<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Net Advice Solutions — Insights (EN)</title>
    <link>https://www.netadvice.ro/en/insights</link>
    <atom:link href="https://www.netadvice.ro/en/insights/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Short articles on cost, risk and results in IT projects, written by people who approved such projects on the client&#39;s side.</description>
    <language>en</language>
    <item>
      <title>NIS2: what it is and whether it applies to your company</title>
      <link>https://www.netadvice.ro/en/insights/nis2-what-it-is-and-whether-it-applies-to-your-company</link>
      <guid isPermaLink="true">https://www.netadvice.ro/en/insights/nis2-what-it-is-and-whether-it-applies-to-your-company</guid>
      <description>NIS2 is law in Romania through OUG 155/2024. A practical guide for SMEs: how to check whether you are in scope, what you must do and why it matters anyway.</description><content:encoded>&lt;p&gt;As of September 2026, NIS2 is no longer a conference topic. The DNSC has started sanctioning procedures, for now against the companies that never registered. The fines in the law start at 1,000 lei and can reach 10 million euros or a percentage of turnover.&lt;/p&gt;
&lt;p&gt;Most of the business owners we talk to have heard of NIS2 and have two questions: &amp;quot;does it apply to me?&amp;quot; and &amp;quot;what exactly do I have to do?&amp;quot;. This article answers both, in that order.&lt;/p&gt;
&lt;p&gt;A necessary warning: we are not lawyers, and whether a company is in scope depends on its concrete situation. What follows is an orientation guide, not a legal opinion.&lt;/p&gt;
&lt;h2 id=&quot;what-nis2-is-in-short&quot; tabindex=&quot;-1&quot;&gt;What NIS2 is, in short&lt;/h2&gt;
&lt;p&gt;NIS2 is the European directive on the cybersecurity of networks and information systems. Its purpose is simple to state: the companies the economy and society depend on must have a minimum, verifiable level of cybersecurity, and they must report serious incidents.&lt;/p&gt;
&lt;p&gt;In Romania, the directive was transposed through Emergency Ordinance (OUG) 155/2024, in force since 30 December 2024, approved and amended by Law 124/2025. The competent authority is the National Cyber Security Directorate (DNSC), which keeps the register of entities, receives incident reports and applies the sanctions.&lt;/p&gt;
&lt;p&gt;The law splits the companies in scope into two categories: essential entities (broadly, large companies in the critical sectors) and important entities (large and medium-sized companies in the targeted sectors that are not essential). The obligations are similar, but supervision and fines differ.&lt;/p&gt;
&lt;h2 id=&quot;does-it-apply-to-your-company-three-questions&quot; tabindex=&quot;-1&quot;&gt;Does it apply to your company? Three questions&lt;/h2&gt;
&lt;p&gt;The biggest practical difficulty of NIS2 is precisely working out its scope. Not every company that uses computers falls under the law. The check takes three steps.&lt;/p&gt;
&lt;h3 id=&quot;1-do-you-operate-in-a-sector-listed-in-the-annexes&quot; tabindex=&quot;-1&quot;&gt;1. Do you operate in a sector listed in the annexes?&lt;/h3&gt;
&lt;p&gt;Annexes 1 and 2 of OUG 155/2024 list the sectors in scope. Among them: energy, transport, banking and financial market infrastructure, health, drinking water and waste water, digital infrastructure, electronic communications, cloud services and data centres, managed IT and security services, public administration, postal and courier services, waste management, food production and distribution, the chemical industry, certain manufacturing activities (including medical devices, electronics, machinery and equipment), online marketplaces, search engines, social platforms and research organisations.&lt;/p&gt;
&lt;p&gt;Mind one detail: the annexes describe concrete types of entities, not just sectors. The main CAEN code is not enough to decide. What counts is the actual activity.&lt;/p&gt;
&lt;h3 id=&quot;2-are-you-a-medium-sized-or-large-enterprise&quot; tabindex=&quot;-1&quot;&gt;2. Are you a medium-sized or large enterprise?&lt;/h3&gt;
