Dănuţ MAFTEI, PhD
Mihail-George GURANDA
Abstract. This article examines the role of Public-Private Partnerships (PPPs) as strategic facilitators of cyber resilience and domestic and international security, in a context marked by the exponential growth of vulnerabilities and hybrid threats to critical information infrastructure.
The scientific study clarifies the definition, roles, and typologies of PPPs, highlighting how they bridge the gap between public responsibility and the operational capacity of the industry and the private sector.
Based on a qualitative methodology grounded in documentary analysis, comparative analysis, and conceptual synthesis, this research identifies the success factors of PPPs, their multidimensional benefits, and the necessary governance conditions.
Special attention is given to transnational PPPs, which are relevant for cross-border information sharing, incident response coordination, and the protection of interconnected infrastructures. The analysis shows that, in the context of NIS2 Directive and the maturing of European cyber governance, PPPs are becoming essential tools for prevention, rapid response, and strengthening ecosystem resilience.
Keywords: Public-Private Partnerships; National cyber security strategy; Cybersecurity maturity; Information sharing; Critical information infrastructure; Cyber resilience; National / International security; Good practices
INTRODUCTION. THE SECURITY PARADIGM IN THE DIGITAL AGE
In the 21st century, cybersecurity has become a central aspect of national security, extending beyond the technical realm to influence economic stability, social resilience, and geopolitical positioning. As public administration and critical infrastructure become increasingly dependent on digitalization, their vulnerabilities take on a systemic character, with implications that transcend conventional IT management.
Cyber-attacks, which are becoming increasingly numerous and sophisticated, originate from both state and non-state actors and specifically target critical information infrastructure (CII) in sensitive sectors such as energy, transportation, financial services, healthcare, digital infrastructure, public administration, and space. The evolution of threats is driven by the expansion of the attack surface, generated by digitization, automation, and the convergence of operational systems with traditional IT systems. In this context, emerging technologies, such as artificial intelligence (AI), machine learning, and quantum computing, can function both as multipliers of defensive capabilities and as vectors for more complex attacks, amplifying the challenges of risk management.
Supply chain vulnerabilities, hybrid warfare tactics, disinformation campaigns, and the increasing interconnectivity of CII underscore the need for holistic national,
regional, and international strategies that combine public policies, multisectoral cooperation, skills development, and robust incident response mechanisms. Although governments remain responsible for national security and the regulatory framework, the ownership and operation of many critical elements of digital infrastructure fall primarily to the private sector, creating a structural gap between the public mandate for protection and actual operational capacity.
In response, various forms of cooperation between public authorities and the private sector, known as Public-Private Partnerships (PPPs), have emerged around the world, becoming a central strategic approach to strengthening cyber resilience. PPPs can be: formalized through national public policies, legislative instruments, and regulatory frameworks; institutionalized through joint cyber incident response teams; developed informally through communities of practice and trust. These communities facilitate the sharing of resources (assets, knowledge, information, and funding), as well as the distribution of risks and benefits among governments, private operators, technology providers, academia, and civil society.
The strategic importance of these arrangements has been recognized internationally by relevant organizations and alliances (the UN, OSCE, OECD, etc.), as well as by some countries that have already incorporated PPPs into their national cybersecurity strategies in various forms (at the conceptual level or by formalizing existing partner-ships).
Well-designed PPP architectures contribute to reduced response times, improvements in innovation capacity, more effective prevention mechanisms, and increased resilience to cyber shocks. At the same time, obstacles such as legal uncertainty, a lack of mutual trust, misaligned economic incentives, and the absence of uniform operational standards remain significant barriers to the long-term effectiveness of PPPs.
Furthermore, emerging models of cross-border PPPs extend this cooperation to the transnational level, aiming to harmonize security standards for interconnected infrastructure, facilitate transnational information exchange, and coordinate responses to cross-border incidents. However, the success of these arrangements requires a delicate balance between operational efficiency and the protection of fundamental rights. These cross-border models have begun to be analysed in the academic literature and tested in regional initiatives, offering insights into the specific advantages and challenges of cross-border cooperation.
