September 10, 2026
3 minutes
cybersecurity paradox
cybersecurity study
cybersecurity preparedness
critical digital systems
It was a pleasure for DataDiggers to contribute to the analysis of “Snapshot of Cybersecurity in Romania, 2026” and to support Fort and Promocrat in turning the research into a clearer picture of how Romanian organizations are approaching cybersecurity today.
When we started analyzing the results, one finding immediately stood out.
The organizations that appear to be more mature from a cybersecurity perspective report significantly more incidents than the organizations that appear to be more vulnerable.
At first, this may seem counterintuitive.
Shouldn’t better-prepared companies experience fewer incidents?
Not necessarily.
According to the research, mature organizations reported cybersecurity incidents at a rate of 22%, compared with just 4% among more vulnerable organizations.
That is a difference of 5.5 times.
But the most important interpretation is not that mature organizations are attacked more often.
It is that they are more capable of seeing what is happening.
And that distinction changes the way we should think about cybersecurity preparedness.
One of the risks when discussing cybersecurity is treating the absence of reported incidents as evidence that an organization is secure.
The research suggests that this assumption can be misleading.
A company with stronger monitoring, clearer processes and better-trained employees is naturally more likely to identify suspicious activity, recognize phishing attempts and escalate incidents internally.
An organization with weaker systems may simply fail to detect some of the same events.
In this context, a low number of reported incidents can mean two very different things: either very few incidents actually occurred, or the organization did not have sufficient visibility to identify them.
For approximately 34% of the market covered by the study, this lack of visibility appears to be a particularly important consideration.
Cybersecurity maturity therefore cannot be measured only by asking how many incidents a company has experienced.
We also need to ask how capable that organization is of detecting them.
Another result reinforces this point.
Organizations that train their employees report phishing incidents more than seven times as often as organizations that do not provide such training.
Again, this does not necessarily mean training creates more problems.
It means employees become better at recognizing them.
This is important because cybersecurity is still sometimes perceived primarily as the responsibility of the IT department.
In reality, every employee can become either a line of defense or a potential entry point.
An employee who recognizes a suspicious email and reports it contributes directly to the organization’s security.
An employee who does not know what to look for may allow the same event to pass unnoticed.
For this reason, cybersecurity awareness should not be treated as a purely technical exercise.
It is an organizational one.
There is another gap in the findings that deserves attention.
Approximately 70% of the companies participating in the study say they use critical applications without which their activity could be blocked or severely disrupted.
That is a very high level of operational dependency.
Yet only around 45% report reaching a sufficiently high level of cybersecurity maturity.
When the analysis moves beyond declared maturity and looks more closely at actual preparedness, the percentage falls further, to approximately 27%.
This is where the business implications become particularly clear.
For a company that relies heavily on critical digital systems, a cybersecurity incident is not simply one more point in a statistic.
It can interrupt operations, affect clients, generate financial consequences and create reputational damage.
The gap between technological dependency and cybersecurity preparedness therefore deserves much more attention.
The growing use of AI tools adds another dimension.
Employees increasingly have access to systems that can process documents, summarize information, generate content and support everyday work.
Used correctly, these tools can improve productivity considerably.
But they can also create new risks when employees introduce confidential or sensitive information into platforms without clear company policies governing their use.
The research indicates that, in a number of organizations, the use of AI tools is still insufficiently regulated or not formally regulated at all.
This is an area where cybersecurity policies will increasingly need to evolve.
Companies do not necessarily need to prevent employees from using AI.
They do need to establish clear rules around what information can be shared, which platforms can be used and how employees should handle sensitive data.
One of my strongest impressions after analyzing the study is that cybersecurity maturity cannot be reduced to software, firewalls or technical infrastructure.
Technology matters, of course.
But governance matters too.
Training matters.
Management involvement matters.
And employee behavior matters.
Top management has the ability to establish policies, allocate resources and make cybersecurity a business priority.
Technical teams can implement the necessary systems and safeguards.
But every employee interacts with those systems and can influence the organization’s exposure.
That means the strongest cybersecurity strategy is ultimately one that combines technology with awareness and organizational discipline.
Perhaps the most interesting lesson from this research is also the simplest.
The organizations that see more problems may actually be the organizations that are better prepared.
More incident reporting can reflect better detection.
More phishing reports can reflect better-trained employees.
More internal alerts can reflect stronger monitoring.
For decision-makers, this means cybersecurity metrics need to be interpreted carefully.
The goal should not simply be to make the number of reported incidents as small as possible.
The goal should be to know what is really happening inside the organization and to be prepared to respond when something does happen, because in cybersecurity, what you cannot see can sometimes be more dangerous than what you can.