&lt;p&gt;As a general rule, NIS2 applies to companies in these sectors that exceed the small-enterprise threshold: at least 50 employees, or an annual turnover and balance sheet above 10 million euros. Micro and small enterprises are, in general, outside the scope.&lt;/p&gt;
&lt;p&gt;Two nuances catch many companies off guard. First: size is calculated including partner or linked enterprises, so a small company inside a group can be brought into scope through the group. Second: the law refers to the criteria in Law 346/2004, and the thresholds there do not always read intuitively. When the figures are close to the threshold, a careful check is worth it.&lt;/p&gt;
&lt;h3 id=&quot;3-are-you-a-special-case&quot; tabindex=&quot;-1&quot;&gt;3. Are you a special case?&lt;/h3&gt;
&lt;p&gt;Certain categories fall under the law regardless of size: DNS service providers, top-level domain registries, qualified trust service providers, central public administration. In addition, the DNSC can classify a company as essential or important if it is the sole provider of a critical service or if a disruption of its service would significantly affect health, public safety or the economy.&lt;/p&gt;
&lt;p&gt;If the answer to the first two questions is &amp;quot;yes&amp;quot;, or if you sit in a grey area, the DNSC&#39;s recommendation is to complete the assessment through the NIS2@RO tools and submit the notification. The DNSC analyses it and tells you whether the company is essential, important or outside the scope. The company does not decide on its own.&lt;/p&gt;
&lt;h2 id=&quot;i-m-not-directly-in-scope-fine-but-your-clients-are&quot; tabindex=&quot;-1&quot;&gt;&amp;quot;I&#39;m not directly in scope.&amp;quot; Fine, but your clients are&lt;/h2&gt;
&lt;p&gt;This is the part most SMEs miss.&lt;/p&gt;
&lt;p&gt;Among the mandatory measures for essential and important entities is supplier and supply-chain security. A company under NIS2 has to manage the risk its suppliers bring. In practice, that means it will ask you for: security clauses in the contract, an obligation to notify it in case of an incident, evidence that you have basic measures in place, sometimes a right to audit.&lt;/p&gt;
&lt;p&gt;If you provide IT services, software, maintenance, logistics, accounting or anything else to a company in the sectors above, these requirements reach you through the contract, not through the law. And the answer &amp;quot;we are not under NIS2&amp;quot; does not get you out of them. It gets you off the supplier list.&lt;/p&gt;
&lt;p&gt;For an SME, this is the real exposure to NIS2 in most cases: not the fine from the DNSC, but the contract you can no longer sign or renew.&lt;/p&gt;
&lt;h2 id=&quot;if-you-are-in-scope-what-you-have-to-do&quot; tabindex=&quot;-1&quot;&gt;If you are in scope: what you have to do&lt;/h2&gt;
&lt;p&gt;The main obligations, in the order they arise:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Registration with the DNSC.&lt;/strong&gt; For companies that were already in scope when the procedure launched, the general deadline expired on 22 September 2025. Missing it did not remove the obligation; the DNSC has warned that the penalty for failing to register can reach 500,000 lei, and the first sanctioning procedures target exactly these companies. Companies that fall under the law later must submit the notification within 30 days at most.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The NIS2 officer.&lt;/strong&gt; The company must designate a person responsible for cybersecurity and declare them to the DNSC. For small companies an external or shared officer is acceptable, but the person must exist and must be trained.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Risk assessment and maturity self-assessment.&lt;/strong&gt; After the DNSC&#39;s decision to enter the company in the register, the company has 60 days to submit an assessment of its own risk level, following the DNSC methodology, and another 60 days for the self-assessment of the maturity of its security measures. The deadlines run in sequence, so there is no single cut-off date for everyone.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Technical and organisational measures.