This article aims to provide an analytical framework for evaluating PPPs in the field of cybersecurity and offers practical recommendations for their implementation at the national and international levels.
Research methodology
This paper employs a qualitative methodology based on documentary analysis, comparative analysis, and conceptual synthesis. The analysed corpus includes regulatory frameworks, public policy documents, laws, institutional reports, and relevant European and international best practices pertaining to public-private partnerships in the field of cybersecurity.
The comparative approach aims to identify the convergences and differences between national models of governance and cyber maturity, as well as to capture how these influence cooperation between the public and private sectors. The conceptual synthesis supports the formulation of an analytical framework regarding the role of PPPs in CII resilience and transnational cooperation.
The method used is appropriate for the subject matter, which lies at the inter-section of regulation, governance, and operational practice. The aim is not to statistically test hypotheses, but to develop a comparative and normative interpretation.
1. CONCEPTUAL FOUNDATIONS
AND THE STRATEGIC IMPORTANCE OF PPPS IN CYBERSECURITY
Public-private partnerships in the field of cybersecurity are based on the premise that critical digital infrastructure is largely owned and operated by private actors, while the state remains responsible for national security and public resilience. Initially emerging as ad-hoc forms of cooperation following the privatization of critical infrastructure and the escalation of digital threats, PPPs have evolved into structured, multisectoral arrangements that have become fundamental components of national and regional cybersecurity resilience strategies.
According to the European Union Agency for Cybersecurity (ENISA 2026), in an operational sense, a PPP refers to a form of long-term cooperation between public and private entities, designed to facilitate information sharing, coordinated response, and the joint use of resources for managing cyber risks (ENISA 2017). European documents and recommendations summarize this concept as a structured cooperation framework between parties with complementary mandates, resources, and responsibilities.
The actors involved in PPPs for cyber resilience primarily include:
-
Governments and public authorities: relevant ministries, national cybersecurity agencies, regulatory bodies, courts and law enforcement agencies, defence structures, and intelligence services.
-
Private sector: owners and operators of CII, providers of cybersecurity solutions and services, technology providers, industry associations, information sharing and analysis centres (ISACs), and small and medium-sized enterprises (SMEs).
-
Technical and operational community: Computer Emergency Response Teams (CERTs) and Computer Security Incident Response Teams (CSIRTs), standardi-zation organizations, protocol providers, and network operators.
-
Academia and research: universities, research institutes, think tanks, and indepen–dent experts contributing to risk assessments, policies, and technological solutions.
-
Civil society and non-profit organizations: advocacy groups, foundations, non-governmental organizations, relevant community networks, etc.
-
International organizations and mechanisms relevant to transnational cooperation.
The strategic importance of PPPs stems from their ability to facilitate the rapid exchange of information on threats and vulnerabilities, coordinate incident response, and develop common mechanisms for protecting CII. The literature highlights that well-developed collaborative architectures contribute to reducing response times, increasing interoperability, and strengthening systemic resilience.
At the same time, the effectiveness of PPPs depends on the existence of appropriate institutional and legal conditions. Clear responsibilities, the protection of sensitive information, procedural interoperability, and the building of trust among the stakeholders involved are essential factors for the effective functioning of these partnerships.
2. STRATEGIC FACTORS AND DEFINING CHARACTERISTICS OF PPPS
2.1. Strategic foundations
Public-private partnerships in the field of cybersecurity address a variety of strategic imperatives by aligning public responsibilities with the capabilities of the private sector. Key strategic factors include economic considerations, regulatory mandates, reputational benefits, and social priorities; each of which contributes to addressing gaps in resources, coordination, and awareness (ENISA 2017). Essentially, PPPs are driven by the need to reconcile the state’s monopoly on public security with the private sector’s dominance in operational and technological resources.
