of them being prepared to specifically respond to a cyber attack, according to the results of the study "Cybersecurity Radiography in Romania in 2026", presented yesterday by Fort Cyber and carried out together with the companies Data Diggers and Promocrat. The data was collected between May and July 2026 from 211 companies in our country that should implement the provisions of the European NIS 2 Directive.

The research followed cybersecurity governance, system monitoring, incident response capacity, technical measures, security culture, planned investments, the use of artificial intelligence and preparation for the requirements of NIS2 and DORA. The results are not statistically representative of all organizations in Romania, as the sample over-represented organizations in Bucharest-Ilfov, IT and financial sector companies, large firms and decision-makers already involved in security. However, this limitation makes the conclusion even more worrying: the report's authors estimate that the market as a whole is most likely less prepared than the study data shows.

At a declarative level, 45% of organizations were classified as having the highest cyber maturity, but when the responses were confronted with three practical conditions - permanent monitoring, tested response plan and regular exercises -, the percentage of organizations with verified maturity dropped from 45% to 27%.

Delia Necula, CEO of FORT Cyber, warned that security cannot be bought once and then checked off in a compliance report: "Cybersecurity is not a project that you implement and consider completed, but an organizational capacity that must be constantly verified and improved. We also observe among our clients an increasingly pronounced concern for cybersecurity, but we need to move from the idea of static protection through the acquisition of solutions to a dynamic and mature form, namely continuous preparation for the moment when an incident actually occurs.”

Cybersecurity, isolated in the IT department - the error of Romanian companies

The study shows that basic technical measures are widespread in most participating organizations. 84% use antivirus or firewall on all devices, 82% have implemented multifactor authentication, and 81% periodically make backups and test them. However, 15% of organizations have implemented eight or nine of the nine technical measures analyzed, but have never tested their response plan. They have protection tools, but they do not know for sure whether the people, procedures and systems will work together when a crisis strikes.

"Having the technical solution is not the same as being prepared,” stressed Delia Necula at the launch of the report. FORT Cyber CEO explained that maturity does not stop at antivirus, procedures and monitoring systems, but assumes the existence of a culture that starts from the company's management and reaches every employee: "This starts at the top, but does not stay in the boss's office or in the boardroom, but goes down to the basic level of the organization and each person knows what and how to do it, and the company invests in education.”

However, the data shows that cybersecurity remains, in many cases, isolated in the IT department. Although 77% of respondents believe that security is the responsibility of every employee, only 56% say that management is visibly involved, and only 31% of organizations have designated people from different teams to support security practices.

Most incidents reported by mature companies from a cybersecurity perspective

From the cited study, we also note that more mature entities from a cybersecurity perspective are the ones that report more incidents. In 2025, 22% of organizations in the highest preparedness category identified at least one security incident, compared to only 4% of vulnerable ones. The difference does not show that mature organizations are attacked 5.5 times more often, but that they detect and report 5.5 times more incidents. In the vulnerable segment, 36% of organizations cannot even estimate how long it would take to discover an attack.

"Fewer incidents does not equal safer,” warned Delia Necula, who added: "The fact that we do not report incidents only means that we do not know or that it has not happened to us yet, but most of the time it means that we do not know that we have had them.”

In this context, the overall percentage of 15% of respondents who say their organization suffered at least one incident in 2025 should be interpreted with caution. A low rate of reported incidents may mask not better security, but an inability to notice system compromises.

The same relationship occurs with phishing. Organizations that conduct security training at least quarterly report phishing incidents at a rate of 14.6%, while the percentage drops to 1.9% for those who do not. The study does not prove that training causes incidents, but suggests that trained employees are more likely to recognize attempts and report them. Not coincidentally, employee training is the top cybersecurity priority for 2026, indicated by 52% of respondents, ahead of continuous monitoring, mentioned by 44%, artificial intelligence security, by 41%, cloud security, by 35%, and technology modernization, by 30%.

The confidence expressed by companies is, in some cases, directly contradicted by the measures in place. Approximately 53% of respondents believe that their organization can detect a significant incident in less than 24 hours, but 9% of them have no monitoring system. At the same time, 55% believe that they can respond effectively in less than 24 hours, although 16% of these organizations have no response plan.