&lt;/strong&gt; The law requires measures proportionate to the risk, covering, among other things: risk analysis and management, incident prevention and handling, business continuity and disaster recovery, backups that are made and tested, supplier security, access control and asset management, multi-factor authentication, staff training and periodic evaluation of how effective the measures are. These are not recommendations. Their absence is an offence.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reporting significant incidents.&lt;/strong&gt; An early warning within 24 hours of becoming aware, an incident report within 72 hours, a final report within one month at most. For information on cross-border impact, the deadline is 6 hours.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Management responsibility.&lt;/strong&gt; Management must approve and supervise the measures, and members of the management bodies have a training obligation. Law 124/2025 strengthens the personal liability of management. Concretely: NIS2 compliance cannot be delegated wholesale to the IT department or the IT provider.&lt;/p&gt;
&lt;h2 id=&quot;the-fines&quot; tabindex=&quot;-1&quot;&gt;The fines&lt;/h2&gt;
&lt;p&gt;For major breaches (failing to implement the measures, failing to meet audit and reporting obligations), the caps are up to 10 million euros or 2% of turnover for essential entities and up to 7 million euros or 1.4% for important entities, whichever is higher. Law 124/2025 specifies that the percentage applies to global turnover, not just the Romanian one.&lt;/p&gt;
&lt;p&gt;For other offences, fines range from 1,000 to 300,000 lei for important entities and from 1,500 to 500,000 lei for essential ones. In aggravating circumstances, the amount can be doubled.&lt;/p&gt;
&lt;p&gt;The DNSC has indicated that, in a first stage, it will apply values from the lower end of the ranges. Which does not mean the fine is not coming, only that it comes gradually.&lt;/p&gt;
&lt;h2 id=&quot;what-we-do-in-practice-in-both-cases&quot; tabindex=&quot;-1&quot;&gt;What we do in practice, in both cases&lt;/h2&gt;
&lt;p&gt;The good news is that the NIS2 list of measures contains nothing exotic. It is the list a properly built IT setup should cover anyway: centrally managed identities with multi-factor authentication, backups that are tested, not just configured, role-based access, an inventory of systems and suppliers, an incident response plan that someone has read and rehearsed, security clauses in supplier contracts.&lt;/p&gt;
&lt;p&gt;A study published in September 2026 on a sample of 211 Romanian organisations shows why testing matters: 45% described themselves as having high cyber maturity, but only 27% passed three practical checks, permanent monitoring, a tested response plan and regular exercises. Many companies have the measures on paper. Few have put them to the test.&lt;/p&gt;
&lt;p&gt;If you are under NIS2, the order is: check your classification through NIS2@RO, register, designate the officer, run a gap analysis against the list of measures, remediate in order of risk and prepare the documentation for the assessments the DNSC requires.&lt;/p&gt;
&lt;p&gt;If you are not directly in scope, the order is the same, minus registration. Because the basic measures are the ones your clients will ask you for, and they are the ones that actually matter on the day something happens.&lt;/p&gt;
&lt;p&gt;That is what we do: we check the classification, run the gap analysis, put identities, access, backups and documentation in order, and prepare the company for the conversation with the DNSC or with the client asking for guarantees. If you have already received a security questionnaire from a client, or you are not sure which category you fall into, this is the right moment for a conversation.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Sources: OUG 155/2024, Law 124/2025, DNSC Orders 1/2025, 2/2025 and 1/2026, DNSC communications (&lt;a href=&quot;https://www.dnsc.ro/&quot;&gt;dnsc.ro&lt;/a&gt;). Always check the official text and seek legal advice on your company&#39;s concrete classification.&lt;/em&gt;&lt;/p&gt;
</content:encoded>
      <category>Cyber Security</category>
      <pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Tiberiu Grigorescu</dc:creator>
    </item>
    <item>
      <title>Ransomware: how to protect your company from the 2026 wave of attacks</title>
      <link>https://www.netadvice.ro/en/insights/ransomware-how-to-protect-yourself-2026</link>