2.2. Strategic factors
Economic incentives. Economic motivation is a key driver for private-sector involvement, whether through the creation of markets and export opportunities for security technologies or through adaptation to compliance requirements that generate demand for specialized services. In the long term, public-private collaboration can stimulate industrial development and the global competitiveness of local providers of cybersecurity solutions.
Regulatory and legal imperatives. National and international regulations often require PPP mechanisms to implement obligations regarding CII protection and structured information sharing. The governments must provide legal clarity and operational procedures that enable the effective and lawful involvement of private parties.
Reputational benefits and operational networks. Participation in PPPs generates reputational advantages for companies and creates networking platforms that facilitate the transfer of know-how, best practices, and operational cooperation between government and private actors.
Social priorities and capacity building. Integrating cybersecurity into the public agenda and joint capacity-building programs supports the inclusion of SMEs and the expansion of a security culture at the societal level. Limited public resources during times of crisis make PPPs essential tools for mobilizing capabilities at scale.
2.3. Implementation challenges
In practice, the adoption of PPPs is often limited by barriers such as perceptions of cost and complexity, a lack of awareness of concrete benefits, and procedural uncertainty regarding the initiation of collaborations. To overcome these obstacles, policy incentives, pilot models, and evidence bases are needed to demonstrate added value and create momentum for broader implementation.
2.4. Defining characteristics of PPPs
Effective PPPs in the field of cybersecurity share a number of common features: voluntary and conditional participation; trust-building mechanisms; operational coordination of the response; synergy between competencies and expertise; procedures for the secure exchange of information; clear operational focus; shared responsibility and ownership; efficient allocation of resources for resilience; adaptability to sophisticated threats; and active integration of research and development (R&D). Each characteristic entails distinct managerial and legal requirements that must be incorporated into the partnership’s architecture.
2.5. Types of PPPs
The classification used by leading organizations allows PPPs to be grouped according to functional logic and sustainability (ENISA 2017):
Institutional PPPs – permanent structures, integrated into national cyber governance architectures, characterized by coordinating bodies (e.g., national councils, ISACs), governance protocols, legal agreements, and dedicated funding for sustainability. The main advantage is the building of trust and the standardization of information sharing, while limitations include bureaucratic rigidity and privacy concerns. Institutional PPPs prove essential for nations seeking scalable cyber resilience in the context of constantly evolving threats.
Goal-oriented PPPs are temporary arrangements with clear objectives and a limited time frame, dedicated to specific activities (threat hunting, national exercises, supply chain audits). These models are agile and focused on measurable results, but they risk losing continuity if there are no mechanisms in place to integrate project outputs into permanent structures. They bring together government regulators, private operators, and representatives from academia, who organize national cyber exercises, take measures against disinformation, or conduct supply chain security audits. The advantages lie in agility, cost-effectiveness, and measurable results, fostering innovation by pooling specific expertise. However, success depends on strong leadership to prevent scope creep, and results may disappear after the project ends without knowledge transfer mechanisms. Goal-oriented PPPs complement institutional models by addressing emerging gaps in national cybersecurity strategies.
Service-based PPPs are contracts through which the government procures specialized services (managed detection and response – MDR, testing, incident response) from private providers, governed by service-level agreements (SLAs) and liability clauses. This model provides rapid access to technical capabilities and scalability, but exposes authorities to risks of single-vendor dependency and ambiguities in liability. It also leverages commercial agility and technological superiority to enhance public sector capacity, particularly in resource-constrained environments. When structured with robust oversight, service outsourcing PPPs enhances national security effectiveness and national cyber maturity.
Hybrid PPPs that combine elements from the preceding categories to ensure flexibility and coverage across the entire security cycle (prevention, detection, response, recovery). Hybrid models require sophisticated governance to manage interoperability, diverse member motivations, and heterogeneous legal requirements. These versatile models integrate permanent forums (e.g., cross-sector ISACs) with project-based initiatives and selective outsourcing, enabling seamless transitions between the prevention, detection, response, and recovery phases. Hybrid approaches foster resilience across the entire ecosystem by promoting joint investments in emerging technologies, such as AI-based defence or quantum encryption. Hybrid PPPs represent the gold standard for national strategic cyber resilience in interconnected threat landscapes.
