Cybersecurity for Romanian public institutions

Romanian state institutions.
One practice.
Built for the breach.

Santinela is Romania's dedicated public-sector incident response and monitoring practice. Contracts are structured for SEAP procurement. Deliverables meet CERT-RO submission requirements. Every engagement operates within Law 58/2023 and the NIS2 transposition obligations.

Why state institutions only

Built from the ground up. Not adapted from enterprise.

State-only practice

Santinela was built for state institutions from the ground up. There is no enterprise tooling retrofit, no generic playbook adapted after the fact.

SEAP-native contracting

Retainer contracts map to OPEX quarterly billing cycles. Emergency response scopes fit the emergency CAPEX authorization process.

CERT-RO escalation paths

Every engagement includes documented escalation paths to CERT-RO. Deliverables are formatted for CERT-RO submission from the start.

Built around your procurement reality, not adapted to it.

ServiceBudget lineSEAP mechanismDeliverable format
RetainerOPEX, quarterlyDirect contract, SEAPMonthly report + CERT-RO
Annual pentestCAPEX or OPEXSimplified procedureFull audit report
Emergency responseEmergency CAPEXEmergency authorizationChain-of-custody report

Law 58/2023 establishes mandatory incident reporting and minimum security obligations for Romanian public authorities. All Santinela engagements are designed to satisfy these obligations directly, not as a secondary outcome.

Romania's NIS2 transposition extends these obligations to essential and important entities across energy, transport, health, and public administration. Santinela's service scope covers each category.

CERT-RO submission formatting is included in every deliverable. Your institution does not need to reformat investigation reports or rewrite audit findings to meet the national reporting standard.

What we offer

Services and pricing

Emergency Incident Response

Emergency Incident Response

Fixed-price forensic investigation, containment, and documented eradication report for state institutions under active breach. Delivered within guaranteed SLA windows.

From €4,000.00 and up

Request Emergency Response
Monitored Security Retainer

Monitored Security Retainer

Annual retainer contract billed quarterly to match public budget cycles. Includes a defined monthly hour block, guaranteed incident escalation SLA, quarterly vulnerability scan, and one annual penetration test with one retest included.

From €1,500.00 and up

Request Retainer Proposal
Annual Penetration Test and Remediation Validation

Annual Penetration Test and Remediation Validation

Scoped black-box and grey-box penetration test of defined systems, delivered as a full written report with a one remediation retest within 90 days. Satisfies annual compliance validation obligations under Law 58/2023 and the NIS2 transposition.

From €3,500.00 and up

Request Scoping Call
Regulatory Readiness Audit

Regulatory Readiness Audit

Gap assessment against Law 58/2023 and NIS2 obligations, a prioritized remediation roadmap, and a 30-day follow-up review to confirm progress. Designed as a low-barrier entry point for institutions that need to establish their compliance baseline before committing to a retainer or annual test.

From €2,500.00 and up

Book an Audit
Managed Monitoring (SOC-lite)

Managed Monitoring (SOC-lite)

Continuous log monitoring, alerting, and monthly threat summary delivered in partnership with a certified MSSP. Covers institutions that require 24/7 coverage and cannot wait for in-house SOC build-out.

From €800.00 and up

Request Monitoring Proposal

How we work

Incident response methodology

01

Scope

Define the compromise boundary, gather evidence with chain-of-custody documentation, and establish the investigation timeline.

02

Contain

Isolate affected systems, prevent lateral movement, and secure a clean operational baseline for ongoing institution work.

03

Eradicate

Remove the threat actor, close confirmed access vectors, and validate that no persistence mechanisms remain active.

04

Restore

Return systems to operation with staged validation, a written eradication report, and handover documentation for internal audit.

All engagements operate within Law 58/2023, the NIS2 transposition obligations, and CERT-RO incident reporting requirements.

Procurement guidance

Common procurement questions

Emergency

Active breach?

Request Emergency Response

The team responds within the guaranteed SLA. All communications are documented.

Ongoing protection

Planning ahead?

Request Retainer Proposal

Proposal formatted for SEAP procurement. No commitment required.

All inquiries are confidential and documented for your institutional records.

Built with