Romanian health sector entities scored 2.34 out of 5 on CyFun® control PR.AT-02.1, which requires members of management bodies to demonstrate that they have completed training in cybersecurity and risk management. DNSC rated the result as low and concluded that competencies at management level need strengthening.
Of all the controls measured in the DNSC series, this is the only one with a direct, explicit and mandatory counterpart in Romanian law. It is not a good practice. It is a written requirement, with a penalty attached.
What the law says, word for word
Art. 14 para. (2) of GEO no. 155/2024, approved with amendments by Law no. 124/2025, provides that members of the management bodies of essential and important entities shall complete accredited professional training, so as to hold sufficient knowledge and skills to identify risks, assess cyber risk management practices and understand their impact on the services the entity provides. The same article obliges the entity to provide professional training to all staff.
The preceding paragraph is the one that changes the tone in board meetings: management bodies approve the risk management measures, oversee their implementation and are liable for breaches of these provisions. That liability cannot be delegated to the IT department.
The word “accredited” narrows the field further: an internal one-hour briefing, however well delivered, does not produce the required evidence.
Where the score comes from
The measurement is part of the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, under which 1,599 public and private beneficiaries self-assessed on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.
A 2.34 out of 5 on management training, in a sector where an unavailable system translates into postponed interventions, points to a problem of priority rather than budget. Training for management is the cheapest item in everything the ordinance requires.
What a hospital’s leadership actually decides
The decisions that matter to a healthcare provider’s security are not technical. They are management decisions, taken by people without security training:
whether to sign a contract with a supplier requiring permanent remote access into the hospital network;
whether to accept a medical device running an unsupported operating system because the manufacturer offers nothing else;
whether to approve the budget for separate backups or defer it another year;
whether, mid-attack, to pay the ransom or switch to paper procedures;
who speaks to the press and what is said in the first hours;
whether to report to DNSC within the 24-hour deadline or wait “until the situation is clearer”.
The last decision is the most expensive. Art. 15 para. (7) requires an early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours and a final report within one month. Delay out of caution is, legally, delay.
The precedent written into the ordinance
The preamble of GEO no. 155/2024 explicitly cites the incident of the first quarter of 2024, in which 26 hospitals in Romania were affected simultaneously through a managed service provider. It is the only concrete case named in the ordinance’s justification, and the sector concerned is exactly the one now scoring 2.34 on management training.
The lesson of that incident was not about antivirus. It was about the supply chain, dependence on a single provider and the absence of a plan for operating without systems, all management decisions.
Training that produces evidence
The training the law requires is not a technical course. A health entity’s leadership needs to understand four things: what legal obligations the entity carries and within what deadlines; how to read a risk analysis and what to ask about it; how to make a decision in the first hours of an incident, including the decision to report; and what personal liability follows from art. 14.
The evidence is built in parallel: the course syllabus, the participant list, the certificates issued by an accredited provider, the minutes of the meeting in which management approved the measures. At an inspection, these are requested together.
The applicable penalties are real: for essential entities, fines from RON 10,000 up to EUR 10,000,000 or 2% of net turnover; for important entities, up to EUR 7,000,000 or 1.4%, whichever is higher. Order no. 3 of 27 November 2025 approved the supervision, verification and control rules, together with the risk-based prioritisation methodology.
The most common objection
The argument heard most often in healthcare is that the priority is patients, not procedures. It is a correct argument, used wrongly. An incident that stops the laboratory system, the electronic patient record or surgical scheduling affects patients directly, and in such moments nothing is improvised. What was prepared in advance is what gets applied.
The second objection is budget. Here it is worth separating what costs money from what does not: management training, the obligations register, the notification procedure, the register of suppliers with access and the testing of backup restoration are all done with working time, not purchases. The expensive part comes later, and the right order reduces even that, because you buy what is missing rather than what is being offered.
Next steps
The first check is scope: not every healthcare provider falls under the ordinance, and the resulting level changes the volume of obligations. The CysNis platform walks through the criteria with references to the legal text.
For the real state of the measures and the documentation presented at an inspection, the next step is a NIS2 compliance analysis with a remediation plan, carried out by NIS auditors accredited by DNSC. Providers without an internal owner for the process can cover the role through an outsourced NIS2 officer, including preparing management meetings and handling the relationship with the authority. The full range of services is in the cybersecurity services register.
Romania’s transport sector scored 2.68 out of 5 on CyFun® control ID.AM-07.1, worded as plainly as possible: “The data the organisation stores and uses must be identified.” DNSC rated the result as low and concluded that identification and record-keeping of data need strengthening.
It is the least spectacular control in the whole series and, at the same time, the one that blocks everything else. Without knowing what data you hold and where it sits, there is no risk analysis, no classification, no continuity plan and no accurate incident notification.
Where the figure comes from
The measurement is part of the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”. In total, 1,599 beneficiaries from the public and private sectors assessed their own maturity on the SecureRO platform, using the CyberFundamentals (CyFun®) framework defined by the Centre for Cybersecurity Belgium.
The control’s objective, as DNSC states it, is for all data stored and used by the organisation to be clearly identified, which supports its proper management and protection and alignment with organisational and regulatory requirements.
What “identifying data” means in a transport company
A transport operator holds data in far more places than the systems inventory suggests. Categories most often missing:
location and telemetry data from on-board units, stored with the fleet monitoring provider rather than with the operator;
tachograph records and driver data, with their own statutory retention regime;
transport documents, consignment notes and customs declarations, often living in mailboxes rather than systems;
passenger data in reservation and ticketing systems, including records held by intermediaries;
operational control parameters, signalling, dispatch, terminal automation, moving between the operational and office networks;
video archives from depots, terminals and vehicles;
backups hosted with third parties, whose contents nobody can describe precisely.
An inventory that does not reach these places is not an inventory. It is a list of servers.
The link to the legal obligation
Art. 11 para. (1) of GEO no. 155/2024 requires essential and important entities to take proportionate and appropriate measures to identify, assess and manage the risks affecting the networks and information systems they use. “Identify” comes first in the text for a reason: the remaining obligations are built on top of it.
An incomplete inventory produces consequences at three distinct moments:
at the risk level assessment, carried out with the ENIRE@RO tool provided by DNSC: the answers about systems and data determine the resulting level, Basic, Important or Essential, and therefore the volume of mandatory measures;
at the annual maturity self-assessment required by art. 12 para. (4) and submitted to DNSC: you cannot assess the protection of data you have not listed;
at incident notification, within the 24- and 72-hour deadlines of art. 15 para. (7): the question “which data was affected” is answered in hours only if the inventory existed beforehand.
