Cyber threats 2024 — statistics and trends in Romania
Romania ranks among the most targeted countries in Eastern Europe for cyber attacks. According to CERT-RO (the National Cyber Security Incident Response Center) data, over 80 million security alerts were reported in 2023, and ransomware attacks increased by 35% compared to the previous year.
Small and medium businesses are the most vulnerable. According to an ENISA (EU Agency for Cybersecurity) study, 60% of European SMEs that suffer a major cyber attack cease operations within 6 months. In Romania, the most common attacks are phishing (fraudulent emails), ransomware (data encryption with ransom demand), and business email compromise (BEC).
Top 5 security measures for any business
Regardless of company size, five fundamental measures dramatically reduce the risk of a successful attack. Implementing them doesn't require huge investments, but it does require discipline and consistency from the entire team.
- Multi-factor authentication (MFA) on all accounts — email, cloud, banking, ERP. MFA blocks over 99% of account compromise attacks.
- Automatic updates — the operating system, browser, and applications must be updated within 48 hours of a security patch release.
- Next-generation antivirus (EDR) — traditional solutions are no longer sufficient. An EDR (Endpoint Detection and Response) detects suspicious behavior, not just known signatures.
- Strong password policy — minimum 12 characters, unique per account. Using a password manager (Bitwarden, 1Password) is essential.
- Regular employee training — at least quarterly awareness sessions: how to recognize a phishing email, what to do if you click a suspicious link.
Backup and recovery — the plan that saves you
The golden rule in security is the 3-2-1 strategy: three copies of data, on two different media types, with one off-site. Cloud backup alone is not sufficient if the cloud account can be compromised by an attacker — that's why the off-site backup must be isolated (air-gapped or with restricted access).
Equally important is periodic restore testing. An untested backup is almost as dangerous as having no backup at all. We recommend a full restore test at least quarterly. Our IT team configures and monitors automated backup solutions for our clients.
GDPR and data security — legal obligations
The General Data Protection Regulation (GDPR) requires appropriate technical and organizational measures to protect personal data. Article 32 of the GDPR explicitly mentions: pseudonymization and encryption of data, ensuring confidentiality and integrity of systems, the ability to restore data quickly in case of incident, and regular testing of security measures.
GDPR violations can result in fines of up to 4% of annual global turnover or EUR 20 million. ANSPDCP (the National Supervisory Authority) has already imposed significant fines in Romania, including on SMEs that lacked minimum protection measures.
IT security audit — why it's necessary annually
An IT security audit systematically evaluates your infrastructure vulnerabilities: misconfigurations, outdated software, excessive access rights, lack of encryption, and inadequate backup policies. The audit produces a report with clear priorities and a short and medium-term remediation plan.
We recommend a full audit at least once a year, plus a rapid assessment after any major infrastructure change (cloud migration, provider change, new office). Geseidl consulting includes IT security assessments tailored to your company's size and budget.
Need IT services and cybersecurity? The Geseidl Consulting Group team, CECCAR Prahova leader for 18 consecutive years, is ready to help. Discover our services or contact us for a free consultation.
Geseidl Consulting Group
CECCAR #1 Prahova · CAFR Rating A · ANEVAR · CCF #233 · ISO 9001:2015
Learn more about us →
