Press Release
September 9, 2026

DataDiggers took part in the launch event for “Snapshot of Cybersecurity in Romania”, a market research study examining how Romanian organizations approach cybersecurity, incident detection, employee preparedness and emerging risks such as the use of artificial intelligence.
The event, organized by FORT and Promocrat and held on September 9 in Bucharest, brought together cybersecurity specialists, business leaders, legal experts and representatives from organizations exposed to increasingly complex digital risks.
DataDiggers supported the research by contributing to the analysis and interpretation of the findings, helping transform the responses collected from more than 200 decision-makers into a clearer picture of cybersecurity maturity across Romanian organizations.
Representing DataDiggers at the event were Liviu Micu, Research & Insights Manager, and Cristian Craciun, Senior Director, Customer Success.
Liviu also opened the event with several observations emerging from the research, emphasizing that cybersecurity should not be considered exclusively an IT responsibility.
“Cybersecurity depends on every employee in a company, regardless of their position. Top management has the ability to implement strong cybersecurity policies, but any employee can also become an entry point for a malicious actor,” Liviu explained.
One of the study’s most striking findings appears counterintuitive at first.
Organizations with a higher level of cybersecurity maturity reported incidents at a rate of 22%, compared with only 4% among more vulnerable organizations.
The difference does not necessarily mean that mature organizations experience more attacks. Instead, it points to a greater ability to identify, recognize and report incidents that may otherwise remain unnoticed.
A similar pattern appears when looking at phishing.
Organizations that regularly train their employees report phishing incidents more than seven times as often as organizations that do not provide regular cybersecurity training.
The conclusion is important: a low number of reported incidents does not automatically indicate a safer organization. It may also indicate weaker visibility.
Published findings from the research confirm this pattern, showing phishing reporting rates of 14.6% among organizations conducting regular training compared with 1.9% among those that do not.
The study also highlights a significant difference between how dependent organizations have become on technology and how prepared they are to respond when something goes wrong.
Around 70% of participating companies say they rely on critical applications without which their activity could be interrupted.
At the same time, only around 45% report a sufficiently high level of cybersecurity maturity, while the proportion falls to approximately 27% when practical preparedness and the ability to respond to an incident are considered.
For organizations whose operations depend heavily on digital infrastructure, this gap can have serious consequences.
A cyber incident may represent only one data point in a study, but for the affected organization it can mean operational disruption, financial losses, reputational damage and impact on clients or partners.
Recent reporting on the study similarly highlights that only 27% of participating companies demonstrated concrete preparedness to respond to a cyberattack.
Artificial intelligence is becoming another important component of cybersecurity governance.
The research found that the use of AI tools is already widespread, while formal policies governing their use have not always developed at the same pace.
Published results show that 94% of participating organizations use AI in some form, while only 37% have written policies regarding its use that have been communicated to employees. Approximately 70% are concerned about employees entering sensitive company information into AI tools.
For organizations, this creates a new challenge: enabling employees to benefit from AI while establishing clear rules around sensitive information, approved platforms and responsible use.
The event combined perspectives from cybersecurity, regulation, data protection, legal practice and business.
The panel included:
The discussion was moderated by Bogdan Moldovan, CEO of Axigen, while Delia Necula, CEO of FORT, presented the study results and Andrei Resmerita, CRO of FORT, delivered the event conclusions.
For DataDiggers, the project also demonstrates the role market research can play in areas that are traditionally seen as highly technical.
Cybersecurity maturity cannot be understood through technology adoption alone. Research can help reveal how organizations behave, what they believe they are prepared for, where gaps exist between perception and reality, and how factors such as employee training, governance and internal culture influence preparedness.
The research was conducted during May–July 2026 among more than 200 Romanian organizations and examined areas including cybersecurity governance, monitoring, incident response capabilities, technical measures, organizational security culture, AI use and preparedness for NIS2 and DORA requirements. Published information specifies a final sample of 211 organizations.
As Liviu Micu highlighted during the event, the absence of reported cybersecurity incidents should not automatically be interpreted as evidence that an organization is secure.
Sometimes, the most important question is not how many incidents an organization has reported.
It is whether it has the ability to see them.
DataDiggers is a global, technology-driven market research agency providing research, data collection and insight solutions to brands and agencies worldwide.
Founded in 2015, DataDiggers combines research expertise, proprietary technology and rigorous data-quality processes to help organizations make informed decisions based on reliable evidence.
Its research capabilities are supported by MyVoice, a proprietary international panel network covering more than 30 markets, alongside a growing portfolio of technology and AI-driven research solutions.
DataDiggers is ISO 20252:2019 certified and an ESOMAR member.