Transport has an extra difficulty
In transport, the boundary between office systems and operational ones is porous. A dispatch terminal, a depot workstation or a terminal management system belongs technically to the operational technology world, yet is administered with IT accounts and IT tooling. Inventories drawn up separately, by different teams, leave between them precisely the zone through which incidents propagate.
The second difficulty is suppliers. A large share of an operator’s operational data is hosted by third parties: fleet monitoring platforms, reservation systems, freight forwarding services. The data remains the operator’s responsibility even when the infrastructure does not belong to it. A serious inventory includes the column “where it physically resides” and the column “who has access”.
An inventory that holds up
The exercise is faster than it looks if done in the right order: start from the services the organisation provides, not from the list of applications. For each service, identify the data without which the service stops, then where it sits, who administers it, how long it must be kept, and what happens if it becomes unavailable or public. The result feeds directly into the risk analysis and the continuity plan, without being rewritten.
A good inventory updates itself through process: every new service, every new supplier and every new integration passes through a step that refreshes the record. Otherwise the document is accurate exactly once, on the day it was signed.
The question asked at an inspection
Through Order no. 3 of 27 November 2025, the DNSC director approved the rules on supervising, verifying and enforcing compliance with GEO no. 155/2024, together with the risk-based prioritisation methodology for those activities. The supervisory framework is in force and works on risk criteria.
In a check, the first question is not which security products you bought, but which systems and which data you hold. An operator answering with an up-to-date document that also covers supplier-hosted systems demonstrates a working process. An operator who starts asking colleagues on the spot demonstrates the opposite, and the rest of the conversation proceeds accordingly.
There is one more practical reason to do the inventory first: it lowers the cost of every step that follows. A risk analysis run over a complete record finishes in days rather than months, and the security clauses in supplier contracts can be written concretely, against identified data, instead of in general terms that oblige nobody to anything.
Where to start
Scope comes before inventory, because it determines the level of effort. The CysNis platform walks through the criteria step by step, with references to the legal text.
The question comes up in almost every scoping discussion: “we are an important entity, do we still have to appoint a NIS officer?” The answer is yes, and the legal basis requires no interpretation at all. The confusion comes from a single word missing from one paragraph, and this article shows exactly where it comes from and why it changes nothing.
In short
Art. 14 para. (3) of Romania’s GEO no. 155/2024 requires the appointment of the officer responsible for the security of networks and information systems at both essential and important entities, expressly.
Para. (4) does not create the obligation. It sets the minimum profile criteria for that person, in a subset: essential entities, excluding public administration entities, micro and small enterprises.
The difference between the two categories lies in sanction levels and supervision mode, not in the scope of obligations.
The 30 day deadline runs from communication of the DNSC director’s decision on identification and entry in the register, not from the entry into force of the law.
What the text says, literally
Art. 14 para. (3) of Government Emergency Ordinance no. 155/2024, as amended by Law no. 124/2025:
“The management bodies of essential entities and of important entities establish permanent means of contact, ensure the allocation of the resources needed to implement cybersecurity risk management measures and appoint, within 30 days from communication of the DNSC director’s decision on identification and entry in the register, the officers responsible for the security of networks and information systems whose role is to implement and supervise cybersecurity risk management measures at the level of the entity.”
Both categories are named. The verb is “appoint”, not “may appoint”. There is no grey area here. Anyone claiming that important entities are exempt has to explain how they read this paragraph, and there is no way to do it.
Where the confusion actually comes from
From the next paragraph. Para. (4) sets the conditions the appointed person must meet, but limits them to part of the entities:
“The person responsible for the security of networks and information systems, provided for in para. (3), appointed within essential entities, with the exception of public administration entities, as well as micro and small enterprises … must cumulatively meet at least the following: a) has managerial authority; b) reports directly to the management bodies of the entity; c) operates independently of the IT and operational technology structures; d) has access to the resources needed …; e) has obtained an accredited specialist course, recognised by DNSC, in the field of cybersecurity, within 12 months of appointment.”
Because only essential entities appear here, people quickly reach the wrong conclusion that important entities have no obligation. That is the exact opposite of what the text says.
Three reasons why para. (4) confirms the obligation rather than narrowing it
First, and decisive: para. (4) refers back to para. (3). The wording is “The person responsible … provided for in para. (3)”. Para. (4) does not establish a new appointment; it qualifies a person whose appointment is already imposed elsewhere. For that cross-reference to make sense, the appointment must exist in both categories. A paragraph describing a person’s profile cannot abolish the paragraph that requires that person to exist.
Second, where the law does not distinguish, neither should we. Para. (3) makes no difference between essential and important. The interpretive rule is classic, ubi lex non distinguit, nec nos distinguere debemus, and applies without difficulty to a text that expressly lists both categories.
Third, the legislator knew how to distinguish and did so where it wanted to. Para. (4) does not exclude only important entities. It also excludes public administration entities, micro enterprises and small enterprises, with an express reference to art. 4 para. (1) letters a) and b) of Law no. 346/2004. That is a deliberate proportionality pattern, not a drafting slip. And if the legislator distinguished that precisely in para. (4), the absence of any distinction in para. (3) is equally deliberate.
The practical conclusion: the difference between the two categories is not whether you appoint, but whom you may appoint.
What actually differs between essential and important
Requirement
Essential entity (excluding public administration, micro and small)
Important entity
Appointment of the officer, para. (3)
Mandatory
Mandatory
30 day deadline from communication of the DNSC decision
Yes
Yes
Role: implementing and supervising the measures
Yes
Yes
Managerial authority
Required by law
Not required
Direct reporting to the management body
Required
Not required
Independence from IT and OT structures
Required
Not required
Access to the necessary resources
Required
Not required
Accredited course recognised by DNSC, within 12 months of appointment
Required
Not required
An important entity therefore has freedom in choosing the person. It may appoint someone from the IT function, without managerial authority and without an accredited course. It may, but it is worth thinking twice, for the reason set out further down.
The trap: two different training obligations, for two different people
This is the most common reasoning error on both sides of the argument, and it deserves a clear separation.
Para. (2) requires accredited professional training for the members of the management body, at essential and important entities. That means the director, the CEO, the board.
Para. (4) letter e) requires an accredited specialist course recognised by DNSC, within 12 months of appointment, for the appointed person, only in the subset of essential entities described above.
Two distinct people, two distinct obligations. The board of an important entity takes training because para. (2) requires it, independently of anything in para. (4). Confusing the two leads either to believing that para. (4) “forgot” important entities, or that para. (2) applies to the appointed officer. Neither reading survives contact with the text.