2.6. Functional models for CII resilience
Another useful classification dimension relates to the operational purpose of the PPP: Prevention (Proactive), Response (Reactive), and Integrated (Umbrella-type) Models. Each of these addresses distinct phases of cybersecurity, risk management, and incident response. These models reflect the evolving collaboration strategies essential to national cyber resilience in an era of sophisticated threats targeting sectors such as energy, finance, and healthcare.
Proactive PPPs (Prevention) focus on identifying and mitigating risks before they materialize: joint risk assessments, cybersecurity hygiene campaigns, training programs, and threat intelligence-sharing platforms. They support practical standardization and capacity building in the medium and long term.
By bringing together private operators, regulators, and public authorities, these partnerships promote a mindset of collective defence through capacity building, workforce training, and initiatives to mitigate vulnerabilities. They form the foundation of national cyber strategies, significantly reducing CII exposure through a preventive approach to risks and the promotion of sectoral standards.
Reactive PPPs (Response) are activated during incidents and prioritize rapid detection, containment, and mitigation of effects. They coordinate the relationship between CERTs/CSIRTs, Security Operations Centres (SOCs), ISACs, and law enforcement, which is essential for effectiveness. Periodic exercises enhance operational agility and institutional memory. These partnerships excel in high-stakes scenarios affecting critical sectors such as healthcare and finance, and are enhanced by regular exercises that develop agility and institutional memory. Through streamlined joint responses to attacks, the proliferation of threats in emergency situations is limited, thereby minimizing economic and social disruptions.
PPP Umbrella (Integrated) covers the entire cybersecurity lifecycle (prevention, detection, response, and recovery) through mature governance structures that align na–tional policies with operational implementations and facilitate cross-border coordination and societal engagement.
2.7. Comments on initiation and governance
PPPs can be initiated and guided by the government, with defined structures and oversight (Top-down PPPs), which provide legal clarity and resources. On the other hand, PPPs can be initiated by industry or the private sector, often being more flexible and voluntary (Bottom-up PPPs). Bottom-up models typically allow for greater participation, local innovation, and adaptability, as decision-making is decentralized and reflects the needs of those directly affected. An effective architecture combines elements from both approaches, through layered representation mechanisms, operational standards, and performance monitoring tools.
2.8. Transnational PPPs and cross-border cooperation
These cross-border PPP models have begun to be analysed in the literature and tested in regional initiatives, offering insights into the specific advantages and challenges of cross-border cooperation.
Transnational PPPs extend cooperation beyond national borders and become relevant in the context of interconnected infrastructures, distributed supply chains, and digital service providers operating across multiple jurisdictions. They support the trans-national exchange of information, the coordination of responses to cross-border incidents, and the gradual harmonization of security standards.
In practice, transnational PPPs can take the form of agreements between authorities, sectoral networks, joint exercises, or permanent information-sharing mechanisms. These models complement national frameworks and serve as a functional extension of them rather than an alternative. At the same time, their effectiveness is limited by regulatory differences, uneven levels of institutional maturity, and requirements regarding confidentiality and data protection.
From a strategic perspective, transnational PPPs serve three major functions: early warning, operational coordination, and the gradual harmonization of standards. They are particularly useful in situations where an incident simultaneously affects infra-structure, providers, or services operating across borders. To be sustainable, these mechanisms require clear rules on data sharing, the delineation of responsibilities, and the protection of sensitive information.
The importance of these partnerships is amplified by global digital dependencies and supply chain vulnerabilities. Cloud providers, digital platforms, and shared techno-logical infrastructures generate systemic risks that can no longer be managed exclusively at the national level.
Furthermore, transnational PPPs are relevant for strengthening European strategic autonomy and countering hybrid threats targeting critical infrastructure and Western digital ecosystems.
