Health: 2.34 out of 5 on management training. The one CyFun control written directly into law
Romanian health sector entities scored 2.34 out of 5 on CyFun® control PR.AT-02.1, which requires members of management bodies to demonstrate that they have completed training in cybersecurity and risk management. DNSC rated the result as low and concluded that competencies at management level need strengthening.
Of all the controls measured in the DNSC series, this is the only one with a direct, explicit and mandatory counterpart in Romanian law. It is not a good practice. It is a written requirement, with a penalty attached.
What the law says, word for word
Art. 14 para. (2) of GEO no. 155/2024, approved with amendments by Law no. 124/2025, provides that members of the management bodies of essential and important entities shall complete accredited professional training, so as to hold sufficient knowledge and skills to identify risks, assess cyber risk management practices and understand their impact on the services the entity provides. The same article obliges the entity to provide professional training to all staff.
The preceding paragraph is the one that changes the tone in board meetings: management bodies approve the risk management measures, oversee their implementation and are liable for breaches of these provisions. That liability cannot be delegated to the IT department.
The word “accredited” narrows the field further: an internal one-hour briefing, however well delivered, does not produce the required evidence.
Where the score comes from
The measurement is part of the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, under which 1,599 public and private beneficiaries self-assessed on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.
A 2.34 out of 5 on management training, in a sector where an unavailable system translates into postponed interventions, points to a problem of priority rather than budget. Training for management is the cheapest item in everything the ordinance requires.
What a hospital’s leadership actually decides
The decisions that matter to a healthcare provider’s security are not technical. They are management decisions, taken by people without security training:
- whether to sign a contract with a supplier requiring permanent remote access into the hospital network;
- whether to accept a medical device running an unsupported operating system because the manufacturer offers nothing else;
- whether to approve the budget for separate backups or defer it another year;
- whether, mid-attack, to pay the ransom or switch to paper procedures;
- who speaks to the press and what is said in the first hours;
- whether to report to DNSC within the 24-hour deadline or wait “until the situation is clearer”.
The last decision is the most expensive. Art. 15 para. (7) requires an early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours and a final report within one month. Delay out of caution is, legally, delay.
The precedent written into the ordinance
The preamble of GEO no. 155/2024 explicitly cites the incident of the first quarter of 2024, in which 26 hospitals in Romania were affected simultaneously through a managed service provider. It is the only concrete case named in the ordinance’s justification, and the sector concerned is exactly the one now scoring 2.34 on management training.
The lesson of that incident was not about antivirus. It was about the supply chain, dependence on a single provider and the absence of a plan for operating without systems, all management decisions.
Training that produces evidence
The training the law requires is not a technical course. A health entity’s leadership needs to understand four things: what legal obligations the entity carries and within what deadlines; how to read a risk analysis and what to ask about it; how to make a decision in the first hours of an incident, including the decision to report; and what personal liability follows from art. 14.
The evidence is built in parallel: the course syllabus, the participant list, the certificates issued by an accredited provider, the minutes of the meeting in which management approved the measures. At an inspection, these are requested together.
The applicable penalties are real: for essential entities, fines from RON 10,000 up to EUR 10,000,000 or 2% of net turnover; for important entities, up to EUR 7,000,000 or 1.4%, whichever is higher. Order no. 3 of 27 November 2025 approved the supervision, verification and control rules, together with the risk-based prioritisation methodology.
The most common objection
The argument heard most often in healthcare is that the priority is patients, not procedures. It is a correct argument, used wrongly. An incident that stops the laboratory system, the electronic patient record or surgical scheduling affects patients directly, and in such moments nothing is improvised. What was prepared in advance is what gets applied.
The second objection is budget. Here it is worth separating what costs money from what does not: management training, the obligations register, the notification procedure, the register of suppliers with access and the testing of backup restoration are all done with working time, not purchases. The expensive part comes later, and the right order reduces even that, because you buy what is missing rather than what is being offered.
Next steps
The first check is scope: not every healthcare provider falls under the ordinance, and the resulting level changes the volume of obligations. The CysNis platform walks through the criteria with references to the legal text.
For the real state of the measures and the documentation presented at an inspection, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Providers without an internal owner for the process can cover the role through an outsourced NIS2 officer, including preparing management meetings and handling the relationship with the authority. The full range of services is in the cybersecurity services register.
Data source: DNSC, “Cyber maturity score for Romania’s health sector, CyFun® control PR.AT-02.1”, 27 August 2026.



