Beyond a cyberattack: lessons from recent incidents

What Romania's recent cybersecurity incidents reveal about incident detection and response

Three cyber incidents in one week. Coincidence? Or the new reality?

During the week of July 14–18, 2026, Romania recorded three cybersecurity incidents. ANCPI confirmed that the disruption of the e-Terra system was caused by a cyberattack. The Ministry of Investments and European Projects confirmed an incident that made one of its applications unavailable. Meanwhile, the National Cyber Security Directorate (DNSC) warned of a smishing campaign using a cloned version of the Ghiseul.ro platform to steal users' banking information.

At first glance, the three cases appear unrelated. Two disrupted the operation of critical systems, while the third exploited user trust. Taken together, however, they point to the same conclusion: the way we assess an organization's security needs to change.

For years, cybersecurity discussions have focused on a single question: prevention. Today, the more relevant question is different. What happens after an attack begins, and how quickly do we know?

The impact of a cyberattack doesn't end with the compromised system

Following the attack on ANCPI, the e-Terra system became unavailable, preventing the issuance of land registry extracts. Cadastral services, notarial activities, mortgage registrations, and real estate transactions were all affected until the service was restored.

In the case of MIPE, a cyberattack caused one of its applications to become unavailable, and the impact was compounded by the measures required to contain the incident. During an investigation, isolating affected systems is often just as important as addressing the attack itself, but from the users' perspective, the outcome is the same: the service is no longer available.

The campaign targeting Ghiseul.ro followed a completely different approach. The platform itself was not compromised. Instead, it was cloned, and users were redirected to a fake website designed to steal banking credentials. In cases like this, the organization's infrastructure may continue to operate normally while the attack takes place entirely outside of it.

The three incidents had different consequences, but they highlighted the same need: organizations must be able to quickly assess the impact of an incident, understand which services are affected, and respond as quickly as possible.

Why does NIS2 exist?

These three incidents illustrate the exact capabilities that NIS2 is intended to establish. The directive does not prescribe which technologies organizations must deploy. Instead, it defines what an organization must be capable of doing when an incident occurs.

NIS2, transposed into Romanian legislation through Emergency Ordinance 155/2024, applies to essential and important entities across 18 sectors. Organizations that want to determine whether they fall within the scope of the directive can use Expertware's free NIS2 self-assessment tool.

Four requirements are directly related to the incidents discussed above:

Backup and recovery. Backups must be protected, regularly tested, and validated through actual restoration procedures so that services can be recovered within a realistic timeframe.

Business continuity. Organizations must know how to maintain essential services during an incident and how to safely restore normal operations.

Detection and reporting. Rapid incident detection, log retention, and the ability to report incidents to DNSC within the deadlines established by the directive.

Cyber hygiene and training. Attacks targeting users cannot be prevented through technology alone. Staff awareness and external threat monitoring are part of the NIS2 requirements.

Continuous monitoring. Organizations must continuously monitor their infrastructure and security events to quickly identify suspicious activity, investigate incidents, and limit their impact.

The fundamental change is that cybersecurity is no longer solely the responsibility of the IT department. Management is directly accountable for risk management and compliance with the obligations introduced by the directive.

In essence, NIS2 shifts the focus from compliance to operational resilience: not preventing every attack, but being able to detect, contain, and manage incidents quickly.

How SIEMBIOT responds

SIEMBIOT is a unified cyber defense platform combining SIEM and SOC capabilities, developed by Expertware for continuous monitoring, threat detection, and incident response. The platform is the result of a European research and development project coordinated by Expertware, within a consortium that also includes the National Cyber Security Directorate (DNSC).

In most organizations, the information needed to investigate an incident is spread across multiple systems, including endpoints, firewalls, identity platforms, cloud services, and business applications. Viewed in isolation, these systems generate separate logs and alerts, making ongoing attacks more difficult to identify. A SIEM collects, correlates, and analyzes this data in a single context, enabling security teams to detect and investigate incidents more efficiently.

Business continuity plans define how an organization responds during an incident. SIEMBIOT provides the visibility needed to support those decisions quickly and based on real operational data.

Correlated detection, not isolated alerts. Events from endpoints, networks, identities, and cloud environments are correlated into a single incident context using the MITRE ATT&CK framework. Seemingly unrelated activities, such as privilege escalation, unusual access, or deletion of restore points, are treated as part of the same incident. Anomaly detection complements traditional detection rules by identifying unusual behavior.

Visibility into external threats. Threat Intelligence integrates indicators and infrastructure associated with active phishing and smishing campaigns, allowing organizations to identify attacks abusing their brand more quickly and respond before users report them.

Incident reconstruction. Retroactive threat hunting makes it possible to review historical telemetry and determine whether traces of an attack were already present in the environment. It also supports the documentation required for reporting incidents to the authorities, including under NIS2.

Visibility into exposed assets. Asset inventory and vulnerability management enable rapid identification of affected systems and remediation prioritization based on actual risk.

24/7 operations. Incidents do not follow business hours. A continuously operated SOC reduces the time between the first indicator and the initial response, regardless of when an attack begins.

Prepared people, not just monitored systems. Phishing and smishing attacks cannot be stopped through technology alone. That is why Expertware regularly organizes cybersecurity awareness and training webinars for organizations in sectors such as healthcare, public administration, education, and energy. In addition, SIEMBIOT includes the Cyber Academy extension, a platform designed for user training and building a security-aware culture across the organization.

What the three incidents teach us

The three incidents showed that security maturity is not measured by the number of attacks prevented, but by how quickly an organization can detect an incident, understand it, and limit its impact.

This is also the direction NIS2 is taking: shifting the focus from compliance to operational resilience.

To learn how SIEMBIOT can help your organization detect and respond to incidents more quickly, visit siembiot.eu.

Cloud image

90 Days of Enterprise-Grade Cyber Defense

Step into the future of cybersecurity with full access to a unified, intelligent platform — free for 90 days. Empower your security team with:

  • Advanced SIEM for real-time visibility, smart alerting, and deep forensics across cloud, on-prem, and hybrid environments

  • Continuous Vulnerability Management to identify, prioritize, and remediate risk across all assets

  • Live Cyber Threat Intelligence integrated directly into your workflows, with global insights and attacker profiling

  • AI-Powered Threat Detection that learns from your environment, explains alerts in plain language, and suggests next steps

  • Built-in Compliance Readiness for NIS2, GDPR, ISO 27001, and more, with automated reporting and audit tools

Whether you're managing a lean SOC or a full-scale enterprise security team, this platform gives you the tools to detect faster, respond smarter, and stay ahead of evolving threats — all without the complexity.

Experience enterprise-grade protection, streamlined workflows, and total control.

Your 90-day head start begins now.

Unlock Your 3-Month Free Trial