Romania’s Property Market Shows How Known Vulnerabilities Become Full-Scale Business Crises
Cristian Andron, founder of Romanian GRC startup GovernX, on how basic security failures froze Romania's property market and why the public sector has almost no one who can fix them.

Make The Intelligence Record one of your go-to sources on Google
It wasn't a very sophisticated attack. The attacker used basic steps to exploit known and unpatched vulnerabilities. It was the result of fundamental security gaps.
Romania’s property market ground to a halt after an attacker breached ANCPI, the national cadastre and land registration agency, and wiped the land registry database following a failed extortion attempt. The attack took down e-Terra, the platform notaries use to record every property transaction in the country, leaving buyers unable to file and exposing how a handful of basic security failures could freeze an entire market for more than a week.
Cristian Andron is the founder of GovernX, a Romanian startup building a GRC platform that helps public institutions and private companies manage the controls behind ISO 27001, NIS2, and DORA. He's spent more than a decade in security and privacy roles at KUKA, Bosch, and Aegon, and holds CISSP, CISA, and CEH certifications alongside ISO 27001 lead auditor credentials. Watching the ANCPI response unfold from inside Romania's security community, he keeps landing on how little the attacker needed.
"It wasn't a very sophisticated attack. The attacker used basic steps to exploit known and unpatched vulnerabilities," Andron says. "It was the result of fundamental security gaps."
Nothing about it was advanced
The credentials were already out there. In Andron's telling, the attacker found valid logins leaked online, disabled the Windows Firewall, spotted the weakness in network segmentation, and went for the backups first. Public reporting backs the outline. The intruder entered with valid credentials, stole internal documents, employee credentials, and source code, then deleted what he'd taken when the agency refused to pay. Romania's National Cyber Security Directorate says it had warned ANCPI about the vulnerabilities before the attack, and its own director called the intrusion preventable.
The ransomware angle gets the causality backwards, in Andron's view. "Ransomware is the effect of another attack. You cannot encrypt a database if you don't have access to it." The prescription he walks clients through is the unglamorous list: patch management with clear SLAs, a full asset inventory, MFA everywhere, rapid patching for critical findings, proper segmentation, isolated backups, and system hardening.
Where were the backups
ANCPI says it held offline copies at several locations, and restoration has leaned on them. For Andron, the length of the outage is the tell.
"If you have backups and one location is attacked, you have the second location or the third. So where were these backups? Why did the systems not recover?" A restore that takes more than a week is a plan that was never rehearsed under pressure. He sees the same gap across the country. "A lot of institutions in Romania don't have backups. They have only the primary data source."
A market that pays for speed
Andron traces the conditions to structure and culture at once. "Management should trust the information security expert, and should hire experts. In the public sector in Romania, experts don't exist," he says. The DNSC exists to help, but many organizations don't know to call it, and its financing limits what it can do. The spending tells its own story. Of roughly 135 million euros ANCPI put into digitalization over two decades, about 0.2% went to cybersecurity.
He's blunt about the private sector too, drawing on years inside German and British corporate environments. "In England or in Germany, the pressure to be secure is so high that controls are implemented as soon as possible, because data is the life of a company," Andron says. "In Romania, in the private sector, they care about how to make money fast, with low security."
Not an IT problem
For GRC professionals who can see the gaps but can't force remediation, his answer is the argument, not the org chart. "My role is to translate technical risk into business impact. These vulnerabilities are not IT problems. They are operational problems, financial problems." The ANCPI fallout makes his case for him. He expects the reputational damage to follow the agency to Brussels, where EU funding already spent on resilience invites uncomfortable questions about where it went.
What stays with him is how ordinary the thinking was right up until July 14. "They knew their vulnerabilities, but they said nothing was going to happen. Why us? We are not so important," Andron says. "But look, it was a problem."