The same distinction produces the split that matters in practice: execution responsibility belongs to the appointed person, while accountability stays with the management body under para. (1). The function can be delegated; the accountability cannot.
How the authority itself reads art. 14
DNSC has drafted a decision approving the training standard for members of management bodies and the list of recognised certifications. It is a draft, watermarked DRAFT, and not a legal act in force, so it cannot be cited as a legal basis. It is, however, the clearest public indication of how the authority itself reads art. 14, and that reading confirms everything above.
The declared scope of the standard covers both categories: the title speaks of “the training standard for the members of the management bodies of essential and important entities”, and the qualification level is defined as “Strategic / Executive Management, essential and important entities”. There is no separate, lighter version for important entities.
One of the six competence units is the appointment duty itself. Unit 3, “Organisation, Delegation and Resource Allocation”, declares its source as “GEO 155 Art. 14(3)” and is described as follows: “This unit details how the manager fulfils the legal obligation to ‘appoint’ responsible persons and to ‘supervise’ their activity.” Its first competence element requires the manager to use “the European ENISA ECSF ‘CISO’ profile and the provisions of paragraphs (3) and (4) of GEO 155/2024″ to define the job description, objectives and KPIs, to establish “reporting lines that ensure the CISO’s independence from the IT department”, and to issue “the formal appointment decision in accordance with legal requirements”.
In other words, the authority teaches the appointment as an executive duty of the management of any entity within the scope of the ordinance, and the independence criterion, which in the law appears only in para. (4), is presented as a competence element for the management of both categories. Legally that does not turn the criterion into an obligation for important entities. Practically, it shows plainly what the authority expects.
The draft also states for itself what the difference between the two categories consists of. Under the “Range of Variables” of the first competence unit: “Type of entity: Essential (critical sectors, maximum sanctions) vs. Important (slightly reduced sanctions, ex post supervision).” The difference is one of sanction level and supervision mode, not of the scope of obligations.
The same draft is what names the art. 14 (3) and (4) officer “CISO”, taking the role profile from the European ENISA ECSF framework. If it is adopted, this will become the authority’s de facto terminology, although the legal designation remains “officer responsible for the security of networks and information systems”. The standard is analysed in detail in the article on the DNSC draft training standard for management bodies, which we publish on 29 September.
The 30 day deadline: when it actually starts
This deserves to be said plainly, because it is the only real argument available to those who are waiting. The 30 day deadline does not run from the entry into force of the ordinance, but from communication of the DNSC director’s decision on identification and entry in the register. An entity that has not yet received that decision does not have the clock running.
That is not an exemption, though, it is a deferral of a procedural deadline. The substantive obligation stands, and 30 calendar days are enough to sign a decision, not to find the right person, build their job description, establish the reporting line and secure their independence from IT. Organisations that start only after receiving the decision predictably end up with a formal appointment made in haste, exactly the kind of evidence that collapses at the first inspection.
What an important entity actually risks by waiting
Failure to comply with the obligations in art. 14 is sanctionable in both categories. The maximum caps are higher for essential entities than for important ones under the ordinance’s sanctions regime, but a lower cap is not an exemption from the obligation.
The difference in mechanism matters more. Essential entities are subject to ex ante supervision, meaning they can be checked proactively. Important entities are subject to ex post supervision, which means the check usually comes after an incident or a complaint. The moment at which an important entity has to show who the appointed officer was, what duties they had and what they did is, statistically, the worst possible moment: mid investigation, with the service degraded and the press on the story.
And here is the argument that should weigh more than the letter of the law. At important entities the para. (4) criteria are not mandatory. But an officer reporting to the very structure they are supposed to control, with no managerial authority and no budget, is the first observation any auditor writes and the first weakness any post incident analysis exploits. The law permits it; risk management does not recommend it.
What to do in practice, in the right order
Confirm your classification. Essential or important, on what criterion, in which sector. Everything else follows, including which profile criteria apply to you.
Choose the person before the DNSC decision arrives. The 30 days are for formalisation, not for recruitment.
Issue the appointment decision, with duties, reporting line, indicators and a firm date.
Document the independence, even as an important entity for which the law does not require it. It costs one line in the org chart and it saves your file.
Connect the appointment to the rest of the file: the approved security policy, the signed risk register, the incident reporting procedure with its 24 hour and 72 hour deadlines, and the minutes of a risk review meeting.
For the first step, the CysNis platform walks through the classification criteria step by step and separates legal obligations from technical recommendations, so the board discussion starts from a clear status rather than an assumption.
For steps three to five, the documents do not have to be invented from scratch. The NIS2 documentation packages contain editable templates for appointment decisions, job descriptions, policies, registers and procedures. If you would rather first know how far you are from the requirements, the starting point is a NIS2 compliance assessment with a remediation plan, carried out on evidence rather than declarations. ProDefence is a NIS auditor accredited by DNSC.
Where no internal person can cover the role, and especially where the only candidate would be the head of IT, which is precisely the situation the independence criterion is designed to avoid, the role can be covered through an outsourced NIS2 officer, accountable for deadlines, documentation and the relationship with the authority. Which approach fits the organisation, in-house, consultant or outsourced role, is compared in the article on implementing NIS2 requirements in Romania, three routes.
Frequently asked questions
Do important entities have to appoint a NIS2 officer?
Yes. Art. 14 para. (3) of GEO no. 155/2024, as amended by Law no. 124/2025, requires the appointment by the management bodies of essential entities and of important entities alike. The text lists both expressly.
Then why does para. (4) mention only essential entities?
Because para. (4) does not govern the duty to appoint, but the minimum conditions the appointed person must meet. It refers expressly back to para. (3), so it presupposes that the appointment already exists in both categories. The limitation applies the proportionality principle, in the same way as the exclusion of public administration entities, micro and small enterprises in the same paragraph.
At an important entity, can the officer be the head of IT?
The law does not forbid it, because the independence requirement from IT and OT structures sits in para. (4), which applies to essential entities. From a risk management perspective it is a weak choice: the person controlling the measures ends up reporting to the structure they control, and that conflict of interest is the first observation in an audit or a post incident analysis.
When does the 30 day appointment deadline start?
From communication of the DNSC director’s decision on identification and entry in the register, not from the entry into force of the ordinance. The substantive obligation exists independently of that procedural deadline, and 30 days are not enough to recruit and prepare the right person.
Does the appointed officer need a certification?
An accredited specialist course recognised by DNSC, obtained within 12 months of appointment, is required by para. (4) letter e), so in essential entities, with the exceptions stated in the text. The law does not impose this condition on important entities.
Can the role be outsourced?