2.9. Analytical conclusions
To design effective PPPs, policymakers must clearly articulate strategic objectives and establish legal frameworks and trust mechanisms for cooperation and effective information sharing. At the same time, they must select operational models aligned with national capabilities and sectoral dynamics.
3. THE NIS2 DIRECTIVE AND THE OPERATIONALIZATION OF PPPs THROUGH CYBER MATURITY ASSESSMENT
3.1. From formal compliance to adaptive governance
Directive (EU) 2022/2555 (NIS2) (EUR-Lex 2022) redefines the European cyber–security architecture by focusing on risk management, continuous maturity assessment, and institutionalized cooperation. This transformation reflects the shift from regulatory models based exclusively on formal compliance toward forms of adaptive and collaborative governance (Baldwin, Cave şi Lodge 2013). In this context, PPPs are no longer complementary mechanisms but structural components of national cyber resilience.
3.2. National maturity assessment tools: a comparative study
The comparative study of Finland, Romania, Germany, France, Belgium, and Ireland highlights commonalities in the development of national maturity assessment tools and in the integration of the private sector.
-
Finland: Cybermeter provides a harmonized framework for comparative analysis at the organizational and sectoral levels, facilitating common development goals (TRAFICOM 2026).
-
Belgium: CyberFundamentals (CyFun) is a national assessment and certification scheme, anchored in the functions of identification, protection, detection, response, and recovery (CCB 2026).
-
France has developed MesServicesCyber, an NIS2 simulator, and an expanded CSIRT ecosystem (territorial, sectoral, ministerial) (ANSSI 2025).
-
Germany: Alliance for Cyber Security and UP KRITIS – represent two platforms for cross-sectoral cooperation with CII operators (BSI 2025).
-
Ireland: NCSC-FI combines NIS2 guidelines with CyFun and capacity-building grants (NCSC 2025).
-
Romania: DNSC established the legal and institutional framework for implementation through Government Emergency Ordinance 155/2024, Law 124/2025, the NIS2@RO instrument (DNSC 2026), and subsequent orders (DNSC 2026).
3.3. Institutional convergences
The comparative analysis reveals two major convergences:
1. The coordinating role of the national authority: shifting from a legal regulator to a coordinator of the multi-stakeholder cyber ecosystem. All the countries analysed are expanding traditional PPPs to include sectoral, territorial, and operational structures (ENISA 2025).
2. Standardization of maturity assessment: tools such as Cybermeter (Finland) or CyFun (Belgium, Ireland) reduce fragmentation by creating a common language and comparability between public and private entities.
For Romania, which is making progress through NIS2@RO, the development of an explicit infrastructure for comparative analysis and maturity assessment, combined with sectoral and territorial cooperation structures, could transform compliance with the NIS2 Directive into a permanent mechanism for operational resilience.
3.4. Architectural differences
Difference 1: The model based on a centralized assessment framework versus the model based on operational networks. Finland and Belgium have adopted a tool-centred model, in which a single maturity framework (Cybermeter and CyFun, respectively) serves as the core of cooperation, structuring comparative analysis and common development objectives. Germany and France prefer a model based on a centralized framework, built around operational networks, platforms, and communities (UP KRITIS, the CSIRT ecosystem), in which cooperation is organized through multisectoral interactions rather than through a dominant tool. Ireland occupies an intermediate position, combining CyFun with practical guidance and financial support mechanisms. Romania is currently moving toward a model based on a centralized assessment framework, with a predominant focus on regulatory transposition, oversight, and risk assessment, but without a dedicated national benchmarking tool comparable to the Nordic or Belgian models (DNSC 2025).
Difference 2: The legal status of maturity tools. Belgium grants CyFun the highest degree of legal and operational integration, recognizing it as a national scheme with the potential for a presumption of NIS2 compliance. In Ireland, CyFun serves as a recognized means of demonstrating controls, without, however, generating an automatic legal presumption. In Finland, Cybermeter functions as an assessment and coordination infra–structure, with a predominantly operational and strategic role. Romania, Germany, and France use implementation support tools (NIS2@RO, BSI guidelines, ANSSI simulators), which are subject to oversight by the competent authorities, without treating them as a substitute for compliance verification.
