What separates a cyber incident from a business crisis
The same kind of cyberattack ends very differently from one company to another. For some organizations, the result is a difficult week, with systems restored from backup and a few days of reduced activity, while for others the same event turns, over the following months, into a problem that reaches production, contracts, and cash flow. The difference between the two outcomes isn't decided during the incident but before it, through tested and isolated backups, defined recovery limits, a rehearsed procedure, and monitoring that catches the attack early. A recent case from Romania shows how far the effects of such an incident can stretch over time.
Nearly a year between the attack and the preventive concordat
In March 2025, Romania's National Cyber Security Directorate (DNSC) announced in a press release a ransomware attack on AAylex, the company behind the CocoRico brand. The scale of the reported consequences became public only after nearly a year.
In February 2026, the Romanian press reported that AAylex ONE, the operator of the CocoRico brand and a company with roughly 2,000 employees, had entered a preventive concordat, a court procedure through which a company in difficulty seeks to prevent insolvency. The procedure was admitted by the Buzău Tribunal on February 17, 2026, amid reported losses of over 210 million lei. In statements quoted by the press, the company described the previous year's attack as having a major impact on its operations, including its automated production.
Nearly a year passed between the DNSC press release and the court's decision, and such publicly reported attacks aren't isolated cases. Also in February 2026, the business magazine Biz reported that CONPET, the oil transport company, had disclosed a cyberattack in a communication to the Bucharest Stock Exchange. For management, the lesson of this timeline is about duration. A cyber incident doesn't end with the technical intervention, and its effects can keep accumulating for months after the systems are back online.
The technical incident, the business crisis, and the time between them
A cyber incident starts as a technical event with a perimeter that can be described precisely: encrypted servers, compromised accounts, systems shut down as a precaution. For the team handling it, it translates into a task list, from isolating the network to restoring data from backups. A business crisis operates on a different level, because it concerns orders that can no longer be fulfilled, missed contractual deadlines, and salaries that have to be paid from an interrupted cash flow.
The mechanism linking the two is time. The direct cost of downtime can be estimated from a total cost of €2,500 per employee per month, the equivalent of 168 productive hours. At that level, every hour of interruption means a loss of roughly €15 for each employee who cannot work. Applied to the size of your company, the calculation quickly shows the order of magnitude of a single day of downtime.
That calculation covers only the visible part. As recovery stretches from days into weeks, losses appear that no hourly figure captures, such as canceled orders, clients moving to other suppliers, and contractual penalties. A company that brings its systems and workflows back within days absorbs the incident in a quarter's results. One where recovery drags on for months ends up discussing its effects at the level of the entire balance sheet.
The factors decided before the incident
The public record of these cases covers the timeline and the reported consequences, and the internal situation of the companies involved cannot be assessed from the outside. For that reason, the discussion of preparedness stays general and applies to any company. The first factor is a backup that is tested and isolated from the main network. A copy the attacker can reach gets encrypted along with everything else, which is why isolation and test restores matter as much as the existence of the copy.
The second factor is a limit set by management for the maximum duration of recovery (RTO) and for the volume of data that may be lost (RPO), the limits defined in the continuity plan. They turn recovery from an improvisation into a procedure with measurable targets. The third factor is rehearsing that procedure in advance, because a team that has been through a test restore knows the order of the systems, who is responsible, and how long each step realistically takes.
The last factor is continuous monitoring of the equipment, which catches an anomaly early and allows it to be isolated before it spreads through the entire infrastructure. None of these factors can be built on the day of the incident, since all of them are set up, budgeted, and verified while the infrastructure is running normally.
The continuity plan and the services behind it
The point where these factors come together is the Business Continuity plan, the document through which management sets the recovery limits, the order in which systems come back, and how the company communicates for the duration of an incident. Once written and tested, the plan turns an unpredictable event into a situation that already has a procedure.
Our services support exactly this preparation. We monitor managed devices 24/7 (RMM) so an anomaly is caught early, and secure cloud backup (Azure Backup or Veeam) starts at €30 per month for 500 GB, verified through test restores. For critical systems, cloud replication and Disaster Recovery start at €100 per month.
If you want to know how your company would respond to an incident, our free audit checks exactly these factors, from the state and isolation of your backups to your recovery procedures and existing monitoring. The report stays yours, whatever you decide.