The law speaks of appointing a responsible person and, at essential entities, of criteria on authority, reporting, independence and access to resources. Covering the role through an external provider is widely practised, provided the duties, the reporting line and the contractual accountability are documented. The management body’s own accountability under para. (1) stays with the entity in any case.
What is the real difference between an essential and an important entity?
The level of the sanction caps and the supervision mode. Essential entities are subject to ex ante supervision, important entities to ex post supervision, usually triggered by an incident or a complaint. The risk management and governance obligations in art. 11 to 14 apply to both.
The analysis above is a technical reading of the text of GEO no. 155/2024, approved with amendments by Law no. 124/2025. It is informative and does not constitute legal advice. The DNSC draft decision cited is watermarked DRAFT and is not a legal act in force.
Romania’s managed ICT service providers scored 2.88 out of 5 on CyFun® control ID.IM-03.6, which requires organisations to implement, where feasible, automated mechanisms to support information sharing and collaboration. DNSC rates the result as low and recommends strengthening automation to improve operational efficiency, accuracy and security.
This score carries particular weight. ICT service management is not just another sector in the annexes of GEO no. 155/2024: it is the sector through which everyone else’s networks pass. When the provider is late, the client is late too, and the client has legal deadlines of 24 and 72 hours.
The measurement in context
The data comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, in which 1,599 public and private beneficiaries assessed their own maturity on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.
Being a self-assessment, the figure reflects how organisations see themselves. When a technical sector’s own view of its automation stops at 2.88, the verifiable situation is usually more modest still.
What “automated information sharing” means
The control’s objective is to improve the efficiency, accuracy and security of information sharing and collaboration. In practice, a managed service provider works with dozens of clients, each with its own contact, channel and reporting format. Without automation, every security advisory becomes a manual operation: someone reads the bulletin, someone decides who is affected, someone writes the messages, someone chases the replies.
What real maturity looks like on this control:
a register of clients, the services delivered to each and the technologies involved, updated automatically from management systems rather than kept in a file;
indicator-of-compromise feeds ingested and correlated automatically, not read by hand out of e-mail;
notification of affected clients triggered from the system, with delivery and acknowledgement recorded;
integration between monitoring, ticketing and incident handling, so that an incident timeline builds itself;
secure channels for exchanging information with DNSC, with clients and, where relevant, with other providers in the chain;
reports generated from data rather than assembled manually on request.
The last point is felt fastest. A final incident report written by hand a month after the event, from memory and screenshots, looks exactly like what it is.
Why the deadlines matter
Art. 15 para. (7) of GEO no. 155/2024 sets a tight calendar for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an interim report at the request of the national incident response team, and a final report within one month of the notification.
A provider who discovers that an exploited vulnerability affects, say, 40 clients has two problems at once: its own reporting and informing clients, who have the same clock running. Without automated mechanisms, the order in which clients are told becomes arbitrary, and some of them find out from the press.
The preamble of the ordinance explicitly cites a case from the first quarter of 2024 in which 26 hospitals in Romania were affected simultaneously through a managed service provider. The legislator drafted the text with that incident in mind.
The provider is checked twice
A managed ICT service provider occupies a double position under GEO no. 155/2024. On one hand it is itself an entity that notifies DNSC for registration, assesses its risk level and submits an annual self-assessment of the maturity of its measures under art. 12 para. (4). On the other, it is a link in every client’s supply chain, and clients have their own obligation to manage that chain’s risk.
The commercial consequence already shows up in tenders and contract renewals: the client asks for proof that the provider is registered, that it has notification procedures, and that it can deliver, in a usable format, the information the client needs for its own 72-hour report. A provider who cannot answer loses the contract before price is discussed.
The penalties reinforce the interest: for important entities, fines from RON 5,000 up to EUR 7,000,000 or 1.4% of net turnover; for essential entities, up to EUR 10,000,000 or 2% of net turnover, whichever is higher.
The two-hour test
A simple exercise reveals where a provider actually stands, whatever the declared score. Pick a real vulnerability published in recent months, in a product the provider administers for several clients. Then time two things: how long it takes to say exactly which clients are affected, and how long it takes to prove that all of them were notified.
If the first answer requires a morning of searching through configuration files, the register does not exist. If the second requires searching colleagues’ mailboxes, notification is a habit rather than a process. Both translate into an incident report written under pressure, inside the 72-hour window, with details that contradict each other.
What can be done without year-long projects
Automation on this control does not require a new platform. It requires the information already held in systems to move without human intervention: the client register linked to the technology register, advisories linked to the register, notifications linked to advisories, acknowledgements linked to notifications. Most providers have every piece and no connections between them.
The first step is knowing exactly what is required. The CysNis platform separates legal obligations from technical recommendations and allows scope to be checked before any investment.
For the gap between what exists and what has to be demonstrated, the next step is a NIS2 compliance analysis with a remediation plan, built on evidence. ProDefence is a NIS auditor accredited by DNSC. Providers who would rather not load their technical team with the administrative side can cover the role through an outsourced NIS2 officer, including the relationship with the authority and the answers owed to clients. The remaining services are listed in the cybersecurity services register.
NIS2 requirements in Romania can be implemented in three ways: in-house, with a consultant running the process, or through CISO as a Service, where an external specialist covers the NIS2 officer role. The obligations under GEO no. 155/2024, approved with amendments by Law no. 124/2025, are identical in all three. What differs is who does the work, how long it takes and how the cost is shaped: internal time, a one-off project, or a monthly retainer.
What follows compares the three routes on the same criteria, including the uncomfortable ones. None is inherently better. The choice depends on three things you already know: how many people you have, how quickly you need the result, and who carries the programme after implementation ends.
What has to be done, whichever route you take
Before choosing who does the work, it helps to fix the list of what the work is. It is the same for everyone:
Scoping. Establishing whether the entity falls under the ordinance and in what capacity, essential or important, including the self-assessment of disruptive effect under art. 9.
Notification for registration with DNSC, within 30 days of the moment the provisions become applicable, under art. 18 para. (2). Changes to registration data are reported within two weeks or three months, depending on the category.
Risk level assessment using the ENIRE@RO tool, whose result, validated by DNSC, sets the applicable level: Basic, Important or Essential.
Maturity self-assessment of risk management measures, within 60 days of submitting the risk assessment, and annually thereafter under art. 12 para. (4).
The substantive measures in art. 11: governance, risk analysis, incident handling, business continuity, supply chain security, access control, cryptography, testing.
Management training. Art. 14 para. (2) requires members of the management body to complete accredited professional training, and para. (1) makes them liable for breaches.
Reporting significant incidents, with an early warning within 24 hours, notification within 72 hours and a final report within one month, under art. 15 para. (7).
