Cătălina Dodu, Partner, EMEIA Cyber Managed Services Solutioning Leader, Technology Consulting & Cybersecurity Leader, South Cluster, EY
Cyber-attacks are no longer an “IT” risk, but a direct test for the continuity of essential services – especially in energy, where OT environments, legacy infrastructures, and interconnected ecosystems can quickly turn an incident into a systemic crisis. Based on the conclusions of an EY study, we discussed with Cătălina Dodu the paradigm shift from prevention and compliance to detection, response, and recovery, the lessons of 2025, and investment directions for 2026 – globally and in Romania.
Bogdan Tudorache
What should we do to avoid a possible energy blackout caused by cyberattacks?
Avoiding a power blackout caused by cyberattacks requires a clear paradigm shift: from a reactive approach, focused on compliance and punctual prevention, to one of integrated operational resilience, in which cybersecurity is treated as an essential part of the security and continuity of the power system.
A new EY study (Cybersecurity: From value protection to value creation | EY – Global) shows that the main risks come from the combination of exposed OT infrastructures, limited visibility, fragmented processes and reduced capacity for coordinated response.
A key element is the shift from exclusive prevention to continuous detection, response and recovery capabilities. In energy infrastructures, it is unrealistic to assume that all attacks can be blocked. Therefore, the ability to quickly identify an incident, isolate it and keep critical services operating becomes more important than absolutely avoiding any breach. The EY study highlights that organizations with mature response mechanisms significantly reduce the risk of systemic disruptions, even in the event of successful attacks.
Also, network segmentation, continuous monitoring of OT environments and periodic testing of crisis scenarios are key measures to limit the propagation of an incident. An attack that compromises one point in the infrastructure should not be able to automatically escalate to a blackout at a regional or national level. This requires both robust technical architectures and clear decision-making and escalation processes.
Another critical aspect highlighted by EY is organizational and executive preparedness. Energy blackouts are not just technical events, but systemic crises, with major economic, social and reputational impact. Therefore, cybersecurity must be integrated into business continuity and crisis management plans, and decisions regarding investments and security priorities must be assumed at the top management level, not left exclusively to the technical area.
Last but not least, cooperation at the ecosystem level is essential. The energy sector is deeply interconnected, and the real level of security is determined by the most vulnerable link in the chain. The EY study shows that sharing threat intelligence, joint exercises and alignment with NIS2 requirements are critical factors in reducing the risk of attacks with systemic impact.
In conclusion, avoiding a power blackout caused by cyberattacks is not about a single technology or one-off investment, but about building end-to-end digital resilience, in which security, operations and executive leadership work together to protect critical infrastructure and the continuity of essential services.
What were the main challenges of 2025 in terms of cybersecurity threats? What were the response vectors?
The year 2025 confirmed that cybersecurity can no longer be treated as a defensive function, oriented exclusively towards risk reduction, but as a structural component of resilience and business value. The threat landscape has become significantly more complex, with attacks increasingly becoming isolated events and increasingly multi-vector scenarios that simultaneously impact IT infrastructure, OT environments, data, digital identity and supply chains. Increasingly, a single incident combines technological vulnerabilities, configuration errors, social engineering vectors and a lack of mature response processes.
Globally, ransomware and cyber extortion continued to dominate, but in much more sophisticated forms, with successive stages of compromise, lateral movement, data exfiltration and reputation pressure. Attackers no longer simply aim to encrypt systems, but use data as a bargaining chip. In parallel, attacks on supply chains highlighted the fragility of interconnected digital ecosystems, demonstrating that the true level of security is determined by the weakest link in the ecosystem.
A defining factor for 2025 was the increasing exposure of OT environments. The accelerated digitalization of industrial and energy infrastructures, combined with limited integration between IT and OT security, created extensive attack surfaces that are difficult to monitor with traditional tools. In this context, a cyber incident no longer only has an IT impact, but can also generate operational disruptions, direct financial losses and even physical risks.
Another defining element of 2025 was the increasingly advanced use of artificial intelligence by attackers. AI was used for adaptive phishing, automatic generation of credible content, personalization of attacks and evasion of classic detection mechanisms. This evolution drastically reduced the effectiveness of static controls and increased pressure on organizations to adopt security models based on behavior, context and advanced analytics.
The geopolitical context amplified these risks, with the increase in specialized attacks, oriented more towards systemic disruption and persistence than immediate financial gain. This type of threat has significantly raised the stakes for organizations operating critical infrastructure or essential services, where the impact of an incident goes beyond organizational boundaries and can affect entire sectors.
