ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

The Romanian National Cyber Security Directorate (DNSC) is the competent authority at the national level for the national civilian cyberspace, including the management of risks and cyber incidents. It is tasked with ensuring the security, confidentiality, integrity, availability, and resilience of the national civilian cyberspace and with defining and implementing the framework of strategies, policies, and regulations that support the implementation of the national vision in the field of cyber security.

The Romanian National Cyber Security Directorate A.I CyberSecurity Scoring

RNCSD

Company Details

Linkedin ID:

directoratul-national-de-securitate-cibernetica

Employees number:

111

Number of followers:

22,886

NAICS:

541514

Industry Type:

Computer and Network Security

Homepage:

dnsc.ro

IP Addresses:

0

Company ID:

THE_2721506

Scan Status:

In-progress

AI scoreRNCSD Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/directoratul-national-de-securitate-cibernetica.jpeg
RNCSD Computer and Network Security
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreRNCSD Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/directoratul-national-de-securitate-cibernetica.jpeg
RNCSD Computer and Network Security
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

RNCSD Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Romanian Government WebsitesCyber Attack2515/2025
Rankiteo Explanation :
Attack without any consequences

Description: Over the weekend, multiple Romanian government websites, including those of the Ministry of Foreign Affairs and the Constitutional Court, were subjected to distributed denial-of-service attacks orchestrated by the pro-Russian hacktivist group NoName057(16). The targeted sites experienced a sustained flood of traffic that rendered them inaccessible to legitimate users, disrupting access to official election information and public services during the crucial rerun of Romania's presidential election. The election rerun itself had been prompted by the nullification of the initial vote after evidence of Russian interference emerged. Despite the severity of the timing and the potential for undermining public trust in the electoral process, no data breach or information theft occurred. All impacted websites were swiftly restored to normal operations by the Romanian National Directorate for Cyber Security, minimizing long-term operational disruption. However, the incident caused temporary service outages, prevented citizens and international observers from obtaining timely updates, and highlighted the vulnerability of state infrastructure to geopolitically motivated cyber attacks. The example underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services. The rapid recovery also demonstrated the effectiveness of coordinated incident response efforts and the importance of continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions.

Romanian Government Websites
Cyber Attack
Severity: 25
Impact: 1
Seen: 5/2025
Blog:
Rankiteo Explanation
Attack without any consequences

Description: Over the weekend, multiple Romanian government websites, including those of the Ministry of Foreign Affairs and the Constitutional Court, were subjected to distributed denial-of-service attacks orchestrated by the pro-Russian hacktivist group NoName057(16). The targeted sites experienced a sustained flood of traffic that rendered them inaccessible to legitimate users, disrupting access to official election information and public services during the crucial rerun of Romania's presidential election. The election rerun itself had been prompted by the nullification of the initial vote after evidence of Russian interference emerged. Despite the severity of the timing and the potential for undermining public trust in the electoral process, no data breach or information theft occurred. All impacted websites were swiftly restored to normal operations by the Romanian National Directorate for Cyber Security, minimizing long-term operational disruption. However, the incident caused temporary service outages, prevented citizens and international observers from obtaining timely updates, and highlighted the vulnerability of state infrastructure to geopolitically motivated cyber attacks. The example underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services. The rapid recovery also demonstrated the effectiveness of coordinated incident response efforts and the importance of continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions.

Ailogo

RNCSD Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for RNCSD

Incidents vs Computer and Network Security Industry Average (This Year)

The Romanian National Cyber Security Directorate has 112.77% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

The Romanian National Cyber Security Directorate has 53.85% more incidents than the average of all companies with at least one recorded incident.

Incident Types RNCSD vs Computer and Network Security Industry Avg (This Year)

The Romanian National Cyber Security Directorate reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — RNCSD (X = Date, Y = Severity)

RNCSD cyber incidents detection timeline including parent company and subsidiaries

RNCSD Company Subsidiaries

SubsidiaryImage

The Romanian National Cyber Security Directorate (DNSC) is the competent authority at the national level for the national civilian cyberspace, including the management of risks and cyber incidents. It is tasked with ensuring the security, confidentiality, integrity, availability, and resilience of the national civilian cyberspace and with defining and implementing the framework of strategies, policies, and regulations that support the implementation of the national vision in the field of cyber security.

