Cybersecurity obligations are not negotiable. How you meet them is.
We determine whether your organisation is an essential or important entity, which requirements apply to you in concrete terms, and in what order they must be addressed. We then stay with you through implementation, testing and preparation for supervision.
Regulated sectors and applicable analyses
The annexes to GEO 155/2024 list the sectors of high criticality and the other critical sectors. For each of them we have published an analysis of the cybersecurity measures applicable to essential services.
| No. | Sector of activity | Classification |
|---|---|---|
| 01 | Energy | Annex I |
| 02 | Health | Annex I |
| 03 | Transport | Annex I |
| 04 | Drinking water | Annex I |
| 05 | Banking sector | Annex I |
| 06 | Financial market infrastructure | Annex I |
| 07 | Digital infrastructure | Annex I |
| 08 | Public administration | Annex I |
| 09 | Space | Annex I |
Service register
The same teams that draft compliance documentation also carry out technical testing and incident analysis. The measures we recommend are therefore verified in practice, not merely stated on paper.
NIS2 consulting and audit
ComplianceScope assessment, gap analysis against the legal requirements, drafting of documentation, support for implementing technical and organisational measures, preparation for audits and inspections.
Outsourced NIS2 officer
Recurring serviceCoordination of cybersecurity activities, monitoring of progress against requirements, upkeep of documentation and support for incident reporting, without an internal hire.
Web and network security audit
Technical testingTesting of web applications and APIs, external infrastructure and the internal network, wireless, Active Directory and security configurations, with a detailed report and retesting.
Malware and electronic fraud analysis
Incident responseAnalysis of suspicious files, phishing campaigns and network traffic, investigation of security incidents and clarification of the nature of the attack.
Cybercrime investigations
Expert analysisIdentification and interpretation of artefacts with criminal relevance, documentation of incidents and support in dealings with investigating authorities.
Cybersecurity training courses
Professional trainingCyber hygiene and social engineering for staff and for management, an explicit requirement under the NIS2 obligations.
How we work
Order matters: without a correct scoping assessment, the measures implemented risk being either insufficient against the legal obligations or disproportionately expensive.
Scoping
Establishing whether you are an essential or important entity and which obligations apply.
Gap analysis
Comparing the current situation against the legal requirements, on both the technical and the organisational side.
Implementation
Documentation, technical measures, internal governance, supplier assessment, incident reporting procedure.
Verification
Technical testing, preparation for audits and inspections, continuous monitoring of compliance.
Competence
Most compliance providers stop at documentation. For over 15 years we have published analyses of attacks, phishing campaigns and malware targeting organisations in Romania. That same experience underpins the measures we recommend.
- Principal field
- NIS2 and GEO 155/2024: scoping, implementation, audit, outsourced officer
- Technical capability
- Penetration testing, malware analysis, investigation of incidents and cybercrime
- Research
- An in-house department for research and innovation in cybersecurity
- Membership
- CYSCOE, CSA Romania, RoHealth; participation in national and international conferences
- Teaching
- Courses delivered in the private sector, in public institutions and in universities
In-house platforms
Platforms developed internally to support organisations in implementing the requirements and in prevention work.
CysNis
Structuring the NIS2 obligations, tracking implementation progress and keeping documentation in a single place, in a form that can be presented during an inspection.
Visit cysnis.ro ↗CysEdu
Cybersecurity courses structured by level, interactive guides, practical simulations and AI-assisted tools. Supports the obligation to train staff and management.
Visit cysedu.eu ↗Recent publications
Analyses and explanations covering the legal framework and current threats.
AI vs Phishing – who wins?
How generative models change both the attack and the defence.
AI · DisinformationFinancial fraud and fake news: the role of artificial intelligence
Disseminating and combating false information.
ResearchRestoring perceptual sovereignty in an engineered reality
On the manipulation of perception and how it can be countered.
What organisations ask us most often
Short answers to the questions that come up in almost every first conversation.
01How do I know whether my organisation falls under NIS2?
Three criteria decide it in most cases: whether you operate in one of the sectors listed in the annexes to GEO 155/2024, whether you have at least 50 employees or an annual turnover above EUR 10 million, and whether you supply services to an essential or important entity as part of its supply chain. The business activity code alone is not sufficient to establish classification.
02What is the difference between an essential and an important entity?
Both carry cybersecurity obligations. The main difference is the supervisory regime: essential entities are subject to proactive supervision, whereas important entities are checked mainly following an incident or a complaint.
03Where does NIS2 implementation start?
With the scoping analysis, not with buying technical solutions. First establish which obligations actually apply to you, then compare the current situation against those requirements, and only then decide on measures. In the reverse order you risk either insufficient measures or disproportionate spending.
04Who is accountable within the organisation for NIS2 compliance?
Management. Legal responsibility rests with the management bodies and cannot be transferred in full to an external provider or to the IT department. An outsourced officer coordinates the work and prepares the documentation, but accountability remains with management.
05What does an outsourced NIS2 officer do?
It is a recurring service through which we coordinate cybersecurity activities, monitor progress against the legal requirements, keep documentation up to date and support incident reporting, without the organisation having to hire a dedicated person internally.
Tell us your sector of activity. We will tell you which obligations apply.
The preliminary scoping conversation is free of charge. If your organisation does not fall under NIS2, we will say so directly.
- Phone
- +40 763 204 739
- [email protected]
- Response time
- One working day at most
