{"id":10108,"date":"2026-07-28T15:34:48","date_gmt":"2026-07-28T12:34:48","guid":{"rendered":"https:\/\/www.roweb.ro\/blog\/?p=10108"},"modified":"2026-07-28T15:34:48","modified_gmt":"2026-07-28T12:34:48","slug":"when-critical-systems-go-offline-what-the-ancpi-cyberattack-teaches-us-about-cyber-resilience","status":"publish","type":"post","link":"https:\/\/www.roweb.ro\/blog\/when-critical-systems-go-offline-what-the-ancpi-cyberattack-teaches-us-about-cyber-resilience\/","title":{"rendered":"When Critical Systems Go Offline: What the ANCPI Cyberattack Teaches Us About Cyber Resilience"},"content":{"rendered":"<h2>When Critical Systems Go Offline: What the ANCPI Cyberattack Teaches Us About Cyber Resilience<\/h2>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber6.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10115\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber6.png\" alt=\"\" width=\"770\" height=\"404\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber6.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber6-300x157.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber6-624x327.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>On 14 July 2026, the information systems operated by Romania\u2019s National Agency for Cadastre and Land Registration, ANCPI, became unavailable following a cyberattack. The disruption affected the e-Terra land registry application, institutional email services and the digital workflows used to register and process property-related requests.<\/p>\n<p>What followed showed how quickly a technical incident can become an economic and operational problem.<\/p>\n<p>Without access to land registry extracts and registration services, property transactions could not be completed. Notaries, developers, buyers, banks and public authorities all depended on systems they could no longer use. Because the process is largely digital, there was no simple offline alternative capable of absorbing the workload.<\/p>\n<p>The incident was described as the most extensive technical disruption in ANCPI\u2019s history. Romanian authorities stated that property data had not been compromised and that backups were available, while the circumstances of the attack remained under investigation. The affected applications were moved to the government cloud and subjected to additional security assessments before services could resume.<\/p>\n<p>The case offers a useful reminder for any organization that operates critical software: cybersecurity is not limited to protecting information from theft. It is also about keeping essential services available and restoring them safely when something goes wrong.<\/p>\n<p>&nbsp;<\/p>\n<h2>A cyberattack can affect an entire business ecosystem<\/h2>\n<p>The direct target in this case was a public institution, but the consequences extended far beyond it.<\/p>\n<p>Land registry extracts and registration records are required for most property transactions in Romania. When these documents became unavailable, sales could not be finalized and new requests could not be processed. Delays then spread to related activities, including financing, permits, contractual deadlines and property development documentation.<\/p>\n<p>The timing added further pressure. The disruption occurred shortly before a tax deadline affecting certain residential purchases. According to Profit.ro, the difference generated by the VAT change could reach EUR 14,000 for an individual property. Buyers and developers already working under preliminary agreements faced administrative delays, possible contract amendments and additional financial uncertainty.<\/p>\n<p>This is a common pattern in major cybersecurity incidents. The cost is rarely confined to the affected servers. It can include:<\/p>\n<ul>\n<li>interrupted operations and lost productivity;<\/li>\n<li>contractual penalties or missed commercial deadlines;<\/li>\n<li>delayed payments and transactions;<\/li>\n<li>recovery and forensic investigation costs;<\/li>\n<li>regulatory and legal exposure;<\/li>\n<li>reputational damage;<\/li>\n<li>loss of confidence among customers and partners.<\/li>\n<\/ul>\n<p>For systems connected to public services, finance, healthcare, real estate or utilities, availability is part of the service itself. If the platform cannot be accessed, the organization may be unable to perform its core function, even when the underlying data has not been permanently lost.<\/p>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber5.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10114\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber5.png\" alt=\"\" width=\"770\" height=\"458\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber5.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber5-300x178.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber5-624x371.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Backups are essential, but they are not the whole recovery plan<\/h2>\n<p>ANCPI stated that it had backup copies that could be used to restore its data. This is an important safeguard, but the length and complexity of the disruption illustrate a broader point: having backups does not automatically guarantee rapid recovery.<\/p>\n<p>A usable recovery process depends on several questions:<\/p>\n<ul>\n<li>Are backups isolated from the production environment?<\/li>\n<li>Are they protected against unauthorized modification or deletion?<\/li>\n<li>How frequently are they created?<\/li>\n<li>When were they last restored in a controlled test?<\/li>\n<li>How long would it take to rebuild the infrastructure?<\/li>\n<li>Which applications must return first?<\/li>\n<li>Can the organization verify that restored systems are clean before reconnecting them?<\/li>\n<\/ul>\n<p>If a backup is connected to the same environment and managed through the same compromised accounts, an attacker may be able to reach it. Even when the data remains intact, restoring a complex platform can take time. Servers, applications, identity systems, integrations and access rights must all be checked before operations restart.<\/p>\n<p>This is why business continuity and disaster recovery plans need to be tested, rather than stored as documents that are reviewed only after an incident. Recovery exercises reveal dependencies and technical gaps while there is still time to address them.