Readiness for inspection. The supervision, verification and control rules were approved by DNSC director’s Order no. 3 of 27 November 2025, together with the risk-based prioritisation methodology.
One thing does not change in any route: liability stays with the management body. Neither the consultant nor the outsourced officer takes it on. What is outsourced is the work and the expertise, not the legal responsibility.
Route 1. In-house implementation
The organisation runs the programme with its own resources: an IT or security team, an internally designated officer, and support from legal, procurement and HR.
When it works
It works where an information security management system already exists, whether certified to ISO/IEC 27001 or built internally, and where someone’s job description includes tracking legal requirements. It also works in organisations that went through GDPR with a serious process, because part of the inventories, registers and documentary discipline can be reused.
What it actually costs
There is no fee, but there is time, and time is the resource most often missing. For a medium-sized important entity, realistic effort runs to several hundred hours spread over six to twelve months, plus management time for approvals and training. That allocation shows up as other projects postponed.
Where it stalls
Stalls rarely happen on the technical side. They happen on documentation, on interpreting an ambiguous requirement, and at the first self-assessment, where the question is not what you implemented but what you can prove. The second classic obstacle is objectivity: the team that built the systems tests exactly the assumptions it used when building them, and self-assessment scores come out systematically more generous than what can be verified.
Route 2. Implementation with a consultant
An external consultant runs the project: scoping analysis, assessment of the current state against requirements, remediation plan, documentation and knowledge transfer to the internal team. The organisation still owns the programme, but does not start from zero and does not learn on its own.
When it works
This is the right route when the deadline is short, when the organisation has capable people without experience of this particular framework, or when a security function exists that needs method rather than execution. It also fits situations calling for an independent view, requested by shareholders, by a major client or by a sector authority.
What it costs
At ProDefence, consulting and implementation start from EUR 10,000 per project, and a compliance audit from EUR 5,000 per engagement. Price varies with the number of sites, infrastructure complexity, the presence of operational technology environments and the level produced by the risk assessment.
Where it stalls
The specific risk here is the project that finishes beautifully and stops there. The consultant leaves, the documentation stays, and at the first annual self-assessment nobody remembers where the evidence register was. A well-run consulting project includes knowledge transfer and a named internal owner, not only deliverables.
Route 3. CISO as a Service, acting as the outsourced NIS2 officer
An external specialist covers the cybersecurity officer role continuously, in the model known as CISO as a Service. It is not a project with a start and an end but a standing function on partial allocation: keeping the obligations calendar, updating documentation, preparing management meetings, handling the relationship with DNSC and coordinating incident response.
When it works
It suits organisations that fall under NIS2 without having the critical mass for a full-time post, which describes most important entities in Romania. An experienced specialist on permanent staff costs considerably more than a partially allocated role, and in many organisations the actual workload does not justify a full-time hire.
It also suits organisations that have finished implementation and discovered that the hard part is only starting: the obligation repeats annually, legislation changes, suppliers change, and incidents give no notice.
What it costs
At ProDefence, the outsourced NIS2 officer role starts from EUR 1,200 per month, on a 12-month contract with monthly invoicing. The fee depends on organisation size, the number of critical systems and suppliers, and the applicable assurance level.
Where it stalls
An external role works only if it has access and authority. If the outsourced officer learns about a new supplier after the contract is signed, or about an incident the next day, the role becomes decorative. The mandate, the access rights and the direct channel to management are settled at the start, not at the first incident.
Compared on the same criteria
Criterion
In-house
With a consultant
Outsourced officer
Who runs the programme
The internal team
The consultant, with the team
The external specialist, as a standing role
Internal time required
High
Medium
Low
Speed to first evidence
Slow
Fast
Moderate but steady
Cost shape
Internal time, no fee
Project, paid once
Monthly retainer
Entry cost at ProDefence
Documentation package, EUR 1,500 or 2,000
From EUR 10,000 per project
From EUR 1,200 per month
Legal liability
Management body
Management body
Management body
What happens after go-live
Stays with the team
Stays with the team, if handover happened
Continues without interruption
Objectivity of self-assessment
Weak point
Good
Good
Fits when
You have process and people
You have a deadline and people
You have the obligation but not the person
How to choose without asking a vendor
Three questions separate the routes better than any sales deck.
Whose job description currently includes tracking legal security requirements? If the answer is a name, in-house is realistic. If the answer is a department rather than a person, the obligation will fall between chairs.
How long would it take to prove that a declared measure actually works? If the answer is hours, you have a process. If it is days of reconstruction, you need method, which means a consultant.
Who will do next year’s self-assessment? This question dispels illusions fastest. The obligation in art. 12 para. (4) repeats annually, and a closed project does not answer it.
What all three routes have in common
Whoever does the work, two things help in every scenario.
The CysNIS platform, for records and tracking
CysNIS connects in one place the elements that in practice sit apart: the scoping assessment, the maturity level, risks, measures, plans, owners, deadlines and evidence. In-house it replaces a tool you do not have. With a consultant it keeps the programme visible to management during the project. With an outsourced officer it is the shared space where they and your team work.
The first step in any route is the indicative scoping check, by sector, service, size and the special criteria that may apply.
The NIS2 documentation package, for the written part
Most of the compliance effort is not technical but documentary: policies, procedures, registers, plans, self-assessment forms and the evidence file presented at an inspection. The NIS2 documentation package covers exactly that, with 219 documents for important entities and 229 for essential ones, the difference being the modules for the Essential assurance level, for ICT and cloud environments and for OT, ICS and SCADA environments.
It fits all three routes, for different reasons. In-house it saves months of drafting from scratch. With a consultant it shortens the project, because the conversation starts from existing documents to be adapted rather than a blank page. With an outsourced officer it becomes the base they keep current.
Prices are EUR 1,500 for important entities and EUR 2,000 for essential entities, paid once, licensed for a single organisation. ProDefence S.R.L. is not registered for VAT, so the price shown is final. The package is sold only to organisations in scope of NIS2, for their own compliance programme.
Frequently asked questions
Can NIS2 be implemented without a consultant?
Yes. The ordinance does not require a consultant. It requires the outcome: measures proportionate to risk, documented, with evidence that can be presented at an inspection. An organisation with a mature security process and a designated internal officer can implement on its own.
Does an outsourced NIS2 officer take on the legal liability?
No. Under art. 14 of GEO no. 155/2024, management bodies approve the measures, oversee their implementation and are liable for breaches. Outsourcing covers execution and expertise, not liability.
How long does NIS2 implementation take?
It depends on the level produced by the risk assessment and on the starting point. For an important entity with existing security practices, a consultant-led programme reaches a first complete set of evidence in two to four months. In-house, the usual range is six to twelve months, because the work runs alongside day-to-day operations.
What does CISO as a Service mean?
It is the model where the information security officer role is covered by an external specialist on partial allocation and a long-term contract, instead of a full-time hire. In the NIS2 context, it covers the duties of the designated officer for the relationship with DNSC and for the compliance programme.
Does the documentation package replace consulting?
No. The documents cover the form, not the content specific to your organisation. Risk analysis, scoping decisions and adapting measures to the real infrastructure still have to be done, internally or with external support. The package removes the drafting work, not the analysis.
Can the route change along the way?
Yes, and the most frequent combination is a consultant-led implementation project followed by an outsourced role that keeps the programme running. The reverse, from outsourced role to in-house, works when the organisation hires a specialist in the meantime.
Where to start
The order that saves the most time is the same in all three routes: scoping first, then risk level, then the decision about who executes. Doing it the other way round, choosing a supplier before knowing the applicable level, produces quotes that cannot be compared.
Romania’s National Cyber Security Directorate (DNSC) has published the cyber maturity score of the Romanian chemical sector for CyFun® control PR.PS-05.1: 4.40 out of 5. It is one of the strongest sector results in the series of measurements carried out under the PNRR 184 project, and the control assessed is about as concrete as they come: web and e-mail filters must be installed and used.
The figure deserves careful reading, in both directions. It confirms that the chemical industry has invested in the layer of defence that stops the most common attack vectors. It says very little about the distance still to cover towards compliance with GEO no. 155/2024, and that difference costs money when an inspection arrives.
What DNSC actually measured
Under the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, 1,599 beneficiaries from the public and private sectors assessed their own cyber maturity on the SecureRO platform, using the CyberFundamentals (CyFun®) framework developed by the Centre for Cybersecurity Belgium.
Two qualifications change how the result should be read. First, this is a self-assessment, not an audit. No evidence was requested for the answers given, and field experience consistently shows that declared scores are more generous than what can be verified. Second, CyFun® is not Romania’s compliance framework. It is a useful working instrument, conceptually aligned with NIS2, but the legal obligation is measured against GEO no. 155/2024, approved with amendments by Law no. 124/2025, and against the orders issued by DNSC under it.
A 4.40 out of 5 on a single technical control is a good signal. It is not a statement of compliance.
What control PR.PS-05.1 requires
The control text is short: “Web and e-mail filters must be installed and used.” Its stated objective is to reduce the risk of malware infection, phishing attacks and data breaches through the implementation and maintenance of effective web and e-mail filtering solutions.
The word that separates a score of 3 from a score of 5 is “maintenance”. An e-mail gateway bought in 2021 and left on its default configuration ticks the box for having a solution, not for its effectiveness. Real maturity looks different:
filtering applied to every flow, including shared mailboxes, office@ addresses and accounts used by applications;
sender authentication fully configured: SPF, DKIM and DMARC in reject mode, not merely monitoring;
attachments and links inspected at the time of access, not only at delivery;
web filtering that also covers endpoints outside the corporate network;
rules reviewed periodically, with logs retained and actually examined, not merely generated;
exceptions documented, each with an expiry date and an owner, rather than accumulated on request.
In a chemical company, filtering carries an additional stake. E-mail is how orders, safety data sheets, customs documents and correspondence with suppliers of regulated substances arrive. A forged message that changes a bank account, or an altered safety data sheet, produces more than a financial loss, it produces process risk.
Where a good technical score stops
The chemical sector appears in the annexes of GEO no. 155/2024, and entities above the qualifying thresholds fall into the essential or important category. The obligations that follow are not covered by e-mail filters.
In practice, an entity in the sector has an administrative path with its own steps and deadlines:
self-assessment of disruptive effect, governed by art. 9 of GEO no. 155/2024, for which DNSC has published a dedicated guide;
notification for registration, generated with the NIS2@RO tool, signed by the legal representative and sent to [email protected] or filed at DNSC headquarters;
risk level assessment using the ENIRE@RO tool, whose score, once validated by DNSC, sets the applicable level: Basic, Important or Essential;
self-assessment of the maturity of risk management measures, required by art. 18 para. (7), using the instrument matching the resulting level;
the substantive measures: governance, risk analysis, incident handling, business continuity, supply chain security, access control, cryptography, management training.
That last point is what catches out companies with solid technical infrastructure. The filters work, but the approved policy, the responsibility matrix, the incident register, the tested response plan and the evidence that the management body was trained are all missing. At an inspection, the documents are what is asked for.
Three checks that reveal the real score
First: send a test message with a harmless attachment carrying a double extension to a shared company address, not to the CTO’s mailbox. If it arrives, filtering covers only the main flow.
Second: check the domain’s DMARC record. If the policy is “none”, anyone can send messages in the company’s name without them being rejected. It is the cheapest control on the list and the one most often left half-finished.
Third: ask for the list of active exceptions in the filtering solution. If nobody can produce it the same day, the control is not being maintained, whatever the self-assessment says.
Supervision is no longer hypothetical
Through Order no. 3 of 27 November 2025, the DNSC director approved the rules for supervising, verifying and enforcing compliance with GEO no. 155/2024, together with the risk-based methodology for prioritising those activities. The supervisory framework exists, is public and operates on risk criteria, which means entities with a high risk level and thin documentation reach the authority’s attention first.
Where to start
The first useful step is not buying a solution, but establishing scope precisely. The CysNis platform walks through the qualifying criteria step by step and separates legal obligations from technical recommendations.
To measure the distance between the current state and the legal requirements, the next step is a NIS2 compliance analysis with a remediation plan. ProDefence is a NIS auditor accredited by DNSC, and the assessment is built on evidence rather than declarations. Organisations without an internal owner for the process can cover the role through an outsourced NIS2 officer, accountable for deadlines, documentation and the relationship with the authority. The rest of the work is listed in the cybersecurity services register.
A 4.40 out of 5 on filtering is a good starting point. The rest still has to be demonstrated.
The CysNIS platform, built by ProDefence for coordinated NIS2 implementation, has been ranked 9th in the IT & Tech category at INNOVENTURE 2025-2026, Romania’s National Innovation Competition for SMEs, with a final score of 3.85.
The recognition matters to us for a specific reason: the category was contested by software companies with hundreds of employees, and the entry assessed is not a general-purpose suite but a tool built for a single problem, NIS2 compliance in Romania.
The official IT & Tech ranking
Rank
Company
Project
Score
1
Egnosis SRL
Biobank.ro
4.32
2
Expertware S.R.L.
