Skip to content
Acasă » General Interest » More than 70% of Romanian companies completely vulnerable to cyberattacks

More than 70% of Romanian companies completely vulnerable to cyberattacks

    7 July 2026
    General Interest
    Bogdan Tudorache

    Cybersecurity has long ceased to be an isolated technical issue in the IT department. In the era of Industry 4.0, in which factories, utility networks and cities become hyperconnected systems, the border between digital and physical has almost completely disappeared. Cyberattacks have migrated from computer screens directly to critical infrastructure — with production lines blocked, hospitals paralyzed, energy networks endangered and transportation systems shut down. According to a study conducted by the consulting company Frames and Infosec Center, over 70% of Romanian companies are completely vulnerable to cyberattacks, and the potential damages exceed billions of lei.

    Data published by Romanian authorities and international security organizations in 2025 and 2026 confirm that we are witnessing a real criminal phenomenon, with effects already produced on some Romanian companies and public institutions.

    The main source of new structural vulnerabilities comes from the way in which production and administration flows have been transformed in which digitalization, software infrastructure connected to online services, has become extremely vulnerable to cyber attacks.

    According to experts, the convergence between IT (Information Technology) and OT (Operational Technology – systems that control industrial equipment and physical processes) means that a digital breach instantly translates into real operational damage. Companies no longer just lose data, they also lose the ability to function.

    According to a barometer conducted by Frames between June 30 and July 2, 2026, 7 out of 10 entrepreneurs admit that they have not taken additional security measures against cyber attacks. 53% of them rely on IT teams and classic software protection solutions, and 87% of companies do not have any special protocol designed to manage cyber incidents.

    The survey, conducted online, targeted over 350 entrepreneurs and managers with responsible positions from over 800 Romanian companies from all sectors of activity.

    “Too few companies are prepared for cyber attacks, for situations in which their production can be shut down remotely, in which their data can be deleted or stolen, in which all activity can be paralyzed with huge financial consequences,” says Adrian Negrescu, Frames manager.

    Threat X-ray in Romania: 27 million cyber events

    According to data centralized by the National Directorate of Cyber ​​Security (DNSC), the scale of cyber attacks has become systemic at the national level.

    The institution’s sensors recorded approximately 27,080,000 relevant cybersecurity events in 2024.

    Of this total, most were brute force infiltration attempts — approximately 7.96 million — followed by information gathering scans, approximately 6.55 million, and events related to unjustified traffic volumes, 6.17 million.

    Cyber ​​fraud increased by 40.2% compared to the previous period, while the malware phenomenon increased by 286.8% — an increase that reflects, according to DNSC, increasingly aggressive and innovative techniques and tactics of criminals, correlated with the intensification of telephone spoofing attacks and false financial investment schemes.

    Significant increases were also recorded in the area of ​​Bruteforce attacks (+30.3%) and Account Compromise (+21%). In contrast, phishing attacks decreased by 21%, and infected IPs decreased by 27.8% — a sign, according to the institution, of better protection at the network level.

    The impact of these threats has already been felt directly in the real economy through the 101 ransomware incidents managed by DNSC recorded in a single year. One of these attacks paralyzed the activity of 26 hospitals for a week. The compromise of over 800 servers and 4,000 workstations also demonstrated the vulnerability of electricity distribution networks.

    The incidents also affected major players in the fuel market but also public administration — the attack on Timisoara City Hall affected 112 internal systems. The banking sector has also been a constant target, with incidents reported at Alpha Bank, Banca Transilvania, Banca Comercială Română, Creditcoop, Exim Bank, the National Bank of Romania, Banca Română de Credite și Investiții, the Bucharest Stock Exchange and the Guarantee Fund, along with the CFR railway network.

    DNSC states that the level of cyber threats remains high, with ransomware representing the main danger to the national civilian cyber environment.

    Experts’ estimates also show that fully automated cyber attacks with artificial intelligence will become a reality in 2-3 years.

    Romania has 12-13 million daily internet users, many without basic security knowledge — and 80% of reported attacks are fraud and scams, mostly through phishing and social engineering.

    Modern factories need cybersecurity

    According to experts from Infosec Center, the scale of the criminal phenomenon is caused by the fact that modern factories, businesses in the industrial production area no longer operate in isolation, disconnected from the global network.

    “The total connectivity of equipment through IoT sensors optimizes efficiency, but simultaneously opens thousands of new entry points for malicious actors.

    Remote access by vendors for predictive maintenance expands the attack surface beyond the perimeter directly controlled by the organization.

    On top of all this, the integration of Artificial Intelligence accelerates the speed of industrial processes, but the same technology is used by attackers to automate the discovery of vulnerabilities. Many active industrial equipment — legacy systems, with decades of operation — were designed in an era when cybersecurity was not a requirement, being completely devoid of modern defense mechanisms,” says Marius Hărătău, manager of the Infosec Center.

    What the latest global report says about the cost of these breaches

    The IBM Cost of a Data Breach report, published based on the analysis of 600 organizations globally, provides a concrete financial context.

    The industrial sector remains one of the most financially affected. Security breaches cost industrial organizations 13% more than the global average of $4.44 million — the industrial sector ranks third in terms of damage, with an average cost of $5 million, after healthcare ($7.42 million, after 14 consecutive years in first place) and financial services ($5.56 million). The energy sector follows closely, with $4.83 million per incident.

    A technical detail partly explains why the industrial sector suffers higher losses: industrial organizations take an average of 199 days to identify a breach and 73 days to combat it — both above the global average of 194 and 64 days, respectively. The longer an attack goes undetected, the greater the operational damage.

    In addition, the problem of a shortage of specialized personnel remains one of the greatest structural vulnerabilities.