<\/p>\n<p><a class=\"red_btn_blog\" href=\"https:\/\/www.roweb.ro\/cybersecurity-services\">View our Cybersecurity expertise<\/a><\/p>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber4.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10113\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber4.png\" alt=\"\" width=\"770\" height=\"458\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber4.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber4-300x178.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber4-624x371.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Security testing must reflect real attack paths<\/h2>\n<p>Automated vulnerability scans are useful for identifying known weaknesses, outdated software and common configuration errors. They provide visibility, but they do not show the complete route an attacker might take through a system.<\/p>\n<p>A penetration test approaches the environment from the perspective of a real attacker. It examines whether separate weaknesses can be combined to gain unauthorized access, escalate privileges, move between systems or reach sensitive information.<\/p>\n<p>For an organization operating a critical application, testing should cover more than the public-facing platform. The scope may need to include:<\/p>\n<ul>\n<li>web applications and APIs;<\/li>\n<li>servers, networks and cloud infrastructure;<\/li>\n<li>identity and access management;<\/li>\n<li>administrative interfaces;<\/li>\n<li>source code repositories and deployment pipelines;<\/li>\n<li>third-party integrations;<\/li>\n<li>remote access systems;<\/li>\n<li>internal segmentation;<\/li>\n<li>employee exposure to phishing and social engineering.<\/li>\n<\/ul>\n<p>The purpose is not simply to produce a list of findings. It is to understand which weaknesses create a realistic business risk and which ones should be fixed first.<\/p>\n<p>Our cybersecurity services combine penetration testing, vulnerability assessment, attack surface discovery and phishing simulations. This makes it possible to examine both the technical environment and the human entry points that attackers commonly exploit.<\/p>\n<p><a class=\"red_btn_blog\" href=\"https:\/\/www.roweb.ro\/cybersecurity-services\">Check out our Cybersecurity services<\/a><\/p>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10112\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber3.png\" alt=\"\" width=\"770\" height=\"458\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber3.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber3-300x178.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber3-624x371.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Unknown assets create unmanaged risk<\/h2>\n<p>Organizations often secure the systems they know about while overlooking older applications, test environments, forgotten subdomains or services exposed during previous projects.<\/p>\n<p>These assets may still be connected to the company\u2019s infrastructure. They may contain outdated software, weak credentials or administrative interfaces that were never intended to be publicly accessible. Because they are no longer part of routine maintenance, they can remain vulnerable for long periods.<\/p>\n<p>Attack surface discovery helps identify what an external attacker can see. It maps domains, IP addresses, applications, services and other exposed assets, including systems that may not appear in the current IT inventory.<\/p>\n<p>For public institutions and companies with large digital environments, this visibility is particularly important. Infrastructure changes over time, teams use different tools and new services are introduced. A security assessment based on an incomplete asset list can provide a false sense of protection.<\/p>\n<p>Continuous discovery and monitoring allow security teams to detect these exposures before they become an entry point.<\/p>\n<p>&nbsp;<\/p>\n<h2>Access should be limited before an account is compromised<\/h2>\n<p>Many serious incidents begin with a compromised account rather than an advanced technical exploit. Credentials may be obtained through phishing, password reuse, malware or an exposed service.<\/p>\n<p>Multi-factor authentication can reduce this risk, but it needs to be combined with tighter access controls. Users and applications should receive only the permissions required for their work. Privileged accounts should be separated from normal day-to-day accounts, monitored closely and reviewed regularly.<\/p>\n<p>Network segmentation also matters. If an attacker gains access to one workstation or application, they should not be able to move freely through the infrastructure. Critical databases, backup systems, source code repositories and administrative tools should be isolated and protected by separate controls.<\/p>\n<p>A useful security review therefore asks what happens after the initial breach. Can the attacker escalate privileges? Can they reach other systems? Can they disable backups or security tools? Can unusual activity be detected before the incident spreads?<\/p>\n<p>This is one of the areas where realistic penetration testing provides more useful information than a checklist-based audit.<\/p>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10111\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber2.png\" alt=\"\" width=\"770\" height=\"458\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber2.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber2-300x178.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber2-624x371.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Detection speed changes the scale of an incident<\/h2>\n<p>Preventive controls will never eliminate every risk. Organizations also need the ability to identify abnormal activity and respond before it affects the wider environment.<\/p>\n<p>Logs from applications, servers, cloud platforms, authentication systems and network devices should be collected and correlated. Alerts need clear ownership, and the people receiving them must know what to do next.<\/p>\n<p>An incident response plan should define:<\/p>\n<ul>\n<li>who coordinates the response;<\/li>\n<li>how affected systems are isolated;<\/li>\n<li>which internal and external parties must be informed;<\/li>\n<li>how evidence is preserved;<\/li>\n<li>how critical services are prioritized;<\/li>\n<li>who has the authority to shut down or restore systems;<\/li>\n<li>how communication is handled during the disruption.<\/li>\n<\/ul>\n<p>These decisions are difficult to make for the first time during an active attack. Tabletop exercises and technical simulations allow teams to test the process in advance and find unclear responsibilities or missing information.<\/p>\n<p>Roweb supports this work through security audits, automated assessments, security maturity planning and purple team operations. The aim is to connect prevention, detection and response instead of treating them as unrelated activities.<\/p>\n<p>&nbsp;<\/p>\n<h2>Secure software requires continuous attention<\/h2>\n<p>Applications change. New features are released, dependencies are updated and integrations are added. A system that passed a security test last year may have a different risk profile today.<\/p>\n<p>Security therefore needs to be part of the development lifecycle. Static application security testing, dynamic testing and software composition analysis can help identify insecure code and vulnerable third-party components before they reach production.<\/p>\n<p>These tools are more effective when paired with secure coding practices and manual review. Automated checks can detect many known patterns, but they may miss flaws in business logic, authorization rules or complex workflows.<\/p>\n<p>Roweb integrates SAST, DAST and SCA tools into its security services and also provides secure coding training for development teams. This helps organizations address vulnerabilities during development, when they are generally easier and less expensive to fix.<\/p>\n<p>Assessments should also be repeated after major infrastructure changes, cloud migrations, new integrations or significant application releases. Migration can improve security, but changing the hosting environment alone does not remove vulnerabilities from the application, access model or operational process.<\/p>\n<p><a class=\"red_btn_blog\" href=\"https:\/\/www.roweb.ro\/cybersecurity-services\">Secure your software with our cybersecurity services<\/a><\/p>\n<p><a href=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-10110\" src=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber1.png\" alt=\"\" width=\"770\" height=\"458\" srcset=\"https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber1.png 770w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber1-300x178.png 300w, https:\/\/www.roweb.ro\/blog\/wp-content\/uploads\/2026\/07\/cyber1-624x371.png 624w\" sizes=\"(max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2>Cybersecurity is an operational responsibility<\/h2>\n<p>Commenting on the ANCPI disruption, Romania\u2019s interim prime minister called it a lesson for organizations responsible for managing important data. He pointed to the need for consistent standards, qualified staff and continuously updated applications. Authorities also announced tighter monitoring of compliance across public institutions, according to Digi24.<\/p>\n<p>The same principles apply in the private sector.<\/p>\n<p>Cybersecurity cannot remain solely with the IT department. Management must decide which services are critical, what level of downtime is acceptable and which risks require immediate investment. Technical teams need accurate asset inventories, clear ownership and enough time to maintain systems properly. Employees need practical training, while response teams need rehearsed procedures.<\/p>\n<p>No cybersecurity provider can guarantee that an organization will never be attacked. The realistic objective is to reduce the available attack paths, identify incidents earlier, restrict their spread and recover critical services within an acceptable timeframe.<\/p>\n<p>The ANCPI incident shows why that distinction matters. A platform may hold secure backup copies and still remain unavailable for an extended period. Data protection, service availability and recovery readiness must be planned together.<\/p>\n<p>Roweb helps organizations assess their current security posture, identify exploitable weaknesses and build a practical improvement plan. Through penetration testing, vulnerability assessments, attack surface discovery, phishing simulations, secure development practices and cybersecurity training, companies can address risks before they turn into prolonged operational disruptions.<\/p>\n<p>Cybersecurity preparation rarely attracts attention when systems are working normally. Its value becomes visible when an organization is able to contain an attack, protect its data and continue delivering the services on which others depend.<\/p>\n<p><a class=\"blue-link\" href=\"https:\/\/www.roweb.ro\/cybersecurity-services\">Read more about cybersecurity.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When Critical Systems Go Offline: What the ANCPI Cyberattack Teaches Us About Cyber Resilience On 14 July 2026, the information systems operated by Romania\u2019s National Agency for Cadastre and Land Registration, ANCPI, became unavailable following a cyberattack. The disruption affected the e-Terra land registry application, institutional email services and the digital workflows used to register [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":10115,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[166],"tags":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/posts\/10108"}],"collection":[{"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/comments?post=10108"}],"version-history":[{"count":2,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/posts\/10108\/revisions"}],"predecessor-version":[{"id":10116,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/posts\/10108\/revisions\/10116"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/media\/10115"}],"wp:attachment":[{"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/media?parent=10108"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/categories?post=10108"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.roweb.ro\/blog\/wp-json\/wp\/v2\/tags?post=10108"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}