Romania’s Cyber Wake-Up Call for Boards 

Eduard Cristian Simionescu

2 Min Read

Nearly one in four companies in Romania (23%) has already experienced a cyberattack, yet many still treat the risk as moderate until disruption becomes real.

Cyber risk is now a boardroom issue, not simply a technical one. In an environment shaped by volatility, digital dependence and constant disruption, the real challenge for leaders is not whether cyber threats exist, but how confidently they can steer their organisations when uncertainty escalates and operational resilience is put to the test. 

We recently conducted a Cybersecurity Study in collaboration with BCR which offers a timely snapshot of how Romanian businesses are assessing cyber exposure, where preparedness remains weak and what this means for boards trying to lead through complexity. Its message is clear: resilience depends less on reacting to crises and more on acting earlier, asking harder questions and treating cyber as a leadership responsibility.

Boardroom Lesson 1: Awareness Is Not the Same as Preparedness 

70% of Romanian companies have never conducted a cybersecurity audit and 73% spend less than 1% of annual turnover on cybersecurity. Our study shows a familiar gap: risk is recognised, but not yet governed with enough discipline. For boards, the priority is to turn awareness into oversight, investment and earlier action. 

This matters because cyber exposure rarely stays confined to IT. It affects continuity, trust, supply chains and decision-making under pressure. Boards do not need to become technical specialists, but they do need clearer visibility, sharper challenge and the discipline to test whether investment and governance match the level of risk.

Boardroom Lesson 2: Complexity Becomes Dangerous When Risk Feels Distant 

Nearly one in four companies in Romania (23%) has already experienced a cyberattack, yet many still treat the risk as moderate until disruption becomes real. For boards, the lesson is simple: cyber resilience should be managed as a business continuity issue, not left to technical teams alone. 

The danger is that experience often changes perception too late. Once an incident affects operations, customers or reputation, leadership choices become narrower and more costly. Mature boards learn from market signals before learning the hard way themselves and make cyber resilience part of wider continuity planning. 

Boardroom Lesson 3: Regulation Is Raising the Leadership Standard 

Awareness of the EU NIS2 Directive remains low, with only 13% of companies seeing it as relevant to their business. But NIS2 is raising the bar for governance, risk management and continuity. Romanian boards that engage early will be better prepared both for compliance and for disruption. 

That is why regulation should not be seen simply as an administrative burden. For leadership teams, it is a prompt to clarify accountability, strengthen governance and build a more resilient operating model. Boards that take this seriously early will be in a far stronger position when disruption occurs. 

What Boards Need Next: Clarity, Advice and Risk Transfer 

Our study also shows a protection gap. While 39% of companies are aware of cyber insurance, only 4% have implemented it, with lack of information the main barrier. This suggests that many organisations still need clearer guidance on how advisory support and risk transfer fit into a broader resilience strategy rather than being treated as isolated products or last-minute fixes. 

For boards, the value of cyber advisory lies in creating orientation. Leaders facing complexity do not need more noise; they need a clearer view of exposure, better understanding of priorities and confidence about which actions will reduce risk most effectively. Insurance has an important role, but it works best when grounded in sound assessment and informed decision-making. 

What our study ultimately makes clear is that Romanian companies are not short of warning signs. The more pressing challenge is whether leadership translates those signals into earlier decisions, stronger governance and meaningful investment in resilience. 

In today’s environment, one of the clearest tests of leadership maturity is whether boards are prepared to act before complexity turns into crisis. The organisations that will navigate disruption best are those whose leaders treat cyber resilience not as a specialist topic, but as a core boardroom responsibility.

Eduard Simionescu

General Manager
GrECo Romania

T +40 (756) 104 104

Related Industries & Solutions

Share this article

Related Insights

We spoke with three leaders from different industries about energy independence in Europe.
GrECo and DIGNITA Join Forces to Strengthen Their Position in Bosnia and Herzegovina
 Paul Johannes Spittau explores transformation with Olivera Böhm-Rybak, Chief Corporate Business Officer International and CEO of UNIQA Sustainable Business Solutions.