The National Directorate for Cyber Security (DNSC) has fined an institution within the central public administration 50,000 lei after it failed to fulfill its legal obligation to report a cybersecurity incident on time. The sanction was imposed through a decision issued on September 29, 2026, but DNSC did not disclose the institution’s name or the nature of the incident.
According to the official statement, the sanctioned entity is a legal person and a specialized body of the central public administration, classified in the “Public administration” sector covered by Government Emergency Ordinance No. 155/2024.
The offense concerns a breach of Article 18, paragraph (2) of the ordinance, which sets the deadline for reporting incidents. Failure to comply with this obligation constitutes a contravention under Article 60, paragraph (1), letter o), and the fine imposed by DNSC is 50,000 lei.
The institution provided no details about when the incident occurred, its impact, or the systems affected. DNSC emphasizes that prompt reporting is essential for identifying, managing, and limiting the effects of incidents, as well as for strengthening the cyber resilience of entities covered by the legislation.
Sources
Latest News
07:34
07:29
07:26
07:15
07:15
See more news