Most companies in the Romanian energy sector have not implemented basic cybersecurity measures for their OT (Operational Technology) infrastructure, despite the requirements of the European NIS 2 Directive, said Cătălin Gherghiceanu, Presales Manager at Safetech Innovations, a company specializing in cybersecurity.
“Risk analysis in the OT area is a matter of science fiction. Asset inventory is a matter of science fiction. Segmentation is a matter of science fiction,” said Gherghiceanu at the DigitALL 2026 conference organized by Energynomics in Bucharest.
He described a situation in which no one documents what they are building: networks are implemented without an architectural diagram, and whoever takes over that infrastructure later is unable to understand what they are dealing with. “They come and do it for you. They’re wonderful, but until you get them to put what they’ve done on paper. That’s where everything gets stuck,” he said.
The direct consequence is that any reactive remediation becomes costly and time-consuming.
He added that proprietary protocols, known only to the manufacturer, do not constitute protection because experienced attackers, backed by some governments, have sufficient funds, knowledge, and intelligence from secret services to penetrate any inadequately protected system. “This is, at best, a bad practice known as security through obscurity,” he said, comparing the situation to the argument from many years ago that Linux cannot be attacked. Another frequently identified false sense of security is the use of telecom operators’ VPN services instead of an in-house infrastructure.
As minimum requirements for any company in the OT sector, Gherghiceanu recommends three essential steps. First, a risk assessment, an asset inventory (asset management), and a clear diagram of the network architecture. Without visibility into what exists on the network, no security solution can be effective, no matter how powerful the implemented tools are. “That inventory must be done so you know what you want to protect,” he emphasized.
Regarding compliance with the NIS 2 directive, Gherghiceanu identified two categories of companies and “a chasm between them.” On the one hand, large companies and multinationals, which have resources, mature processes, and are relatively prepared—they only need fine-tuning and documentation for potential audits. On the other hand, smaller companies and state-owned enterprises, where funding is scarce, systems have been cobbled together, and OT staff lack cybersecurity training. IT, for its part, avoids getting involved in the OT area, viewing it as an additional burden on top of already overwhelming daily tasks.
The Safetech representative expressed hope that the NIS 2 directive will bring discipline to the market, noting that the DNSC is likely to issue warnings and even penalties to companies that have not registered on their own initiative, as they were required to do.
The DigitALL 2026 conference was organized by Energynomics, with the support of our partners: CBRE Romania, Eaton Electric, EnergoBit, KSTAR New Energy, WALDEVAR Energy, and WTW Romania.
