{"id":30836,"date":"2026-07-23T15:16:04","date_gmt":"2026-07-23T12:16:04","guid":{"rendered":"https:\/\/safetech.ro\/what-romanian-companies-need-to-learn-after-the-ancpi-attack-ionut-georgescu-ceo-of-safetech-at-zf-live\/"},"modified":"2026-07-23T15:49:05","modified_gmt":"2026-07-23T12:49:05","slug":"what-romanian-companies-need-to-learn-after-the-ancpi-attack-ionut-georgescu-ceo-of-safetech-at-zf-live","status":"publish","type":"post","link":"https:\/\/safetech.ro\/en\/what-romanian-companies-need-to-learn-after-the-ancpi-attack-ionut-georgescu-ceo-of-safetech-at-zf-live\/","title":{"rendered":"What Romanian companies need to learn after the ANCPI attack. Ionu\u021b Georgescu, CEO of Safetech, at ZF Live"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30836\" class=\"elementor elementor-30836 elementor-30827\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-183f9ca0 e-flex e-con-boxed e-con e-parent\" data-id=\"183f9ca0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89f99b0 elementor-widget elementor-widget-ld_breadcrumb\" data-id=\"89f99b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"ld_breadcrumb.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"lqd-breadcrumb-wrapper\"><nav role=\"navigation\" aria-label=\"Breadcrumbs\" class=\"breadcrumbs\"><ol class=\"breadcrumb reset-ul inline-nav inline-ul comma-sep-li\"><li class=\"breadcrumb-item active\"><a href=\"https:\/\/safetech.ro\/en\/\" rel=\"home\"><span>Home<\/span><\/a><\/li><\/ol><\/nav><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30467982 elementor-widget elementor-widget-text-editor\" data-id=\"30467982\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3>What Romanian companies need to learn after the ANCPI attack. Ionu\u021b Georgescu, CEO of Safetech, at ZF Live <\/h3><p>The cyber attack that paralyzed the systems of the National Agency for Cadastre and Real Estate Advertising has brought to the surface a discussion that the Romanian business environment has been postponing for too long: how prepared are organizations in Romania to withstand a large-scale attack? Ziarul Financiar opened this topic during the ZF Live show, in a discussion between Cristian Ho\u0219tiuc, editor of ZF, and Ionu\u021b Georgescu, CEO of Safetech Innovations \u2014 an approach through which the publication sought the opinion of market experts, in order to outline the lessons that Romanian companies should draw from this incident. <\/p><p> <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-718d049 elementor-widget elementor-widget-image\" data-id=\"718d049\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"780\" height=\"436\" src=\"https:\/\/safetech.ro\/wp-content\/uploads\/2026\/07\/ZF-Live-Safetech-1024x572.webp\" class=\"attachment-large size-large wp-image-30830\" alt=\"\" srcset=\"https:\/\/safetech.ro\/wp-content\/uploads\/2026\/07\/ZF-Live-Safetech-1024x572.webp 1024w, https:\/\/safetech.ro\/wp-content\/uploads\/2026\/07\/ZF-Live-Safetech-300x167.webp 300w, https:\/\/safetech.ro\/wp-content\/uploads\/2026\/07\/ZF-Live-Safetech.webp 1600w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e046fea elementor-widget elementor-widget-text-editor\" data-id=\"e046fea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p> <\/p><p>The full interview can be watched here:<\/p><p><iframe title=\"ZF Live: 21.07.2026 \u2013 Ionu\u021b GEORGESCU, CEO, Safetech\" width=\"780\" height=\"439\" src=\"https:\/\/www.youtube.com\/embed\/-0I3t6XGchU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p><h3>An attack that is not isolated, although it seems so<\/h3><p>Being an ongoing investigation, the discussion did not concern the ANCPI case itself, but the general mechanisms of such incidents, as they have been observed in other similar situations. The conclusion remains the same: what happened at the Cadastre is not a singular case, but the symptom of a broader trend. In the private sector, ransomware attacks have become as frequent and aggressive as those targeting public institutions \u2014 the difference is that many companies choose not to make them public, for fear of the impact on reputation or market value.  <\/p><p>The attackers do not distinguish between public and private. They look for loopholes that they can exploit financially, and organizations that have not updated their infrastructure or trained their employees remain easy targets. <\/p><h3>From weeks to days: the speed has changed radically<\/h3><p>One of the most important aspects of the discussion at ZF Live concerns the speed with which an attack is carried out today. If a few years ago an attacker could spend between a week and a month in an infrastructure before reaching data exfiltration or encryption, today this interval has been compressed to just two to three days. The explanation lies in the tools used: attackers are increasingly relying on AI-driven agents, which automatically scan the internet and quickly identify exploitable vulnerabilities, without the need to manually search for breaches.  <\/p><p>The profile of those who launch these attacks has also changed, and the average age of the attackers has visibly decreased \u2014 more and more of them being teenagers, not just adults with technical experience.<\/p><p>The entry point, however, remains the same as always: you need only one &#8220;open door&#8221; \u2014 that &#8220;weakest link&#8221; that is constantly talked about in cybersecurity. The rest of the infrastructure can be well protected, but if a single link fails, the entire system becomes vulnerable. That is why protection must be thought of as a unitary whole, not as a sum of isolated measures.  <\/p><p><em>&#8220;The technique of attackers has changed radically with the emergence and integration of Artificial Intelligence. If until a few years ago a cyberattack was carried out slowly, over weeks or even months, during which hackers analyzed the network, tested the ground and advanced step by step, today we are talking about an unprecedented acceleration. By using autonomous agents and AI-powered tools, attackers are no longer wasting time. In just two to three days \u2014 or even a few hours \u2014 things happen instantly: the vulnerability is identified, exploited, and the data is already exfiltrated before the victim understands what is happening and reacts,&#8221;   <\/em>said <strong>Ionut Georgescu, CEO Safetech Innovations<\/strong>.<\/p><h3>How does an attack take place in practice?<\/h3><p>Beyond the context, the discussion also descended into the actual dynamics of a ransomware incident: once attackers find the entry point, the first objective is to locate and compromise backup systems \u2014 to eliminate any way for the victim to recover without paying. This is followed by data exfiltration and encryption, and then negotiation. Even when a company decides to pay, there is no guarantee that it will receive the correct decryption keys or that the data will be fully recovered \u2014 the risk of being left with unavailable information persists regardless of the outcome of the negotiation.  <\/p><p>That is why prevention matters infinitely more than any negotiation after an attack.<\/p><h3>Romania, between awareness and maturity<\/h3><p>The level of awareness regarding cyber risks has visibly increased in recent years in Romania, but the business environment remains, overall, in an intermediate maturation phase. Large corporations and the banking sector have robust protection systems, but small and medium-sized companies remain exposed. Unlike markets in Western Europe or the US, where cybersecurity is treated as a mandatory strategic investment, in Romania it is still viewed, in many cases, as an optional cost \u2014 until a serious incident occurs. Essentially, however, the level of protection is very much about understanding and openness of management.   <\/p><h3>How much does prevention actually cost?<\/h3><p>One of the natural questions that any discussion about cybersecurity raises is the one related to cost, and Cristian Ho\u0219tiuc asked Ionu\u021b Georgescu explicitly &#8220;What costs does a company have to ensure a decent level of protection and resilience?&#8221;<\/p><p>The financial structure of a real protection is usually divided into two stages:<\/p><ul><li><strong>Initial assessment and audit<\/strong> \u2014 identification of vulnerabilities through a security audit, with a cost that is usually up to 10,000 Euro.<\/li><li><strong>Proactive and continuous protection<\/strong> \u2014 services carried out through a security operations center (SOC), with 24\/7 threat detection and response, at a cost of several thousand euros per month.<\/li><\/ul><p>Balanced against the losses caused by a total blockage of activity \u2014 days or weeks of stopped operations, lost data, damaged reputation \u2014 this monthly investment becomes a perfectly sustainable financial effort.<\/p><p><em>&#8220;To have a functional cybersecurity, organizations must understand that protection is an ongoing process, not a one-off project. An initial analysis and a rigorous security audit, which shows exactly where the network breaches are, reach a cost of up to 10,000 euros, an absolutely affordable amount for any business that depends on the digital environment. <\/em><\/p><p><em>Subsequently, prevention involves proactive monitoring and detection of threats in real time, services that amount to several thousand euros per month. If you balance these monthly costs with the risk of losing your entire database or having your operations blocked for weeks, it is clear that prevention is infinitely cheaper than managing a major crisis,&#8221; <\/em>, said <strong>Ionut Georgescu, CEO Safetech Innovations<\/strong>.<\/p><h3>The lesson for organizations in Romania<\/h3><p>The discussion at ZF Live confirms a simple but frequently ignored truth: cybersecurity is no longer a one-off project, but an ongoing process. Attacks have accelerated, the tools used by attackers have evolved, and the difference between a prepared organization and a vulnerable one is ultimately measured in the ability to invest early in prevention \u2014 auditing, continuous monitoring, and a clear response plan \u2014 before that &#8220;open door&#8221; is found by someone who shouldn&#8217;t have access. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Summary of the ZF Live interview with Ionu\u021b Georgescu, CEO of Safetech Innovations<\/p>\n","protected":false},"author":2,"featured_media":6664,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[125],"tags":[103,106,110,140],"class_list":["post-30836","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-company-news","tag-cert-en","tag-monitoring-and-response","tag-risk-management","tag-safetech-results"],"_links":{"self":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30836","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/comments?post=30836"}],"version-history":[{"count":3,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30836\/revisions"}],"predecessor-version":[{"id":30841,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/posts\/30836\/revisions\/30841"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/media\/6664"}],"wp:attachment":[{"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/media?parent=30836"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/categories?post=30836"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/safetech.ro\/en\/wp-json\/wp\/v2\/tags?post=30836"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}