A recent cyberattack on the Romanian land registry shows how quickly an IT security incident can have real economic consequences. According to media reports, an attacker used valid credentials obtained beforehand to gain access to the systems of the National Agency for Cadastre and Land Registration (ANCPI) and deleted key data sets after a failed extortion attempt, thereby blocking the processing of property transactions.
What stood out was less the "how" than the "why". According to reports by security researchers, the incident was caused by preventable failures including outdated operating systems, trivial passwords, disabled firewalls, and an insufficient IT security budget of only around 0.2% of the IT budget over the past 20 years. Only separately stored offline backups prevented a total loss.
The case clearly shows that cyberattacks are not merely an IT problem. They can bring business processes to a standstill.
Why action is needed now
In Austria, the NISG 2026 implements the European NIS 2 Directive. From 1 October 2026, new mandatory security obligations will apply to affected companies in critical and important sectors such as energy, finance, and the food industry, as well as to their supply chains.
The NISG does not require cutting-edge technology but measures appropriate to the risk - measures that were neglected in the Romanian case. Typically, this means implementing a risk management or cybersecurity framework. Established frameworks such as the NIST CSF 2.0 follow the same risk-based approach as the NISG 2026 and are therefore well-suited for implementation and evidence grids:
- Identify: Asset and data inventories, criticality assessments
- Protect: Risk-based measures; not uniformly applied across the board
- Detect/Respond: Measures for identifying incidents
- Recover/Govern: Restoration tests with a results report for management bodies
From criticality to concrete measures
According to this approach, databases containing essential data are a company's "crown jewels" and must be protected accordingly. The risk assessment must factor in the scenario of an account being leaked through social engineering or phishing. Concrete measures should then be derived from the risk, for example:
- Password policies and multi-factor authentication as basic protection against compromised access credentials
- Role-based access control, so that a single compromised account does not determine the fate of key databases, backups, and administration systems
- Automated anomaly detection that blocks or immediately reports unusual activities such as mass data queries, the deletion of large data sets, or access to backup environments
Anyone who fails to address and document these points risks not only the chaos resulting from a successful attack but also a breach of the obligations under the NISG 2026.
These obligations are explicitly management responsibilities. Management bodies must monitor implementation, release a sufficient budget, and be able to qualify the risk. Otherwise, they face personal liability. Breaches of the obligations carry fines of up to EUR 10 million or 2% of global annual revenue.
What to do specifically
Companies must assess their risks. The groundwork for this must be laid now:
- Review of legal requirements: NISG 2026 compliance, contractual information obligations towards customers and business partners
- Identify & risk assessment: Record all assets and assess the risk.
- Training for management bodies: Without the necessary basic understanding, a cyber risk can neither be qualified nor monitored. The NISG therefore explicitly mandates such training.
- Incident response: Clear responsibilities, reporting chains, external contacts, and prepared communications with authorities, customers, and service providers – aligned with an early warning within 24 hours and a detailed report within 72 hours
The attack on the Romanian land registry shows that the greatest damage rarely results from the data outflow itself, but from its consequences for ongoing operations – and the causes are usually mundane rather than highly technical.
The best time to anchor cybersecurity in legal and organisational terms was years ago –the second-best time is now.
We are happy to assist your company in reviewing whether the NISG 2026 applies, implementing the required measures under the NISG 2026, and providing training on this topic.