Secretus logoSecretus

Romania's ANCPI Outage: Cyber Resilience Is a Public Service

·7 min read

The disruption at Romania's National Agency for Cadastre and Land Registration (ANCPI) is a useful reminder that cyber resilience is not an abstract compliance exercise. When a public registry becomes unavailable, the impact reaches property transactions, local administrations, businesses and citizens waiting for a routine service. ANCPI confirmed that it had been targeted by a cyberattack and that its IT systems, e-Terra services and email were unavailable while it investigated and restored operations.

The facts will evolve as the investigation does. At the time of ANCPI's public statement, the agency said the available information indicated that its data had not been compromised. That distinction is important: an availability incident can be severe even where confidentiality loss has not been established, and unverified attacker claims should not be reported as fact.

Availability is a security outcome

Security discussions often centre on stolen records, but public services also have a duty to remain usable. A cadastral registry is a dependency for other real-world processes. If it cannot be consulted or updated, organisations may be unable to complete transactions, validate information or meet their own deadlines. The incident therefore belongs in the same board-level conversation as data protection, even when there is no confirmed exfiltration.

This is also why recovery is not simply "bring the servers back." Teams must know which systems are authoritative, whether restored data and queued transactions are complete, which integrations can safely reconnect, and how to communicate service limits without creating confusion or exposing investigation-sensitive detail.

Three practical lessons for organisations in Romania

  1. Map dependencies beyond your own network. Identify the public registers, identity providers, payment rails, cloud platforms and suppliers that can halt a critical business process. For each, define a manual fallback, the maximum acceptable outage and a named decision-maker.
  2. Test integrity as well as restoration speed. A backup that can be restored is only the start. Test whether it is immutable, separated from production credentials, recent enough for the service objective and capable of reconciling transactions made just before an incident.
  3. Prepare public communications before the crisis. A short status page, clear update cadence and known contact path are operational controls. Say what is unavailable, what users should do now, what is known and what is still being investigated. Do not fill gaps with speculation.

What incident communication should look like

The first announcement rarely answers every question. Good communication separates confirmed facts from investigation hypotheses; provides an observable service status; tells users whether an alternative route exists; and corrects prior statements when evidence changes. This reduces harmful rumours and enables affected organisations to activate their own continuity plans on reliable information.

The Directoratul Național de Securitate Cibernetică (DNSC) has stressed the concrete impact a cyber incident can have in the real world. For entities covered by Romania's NIS2 regime, that is a timely prompt to make incident-notification and business- continuity plans executable — with current contact lists, decision thresholds and evidence preservation steps — rather than merely documented.

A resilient service has a recovery story

The most useful outcome from any major outage is a better recovery model: segregated administration, tested offline or immutable backups, asset inventories that make it possible to scope impact quickly, rehearsed restoration priorities and a transparent communications channel. Public institutions and private businesses share the same standard here. Users do not experience the distinction between a technical outage and a cyber incident; they experience whether the service can be trusted when it matters.

Sources

Share a secret the safe way

End-to-end encrypted, one-time links — free, no account needed.

Try Secretus