GMB Computers
News

Articol GMB

NIS2 in Romania: Fines Are Coming, but Prevention Remains the Priority

Cybersecurity is entering a new phase in Romania. With the implementation of the NIS2 requirements, companies and public organizations covered by the legislation need to look at cybersecurity not simply as an IT issue, but as a core business responsibility.

The message recently delivered by representatives of the Romanian National Cyber Security Directorate (DNSC) is clear: sanctions for non-compliance with NIS2 will eventually be imposed, but the authority’s immediate priority remains education, prevention, and improving organizations’ cybersecurity maturity.

According to Andi Mihai, adviser to the Director General of DNSC, the Directorate has identified more than 1,800 organizations that fall under the scope of Romania’s NIS2 legislation. More than 300 of them were notified because they had not yet started the registration procedures.

NIS2 Is Changing How Companies Approach Cybersecurity

One of the most important changes introduced by NIS2 is the shift from simply “checking compliance boxes” toward a risk-based approach to cybersecurity.

In practice, it is no longer enough for an organization to have policies and procedures documented on paper. Those measures need to be integrated into the way the organization operates and manages cyber risks.

For business leaders, this represents an important change in perspective.

Cybersecurity can no longer be treated exclusively as the responsibility of the IT department.

Risks need to be identified, assessed, prioritized, and managed, while security measures should reflect the specific characteristics and risk profile of each organization.

More Than 1,800 Organizations Identified

The scale of the compliance process is significant.

DNSC has identified more than 1,800 organizations that fall under the NIS2 legislation and has notified more than 300 organizations that had not yet started the required registration procedures.

This highlights one of the main challenges surrounding NIS2: compliance is not only a technical issue. Organizations first need to understand whether the legislation applies to them and what their specific obligations are.

For any company potentially covered by NIS2, the first step should therefore be to determine its regulatory status and understand which requirements apply.

Fines Will Come, but Prevention Comes First

According to Andi Mihai, DNSC’s objective is not primarily to punish organizations.

The current focus is on education, prevention, and increasing cybersecurity maturity across the organizations covered by the legislation.

At the same time, DNSC has made it clear that sanctions for non-compliance will eventually become part of the enforcement process.

For organizations, this sends an important message:

NIS2 compliance should not be treated as something to address only after an inspection or a potential fine.

Companies that are within the scope of the legislation should use this period to identify gaps, strengthen their security measures, and establish the processes needed to respond effectively to cyber incidents.

Third-Party Risk Is Becoming More Important

Another important aspect of NIS2 is the increased focus on the cybersecurity of the supply chain.

An organization may have relatively strong internal security controls and still be exposed through a compromised supplier, software provider, cloud service, or business partner.

This means cybersecurity assessments can no longer stop at the organization’s own infrastructure.

Companies need to understand how their suppliers manage security and what risks could arise from their relationships with third parties.

Supplier assessment, contractual security requirements, monitoring, and appropriate audit mechanisms are therefore becoming increasingly important elements of cybersecurity governance.

Energy, Public Administration and Healthcare Face Significant Risks

According to data presented by DNSC, certain sectors face particularly significant cybersecurity challenges.

Based on sector-specific workshops and organizational self-assessments, Romania’s overall cybersecurity risk level has been described as medium, with higher-risk areas particularly visible in sectors such as:

  • energy;
  • public administration;
  • healthcare.

The importance of these sectors goes beyond the potential financial impact on an individual organization.

A cyberattack affecting an energy provider can disrupt critical services and infrastructure. In healthcare, the unavailability of digital systems can affect access to essential services and information. In public administration, attacks can interfere with digital services used by citizens and businesses.

This is one of the reasons why NIS2 places greater emphasis on resilience and incident preparedness.

Ransomware Remains a Real-World Threat

NIS2 is not simply about compliance documents and regulatory requirements.

Behind the legislation is a very practical problem: cyberattacks continue to disrupt organizations and their operations.

According to figures presented by DNSC, the Directorate handled 256 ransomware incidents in 2025, supporting organizations affected by attacks and helping restore services and databases.

The incidents affected public institutions, legal entities, and individuals, illustrating the continuing scale of the ransomware threat.

For businesses, this reinforces an important point: cybersecurity is directly connected to business continuity.

The relevant question is not only whether an organization is compliant, but also whether it can continue operating when its systems are compromised.

What Should Organizations Covered by NIS2 Do?

Organizations that fall under the NIS2 framework should use the current period to strengthen both their technical controls and their internal processes.

A practical approach can start with five basic questions.

1. Does NIS2 Apply to Our Organization?

The first step is determining whether the organization falls within the scope of the legislation and identifying the specific obligations that apply.

2. Do We Know Our Most Important Cyber Risks?

Organizations need to understand their critical systems, applications, data, infrastructure, and business processes.

Risk assessments should identify where a cyber incident could have the greatest operational impact.

3. Do We Have an Effective Incident Response Plan?

Organizations should not wait for an attack to determine what to do.

They need to know:

  • who is responsible for incident response;
  • who has decision-making authority;
  • which systems should be isolated;
  • which business processes are critical;
  • how backups will be restored;
  • how internal and external communication will be handled;
  • and when the relevant authorities need to be notified.

4. Do We Understand Our Supplier Risk?

A compromised supplier can potentially become an entry point into an organization’s environment.

Companies should therefore identify their critical suppliers and evaluate the cybersecurity risks associated with those relationships.

5. Is Management Involved?

Cybersecurity should not be viewed as an issue that belongs exclusively to IT.

Management needs to understand the organization’s cyber risks, determine acceptable levels of risk, allocate appropriate resources, and ensure that cybersecurity is integrated into business continuity and risk management processes.

From “We Are Compliant” to “We Are Prepared”

Perhaps the most important change brought by NIS2 is the shift in mindset.

An organization may have policies, procedures, security tools, and compliance documentation. But the more important question is:

What happens during the first 30 minutes of a cyberattack?

Who detects the incident?

Who makes the decision to isolate systems?

How quickly can critical operations be restored?

Are backups available?

Have those backups actually been tested?

Does management understand the potential business impact?

Can critical suppliers and partners be contacted immediately?

These questions move cybersecurity beyond regulatory compliance and toward real organizational resilience.

Conclusion

The implementation of NIS2 represents an important change for Romanian businesses and public organizations.

DNSC has identified more than 1,800 organizations that fall under the legislation, while the authority has already begun paying closer attention to compliance and organizational preparedness.

As enforcement develops, organizations can expect greater regulatory pressure, including the possibility of sanctions.

But the real objective should go beyond avoiding a fine.

The bigger issue is whether an organization can continue operating when a serious cyber incident occurs.

NIS2 can therefore be viewed not only as a regulatory requirement, but also as an opportunity for organizations to better understand their cyber risks, strengthen their security controls, improve incident response, and build genuine digital resilience.

For companies that have not yet started the process, the most important step is simple: start now, understand your obligations, identify your gaps, and build a cybersecurity program that works in practice—not just on paper.

GMB Computers
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.