Cyber-attacks have become a business and anyone intent on compromising a company or institution’s cyber-system can buy this service on the dark web, said Yugo Neumorni, president of the CIO Council at the DigitALL 2025 conference organised by Energynomics.
“Ransom as a Service is real. Anyone can go on the dark web and order a cyber attack on a company, and the payment is not upfront, but only if the attack is successful. Basically, cyber-attacks have become a business model, with clear terms and a ‘guarantee’ of the outcome,” Neumorni said.
The situation is made worse by the increasing use of artificial intelligence by attackers. For example, 42% of organisations have already fallen victim to cyber-attacks based on psychological manipulation techniques powered by AI, and technologies such as deepfake are becoming increasingly dangerous.
According to Neumorni, no company can defend itself against these threats. Currently, only 0.5% of a company’s revenue is allocated to cybersecurity, which is insufficient.
However, awareness is starting to grow in large organisations, and a third of executives are already concerned about the risk of economic espionage and loss of intellectual property. Progress is also being seen on company boards, which are starting to treat cyber security more seriously.
Romania, says Neumorni, has the potential to become a regional leader in areas such as energy and IT, but to succeed it needs to invest in cyber protection and treat these risks seriously. Otherwise, the price will be much higher.
The World Economic Forum estimates that global losses from cybercrime will reach $10.5 trillion by 2025. The rise in attacks is fuelled by factors such as geopolitical tensions, weaknesses in supply chains, the emergence of artificial intelligence, a shortage of cybersecurity specialists and the increasing difficulty of complying with complex EU regulations.
A common reason for security breaches is companies’ carelessness in vetting technology vendors. Thus, in many cases, attackers have penetrated companies’ systems through these vendors, taking advantage of the lack of controls. In fact, 54% of organisations admit that they cannot achieve a good level of cyber protection precisely because they do not have control over the entire supply chain.
Another worrying aspect is the huge amount of time it takes from the moment an attacker breaks into a system until the company realises it. On average, according to IBM, it takes nine months for an organisation to detect and stop an intrusion. In Romania, the situation is even more delicate. Many companies, including in strategic sectors such as energy, do not even have basic systems to detect attacks. What’s more, most incidents go unreported. About 90% of cyber attacks are not made public. Even if they are known to have occurred, especially in the banking sector, the details remain hidden, Neumorni said.
The “DigitALL 2025” conference was organised by Energynomics, in partnership with reputed organisations such as the CIO Council and EPG, with the support of our partners: ABB, Corning, Datacor, Eaton Electric, Enevo Group, Enevo Group, Procesio, Renomia, script.ai, Sunwire, Vertiv.