      <guid isPermaLink="true">https://www.netadvice.ro/en/insights/ransomware-how-to-protect-yourself-2026</guid>
      <description>Ransomware attacks in Romania rose by more than 150% in a year. How they really start, what decides whether a company is back in two days or loses its data, and what needs to be in order beforehand.</description><content:encoded>&lt;p&gt;The DNSC&#39;s activity report for 2025, published in August 2026, contains one figure that should land on the desk of every company director: the number of ransomware attacks in Romania grew by more than 153% compared with the previous year. The DNSC handled 256 major incidents of this kind and supported 119 companies, 22 public institutions and 115 private individuals. Among the public cases: an attack that disrupted the National Administration Romanian Waters and its regional branches for roughly a week.&lt;/p&gt;
&lt;p&gt;And those are only the cases the DNSC was called into. The companies that paid, or quietly rebuilt everything, never make it into the statistics.&lt;/p&gt;
&lt;p&gt;We are not writing this article to scare anyone. We are writing it because protection against ransomware is not a technology you buy, but a set of decisions you take beforehand. Almost all of them are cheap. All of them are boring. And every one of them decides whether, on the day it happens, the company is back in two days or loses its data.&lt;/p&gt;
&lt;h2 id=&quot;how-an-attack-really-starts&quot; tabindex=&quot;-1&quot;&gt;How an attack really starts&lt;/h2&gt;
&lt;p&gt;The movie image, with the hacker breaking through a firewall, is the least common one. The DNSC report shows very concretely how simply an attack can start: an ordinary-looking email, a reused password, a hijacked email account or an unpatched program. Compromised accounts more than quadrupled in 2025 compared with the year before, and phishing attacks rose by more than 70%.&lt;/p&gt;
&lt;p&gt;The trend is confirmed globally too: stolen accounts and credentials have overtaken the exploitation of vulnerabilities as the main way ransomware attacks are launched. The attacker no longer breaks the door down. He walks in with the key.&lt;/p&gt;
&lt;p&gt;The business model behind it is industrialised: specialised groups rent their attack tooling to others, for a fee, the so-called “ransomware-as-a-service”. That means you do not have to be an interesting target to get hit. Being an easy target is enough. And the DNSC even flags a group of Romanian origin, active mostly in the finance and accounting space.&lt;/p&gt;
&lt;p&gt;One detail changes the maths: today&#39;s attacks do not just encrypt. Before encryption, the data is copied. Even if you have a backup and refuse to pay, the attacker threatens to publish your contracts, your employees&#39; data, your clients&#39; data. The backup saves you operationally. It does not save you from the conversation with your clients and with the data protection authority.&lt;/p&gt;
&lt;h2 id=&quot;five-decisions-that-make-the-difference&quot; tabindex=&quot;-1&quot;&gt;Five decisions that make the difference&lt;/h2&gt;
&lt;h3 id=&quot;1-centrally-managed-identities-with-multi-factor-authentication-everywhere&quot; tabindex=&quot;-1&quot;&gt;1. Centrally managed identities, with multi-factor authentication everywhere&lt;/h3&gt;
&lt;p&gt;If the attack starts with a password, the first line of defence is to make a password not enough. The DNSC explicitly lists password reuse and the absence of multi-factor authentication among the factors that favour attacks. That means: MFA enforced on email, on the business systems, on remote access, on administrator accounts. Not “recommended”, not “for whoever wants it”. Enforced from the console, with zero exceptions.&lt;/p&gt;
&lt;p&gt;One step further, for the accounts that matter: phishing-resistant authentication (hardware keys or passkeys), because classic MFA by SMS code can be tricked by a fake login page.&lt;/p&gt;
&lt;p&gt;And administrator accounts are separate from everyday accounts. The person reading email with administrator rights over the whole domain is the shortest path from one wrong click to a paralysed company.&lt;/p&gt;
