Cybersecurity

Cybersecurity built into managed IT, not sold on the side

We run the IT infrastructure of more than 100 companies in Romania. In all of them, security comes in the same subscription as IT support, in five layers that we set up, watch and answer for.

Get my free 45-minute assessment
ISO/IEC 27001:2022, certificate RO231109006, verify it publicly Microsoft Solutions Partner 25 years of managed IT
Security included

You have security. But what exactly do you have?

Almost every company has antivirus and believes that covers it. Ask what happens when someone signs in to a company computer at three in the morning, and what usually follows is a pause.

Security is not a product you buy once. For the companies we run, the answer has five layers. We set them up, we watch them, and we are the ones who answer when the alarm goes off.

What changed in Romania over the past year

These are not our numbers. They come from the annual report of the National Cyber Security Directorate for 2025, published in August 2026.

+353% Compromised accounts

From 248 cases in 2024 to 1,125 in 2025. The Directorate puts the rise down to reused passwords and missing two-step sign-in.

+71% Phishing

Up 70.6%, to 4,975 incidents, which is 36% of everything reported. It has become the main way attackers get in.

+153% Ransomware

256 major incidents. Among the victims, 119 companies and 22 public institutions.

+91% Fraud

3,937 cases. One company in the defense industry lost more than 20,000 euros in a single incident.

One detail from the report is worth reading twice: phishing messages are now written in correct Romanian and convincingly imitate the visual identity of real organizations. The advice everyone repeats, that you spot them by the spelling mistakes, no longer works.

Source: the 2025 activity report of the National Cyber Security Directorate, public version, approved by CSAT Decision no. 117 of 7 August 2026.

What we put on top of your IT, layer by layer

Each layer catches something different. What one misses is exactly what the next one covers. Under each layer you will also find what we do, specifically, at that level.

Antivirus looks at files

It recognizes a dangerous file because it has seen it before. It stops known ransomware and programs already catalogued as harmful.

What it sees

Infected files, programs known to be dangerous, downloaded attachments.

What it misses

An attack with no file at all. If someone signs in with a stolen password and uses the programs already on the computer, antivirus has nothing to recognize. And the email that delivered the password looks flawless: the Directorate reports that phishing messages are now written in correct Romanian.

Our part We install it on every new device from day one, check monthly that it is running everywhere, and reinstall it when someone turns it off. We do not ask you to check.

Layer 02 covers this gap

Endpoint detection looks at behavior

It does not ask whether a file is dangerous. It asks whether what is happening makes sense right now, on this computer, at this hour.

What it sees

A remote access program opening a connection to an address in another country, at three in the morning, on the bookkeeper's computer. No file is infected. The action makes no sense, and the machine is cut off from the network within seconds, automatically.

What it misses

Nothing, as long as somebody actually looks at what it reports. Without the next layer, the alert lands in a mailbox nobody opens until morning.

Our part We establish what normal looks like in your company, so machines are not isolated for nothing. An accounting program sending data to the tax authority is not an alert. We do that tuning in the first month and adjust it as we go.

Layer 03 covers this gap

Managed detection means somebody is actually watching

A security operations center follows the alerts around the clock, in shifts, including at night and at weekends.

What it sees

Analysts confirm whether the alert is real, how far the attacker got and what needs to happen next. Our average from alert to response is under ten minutes.

What it misses

Everything that does not happen on a device. An attacker who walks straight into the email account, with the correct password, never touches a computer.

Our part We are the contact who receives the confirmed alert. We decide what gets stopped, who we call in your company and in what order. You get one explanation, not three reports from three suppliers.

Layer 04 covers this gap

Identity detection looks at accounts, not at computers

Included for every client we run, not as an option bought separately. It is also the layer that became the most necessary: compromised accounts rose by 353% in Romania in a single year.

What it sees

Someone signs in to Microsoft 365 from another country, at four in the morning, with the correct password, taken by a phishing email three weeks earlier. They create a rule that quietly moves every email containing the word "invoice" into a hidden folder. Then they wait.

What it misses

Nothing on the detection side. But detection stops the attack, it does not repair what is left behind. The isolated computer is still isolated, and the person who worked on it cannot work.

Our part We run your Microsoft 365 environment, so we are the ones who see the hidden rule, delete it, reset the account and check what left it. Without you opening any console.

Layer 05 covers this gap

We put the company back on its feet

Isolation stops the attack. But the computer stays disconnected, and the employee who worked on it has a blocked day. This is where any detection supplier's job ends and ours begins.

What we do

We clean the machine, reconnect it, check what the attacker managed to touch, and give the employee their working day back. Then we write down what happened and what we changed, so it does not happen again.

Why it matters Anyone can resell detection. The hard part is what comes after: someone who knows your company, knows what each person works on, and stays with them until they are back at work. We have been doing that for 25 years.

This is where the chain closes

A Tuesday night at a company we run

The same attack, minute by minute, through all five layers.

With the five layers Without

A remote access program starts on the computer in accounting and opens a connection to an address outside the country.

The same thing happens. Nobody has any way of knowing.

The computer is automatically cut off from the network. It stays on, but it can no longer reach anything else.

The attacker starts moving laterally, from one machine to the next. It is the pattern the Directorate describes in the attack on Bucharest City Hall.

An analyst confirms the alert is real and checks whether the attacker reached other machines.

They reach the file server. They copy what they find.

You call us or we call you. You already know what happened, in words you understand.

The first employee arrives at the office. Everything looks normal.

The computer is cleaned and reconnected. The bookkeeper is working.

The bookkeeper is working too. Nobody knows anything yet.

You get the report: what happened, how they got in, what we changed.

Nothing. The same day as any other.

Nothing. The incident was closed three weeks ago.

A client calls to ask why they paid an invoice into a different account.

The example is constructed. The pattern is not.

Which of the two columns is your company in right now?

Find out in 45 minutes, free

Who answers when the alarm goes off

The five layers exist at plenty of companies. What is missing almost everywhere is one name you can call at three in the morning.

One contact

You do not call the detection supplier, then the network one, then the backup one. You call one number, and we talk to the rest.

No passing the blame

When three suppliers share a problem, each one points at the others. With us there is nobody to argue with: we answer for the whole chain.

The same team, for years

The people who step in at three in the morning are the ones who built your network. The team is in Bucharest, has worked together for years, and knows what cannot be switched off at your company.

What a client says about the security side

Compared with where we were before, the current state of our IT infrastructure, in organization, structure, security and monitoring, is far better. A significant upgrade that lets us look to the future with confidence and certainty, both internally and in our relationship with our clients.

Translated from Romanian.

Ovidiu Filip Operations Manager, Wayfare

What you get from us, without asking separately

We do not sell an IT support subscription without security. Everything below is part of the day-to-day work, at the same price.

  • Protection on every device, isolating an affected machine straight away, not after someone calls
  • Round-the-clock monitoring, with people who check every alert, including at night and at weekends
  • Protection for Microsoft 365 accounts, not only for computers
  • Filters for phishing emails, dangerous links and attempted fraud
  • A firewall configured and monitored, controlling what enters and leaves the network
  • Access and password rules, configured once and applied everywhere
  • A report after every incident: what happened, how they got in, what we changed
  • Periodic review of the external accounts that still have access to your data

What you can check about us, without asking

Three of the numbers below are ours and we can stand behind them. The fourth you verify in a public database.

ISO 27001

Our own information security management system, certified and externally audited every year. Certificate no. RO231109006. Verify it in IAF CertSearch

< 10 min

Average time from alert to response, for security incidents.

< 1 h

Average resolution time for the issues that stop work.

100%

Of the clients we manage have backups that are tested, not just taken.

What we will not tell you

We will not promise you will never be attacked. Anyone who promises that either does not understand how this works, or hopes you will not ask further.

We promise the attack is seen in minutes, not weeks. That it is stopped before it spreads across the network. And that the next day you know exactly what happened.

The difference between an attacked company that is back at work the same day and one that loses a week is not luck. It is what was in place beforehand.

The questions we get most often

How much does cybersecurity cost for a small company?

It does not appear as a separate line on the invoice, because we do not sell it separately. It sits inside the IT support subscription, and the cost depends on how many users you have, how many locations, how many servers, and whether you already have an internal team.

What we can say before any conversation: at a company of 30 people, full security costs less than one day of stopped work. You get the exact figure at the free assessment, along with what you already have and no longer need to pay for.

We already have antivirus. Why would we need anything else?

Because antivirus looks at files, and the attacks that cause damage in Romania no longer use files. An attacker who signs in with a stolen password and uses the programs already on the computer triggers nothing.

The National Cyber Security Directorate reported a 353% rise in compromised accounts in a single year. None of those cases was stopped by antivirus, because there was nothing for it to stop.

What does it mean that security is included?

That you cannot buy managed IT from us without it. There is no basic package without protection and a paid security add-on. All five layers above come at the same price, for every client.

The reason is simple: a company we run that gets attacked becomes our problem, whatever the contract says.

What happens if we are attacked anyway?

The attack is flagged within minutes, the affected computer is isolated automatically, and an analyst checks whether it spread. We clean the machine, reconnect it and get your people back to work.

The next day you receive a written report: how they got in, what they touched, what we changed. We do not promise you will never be attacked. We promise you will not hear about it from a client, three weeks later.

Is cybersecurity mandatory under NIS2?

It depends on the sector you operate in and on the size of the group your company belongs to. If NIS2 applies to you, security measures stop being a choice, and accountability sits with management, not with the IT department.

Check in five questions whether it concerns you, in our guide to NIS2 in Romania.

How long until we are protected?

The first two layers go in within days, because they are installed on devices. The tuning, that is establishing what normal looks like at your company so machines are not isolated for nothing, takes the first month and is adjusted as we go.

Protection for Microsoft 365 accounts is switched on in the same week, if the environment is already yours.

We already have an IT person. Does this still make sense?

It does, and it is the most common case. Your IT person cannot stay awake at three in the morning, and should not have to. We take over monitoring and incident response, and they stay on the projects that matter to the company.

The model is called co-managed IT and it was built for exactly this situation.

Check for yourself, in five questions

Tick what you already have at your company. Nothing is sent anywhere, you are not requesting a quote, and we are not asking for your email. This is just for you.

If you ticked all five, you are covered and you do not need us. If you ticked three or four, the gap is usually at layer three or four, which is exactly where the damaging attacks get through. If you ticked fewer than three, a 45-minute conversation is worth it, even if we never end up working together.

What to read next

Security does not stand on its own. It is part of how we run the whole IT of a company.

This page was reviewed in September 2026. The figures on incidents in Romania come from the 2025 activity report of the National Cyber Security Directorate, published in August 2026.

Start with a free assessment

We look together at what you have now and tell you what is missing. 45 minutes, online, with a written report afterwards.

Get my free 45-minute assessment