Loading...
similarCompanies

RNCSD Similar Companies

Palo Alto Networks

Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest s

CrowdStrike

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-clas

newsone

RNCSD CyberSecurity News

November 13, 2025 08:00 AM
Global cybersecurity rankings 2025: Countries with strongest online defences

The national cybersecurity index is a global live index of a country measured on its preparedness to prevent cyber threats and manage cyber...

November 05, 2025 08:00 AM
Cybercor, UTM, and NCC Romania sign a protocol to boost Moldova’s cybersecurity

The Republic of Moldova has made a significant advance in enhancing national security and integrating into the European digital space by...

October 21, 2025 07:00 AM
Romania drafts cybersecurity rules for PV, cogeneration up to 1 MW

Romania plans to amend its energy law to require the National Cybersecurity Directorate (DNSC) to define technical standards for PV and...

October 14, 2025 07:00 AM
Revealed: Hundreds of passwords linked to government departments leaked on dark web

Exclusive: Nine attempts have been made to sell classified UK military documents in the past year – with experts warning it could 'directly...

October 14, 2025 07:00 AM
Pakistan, UAE agree to boost cooperation in AI, digital governance at GITEX Global 2025

https://arab.news/be3n6. Shaza Fatima Khawaja held meetings on the sidelines of the event featuring Pakistani startups and tech firms...

October 08, 2025 07:00 AM
Kenya and Romania sign MoU to enhance cybersecurity cooperation

Kenya and Romania have signed a memorandum of understanding (MoU) aimed at strengthening cooperation in digital security.

October 08, 2025 07:00 AM
Kenya and Romania forge cybersecurity partnership

Kenya and Romania have signed a memorandum of understanding (MoU) aimed at developing advanced cybersecurity solutions between the two...

October 08, 2025 07:00 AM
Fidalgo (DG Connect): The European Union is a leader in cybersecurity policy

The European Union is a leader in cybersecurity policy and the Cyber Resilience Act (CRA) represents a major achievement as well as a source...

October 07, 2025 07:00 AM
Expert Rigoni at the Bucharest Cybersecurity Conference 2025: In cyberspace, we are in a continuous war

In cyberspace we are in a continuous war and, although we are talking about millions or billions of cyber attacks we do not see,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

RNCSD CyberSecurity History Information

Official Website of The Romanian National Cyber Security Directorate

The official website of The Romanian National Cyber Security Directorate is https://dnsc.ro/.

The Romanian National Cyber Security Directorate’s AI-Generated Cybersecurity Score

According to Rankiteo, The Romanian National Cyber Security Directorate’s AI-generated cybersecurity score is 738, reflecting their Moderate security posture.

How many security badges does The Romanian National Cyber Security Directorate’ have ?

According to Rankiteo, The Romanian National Cyber Security Directorate currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does The Romanian National Cyber Security Directorate have SOC 2 Type 1 certification ?

According to Rankiteo, The Romanian National Cyber Security Directorate is not certified under SOC 2 Type 1.

Does The Romanian National Cyber Security Directorate have SOC 2 Type 2 certification ?

According to Rankiteo, The Romanian National Cyber Security Directorate does not hold a SOC 2 Type 2 certification.

Does The Romanian National Cyber Security Directorate comply with GDPR ?

According to Rankiteo, The Romanian National Cyber Security Directorate is not listed as GDPR compliant.

Does The Romanian National Cyber Security Directorate have PCI DSS certification ?

According to Rankiteo, The Romanian National Cyber Security Directorate does not currently maintain PCI DSS compliance.

Does The Romanian National Cyber Security Directorate comply with HIPAA ?

According to Rankiteo, The Romanian National Cyber Security Directorate is not compliant with HIPAA regulations.

Does The Romanian National Cyber Security Directorate have ISO 27001 certification ?

According to Rankiteo,The Romanian National Cyber Security Directorate is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of The Romanian National Cyber Security Directorate

The Romanian National Cyber Security Directorate operates primarily in the Computer and Network Security industry.