In Romania, these global trends have been felt even more acutely, due to uneven levels of cyber maturity, legacy infrastructures, and limited coverage of OT environments. Many organizations realized in 2025 that the problem is not the lack of technological solutions, but the lack of real operational capabilities for detection, response, and recovery, as well as insufficient integration of security into business processes.
In response, 2025 accelerated the transition to intelligence- and risk-based security models, with a much greater emphasis on strengthening SOCs, automating detection and response processes, and integrating security into business continuity and operational resilience. More importantly, security has begun to be treated as an executive decision topic, not just a technical one, amid awareness of the direct impact on organizational continuity and value.
What are the latest trends in cybersecurity investments for 2026, globally and in Romania? How have budgets been resized, especially in banking and energy?
For 2026, the discussion about cybersecurity goes beyond “how much” is invested and increasingly focuses on where and how value is created from these investments. EY data clearly shows that organizations are entering a stage of strategic optimization, in which they are reevaluating their security architectures to reduce complexity, eliminate redundancies and increase operational efficiency.
Globally, there is an accelerated migration from point solutions to integrated security platforms, capable of correlating data from multiple sources, automating the response and providing end-to-end visibility over the attack surface. Investments in AI-driven detection and response are becoming standard, and automation of security processes is starting to generate measurable benefits not only from a risk perspective, but also from a cost perspective.
The EY study highlights that organizations that have simplified and automated the cybersecurity function are already achieving significant annual savings, in the millions of dollars, as a result of reducing the number of tools, operational optimization and decreasing detection and response times. As the use of AI matures, these benefits are expected to increase, both through direct savings and through the ability to support faster and more secure strategic initiatives.
In the banking sector, budgets are mainly directed towards identity, data protection, application security and operational resilience, in the context of DORA and NIS2 requirements. The focus is on the ability to prevent fraud, ensure the continuity of digital services and demonstrate compliance in a transparent and auditable way.
In energy and utilities, the focus is on OT security, network segmentation, continuous monitoring and the ability to quickly detect and respond to incidents that can have physical and operational impact. The NIS2 directive has brought additional clarity and support in prioritizing cybersecurity measures, moving the discussion from minimal compliance to resilience and protection of operational value.
In Romania, the resizing of budgets largely reflects a need to catch up. Investments are focused on SOC modernization, the use of outsourced services and sourcing models that allow obtaining the same level of security with more efficient costs, in a context of a sharp shortage of specialists.
How has the appetite and openness of managers towards cybersecurity services evolved? Has reluctance disappeared in Romania?
One of the most relevant signals from the EY study is the change in perception at the executive level. Cybersecurity has clearly gone beyond the area of “IT risk” and is increasingly treated as a factor in protecting value and supporting digital transformation. Organizations where the security function is involved early in strategic initiatives generate measurably greater value, including by accelerating technology adoption, strengthening brand trust and improving customer experience.
However, the study also shows a persistent challenge: while cybersecurity significantly contributes to the value of strategic initiatives, most security leaders find it difficult to articulate this value beyond risk reduction. Early involvement of CISOs in strategic decisions remains limited, which explains why, in many organizations, security is still perceived as a control function rather than an enabler of growth and innovation.
In Romania, the traditional reluctance to invest in cybersecurity has visibly diminished, especially in organizations exposed to critical infrastructure, complex digital operations and European compliance requirements. Managers increasingly demand clear indicators of efficiency, impact and contribution to business objectives, not just technology implementations or compliance reports.
What should CIOs and CTOs in Romania consider in the coming period?
For CIOs and CTOs, the next period will be defined by the ability to integrate security directly into the business and technology architecture. The EY study notes that organizations with superior results are those that treat cybersecurity not as a layer applied later, but as an enabler of technological adoption, including artificial intelligence.
The priority is no longer exclusively prevention, but the development of continuous detection, response and recovery capabilities, supported by automation and AI. At the same time, simplifying security architectures and reducing the number of tools is becoming essential to fully leverage the benefits of AI and increase visibility into the attack surface.
Skills shortages remain a major constraint, which is why hybrid models and managed services will continue to play a key role. Equally important is the ability of technology leaders to translate cyber risk and value into business-relevant language so that security is integrated into strategic decisions.
In this context, the role of the CIO and CTO is evolving to that of orchestrator of digital resilience, and cybersecurity is becoming a fundamental component of organizational architecture and long-term value creation.