Companies with a single IT employee, no cyber incident reports

The risk is even greater in the case of critical applications, on which the functioning of a business directly depends. Such applications are used by 72% of participating organizations, but 34% of them do not benefit from permanent monitoring, and 49% do not have a tested response plan. A single incident can stop activity, block access to data, compromise relationships with partners and customers, and produce losses that far exceed the cost of preventive measures. "We can't stress enough how important cybersecurity is in a context where an attack can shut down your business for three days,” said Delia Necula.

The level of preparedness is also closely linked to the available IT resources. Organizations with in-house IT teams achieved an average maturity score of 80 points, those using a mixed model, with internal staff and external support, reached 73, and organizations that have fully outsourced their IT services achieved 64 points. The score drops to 52 for companies that rely on a single IT employee and only 33 for those without dedicated IT staff.

None of the 22 organizations that rely on a single IT employee reported any incidents. This result may seem ideal, but when combined with the low maturity score, it may indicate a weak detection capacity. However, the study does not establish an automatic causal relationship between the existence of an internal team and the level of security, since the size of the organization, the budget and the complexity of the infrastructure influence both IT resources and training.

The cited study also shows that approximately 54% of mature organizations plan to increase their cybersecurity budget in 2026. In the vulnerable segment, only 4% anticipated an increase, and 56% did not have a budget set at the time of the research. "More mature companies tend to invest in security, and those that have invested so far are more likely to invest further,” explained Delia Necula, who added: "However, what is worrying is that those that have not invested so far do not plan to do so.”

Artificial intelligence opens a new front of vulnerability. No less than 94% of the participating organizations use AI tools in one form or another. In 49% of cases, they are used formally for certain tasks, without extensive integration, 30% of organizations have already integrated them widely into processes, and in 15% of cases, employees use AI tools on their own, without formal implementation. Rules lag far behind adoption: only 37% of organizations have written policies communicated to employees, 25% operate on the basis of informal rules, 21% have no rules, and 15% are in the process of developing them. At the same time, 36% of respondents say that their organization exercises limited control over the AI tools used by employees, and 12% admit that there is no control at all. Almost 70% fear that employees could introduce sensitive company information into such systems, 58% are concerned about decisions made based on incorrect answers generated by AI, and 38% report legal risks.

Preparation for the implementation of NIS2 and DORA, deficient

Approximately 41% of the organizations in the sample consider that they fall under the scope of one of the two European regulations, the cited study shows. Of these, only 29% state that they meet all the requirements, 14% are almost ready, 31% are in the process of implementation, and 14% are still in the analysis stage. Technology and consulting costs represent the main difficulty for 48% of the targeted organizations, followed by documentation and procedures, indicated by 47%, establishing responsibilities, by 34%, and the lack of specialized personnel, by 24%.

Even among the 25 organizations that consider themselves fully prepared, there are gaps: six do not conduct regular resilience exercises, and five do not have a tested response plan. At the same time, among the respondents who claim that NIS2 or DORA do not apply to them, at least 15 organizations seem to have misestimated their obligations, including entities in the financial-banking, healthcare, transport and energy sectors.

Gabriel Dinu, deputy director of the National Cyber Security Directorate, stated yesterday that the overestimation arises either from ignorance of the requirements or from the attempt of some organizations to hide the reality. He noted that DNSC does not expect all entities to achieve full compliance from the first self-assessment and has given them time to adapt before the audits begin. Tolerance for the accommodation period should not be confused with accepting false statements, however, warned the DNSC representative, who noted that the institution he is part of will analyze the links and contradictions between the reported controls, will keep the data for later comparisons and will be able to revisit the self-assessments when incidents occur.

"A serious organization should not rely on a falsely optimistic self-assessment, because insincerity in the relationship with the authority constitutes an aggravating circumstance when determining sanctions,” warned Gabriel Dinu. According to him, findings have already begun to be issued and sanctioning decisions will follow for non-application of NIS requirements, and concrete audits will begin after the order that will regulate this procedure is finalized.

Reader's Opinion

Accord

By writing your opinion here you confirm that you have read the rules below and that you consent to them.

Bursa Construcţiilor

www.constructiibursa.ro

www.agerpres.ro
www.dreptonline.ro
www.hipo.ro

adb