3.5. Implications for national resilience
The implementation of NIS2 highlights a common strategic thesis: cyber resilience cannot be achieved exclusively through state resources or fragmented market dynamics, but requires collaborative ecosystems based on standardized maturity, secure information sharing, and institutional trust (ENISA 2025). Institutional differences reflect distinct administrative traditions, but functional convergence is evident.
For Romania, the existing legal framework provides the foundation for an advanced model, but the next strategic step involves developing an explicit infrastructure for comparative analysis, maturity assessment, and sectorial cooperation. A hybrid approach, combining instrumental elements (such as Cybermeter) with operational networks (such as UP KRITIS), would optimize the transformation of NIS2 compliance into a permanent PPP mechanism.
4. BENEFITS AND IMPACT
PPPs serve as a structural tool for strengthening cybersecurity and national resilience, operating at the intersection of the public sector’s mandate to protect and the private sector’s capacity for innovation. By integrating resources and expertise, they enable a systemic approach to the protection of CII and reduce the risk of cascading effects across interdependent sectors.
At the operational level, PPPs enhance situational awareness, the efficiency of incident response, standardization and interoperability, as well as supply chain security.
At the institutional level, they provide access to specialized expertise and re-sources, support the formulation of realistic policies, and reduce the fragmentation of initiatives. Synergies are created between private initiatives, avoiding fragmentation, and improving the efficiency of public services through tested technologies, supporting the implementation of national and European strategies such as the NIS2 Directive (EUR-Lex 2022) and the Critical Entities Resilience (CER) Directive (EUR-Lex 2022).
For the private sector, PPPs offer access to information and support mechanisms, influence in defining standards, and commercial and reputational benefits.
At the societal level, partnerships help reduce exposure and vulnerabilities, provide rapid access to advanced capabilities during crises, and strengthen the culture of security. They also increase trust in digital services and promote digital literacy. These benefits become sustainable only under conditions of transparent governance, sustainable financing, and a clear legal framework regarding responsibilities and information sharing.
5. LESSONS LEARNED AND BEST PRACTICES ON THE ESTABLISHMENT, GOVERNANCE, AND OPERATION OF PUBLIC-PRIVATE PARTNERSHIPS
Comparative experience demonstrates that effective PPPs result from a deliberate process of institutional design, politically supported and rigorously implemented throughout the partnership’s entire lifecycle.
Strategic and legal framework
The recognition of PPPs as a pillar of cybersecurity must be explicitly anchored in national cybersecurity strategies (AZ_Presidency 2023), (Government Center for Security 2025). Political leadership ensures legitimacy, while consultations with industry and academia guarantee operational relevance and alignment with EU frameworks, such as the NIS2 Directive and Regulation 2024/2847 on Cyber Resilience (EUR-Lex 2024). A clear legal framework is essential for defining responsibilities, sharing risks, and protecting information, including performance indicators and periodic reviews.
Governance and operational cooperation
Optimal governance requires a national coordinating body and a mix of permanent structures (secretariats, ISACs) and ad hoc crisis response mechanisms. Trust is built through confidentiality agreements and anonymization procedures (WEFORUM 2025). Member selection must be based on competence and proportionate vetting procedures, while ensuring the inclusion of SMEs to avoid fragmentation of the ecosystem. Information-sharing channels must be interoperable, and periodic incident response exercises are vital for institutional memory.
Supply chain resilience
Joint assessments, coordinated testing, and shared certification schemes enable the identification of systemic vulnerabilities. Contractual policies and supplier diversification strategies reduce reliance on a single vendor and increase operational resilience.
