More context.
Better-informed decisions.
Guides for choosing IT and security services, alongside articles on privacy and protecting your company.
NIS2 maturity calculator
Find your assurance level from your sector and size, answer 12 simple questions and see your estimated score on the DNSC scale, by function.
Calculate your score TRU GUIDE · NIS2NIS2 risk level: how to find out whether you are at the basic, important or essential level
How the score is calculated under DNSC Order 2/2025, the deadlines, NIS2@RO and ENIRE@RO, and the standard scores for every sector.
Read the article TRU GUIDE · NIS2Step-by-step NIS2 self-assessment: how to apply DNSC Order 1/2026
The deadlines in OUG 155/2024, the assurance levels, the scores for documentation and implementation, and the remediation plan.
Read the article (in Romanian) TRU GUIDE · NIS2The NIS2 audit: who can perform it, when it is mandatory and how to choose the auditor
The DNSC-certified auditor, the independence rules, periodic and ad-hoc audits, and the deadlines after the report.
Read the article TRU GUIDE · NIS2 · PROTONThe encryption NIS2 requires: how Proton Workspace covers it
What OUG 155/2024 requires on encryption, what Proton Workspace covers in the subscription and who holds the keys at Microsoft 365 and Google Workspace.
Read the article TRU GUIDE · PENTESTHow much a pentest costs: prices, cost factors and what you get
Starting prices, what affects the cost of internal or external penetration testing, and how to request a tailored quote.
Read the article (in Romanian) TRU INSIGHTSWhat to do after a pentest if you cannot fix all vulnerabilities straight away
How to prioritise vulnerabilities after a pentest, reduce exposure until they are remediated and complement retesting with 24/7/365 SOC monitoring.
Read the article (in Romanian) TRU INSIGHTSHow to protect confidential information before selling a company
A TRU case from the pharmaceutical industry and the steps to protect emails, documents and know-how with Proton Workspace solutions.
Read the article (in Romanian) TRU INSIGHTSWhen a company needs an outsourced IT director
When CIO-as-a-Service is useful, how it complements the IT team, and which objectives and deliverables are worth setting before working together.
Read the article (in Romanian) TRU INSIGHTSInternal or external PenTest: reports, remediation and retesting
The difference between internal and external PenTest, the information needed for a quote and what you get: reports, recommendations and free retesting included.
Read the article (in Romanian) TRU INSIGHTSWhat an outsourced SOC includes and who responds to an incident
24/7/365 SOC: what is monitored, who receives the alerts and how analysis, device isolation, remediation and recovery are shared.
Read the article (in Romanian) TRU INSIGHTSMigrating your company’s email to Proton: steps and responsibilities
How to prepare the migration to Proton Workspace: users, domain, data to import, configuration and implementation with your IT team or partners.
Read the article TRU INSIGHTSNIS2 in Romania in 2026: DNSC Order 1/2026, the self-assessment and the remediation plan
What the new order approves, how to prepare the self-assessment and the remediation plan, and what the first DNSC fine shows.
Read the article TRU INSIGHTSInsider threats: access, responsibilities and prevention
How to manage insider threats through appropriate access rights, access revocation and an investigation procedure.
Read the article (in Romanian) TRU INSIGHTSArtificial intelligence: use and confidentiality in your company
What to check before using AI in your company: data, access, encryption, the terms of service and verification of the results.
Read the article (in Romanian) TRU INSIGHTSSupplier and supply chain security
How to check supplier access, IT dependencies and responsibilities for notifying and handling incidents.
Read the article (in Romanian) TRU INSIGHTSDDoS attacks: preparation and service continuity
What to prepare for a DDoS attack: provider contacts, traffic filtering, monitoring and a continuity plan.
Read the article (in Romanian) TRU INSIGHTSSoftware vulnerabilities: from inventory to remediation
Organise the inventory, prioritisation, updates and verification of fixes for vulnerabilities in your company’s systems.
Read the article (in Romanian) TRU INSIGHTSProtecting digital identity in your company
Accounts, multi-factor authentication and verification of requests to reduce the risk of digital identity misuse.
Read the article (in Romanian) TRU INSIGHTSLessons and advice for preparing your incident response
Preparation, visibility, response, communication and recovery: the questions a company needs to clarify before an incident.
Read the article (in Romanian) TRU INSIGHTSSecure connections and the risk of interception
What to check for your company’s connections: HTTPS, certificates, updates and the limits of the protection a VPN provides.
Read the article (in Romanian) TRU INSIGHTSMalware: device protection and the IT team’s response
How to reduce malware risk through updates, control over installations, limited privileges and monitoring with clear responsibilities.
Read the article (in Romanian) TRU INSIGHTSPhishing: how to protect your company’s accounts and payments
Practical measures against phishing: verifying requests, multi-factor authentication, filtering and prompt reporting of anything suspicious.
Read the article (in Romanian) TRU INSIGHTSRansomware: prevention, response and recovery
How to prepare your company for ransomware: controlled access, backups, monitoring and responsibilities for recovery.
Read the article (in Romanian) TRU INSIGHTSPhysical security of devices and data
How to organise access to equipment, keep a record of devices and set a procedure for loss or theft.
Read the article (in Romanian) TRU INSIGHTSRecommendations for organising cybersecurity
A starting point for management: critical processes, owners, access, checks and incident response capability.
Read the article (in Romanian) TRU INSIGHTS10 types of threats to your company’s security
Ten categories of threats and the questions that help you prioritise your company’s security measures.
Read the article (in Romanian)Decisions grounded in real situations.
Confidentiality of correspondence, protection of know-how and business continuity.
Interviews and appearances.
Ciprian Pocovnicu on his experience as a CIO, founding TRU and information security in companies.
View media coverage