“It hasn’t happened to us” is not a risk assessment, but a comforting illusion

I’ve heard this phrase hundreds of times in discussions with entrepreneurs and executives in Romania, often even from people who are highly competent in their area of business. The problem is that the phrase confuses the absence of evidence with evidence of absence. It is possible that the organization has not been compromised. It is equally possible that there have been rejected attempts, minor incidents not classified as such, or unauthorized access that simply has not yet been discovered.

Official data contradicts the idea that incidents are rare events, reserved for “others” or only large companies. Eurostat shows that approximately 22% of EU companies with at least 10 employees reported, in 2023, concrete consequences from ICT security incidents: service unavailability, destruction or corruption of data, or data disclosure. However, the figure must be interpreted correctly: it includes both attacks and unauthorized access, as well as unintentional causes such as hardware or software failures and human errors. It is therefore not a pure probability of a cyberattack. Even so, it shows how frequently technology security produces real consequences for businesses.

A more direct benchmark for exposure to attacks comes from the UK government’s Cyber Security Breaches Survey 2025/2026. Over the previous 12 months, 65% of medium-sized businesses and 69% of large businesses identified at least one breach or attack. We cannot mechanically apply these percentages to the Romanian market. For small businesses, the percentages are significantly lower, but the study measures identified incidents, meaning the difference also reflects the greater ability of larger organizations to observe what is happening to them. What remains true is that size, attack surface, and visibility increase together, and so does the likelihood that an incident will be identified.

The maturity study that I launched this year together with our partners, Data Diggers and Promocrat, and to which more than 200 Romanian companies from different industries responded, shows the same pattern locally: a clear gap between awareness of NIS2 and DORA obligations and the level of preparedness organizations believe they have to meet them. Awareness has increased significantly over the past year, but operational readiness is still lagging behind. In practice, we know the risk exists, but we continue to believe that it affects us less and that it simply cannot happen to us.

Therefore, an attack is no longer a hypothesis, but a condition of operation: attempts are part of the normal reality of any digital environment connected to the Internet. What matters is something else: whether they are visible within your own systems, how quickly you understand what is happening, and whether the impact can be contained before the incident becomes a crisis.

What Should Be Mandatory in the Boardroom Discussion

A board does not need the impossible promise that no attack will ever succeed. Anyone who promises that is either lying or does not understand the field. A board and a CEO need evidence that the organization can prevent what is reasonably preventable, quickly detect what gets past the first line of defense, and respond without improvisation, under pressure, and with clear roles.

Five questions I would start any such discussion with:

  1. What assets and data, if lost or unavailable, would actually stop our operations, and how long can we operate without each of them?
  2. How long would it take us today to detect unauthorized access, and where would we find out—from our own systems or from an external source?
  3. Who has the mandate to make decisions in the first hours of an incident—shutting down systems, notifying authorities, communicating publicly—without waiting for the board to be convened?
  4. When was the last time we actually tested backup restoration and our incident response plan—and how long did recovery take?
  5. Which vendors have access to our critical systems or data, what would happen to us if they were compromised, and how would we find out that it had happened?

The questions above only become useful when they receive answers in numbers. A board can request a minimum set of indicators every quarter, without getting into technical details: the median time to detect and isolate an incident compared with the previous period; the proportion of incidents discovered through internal systems versus those reported from external sources; the level of phishing-resistant MFA coverage for privileged accounts and remote access; the timeframe in which patches are applied to actively exploited vulnerabilities; the date and result of the latest real restoration test, including the actual recovery time; and the number of vendors with access to critical data or systems and how many of them are contractually monitored. No single indicator tells you whether the organization is safe. Together, however, they show whether the situation is improving or simply being reported.

The numbers tell us where the organization stands, but priorities should be established based on how attacks actually begin. The same ENISA report identifies phishing, including vishing, as the primary initial access point in approximately 60% of the cases analyzed, followed by vulnerability exploitation at 21.3%. The discussion repeatedly comes back to seemingly mundane, almost boring things: properly managed identity and access, phishing-resistant MFA, consistently applied updates and patches, network segmentation, centralized logs, monitoring, and incident response exercises that are actually conducted, not just documented on paper.

None of this is spectacular and, perhaps surprisingly, none of it is as common as it should be. Attackers do not need to be sophisticated when a weak password, an easily deceived help desk, or an outdated system opens the door directly for them. Unfortunately, it is precisely the boring and simple things that are forgotten or missing altogether.

My Conclusion After All This

The message from the current wave of incidents is simple: what we see in the press is only the visible tip of an activity that never stops. The fact that your company has not yet appeared in a news headline is not a guarantee. At most, it is an incomplete snapshot of the past, not a prediction of the future. My prediction is different: the number of incidents we hear about will increase significantly in the coming years, not because attacks are suddenly multiplying, but because the reporting obligations under NIS2 and DORA make disclosure unavoidable, and attackers have already understood that public claims are a pressure tool, not mere bravado.

Resilience cannot be inferred from the absence of a previous incident. It is deliberately built for the next one. And the test is simple: if the organization cannot answer with a number for three of the indicators listed above, then it is not discussing risk, but impressions. And NIS2 places responsibility for approving and overseeing security measures directly at the management level, not with the IT department: an impression cannot be delegated and cannot be defended afterward.

 

Sources for Verification

French Ministry of Economy and Finance / DGFiP, communications regarding unauthorized access and taxpayer data, August 2026; Reuters, “French taxpayers’ data stolen in cyber attack,” August 14, 2026; Le Monde, articles from August 14 and 18, 2026, regarding the scale of the incident.
ENISA, ENISA Threat Landscape 2025, analysis of 4,875 incidents from July 1, 2024 – June 30, 2025.
CERT-EU, “European Commission cloud breach: a supply-chain compromise via Trivy,” April 2, 2026; European Commission / Reuters, communication regarding the Europa.eu incident from March 2026.
Paris Public Prosecutor’s Office / Reuters, “France opens formal probe into teenage suspect in massive ID data breach,” April 30, 2026.
Reuters, “France’s statistics department reports cyberattack on staff data,” June 26, 2026.
Novo Nordisk, “Incident update,” June 18, 2026; Reuters, communication from June 11, 2026, regarding clinical trial participant data.
Government of Liechtenstein / Reuters, communications from August 3–4, 2026, regarding the beneficial ownership register.
Reuters, “Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others,” August 13, 2026.
Financial Times, “The new cyber threat: young, western and reckless,” 2026.
Eurostat, “ICT security in enterprises,” 2023 data published as part of the 2024 survey on ICT usage and e-commerce in enterprises.
UK Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/2026, published April 30, 2026.
Mandiant / Google Cloud, M-Trends 2026, March 2026; data from incident response investigations conducted in 2025.
Google Threat Intelligence Group, “GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools,” November 5, 2025; GTIG reports on adversarial use of AI, February and May 2026.
Directive (EU) 2022/2555 (NIS2), Articles 20 and 21, regarding governance and cybersecurity risk-management measures; Regulation (EU) 2022/2554 (DORA).

Related articles