Human resources and talent management
The shortage of experts is addressed through fiscal (DNSC 2022) and non-fiscal incentives (competitive salaries, flexibility, automation) (Demeter and Maftei 2025). Mandatory training for the management of critical entities, in accordance with Article 20 of NIS2 Directive, positions the human factor as the first line of defence. Education programs (bachelor’s degrees, micro-credentials) developed through academic-industrial partnerships meet the real needs of the market. At the same time, protecting “critical human assets” requires strict measures to anonymize personnel involved in sensitive activities in order to prevent their exposure online.
Financial sustainability and accountability
PPP sustainability requires long-term budget planning, blended financing mechanisms (co-financed grants, R&D projects), and transparent monitoring (OECD 2008). External audits and the publication of anonymized performance reports strengthen accountability and enable the replication of best practices.
Security culture and broad collaboration
Early education, specialized competitions, and digital literacy campaigns foster a national security culture (Maftei 2024). Standardized procedures for collaboration between CSIRTs, law enforcement, data protection authorities, judicial officials, and CIIs (ENISA 2021), along with participation in global cooperation and information-sharing frameworks, maximize the efficiency of investigations and cross-border response capabilities.
CONCLUSIONS
Public-private partnerships are essential strategic enablers for cybersecurity and national resilience in the digital age.
Their evolution from ad-hoc initiatives to mature institutional structures reflects the need to reconcile the state’s mandate to protect with the private sector’s operational capabilities, transforming the sharing of information, expertise, and risks into a central tool against hybrid threats targeting critical information infrastructure.
The effectiveness of PPPs depends on a solid foundation consisting of three inter–dependent elements: explicit prioritization in national strategies, a legislative framework that balances obligations with operational flexibility, and governance mechanisms that combine public oversight with trusted tools for secure information exchange. Their successful implementation requires political support, functional coordination, human resource strategies, and sustainable financing; in the absence of these conditions, PPPs risk remaining sporadic or generating power imbalances.
The identified operational models (institutional, goal-oriented, outsourcing, or hybrid) cover the entire security cycle (prevention, detection, response, and recovery) and generate multidimensional benefits: at the operational level, they enhance situational awareness and reduce response times; at the institutional level, they provide access to cutting-edge technologies and expertise; and at the societal level, they consolidate trust of citizens in the digital ecosystem.
The lessons learned underscore the need for a holistic approach (strategic integration, multi-stakeholder governance, regular exercises, investment in human capital, and cross-border mechanisms) to address persistent challenges such as a lack of trust or a shortage of professionals.
For Romania, transforming compliance with the NIS2 Directive into a permanent resilience mechanism requires a national benchmarking infrastructure and sectoral cooperation structures.
Ultimately, PPPs are not merely public policy options, but the functional imperative of modern security.
The future of cyber resilience belongs to nations capable of transforming structural public-private interdependence into a sustainable strategic alliance and of developing national digital security cultures resilient to hybrid and transnational threats.
References
-
***. 2017. “Public Private Partnerships – Cooperative models.” Accessed 3 2026.
https://www.enisa.europa.eu/sites/default/files/publications/WP2017%20O-3-1-3%203%20 Public%20Private%20Partnerships%20%28PPP%29%20Cooperative%20models.pdf. -
***. 2019. “https://eur-lex.europa.eu/.” Accessed 2025.
https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng. -
***. 2022. “https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555.” Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (E. Accessed 5 2026.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555. -
***. 2022. “LEGE nr. 366 din 19 decembrie 2022.” Portal Legislativ. Accessed 5 2026.
https://legislatie.just.ro/Public/DetaliiDocumentAfis/262941. -
***. 2024. “EUR-Lex.” Regulamentul (UE) 2024/2847 al Parlamentului European şi al Consiliului din 23 octombrie 2024 privind cerinţele orizontale în materie de securitate cibernetică pentru produsele cu elemente digitale şi de modificare a Regulamentelor (UE) nr. 168/2013 şi (U. Accessed 3 2026.
https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng. -
***. 2025. “ENISA NIS360 2024 report: A comprehensive look at cybersecurity maturity and criticality of NIS2 sectors.” 3 5. Accessed 4 2026.