&lt;h3 id=&quot;2-isolated-versioned-backups-tested-by-restoring-them&quot; tabindex=&quot;-1&quot;&gt;2. Isolated, versioned backups, tested by restoring them&lt;/h3&gt;
&lt;p&gt;Modern ransomware looks for the backups before it encrypts. A backup on a permanently connected disk, on a network share reachable with the same credentials, or in the same cloud tenant without separate protection gets encrypted along with everything else.&lt;/p&gt;
&lt;p&gt;What works: at least one copy isolated from the production network, with versions kept over time and impossible to delete for a defined period (immutability), using credentials different from the production ones. And, essentially, with a restore actually performed, periodically, against the clock. A backup you have never restored is a hypothesis. We will come back to this in a separate article, because it deserves one.&lt;/p&gt;
&lt;h3 id=&quot;3-timely-updates-on-everything-that-is-exposed&quot; tabindex=&quot;-1&quot;&gt;3. Timely updates, on everything that is exposed&lt;/h3&gt;
&lt;p&gt;“Unpatched software” is on the DNSC&#39;s list of causes. Every system reachable from the internet (VPN, remote access, email server, web applications) has to be updated within days, not months, when a vulnerability appears. The same goes for workstations. This is done in a managed way, from a console, with a compliance report, not by “asking colleagues to please restart”.&lt;/p&gt;
&lt;h3 id=&quot;4-endpoint-and-server-protection-that-detects-behaviour-not-just-signatures&quot; tabindex=&quot;-1&quot;&gt;4. Endpoint and server protection that detects behaviour, not just signatures&lt;/h3&gt;
&lt;p&gt;Classic antivirus recognises known files. Today&#39;s ransomware is generated in new variants for every campaign. What matters is a solution that watches behaviour (mass encryption, deletion of backups, privilege escalation) and isolates the machine automatically, within seconds, without waiting for someone to read an alert the next morning.&lt;/p&gt;
&lt;p&gt;Add to that the principle of least privilege: users are not local administrators, file access is role-based, and a compromised account in sales cannot reach accounting.&lt;/p&gt;
&lt;h3 id=&quot;5-a-plan-that-someone-has-actually-read&quot; tabindex=&quot;-1&quot;&gt;5. A plan that someone has actually read&lt;/h3&gt;
&lt;p&gt;What do you do in the first hour? Who disconnects what? Who calls the IT provider, who informs management, who notifies the DNSC and, if personal data is involved, the data protection authority? Which clients need to be told, and by whom? Which backup do you restore from, and how long does it take?&lt;/p&gt;
&lt;p&gt;If the answers to these questions are given for the first time on the day of the attack, they are given badly. The plan does not need 40 pages. It needs one page, people&#39;s names, phone numbers, and to have been rehearsed once, at least on paper.&lt;/p&gt;
&lt;h2 id=&quot;the-rest-which-matters-just-as-much&quot; tabindex=&quot;-1&quot;&gt;The rest, which matters just as much&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Training people, but concretely:&lt;/strong&gt; not an annual course on “internet safety”, but real examples of the emails and messages your colleagues actually receive, including on WhatsApp, which the DNSC names as a campaign vector. A simple channel through which anyone can report “I clicked on something odd” without being told off; the first minutes matter more than blame.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The inventory:&lt;/strong&gt; you cannot protect what you do not know you have. Which servers, which applications, which administrator accounts, which vendors have access to your systems.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The vendors:&lt;/strong&gt; the accounting firm, the IT company, the software vendor with remote access. Each of them is a door into your company. Ask them what they do about points 1 to 5.&lt;/p&gt;
&lt;h2 id=&quot;if-it-happens-anyway&quot; tabindex=&quot;-1&quot;&gt;If it happens anyway&lt;/h2&gt;
&lt;p&gt;Disconnect the affected systems from the network, but do not shut them down and do not wipe them; they hold the evidence. Do not pay by reflex; paying does not guarantee recovery and marks you as a target that pays. Notify the DNSC, which has experience with the groups active in Romania and may hold decryption keys for certain families. If personal data is affected, you have 72 hours to notify the data protection authority. And restore from the backup you have tested.&lt;/p&gt;
