Company Details
directoratul-national-de-securitate-cibernetica
111
22,886
541514
dnsc.ro
0
THE_2721506
In-progress

The Romanian National Cyber Security Directorate Company CyberSecurity Posture
dnsc.roThe Romanian National Cyber Security Directorate (DNSC) is the competent authority at the national level for the national civilian cyberspace, including the management of risks and cyber incidents. It is tasked with ensuring the security, confidentiality, integrity, availability, and resilience of the national civilian cyberspace and with defining and implementing the framework of strategies, policies, and regulations that support the implementation of the national vision in the field of cyber security.
Company Details
directoratul-national-de-securitate-cibernetica
111
22,886
541514
dnsc.ro
0
THE_2721506
In-progress
Between 700 and 749

RNCSD Global Score (TPRM)XXXX

Description: Over the weekend, multiple Romanian government websites, including those of the Ministry of Foreign Affairs and the Constitutional Court, were subjected to distributed denial-of-service attacks orchestrated by the pro-Russian hacktivist group NoName057(16). The targeted sites experienced a sustained flood of traffic that rendered them inaccessible to legitimate users, disrupting access to official election information and public services during the crucial rerun of Romania's presidential election. The election rerun itself had been prompted by the nullification of the initial vote after evidence of Russian interference emerged. Despite the severity of the timing and the potential for undermining public trust in the electoral process, no data breach or information theft occurred. All impacted websites were swiftly restored to normal operations by the Romanian National Directorate for Cyber Security, minimizing long-term operational disruption. However, the incident caused temporary service outages, prevented citizens and international observers from obtaining timely updates, and highlighted the vulnerability of state infrastructure to geopolitically motivated cyber attacks. The example underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services. The rapid recovery also demonstrated the effectiveness of coordinated incident response efforts and the importance of continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions.


The Romanian National Cyber Security Directorate has 112.77% more incidents than the average of same-industry companies with at least one recorded incident.
The Romanian National Cyber Security Directorate has 53.85% more incidents than the average of all companies with at least one recorded incident.
The Romanian National Cyber Security Directorate reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
RNCSD cyber incidents detection timeline including parent company and subsidiaries

The Romanian National Cyber Security Directorate (DNSC) is the competent authority at the national level for the national civilian cyberspace, including the management of risks and cyber incidents. It is tasked with ensuring the security, confidentiality, integrity, availability, and resilience of the national civilian cyberspace and with defining and implementing the framework of strategies, policies, and regulations that support the implementation of the national vision in the field of cyber security.

Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest s

CrowdStrike (Nasdaq: CRWD), a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-clas
.png)
The national cybersecurity index is a global live index of a country measured on its preparedness to prevent cyber threats and manage cyber...
The Republic of Moldova has made a significant advance in enhancing national security and integrating into the European digital space by...
Romania plans to amend its energy law to require the National Cybersecurity Directorate (DNSC) to define technical standards for PV and...
Exclusive: Nine attempts have been made to sell classified UK military documents in the past year – with experts warning it could 'directly...
https://arab.news/be3n6. Shaza Fatima Khawaja held meetings on the sidelines of the event featuring Pakistani startups and tech firms...
Kenya and Romania have signed a memorandum of understanding (MoU) aimed at strengthening cooperation in digital security.
Kenya and Romania have signed a memorandum of understanding (MoU) aimed at developing advanced cybersecurity solutions between the two...
The European Union is a leader in cybersecurity policy and the Cyber Resilience Act (CRA) represents a major achievement as well as a source...
In cyberspace we are in a continuous war and, although we are talking about millions or billions of cyber attacks we do not see,...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of The Romanian National Cyber Security Directorate is https://dnsc.ro/.
According to Rankiteo, The Romanian National Cyber Security Directorate’s AI-generated cybersecurity score is 738, reflecting their Moderate security posture.
According to Rankiteo, The Romanian National Cyber Security Directorate currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, The Romanian National Cyber Security Directorate is not certified under SOC 2 Type 1.
According to Rankiteo, The Romanian National Cyber Security Directorate does not hold a SOC 2 Type 2 certification.
According to Rankiteo, The Romanian National Cyber Security Directorate is not listed as GDPR compliant.
According to Rankiteo, The Romanian National Cyber Security Directorate does not currently maintain PCI DSS compliance.
According to Rankiteo, The Romanian National Cyber Security Directorate is not compliant with HIPAA regulations.
According to Rankiteo,The Romanian National Cyber Security Directorate is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
The Romanian National Cyber Security Directorate operates primarily in the Computer and Network Security industry.
The Romanian National Cyber Security Directorate employs approximately 111 people worldwide.
The Romanian National Cyber Security Directorate presently has no subsidiaries across any sectors.
The Romanian National Cyber Security Directorate’s official LinkedIn profile has approximately 22,886 followers.
The Romanian National Cyber Security Directorate is classified under the NAICS code 541514, which corresponds to Others.
No, The Romanian National Cyber Security Directorate does not have a profile on Crunchbase.
Yes, The Romanian National Cyber Security Directorate maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/directoratul-national-de-securitate-cibernetica.
As of December 05, 2025, Rankiteo reports that The Romanian National Cyber Security Directorate has experienced 1 cybersecurity incidents.
The Romanian National Cyber Security Directorate has an estimated 2,935 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Detection and Response: The company detects and responds to cybersecurity incidents through an recovery measures with swift restoration of websites, and enhanced monitoring with continuous monitoring..
Title: DDoS Attack on Romanian Government Websites
Description: Multiple Romanian government websites, including those of the Ministry of Foreign Affairs and the Constitutional Court, were subjected to distributed denial-of-service attacks orchestrated by the pro-Russian hacktivist group NoName057(16). The targeted sites experienced a sustained flood of traffic that rendered them inaccessible to legitimate users, disrupting access to official election information and public services during the crucial rerun of Romania's presidential election.
Type: Distributed Denial-of-Service (DDoS)
Attack Vector: DDoS
Threat Actor: NoName057(16)
Motivation: Geopolitical
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Systems Affected: Ministry of Foreign AffairsConstitutional Court
Downtime: Temporary service outages
Operational Impact: Disruption of access to official election information and public services

Entity Name: Romanian Government
Entity Type: Government
Industry: Public Sector
Location: Romania

Incident Response Plan Activated: True
Recovery Measures: Swift restoration of websites
Enhanced Monitoring: Continuous monitoring
Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Swift restoration of websites.

Lessons Learned: The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.

Recommendations: Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions.
Key Lessons Learned: The key lessons learned from past incidents are The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions..
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Continuous monitoring.
Last Attacking Group: The attacking group in the last incident was an NoName057(16).
Most Significant System Affected: The most significant system affected in an incident was Ministry of Foreign AffairsConstitutional Court.
Most Significant Lesson Learned: The most significant lesson learned from past incidents was The incident underscores the need for robust DDoS mitigation strategies to safeguard democratic processes and maintain continuity of critical online services.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Continuous monitoring to detect and thwart DDoS threats before they can inflict more widespread disruptions..
.png)
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.
Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If they contain HTML tags, they will be rendered (after some escaping using quotes and textarea tags).
SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files in the web UI. This vulnerability is fixed in 2025.102.
Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the local tid to whatever transition matched the current blockHash before knowing whether that batch would actually be verified. When the loop later broke (e.g., cooldown window not yet passed or transition invalidated), the function still wrote that newer tid into batches[lastVerifiedBatchId].verifiedTransitionId after decrementing batchId. Result: the last verified batch could end up pointing at a transition index from the next batch (often zeroed), corrupting the verified chain pointer.
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.