Number of Employees at The Romanian National Cyber Security Directorate

The Romanian National Cyber Security Directorate employs approximately 111 people worldwide.

Subsidiaries Owned by The Romanian National Cyber Security Directorate

The Romanian National Cyber Security Directorate presently has no subsidiaries across any sectors.

The Romanian National Cyber Security Directorate’s LinkedIn Followers

The Romanian National Cyber Security Directorate’s official LinkedIn profile has approximately 22,886 followers.

NAICS Classification of The Romanian National Cyber Security Directorate

The Romanian National Cyber Security Directorate is classified under the NAICS code 541514, which corresponds to Others.

The Romanian National Cyber Security Directorate’s Presence on Crunchbase

No, The Romanian National Cyber Security Directorate does not have a profile on Crunchbase.

The Romanian National Cyber Security Directorate’s Presence on LinkedIn

Yes, The Romanian National Cyber Security Directorate maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/directoratul-national-de-securitate-cibernetica.

Cybersecurity Incidents Involving The Romanian National Cyber Security Directorate

As of December 05, 2025, Rankiteo reports that The Romanian National Cyber Security Directorate has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

The Romanian National Cyber Security Directorate has an estimated 2,935 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at The Romanian National Cyber Security Directorate ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

How does The Romanian National Cyber Security Directorate detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an recovery measures with swift restoration of websites, and enhanced monitoring with continuous monitoring..

Incident Details

Can you provide details on each incident ?

Incident : Distributed Denial-of-Service (DDoS)

Title: DDoS Attack on Romanian Government Websites

Description: Multiple Romanian government websites, including those of the Ministry of Foreign Affairs and the Constitutional Court, were subjected to distributed denial-of-service attacks orchestrated by the pro-Russian hacktivist group NoName057(16). The targeted sites experienced a sustained flood of traffic that rendered them inaccessible to legitimate users, disrupting access to official election information and public services during the crucial rerun of Romania's presidential election.

Type: Distributed Denial-of-Service (DDoS)

Attack Vector: DDoS

Threat Actor: NoName057(16)

Motivation: Geopolitical

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Distributed Denial-of-Service (DDoS) DIR522050725

Systems Affected: Ministry of Foreign AffairsConstitutional Court

Downtime: Temporary service outages

Operational Impact: Disruption of access to official election information and public services

Which entities were affected by each incident ?

Incident : Distributed Denial-of-Service (DDoS) DIR522050725

Entity Name: Romanian Government

Entity Type: Government

Industry: Public Sector

Location: Romania

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Distributed Denial-of-Service (DDoS) DIR522050725

Incident Response Plan Activated: True

Recovery Measures: Swift restoration of websites

Enhanced Monitoring: Continuous monitoring

Ransomware Information

How does the company recover data encrypted by ransomware ?

Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Swift restoration of websites.

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Distributed Denial-of-Service (DDoS) DIR522050725

Lessons Learned: The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.

What recommendations were made to prevent future incidents ?

Incident : Distributed Denial-of-Service (DDoS) DIR522050725

Recommendations: Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions.

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions..

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Continuous monitoring.

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an NoName057(16).

Impact of the Incidents

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Ministry of Foreign AffairsConstitutional Court.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions..

cve

Latest Global CVEs (Not Company-Specific)

Description

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If they contain HTML tags, they will be rendered (after some escaping using quotes and textarea tags).

Risk Information
cvss4
Base: 7.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files in the web UI. This vulnerability is fixed in 2025.102.

Risk Information
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Description

Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the local tid to whatever transition matched the current blockHash before knowing whether that batch would actually be verified. When the loop later broke (e.g., cooldown window not yet passed or transition invalidated), the function still wrote that newer tid into batches[lastVerifiedBatchId].verifiedTransitionId after decrementing batchId. Result: the last verified batch could end up pointing at a transition index from the next batch (often zeroed), corrupting the verified chain pointer.

Risk Information
cvss4
Base: 8.0
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=directoratul-national-de-securitate-cibernetica' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge