RESOURCES

More context.
Better-informed decisions.

Guides for choosing IT and security services, alongside articles on privacy and protecting your company.

TRU TOOL · NIS2

NIS2 maturity calculator

Find your assurance level from your sector and size, answer 12 simple questions and see your estimated score on the DNSC scale, by function.

Calculate your score
TRU GUIDE · NIS2

NIS2 risk level: how to find out whether you are at the basic, important or essential level

How the score is calculated under DNSC Order 2/2025, the deadlines, NIS2@RO and ENIRE@RO, and the standard scores for every sector.

Read the article
TRU GUIDE · NIS2

Step-by-step NIS2 self-assessment: how to apply DNSC Order 1/2026

The deadlines in OUG 155/2024, the assurance levels, the scores for documentation and implementation, and the remediation plan.

Read the article (in Romanian)
TRU GUIDE · NIS2

The NIS2 audit: who can perform it, when it is mandatory and how to choose the auditor

The DNSC-certified auditor, the independence rules, periodic and ad-hoc audits, and the deadlines after the report.

Read the article
TRU GUIDE · NIS2 · PROTON

The encryption NIS2 requires: how Proton Workspace covers it

What OUG 155/2024 requires on encryption, what Proton Workspace covers in the subscription and who holds the keys at Microsoft 365 and Google Workspace.

Read the article
TRU GUIDE · PENTEST

How much a pentest costs: prices, cost factors and what you get

Starting prices, what affects the cost of internal or external penetration testing, and how to request a tailored quote.

Read the article (in Romanian)
TRU INSIGHTS

What to do after a pentest if you cannot fix all vulnerabilities straight away

How to prioritise vulnerabilities after a pentest, reduce exposure until they are remediated and complement retesting with 24/7/365 SOC monitoring.

Read the article (in Romanian)
TRU INSIGHTS

How to protect confidential information before selling a company

A TRU case from the pharmaceutical industry and the steps to protect emails, documents and know-how with Proton Workspace solutions.

Read the article (in Romanian)
TRU INSIGHTS

When a company needs an outsourced IT director

When CIO-as-a-Service is useful, how it complements the IT team, and which objectives and deliverables are worth setting before working together.

Read the article (in Romanian)
TRU INSIGHTS

Internal or external PenTest: reports, remediation and retesting

The difference between internal and external PenTest, the information needed for a quote and what you get: reports, recommendations and free retesting included.

Read the article (in Romanian)
TRU INSIGHTS

What an outsourced SOC includes and who responds to an incident

24/7/365 SOC: what is monitored, who receives the alerts and how analysis, device isolation, remediation and recovery are shared.

Read the article (in Romanian)
TRU INSIGHTS

Migrating your company’s email to Proton: steps and responsibilities

How to prepare the migration to Proton Workspace: users, domain, data to import, configuration and implementation with your IT team or partners.

Read the article
TRU INSIGHTS

NIS2 in Romania in 2026: DNSC Order 1/2026, the self-assessment and the remediation plan

What the new order approves, how to prepare the self-assessment and the remediation plan, and what the first DNSC fine shows.

Read the article
TRU INSIGHTS

Insider threats: access, responsibilities and prevention

How to manage insider threats through appropriate access rights, access revocation and an investigation procedure.

Read the article (in Romanian)
TRU INSIGHTS

Artificial intelligence: use and confidentiality in your company

What to check before using AI in your company: data, access, encryption, the terms of service and verification of the results.

Read the article (in Romanian)
TRU INSIGHTS

Supplier and supply chain security

How to check supplier access, IT dependencies and responsibilities for notifying and handling incidents.

Read the article (in Romanian)
TRU INSIGHTS

DDoS attacks: preparation and service continuity

What to prepare for a DDoS attack: provider contacts, traffic filtering, monitoring and a continuity plan.

Read the article (in Romanian)
TRU INSIGHTS

Software vulnerabilities: from inventory to remediation

Organise the inventory, prioritisation, updates and verification of fixes for vulnerabilities in your company’s systems.

Read the article (in Romanian)
TRU INSIGHTS

Protecting digital identity in your company

Accounts, multi-factor authentication and verification of requests to reduce the risk of digital identity misuse.

Read the article (in Romanian)
TRU INSIGHTS

Lessons and advice for preparing your incident response

Preparation, visibility, response, communication and recovery: the questions a company needs to clarify before an incident.

Read the article (in Romanian)
TRU INSIGHTS

Secure connections and the risk of interception

What to check for your company’s connections: HTTPS, certificates, updates and the limits of the protection a VPN provides.

Read the article (in Romanian)
TRU INSIGHTS

Malware: device protection and the IT team’s response

How to reduce malware risk through updates, control over installations, limited privileges and monitoring with clear responsibilities.

Read the article (in Romanian)
TRU INSIGHTS

Phishing: how to protect your company’s accounts and payments

Practical measures against phishing: verifying requests, multi-factor authentication, filtering and prompt reporting of anything suspicious.

Read the article (in Romanian)
TRU INSIGHTS

Ransomware: prevention, response and recovery

How to prepare your company for ransomware: controlled access, backups, monitoring and responsibilities for recovery.

Read the article (in Romanian)
TRU INSIGHTS

Physical security of devices and data

How to organise access to equipment, keep a record of devices and set a procedure for loss or theft.

Read the article (in Romanian)
TRU INSIGHTS

Recommendations for organising cybersecurity

A starting point for management: critical processes, owners, access, checks and incident response capability.

Read the article (in Romanian)
TRU INSIGHTS

10 types of threats to your company’s security

Ten categories of threats and the questions that help you prioritise your company’s security measures.

Read the article (in Romanian)
PROJECT EXAMPLES

Decisions grounded in real situations.

Confidentiality of correspondence, protection of know-how and business continuity.

TRU IN THE MEDIA

Interviews and appearances.

Ciprian Pocovnicu on his experience as a CIO, founding TRU and information security in companies.

View media coverage