Digital infrastructure: 4.79 out of 5 on crisis communication. What NIS2 asks beyond a spokesperson
Romania’s digital infrastructure sector scored 4.79 out of 5 on CyFun® control RC.CO-04.2, which requires the designation of a public relations officer to manage public communication during recovery from a cybersecurity incident. DNSC rated the result as advanced maturity in handling public communication.
It is a good score on a control most sectors treat as a formality. It is worth understanding why this sector takes it seriously, and where the protection it offers nonetheless ends.
What was measured
The result comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, in which 1,599 public and private beneficiaries self-assessed on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.
The control’s objective, as DNSC frames it, is for public communication during recovery to be handled professionally, accurately and in line with the organisation’s confidentiality and integrity standards. Designating a trained individual aims to maintain trust, protect reputation and meet legal and regulatory requirements.
Why digital infrastructure is ahead here
Hosting providers, data centres, network operators and domain registries share a particular trait: their incidents are visible instantly, from outside, without them announcing anything. An unavailable service shows up in client monitoring within minutes. Out of necessity, the sector learned to keep a status page, prepared messages and a person who publishes them.
The second explanation is contractual. Service level agreements usually contain communication obligations with their own deadlines, and clients invoke them. Commercial pressure produced maturity that other sectors had no reason to develop.
What the law requires beyond a spokesperson
Voluntary public communication and statutory reporting are two different flows, with different recipients, deadlines and content. Confusing them is the most frequent mistake of an incident’s first hours.
Art. 15 para. (7) of GEO no. 155/2024, approved by Law no. 124/2025, sets the calendar towards the national incident response team: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours including an initial assessment of severity, impact and indicators of compromise where available, an interim report on request, and a final report within one month of the notification.
Separately, the ordinance requires service recipients to be informed about significant incidents and threats, together with the measures they can take. An incident is considered significant under art. 15 para. (6) if it has caused or may cause severe operational disruption or financial loss to the entity, or has affected or may affect other persons by causing considerable damage.
For a digital infrastructure provider, the second condition is met almost always: clients are themselves entities with their own reporting obligations. What you communicate, and how quickly, determines whether they can meet their own deadlines.
What a good communication setup is missing
A high score on designating the person does not cover the whole chain. The elements that turn out to be missing at the first real incident:
- the trigger criterion, who decides the event has become public, and at what threshold;
- texts prepared for the first two hours, when nothing is known yet but silence is already being interpreted;
- the rule against confirming technical details that help an attacker still inside the network;
- a communication channel independent of the affected infrastructure, including a status page hosted elsewhere;
- coordination between the public message, client notification and the report to the authority, so the three do not contradict each other;
- a backup person, for incidents that start at night or during leave.
The last point looks minor until it happens. Most major incidents begin outside working hours.
Reputation is lost on coherence, not on the incident
Clients of an infrastructure provider generally accept that incidents happen. What they do not accept are contradictory messages, minimisation followed by retraction, and a gap between what was said publicly and what ended up in the official report. A final report describing greater impact than was communicated to clients creates a problem separate from the incident itself.
For that reason, crisis communication and compliance cannot be prepared separately. The same facts, the same timeline, three formulations adapted to their audiences.
The one-hour exercise that shows the truth
Pick a plausible scenario, compromise of an administrative account affecting several clients, and convene, without prior warning, the people who would be involved. Time three things: how long it takes to decide the event is significant, who drafts the first public message, and who sends the early warning to the national response team.
In most organisations the first thing to stall is the decision. Nobody wants to declare a significant incident on incomplete information, and the 24-hour deadline runs from becoming aware, not from achieving clarity. A threshold written in advance and approved by management removes that hesitation from the equation.
The second thing to stall is coherence: the public message says “limited impact” while the report describes something else. Both leave the same organisation on the same day.
Next steps
Scope and level determine the volume of obligations. The CysNis platform walks through the criteria with references to the legal text.
For the notification procedure, the response scenarios and the documentation presented at an inspection, the supervision and control rules were approved by DNSC Order no. 3 of 27 November 2025, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Providers who do not want the administrative side landing on the operations team can cover the role through an outsourced NIS2 officer. The full range of services is in the cybersecurity services register.
A 4.79 out of 5 shows a sector that has learned to communicate under pressure. The rest of the road runs through synchronising that capability with the reporting obligations, two flows that start from the same facts and are not allowed to say different things.
Data source: DNSC, “Cyber maturity score for Romania’s digital infrastructure, CyFun® control RC.CO-04.2”, 21 August 2026.