SIEMBIOT
4.30
3
Arhiv360
Archive management system
4.18
4
Wolfpack Digital SRL
3D2Cut
4.15
5
Planograma S.R.L.
Planograma
4.10
6
Linnify
AgentLens
4.06
7
Maya Intercons
COMPLEXIO
4.00
8
AMC Websoft SRL
CRM AMC
3.91
9
ProDefence
CysNIS platform
3.85
10
AROBS Transilvania Software
NC4F
3.62
Assessment ran in two stages. In the first round, a team of 20 experts, five per industry, selected ten innovative companies in each sector. A committee of three leaders of Romanian innovation then decided the grand prizes across all industries. The competition is an initiative of Loop Operations, and the full ranking is published on the organiser’s site.
What CysNIS actually is
CysNIS is the platform an organisation uses to check, on an indicative basis, whether it falls under NIS2, to manage the implementation of its measures and to document compliance in one place, instead of a folder of files scattered across several departments.
It connects the elements that in practice sit apart: the scoping assessment, the maturity level, identified risks, security measures, implementation plans, owners, deadlines and the evidence supporting every measure claimed.
The problem is not reading the law. It is coordination.
Organisations falling under GEO no. 155/2024, approved with amendments by Law no. 124/2025, discover quickly that the legal text can be read in an afternoon. What consumes the months that follow is something else: who owns each measure, in what order they are implemented, what evidence supports each claim, and how to keep track of a programme spanning several departments and several suppliers.
The cost of poor coordination shows up at fixed moments written into the ordinance:
the annual maturity self-assessment of risk management measures, which art. 12 para. (4) requires to be submitted to DNSC year after year, a deadline missed quietly, because nobody has it in a calendar;
notification of a significant incident, with an early warning within 24 hours, notification within 72 hours and a final report within one month under art. 15 para. (7), deadlines that leave no time for hunting through documents;
supervision by the authority, whose rules were approved by DNSC director’s Order no. 3 of 27 November 2025, together with the risk-based prioritisation methodology.
In all three, the question is the same: where is the evidence. An organisation that keeps its records inside a process answers in minutes. One that keeps them in e-mails and spreadsheets spends, at best, a day reconstructing them.
What the platform does not do
Worth saying plainly, because compliance attracts a lot of promises: CysNIS does not replace legal analysis, does not replace an audit and does not stand in for a specialist’s judgement. The scoping check it offers is indicative, and the platform does not substitute for DNSC’s own procedures or official channels.
What it provides is the operational frame: organising activities, letting teams work together, tracking deadlines and preparing evidence. The scoping decision, the evidence-based assessment and the documentation presented at an inspection remain human work, at ProDefence, the work of NIS auditors accredited by DNSC.
Why it matters for a small security firm
In a market where “compliance platform” has become a label attached to any checklist spreadsheet, an assessment by an independent jury, on innovation criteria, provides an outside reference point. It is not a product audit and it guarantees results for nobody. It is, however, confirmation that the direction, turning a legal text into a trackable operational programme, is considered useful by people outside the company.
For clients, the practical signal is different: the platform they rely on is not a project abandoned between two contracts, but a product under continuous development, with reputational stakes for whoever builds it.
What comes next
The INNOVENTURE 2026 gala is scheduled for 24 November 2026 at the Sheraton Bucharest Hotel, in the Platinum Ballroom, where the competition’s grand prizes will be announced.
Our thanks to the organisers and the jury. Development continues, with the emphasis on usefulness and traceability. The rest is marketing detail.
Where to start
If you do not yet know whether your organisation falls under NIS2, the first step is the indicative scoping check on CysNIS, by sector, service, size and the special criteria that may apply.
If scope is already clear and the hard part is next, the starting point is a NIS2 compliance analysis with a remediation plan, built on evidence. Organisations without an internal owner to carry the programme forward can cover the role through an outsourced NIS2 officer, including the annual deadlines and the relationship with the authority. The full range of services is in the cybersecurity services register.
Alexandru Angheluș has published “Transformation”, a work examining artificial intelligence beyond its conventional role as a technological application and analysing it as an emerging cognitive layer positioned between human beings and reality.
Artificial intelligence is increasingly involved in filtering information, generating content, recommending options, interpreting complex environments and assisting human and institutional decision-making.
Against this background, Transformation starts from a fundamental question: not whether artificial intelligence will change the world, but whether that transformation will remain intelligible, governable and compatible with the material limits of Earth.
The work approaches AI from a multidisciplinary perspective that connects technology, human cognition, organisational transformation, cybersecurity, governance, geopolitics and the physical resources required to sustain increasingly complex artificial intelligence infrastructures.
Artificial intelligence as a cognitive layer
AI systems no longer operate exclusively as isolated technological tools. They increasingly mediate the relationship between individuals, organisations and the environments in which decisions are made.
Search engines prioritise information. Recommendation systems influence choices. Generative systems create text, images, software and synthetic media. Decision-support platforms assist organisations in evaluating risks, allocating resources and defining courses of action.
As this mediation expands, artificial intelligence gradually becomes part of the cognitive infrastructure through which reality is perceived, interpreted and acted upon. Transformation explores the consequences of this transition.
The central issue is therefore not simply the technological performance of artificial intelligence systems, but the changing relationship between capability, vulnerability and autonomy.
The cognitively assisted Earth
One of the concepts introduced in the work is the cognitively assisted Earth – a state in which artificial intelligence systems become increasingly integrated into the operational environment of human and institutional life.
However, artificial intelligence is not immaterial. Its development and operation depend on physical infrastructures and resources, including:
energy;
water;
computing infrastructure and data centres;
semiconductors and critical minerals;
telecommunications infrastructure;
large volumes of data;
specialised human labour.
The expansion of artificial intelligence must therefore also be understood as a material transformation. The question of AI development cannot be separated from energy availability, supply-chain resilience, access to strategic resources, environmental constraints and geopolitical competition.
The cognitively assisted Earth is consequently both a technological and a physical system.
HumanAI – the artificially mediated human
A second analytical concept developed in Transformation is HumanAI. The notation describes the individual whose capabilities, vulnerabilities and decision processes are increasingly mediated by artificial intelligence systems.
AI can significantly extend human capability. It can improve access to information, accelerate analysis, support learning, automate repetitive activities and assist decision-making in highly complex environments.
At the same time, increased reliance on artificial systems introduces new vulnerabilities. When individuals delegate information retrieval, interpretation or decision-making to AI systems, their autonomy can either increase or decrease. The direction of that transformation depends on several factors, particularly competence, degree of delegation and mechanisms of verification.