https://www.enisa.europa.eu/news/enisa-nis360-2024-report. -
***. 2025. “Raport anual de activitate 2024.” Accessed 3 2026.
https://www.dnsc.ro/vezi/document/dnsc-raport-anual-2024. -
***. 2025. Government Centre for Security. Accessed 5 2026.
http://rcb.gov.pl/en/about-us/. -
***. 2026. ENISA. Accessed 03 22, 2026.
https://www.enisa.europa.eu/. -
***. 2026. Legislaţie. Accessed 4 2026.
https://www.dnsc.ro/pagini/legislatie-nis2. -
ANSSI. 2025. MesServicesCyber. Accessed 5 2026.
https://messervices.cyber.gouv.fr/. -
AZ_Presidency. 2023. “The Strategy of the Republic of Azerbaijan on Information Security and Cybersecurity for 2023–2027.” Accessed 4 2026.
https://akta.az/en/news/informasiya-tehluekesizliyi-ve-kibertehluekesizliye-dair-oelkenin-ilk-strategiyasi-qebul-olunub. -
Baldwin, Robert, Martin Cave, and Martin Lodge. 2013. Understanding Regulation: Theory, Strategy, and Practice. London. Accessed 5 2026.
doi:10.1093/acprof:osobl/9780199576081.001.0001. -
BSI. 2025. Alliance for Cyber Security. Accessed 4 2026.
https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Allianz-fuer-Cyber-Sicherheit/allianz-fuer-cyber-sicherheit_node.html. -
CCB. 2026. CyFun® 2025 is here! 20 4. Accessed 5 2026.
https://ccb.belgium.be/news/cyfunr-2025-here. -
Demeter, C., and D. Maftei. 2025. “Lessons learned on cybersecurity project proposals for successful EU grant applications.” Bulletin of “Carol I” National Defence University („Carol I” National Defence University Publishing House) 1: 136-153. Accessed 5 2026.
doi:https://doi.org/10.53477/2284-9378-25-09. -
DNSC. 2026. „Înregistrare entităţi.” Accessed 4.
https://www.dnsc.ro/pagini/inregistrare-entitati. -
ENISA. 2021. “2020 Report on CSIRT-le Cooperation – A study of the roles and synergies among selected EU Member States/EFTA countries.” ENISA. January. Accessed 5 2026.
https://www.enisa.europa.eu/publications/2020-report-on-csirt-le-cooperation. -
EUR-Lex. 2022. Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC. 14 12. Accessed 03 25, 2026.
https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng. -
Maftei, Danut. 2024. “The Cyber Competences Act – a Vital EU Regulation Concerning Mandatory Certification of Critical Network and Information Systems’ Operators across the European Union.” Informatica Economică 45-60. Accessed 4 22, 2026.
doi:10.24818/issn14531305/28.2.2024.04. -
NCSC. 2025. Cyber Fundamentals. Accessed 4 2026.
https://www.ncsc.gov.ie/CyFun/. -
OECD. 2008. Public-Private Partnerships. In pursuit of risk sharing and value for money. Accessed 4 27, 2026.
https://www.oecd.org/content/dam/oecd/en/publications/reports/2008/05/public-private-partnerships_g1gh8c7d/9789264046733-en.pdf. -
TRAFICOM. 2026. Kybermittari – Cybermeter. 22 4. Accessed 4 2026.
https://www.kyberturvallisuuskeskus.fi/en/our-services/situation-awareness-and-network-management/kybermittari-cybermeter. -
WEFORUM. 2025. “Growing Cyber Talent through Public–Private Partnerships – White Paper.” Edited by World Economic Forum. 05. Accessed 3 28, 2026.
https://reports.weforum.org/docs/WEF_Growing_Cyber_Talent_Through_Public_Private_Partnerships_2025.pdf.
National Cyber Security Directorate, Bucharest, Romania
Senior Legal and Regulatory Affairs Expert | EU-Level Cybersecurity Policy Specialist | Strategic Advisor in Public Policies