    Globally, the ISC Institute estimates a shortage of 4.8 million cybersecurity professionals — and for the first time, “lack of budget” was cited as the main cause of this shortage, surpassing “lack of qualified talent,” indicating economic pressures, not just a skills shortage.

    NIS2 Directive: Personal Board Liability

    European authorities have tried to respond to this phenomenon. The NIS2 Directive obliges member states to raise cybersecurity to the level of national priority.

    In Romania, the directive was initially transposed by OUG 155/2024 and later consolidated with amendments by Law no. 124/2025.

    The scope has expanded massively, from the 7 essential sectors monitored in the old NIS1 framework to 18 sectors now — Energy, Transport, Banking, Health, Digital Infrastructure, Public Administration, Postal Services, Food, Space, Waste and Wastewater Management, Chemical Production, Digital Suppliers and Research, among others — bringing over 5,000 entities in Romania under the direct scope of the law, according to the DNSC.

    Financial sanctions are designed to deter negligence. For essential entities, fines can reach up to 10 million euros or 2% of the group’s global annual turnover. For significant entities, the threshold is 7 million euros or 1.4% of global turnover.

    Who is accountable within an organization?

    The current legislation strengthens the personal liability of management.

    “Board members can be held directly liable, civilly or administratively, for failing to implement security measures. Cybersecurity has ceased to be a purely technical function of the IT department, becoming a direct legal responsibility — management has a legal obligation to take training courses in risk management,” says Marius Hărătău, manager of Infosec Center.

    According to experts, Romanian companies need concrete compliance and industrial protection plans to face the challenges.

    Faced with an extremely complex industrial ecosystem and a rigid legislative framework, Romanian companies need pragmatic solutions and partners capable of translating cyber risks into business indicators.

    “Romanian companies need expertise, strategic advice, with the role of demystifying the technical language of IT security and exposing vulnerabilities in factories in a form directly understood by financial and operational decision-makers. By directly correlating the risk of production shutdown with profitability and legal liability indicators, expertise helps companies prioritize investments where the impact is vital for the survival of the business,” says Marius Hărătău.

    How do other countries deal with critical infrastructure security?

    The United States uses a model based on close collaboration between the public and private sectors, coordinated by the Cybersecurity and Infrastructure Security Agency (CISA).

    Through the CIRCIA law — Cybersecurity Incident Reporting for Critical Infrastructure Act, adopted in 2022 — American companies in critical sectors are required by law to report any major cyber incident within a maximum of 72 hours, and ransomware attacks in 24 hours after payment. Americans are paying increased attention to defense systems for water and energy networks, areas considered vulnerable to state attacks.

    Germany has integrated European requirements by expanding its national IT-Sicherheitsgesetz law, giving the Federal Office for Information Security (BSI) extensive control powers and the ability to impose binding technical standards directly on manufacturers of industrial equipment.

    In France, the National Agency for the Security of Information Systems (ANSSI) has for many years applied an extremely rigid regime for Critical Operators. French companies in this category must use only state-certified detection systems and are subject to military security audits.

    In the Asia-Pacific region, Australia has passed the SOCI Act — Security of Critical Infrastructure Act —, aggressive legislation that gives the Australian government “last resort intervention powers,” allowing state cyber agencies to take direct technical control of a private company’s networks during a major cyberattack, if the management of that company fails to stabilize the situation.

    Singapore uses a centralized approach through the Cybersecurity Act, where the Cyber ​​Security Authority strictly regulates the licensing of security service providers.

    From servers to the boardroom: who translates technical risk into business language?

    Cybersecurity is no longer an optional cost line in the IT budget. It is a direct variable of operational continuity, the personal legal liability of management and the financial survival of the company, says Adrian Negrescu, the manager of Frames.

    “The figures confirm the pattern at all levels — global, European and Romanian: the increase in the number of attacks, their increasing sophistication through artificial intelligence, the increasing cost of breaches in the industrial sector and the increasingly strict legislative pressure through NIS2. Companies that treat cybersecurity as an exclusively technical issue risk not only financial losses, but also direct legal consequences for their own leaders”, says Negrescu.

    This topic will also be discussed at FACTORY 4.0 2026, the place where managers understand what’s next.

    “In the Industry 4.0 era, factory architecture, infrastructure efficiency and digital security are the same crucial conversation. Cybersecurity must be integrated into governance processes, planned and tested. Investments must target not only technology, but also people and processes. Testing incident scenarios must become standard practice,” the analysis also shows.

    Infosec Center is a Romanian company specialized in cybersecurity, auditing, IT/OT consulting, data protection and secure digital transformation. The company is DNSC certified and ISO/IEC 27001:2023 certified.

    Frames is an economic think tank specialized in developing market analyses and studies on the economy. In its more than 20 years of existence, Frames has become one of the relevant players in the field of business analysis in Romania, its analyses addressed to investors and the general public offering a concrete perspective on business dynamics at local and international level.

    The opinion barometer presented in the analysis was conducted by Frames, commissioned by Infosec Center, on a target group of over 350 entrepreneurs and managers with responsible positions from over 800 Romanian companies from all sectors of activity. The consultation method was online, through a specialized questionnaire. The maximum permissible data error is ± 5%, at a confidence level of 95%.

    Autor: Bogdan Tudorache

    Active in the economic and business press for the past 26 years, Bogdan graduated Law and then attended intensive courses in Economics and Business English. He went up to the position of editor-in-chief since 2006 and has provided management and editorial policy for numerous economic publications dedicated especially to the community of foreign investors in Romania. From 2003 to 2013 he was active mainly in the financial-banking sector. He started freelancing for Energynomics in 2013, notable for his advanced knowledge of markets, business communities and a mature editorial style, both in Romanian and English.

    Leave a Reply

    Your email address will not be published. Required fields are marked *