A person capable of understanding how AI systems operate, evaluating their outputs and independently verifying critical information may use artificial intelligence as a powerful cognitive amplifier. Without those safeguards, the same technology may produce dependency, cognitive outsourcing or an illusion of informed decision-making.
OrgAI – the artificially mediated organisation
The same transformation is taking place at organisational level. Transformation introduces the concept of OrgAI to describe organisations whose operational capabilities, vulnerabilities and decision processes are increasingly mediated by artificial systems.
AI is progressively entering areas such as risk assessment, cybersecurity operations, financial analysis, logistics, intelligence, compliance, customer interaction, strategic planning and executive decision support. This changes organisational capability, but also the nature of organisational risk.
An organisation that delegates critical analytical or operational functions to artificial intelligence must understand what has effectively been transferred to the machine and what remains under human control. Governance therefore becomes essential.
The key question is no longer simply whether an organisation uses artificial intelligence, but how much authority it delegates to artificial systems, what controls exist around those systems and how their outputs are verified.
Security in the era of synthetic intelligence
The work also addresses the transformation of cybersecurity in an environment increasingly populated by synthetic intelligence. Generative AI changes both defensive and offensive capabilities.
Artificial intelligence can support security teams in detecting anomalies, analysing large datasets, identifying vulnerabilities and accelerating incident response. At the same time, the same technologies can support increasingly sophisticated phishing campaigns, automated social engineering, synthetic identities, deepfakes, disinformation operations and scalable manipulation.
Cybersecurity therefore increasingly extends beyond the protection of systems and networks. It also requires protecting the decision environment itself. When humans and organisations operate in information environments containing machine-generated identities, content, arguments and evidence, the ability to establish authenticity, provenance and trust becomes a fundamental security function.
AI governance and geopolitics
Transformation also examines how different political and regulatory environments are responding to artificial intelligence. The work includes European Union and United States case studies, together with chapters addressing AI governance, the geopolitics of artificial intelligence and the strategic implications of access to computing infrastructure, energy, data and critical technological resources.
Artificial intelligence is becoming an increasingly important component of national capability, economic competitiveness and geopolitical influence. The development of advanced AI systems therefore cannot be analysed independently from technological sovereignty, semiconductor supply chains, energy infrastructure, cyber resilience and strategic autonomy.
From prediction to control
Rather than attempting to predict a single technological future, Transformation explores multiple prospective scenarios. The objective is to understand what mechanisms may allow individuals, organisations and institutions to maintain meaningful control while benefiting from increasingly capable artificial systems.
The analysis therefore focuses on questions such as: How much cognitive activity should be delegated to machines? What capabilities must humans retain? How can AI-generated information be verified? How should organisations maintain accountability when decisions are increasingly AI-assisted? What infrastructures and resources are required to sustain global artificial intelligence development? And ultimately, how can technological progress remain compatible with human autonomy and the physical limits of the planet?
Continuing the ADA educational programme
Transformation continues the research and educational direction developed through the ADA programme – Analyse, Decide, Act. The programme focuses on strengthening the ability of individuals and organisations to operate effectively in increasingly complex digital and informational environments.
This direction previously produced the guide “Artificial Intelligence and the Manipulation of Human Perception”, which examined how artificial intelligence, synthetic content and automated persuasion mechanisms can influence perception, beliefs and human decision-making.
With Transformation, the analysis expands from the manipulation of information environments toward the broader transformation generated by artificial intelligence across individuals, organisations, infrastructure and society.
Access “Transformation”
The work is available in both English and Romanian, open access on Zenodo under CC BY-ND 4.0.
Topics: artificial intelligence · AI governance · cybersecurity · AI Act · NIS2 · human–AI interaction · cognitive security · geopolitics of AI · digital transformation · open access.
Prodefence is pleased to announce the publication—now available in both Romanian and English—of the educational guide “Artificial Intelligence & The Manipulation of Human Perception,” developed under the ADA program: “Analyze – Decide – Act.” As the initiator of the ADA project, Prodefence continues to invest in practical, structured resources that strengthen digital resilience and support safer decision-making in an increasingly complex information environment.
Why we launched ADA
The speed at which technology evolves has outpaced society’s ability to consistently assess risk, verify information, and respond responsibly to digital threats. Today, manipulation is no longer limited to human-driven persuasion. AI enables scale, automation, and precision targeting, amplifying influence operations, fraud, disinformation, and social engineering—often faster than individuals and institutions can react.
ADA was created to close this gap by turning high-impact topics into clear guidance, realistic scenarios, and actionable prevention and response steps.
What this publication addresses
This guide focuses on how AI can influence perception and decision-making, including:
Algorithmic amplification and attention manipulation that shapes beliefs and behaviors
Synthetic media and deepfakes (video, image, and voice) used in deception, reputational attacks, and fraud
LLM-enabled persuasion and automation, enabling scalable social engineering and narrative manipulation
Behavioral and psychological vulnerabilities that can be exploited through modern digital channels
Practical protection measures, including verification habits, decision discipline, and response actions when manipulation is suspected
The objective is not only awareness, but resilience—helping readers recognize signals, reduce impulsive reactions, and adopt safer digital routines.
ADA is not a single release, it is a growing program. Through CyberAID and the CysEdu platform, Prodefence and partners will continue to expand the ADA knowledge base with additional guides, simulations, and learning content focused on real-world risks: phishing and fraud, manipulation, AI-driven threats, incident response behavior, and digital safety for diverse audiences.
We invite institutions, educators, professionals, and community stakeholders to engage with this publication, distribute it responsibly, and participate in the broader effort to strengthen societal resilience.
Have you ever received a message that “seems” real, but something doesn’t connect?
As part of the ADA – Analyze – Decide – Act campaign, we tested a phishing message using our AI-powered platform.
Result?
⚠️ Message identified as malicious, with detailed analysis in a few seconds. 💡 The AI recognizes manipulation, hijacks emotion, and provides the user with clear explanations.
Technology is not enough if it is not accompanied by education.
Soon, we are launching the cyber education and prevention platform – an interactive space for children, parents, teachers, employees, managers and seniors.
Based on the concept of “Analyze – Decide – Act”, the platform offers you: – Real attack – Scenarios Phishing simulations and – Interactive tests – quick reaction – Guides content adapted to each type of user
🤖 With an AI assistant that teaches you how to recognize, avoid, and act.
📢 Official launch – coming soon! Pay attention to details. A new era in cyber education is coming.
We use cookies and similar technologies to store and access information on your device, for statistics and for the operation of this site. You can accept, decline, or choose by category. Declining may limit some features.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.