Managed ICT services: 2.88 out of 5 on automation. Providers are checked twice under NIS2

Cyber maturity score 2.88 out of 5 for ICT service management, CyFun control ID.IM-03.6

Romania’s managed ICT service providers scored 2.88 out of 5 on CyFun® control ID.IM-03.6, which requires organisations to implement, where feasible, automated mechanisms to support information sharing and collaboration. DNSC rates the result as low and recommends strengthening automation to improve operational efficiency, accuracy and security.

This score carries particular weight. ICT service management is not just another sector in the annexes of GEO no. 155/2024: it is the sector through which everyone else’s networks pass. When the provider is late, the client is late too, and the client has legal deadlines of 24 and 72 hours.

The measurement in context

The data comes from the PNRR 184 project “Creating new cybersecurity competencies for society and the economy”, in which 1,599 public and private beneficiaries assessed their own maturity on the SecureRO platform using the CyberFundamentals (CyFun®) framework of the Centre for Cybersecurity Belgium.

Being a self-assessment, the figure reflects how organisations see themselves. When a technical sector’s own view of its automation stops at 2.88, the verifiable situation is usually more modest still.

What “automated information sharing” means

The control’s objective is to improve the efficiency, accuracy and security of information sharing and collaboration. In practice, a managed service provider works with dozens of clients, each with its own contact, channel and reporting format. Without automation, every security advisory becomes a manual operation: someone reads the bulletin, someone decides who is affected, someone writes the messages, someone chases the replies.

What real maturity looks like on this control:

  • a register of clients, the services delivered to each and the technologies involved, updated automatically from management systems rather than kept in a file;
  • indicator-of-compromise feeds ingested and correlated automatically, not read by hand out of e-mail;
  • notification of affected clients triggered from the system, with delivery and acknowledgement recorded;
  • integration between monitoring, ticketing and incident handling, so that an incident timeline builds itself;
  • secure channels for exchanging information with DNSC, with clients and, where relevant, with other providers in the chain;
  • reports generated from data rather than assembled manually on request.

The last point is felt fastest. A final incident report written by hand a month after the event, from memory and screenshots, looks exactly like what it is.

Why the deadlines matter

Art. 15 para. (7) of GEO no. 155/2024 sets a tight calendar for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an interim report at the request of the national incident response team, and a final report within one month of the notification.

A provider who discovers that an exploited vulnerability affects, say, 40 clients has two problems at once: its own reporting and informing clients, who have the same clock running. Without automated mechanisms, the order in which clients are told becomes arbitrary, and some of them find out from the press.

The preamble of the ordinance explicitly cites a case from the first quarter of 2024 in which 26 hospitals in Romania were affected simultaneously through a managed service provider. The legislator drafted the text with that incident in mind.

The provider is checked twice

A managed ICT service provider occupies a double position under GEO no. 155/2024. On one hand it is itself an entity that notifies DNSC for registration, assesses its risk level and submits an annual self-assessment of the maturity of its measures under art. 12 para. (4). On the other, it is a link in every client’s supply chain, and clients have their own obligation to manage that chain’s risk.

The commercial consequence already shows up in tenders and contract renewals: the client asks for proof that the provider is registered, that it has notification procedures, and that it can deliver, in a usable format, the information the client needs for its own 72-hour report. A provider who cannot answer loses the contract before price is discussed.

The penalties reinforce the interest: for important entities, fines from RON 5,000 up to EUR 7,000,000 or 1.4% of net turnover; for essential entities, up to EUR 10,000,000 or 2% of net turnover, whichever is higher.

The two-hour test

A simple exercise reveals where a provider actually stands, whatever the declared score. Pick a real vulnerability published in recent months, in a product the provider administers for several clients. Then time two things: how long it takes to say exactly which clients are affected, and how long it takes to prove that all of them were notified.

If the first answer requires a morning of searching through configuration files, the register does not exist. If the second requires searching colleagues’ mailboxes, notification is a habit rather than a process. Both translate into an incident report written under pressure, inside the 72-hour window, with details that contradict each other.

What can be done without year-long projects

Automation on this control does not require a new platform. It requires the information already held in systems to move without human intervention: the client register linked to the technology register, advisories linked to the register, notifications linked to advisories, acknowledgements linked to notifications. Most providers have every piece and no connections between them.

The first step is knowing exactly what is required. The CysNis platform separates legal obligations from technical recommendations and allows scope to be checked before any investment.

For the gap between what exists and what has to be demonstrated, the next step is a NIS2 compliance analysis with a remediation plan, built on evidence. ProDefence is a NIS auditor accredited by DNSC. Providers who would rather not load their technical team with the administrative side can cover the role through an outsourced NIS2 officer, including the relationship with the authority and the answers owed to clients. The remaining services are listed in the cybersecurity services register.

Data source: DNSC, “Cyber maturity score for ICT Service Management in Romania, CyFun® control ID.IM-03.6”, 9 September 2026.

Skip to content