{"id":16594,"date":"2026-10-06T07:45:02","date_gmt":"2026-10-06T07:45:02","guid":{"rendered":"https:\/\/outsourcing-today.ro\/?p=16594"},"modified":"2026-10-06T07:45:49","modified_gmt":"2026-10-06T07:45:49","slug":"espace-it-nis2-extends-responsibility-for-cybersecurity-to-the-level-of-company-management","status":"publish","type":"post","link":"https:\/\/outsourcing-today.ro\/?p=16594","title":{"rendered":"Espace IT: NIS2 extends responsibility for cybersecurity to the level of company management"},"content":{"rendered":"\n<p><strong><span class=\"has-inline-color has-vivid-cyan-blue-color\">The implementation of the NIS2 Directive in Romania brings cybersecurity to the decision-making level of companies, and compliance can no longer be treated exclusively as a responsibility of the IT department, warns Espace IT, a consulting and technical services company specializing in cybersecurity, IT auditing and digital compliance. In this context, management must understand the risks, approve their management measures, provide the necessary resources and supervise their implementation.<\/span><\/strong><\/p>\n\n\n\n<p>NIS2, the European framework for cybersecurity, now applies in 18 sectors of activity, compared to seven in the previous framework. Essential and important entities remain mainly concerned, but in certain situations also small or micro-enterprises with an important role for other organisations or the population. The requirements can also reach their suppliers, who may be required to demonstrate that they have adequate security measures in place, even if they are not directly covered by NIS2. The pressure on companies also comes from the evolution of threats. According to the ENISA report, more than 48,000 new vulnerabilities were published in 2025, 22% more than in the previous year. Ransomware remained the threat with the greatest short-term impact, and vulnerabilities in suppliers and supply chains can also affect organizations that have properly protected their own systems.<\/p>\n\n\n\n<p><span class=\"has-inline-color has-vivid-cyan-blue-color\">&#8220;Romania has a special situation, because we have transposed NIS 2, but this does not automatically mean maturity in terms of cybersecurity. European data show that in 2024 only 53% of the Romanian companies analyzed were using at least three ICT security measures. In Finland, the percentage was 93%. This is actually our real challenge: to move from transposition to implementation and from formal compliance, as we often do, to resilience,&#8221; <strong>said Victor Negrescu, Vice-President of the European Parliament.<\/strong><\/span><\/p>\n\n\n\n<p>For the companies concerned, management has a direct role in managing these risks. The legislation provides for penalties that, in the event of certain violations, can reach \u20ac10 million or 2% of annual worldwide turnover for essential entities.<\/p>\n\n\n\n<p><span class=\"has-inline-color has-vivid-cyan-blue-color\">&#8220;The more we digitize, the more vulnerable we become and the more we need cybersecurity. And the responsibility ultimately lies with management, because decisions and their consequences remain at the company level. Technical services and skills can be outsourced, but decision-makers cannot be outsourced. No matter how much we outsource the technical part, the decision remains in the company, and the human factor continues to play an essential role in cybersecurity,&#8221; <strong>said Alin Mete\u0219an, founder of Espace IT.<\/strong><\/span><\/p>\n\n\n\n<p>A first step for companies is to correctly establish the compliance with the legislation. The analysis is related to the activity carried out and the size of the enterprise. In Romania, the National Directorate of Cyber Security (DNSC) is the competent authority for supervising, verifying and controlling compliance with the NIS2 framework.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" width=\"1024\" height=\"600\" src=\"https:\/\/outsourcing-today.ro\/wp-content\/uploads\/2026\/10\/400cff94-fcb6-4fac-b096-95fd76e8ea7f-1024x600.jpg\" alt=\"\" class=\"wp-image-16596\"\/><\/figure>\n\n\n\n<p><span class=\"has-inline-color has-vivid-cyan-blue-color\">&#8220;It is important for a company to map all its activities and correctly identify the sectors in which it falls, not just the main activity. It is equally important to analyze the size of the enterprise at group level. Such a check done correctly from the beginning helps the company to determine whether it falls under NIS2 and what are its obligations,&#8221; <strong>explained Gabriel Niculescu, coordinator of the Evidence and Support Service within DNSC.<\/strong><\/span><\/p>\n\n\n\n<p>The topics were discussed during the online edition of the NIS2 Business Summit conference, organized by Espace IT. The event brought together 11 professionals directly involved in the application of NIS2 requirements, with essential perspectives from audit, law, the institutional environment and entrepreneurship.<\/p>\n\n\n\n<p>About Espace IT<\/p>\n\n\n\n<p>Espace IT is a consulting and technical services company in Romania, specialized in cybersecurity, IT audit and digital compliance, based in Bucharest and regional offices in Alba Iulia and Cluj-Napoca. The main activity is oriented towards supporting organizations in the process of aligning with the requirements of the NIS2 Directive, providing compliance assessments, GAP analysis, risk management and cybersecurity audits, along with services such as vulnerability testing, incident monitoring and auditing of digitization projects financed by European funds.<\/p>\n\n\n\n<p>The company is among the entities accredited by the National Directorate of Cyber Security (DNSC) and the Authority for the Digitization of Romania (ADR), being also a partner of the Termene.ro platform for the integration of financial and business intelligence data into risk analysis.<\/p>\n\n\n\n<p>The Espace IT team is made up of IT auditors, software engineers, security analysts and legal consultants, the projects being coordinated by specialists with internationally recognized professional certifications, such as CISA or CISSP. So far, the company has provided specialized assistance and services for a portfolio of over 300 organizations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The implementation of the NIS2 Directive in Romania brings cybersecurity to the decision-making level of companies, and compliance can no longer be treated exclusively as a responsibility of the IT department, warns Espace IT, a consulting and technical services company [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16597,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[19,6,3,5,17],"tags":[1330],"_links":{"self":[{"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/posts\/16594"}],"collection":[{"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16594"}],"version-history":[{"count":1,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/posts\/16594\/revisions"}],"predecessor-version":[{"id":16598,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/posts\/16594\/revisions\/16598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=\/wp\/v2\/media\/16597"}],"wp:attachment":[{"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outsourcing-today.ro\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}