&lt;h2 id=&quot;what-we-do&quot; tabindex=&quot;-1&quot;&gt;What we do&lt;/h2&gt;
&lt;p&gt;The five decisions above are exactly the list of measures NIS2 asks for, and exactly what a properly built IT setup means, a subject we cover in the articles that follow. That is no coincidence. Protection against ransomware is not a product separate from the rest of IT. It is IT done properly.&lt;/p&gt;
&lt;p&gt;For our clients, that means: centrally managed identities with enforced MFA, workstations and servers managed from a console, with updates and behavioural protection, isolated backups with periodically tested restores, role-based access rights, and a one-page written response plan with your own people in it.&lt;/p&gt;
&lt;p&gt;If you are not sure where your company stands on the five points, a check takes a few hours and the answer is usually very clear.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Sources: DNSC Activity Report 2025 (public version, approved by CSAT Decision no. 117/2026), DNSC quarterly statistical bulletin 2026, DNSC communications (&lt;a href=&quot;https://www.dnsc.ro/&quot;&gt;dnsc.ro&lt;/a&gt;).&lt;/em&gt;&lt;/p&gt;
</content:encoded>
      <category>Cyber Security</category>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Dragoș Florea</dc:creator>
    </item>
    <item>
      <title>How to bring AI into your company without losing control of it</title>
      <link>https://www.netadvice.ro/en/insights/ai-in-your-company-without-losing-control</link>
      <guid isPermaLink="true">https://www.netadvice.ro/en/insights/ai-in-your-company-without-losing-control</guid>
      <description>A practical guide for SMEs: what to decide before choosing an AI tool, how to keep client data out of personal accounts, and what a proper setup looks like.</description><content:encoded>&lt;p&gt;The question we hear most often is not “should we be using AI?”. It is “what do we do about the fact that people are already using it?”.&lt;/p&gt;
&lt;p&gt;Because that is what is happening in most of the companies we walk into. Someone in sales put a client quote into a free chat to have it rewritten more nicely. Someone in accounting pasted in a bank statement to have a fee explained to them. A colleague in support has a personal account, paid for out of his own pocket, into which he has copied entire conversations with clients. Nobody acted in bad faith. Each of them solved a problem of the moment.&lt;/p&gt;
&lt;p&gt;The result is that the company already has AI adoption. It just doesn&#39;t know about it, doesn&#39;t control it, and can&#39;t show a client or an auditor where the data ended up if anyone asks.&lt;/p&gt;
&lt;p&gt;That is where any serious discussion about AI in a company starts. Not with the tool.&lt;/p&gt;
&lt;h2 id=&quot;the-first-rule-do-not-ban-prescribe&quot; tabindex=&quot;-1&quot;&gt;The first rule: do not ban, prescribe&lt;/h2&gt;
&lt;p&gt;The reflex of many managers, once they realise what is going on, is a ban. “AI is not to be used with company data.” It sounds responsible and it doesn&#39;t work.&lt;/p&gt;
&lt;p&gt;A blanket ban doesn&#39;t stop the usage. It moves it. People who have discovered that they can finish a two-hour job in twenty minutes are not going to give that up. They will carry on on their personal phone, during a break, without telling anyone. You have turned a visible problem into an invisible one.&lt;/p&gt;
&lt;p&gt;A policy only works if it is precise enough to be followed. “Do not put client data into tools the company does not administer” is a rule a person can apply. “Use AI responsibly” is not.&lt;/p&gt;
&lt;p&gt;That lesson was confirmed again in an implementation at an industrial group with operations in several countries: the policy only worked once it was translated into concrete rules and into the technical settings that enforce them. A nicely written document with no controls behind it is a wish, not a policy.&lt;/p&gt;
&lt;h2 id=&quot;step-1-decide-which-data-is-allowed-in&quot; tabindex=&quot;-1&quot;&gt;Step 1: decide which data is allowed in&lt;/h2&gt;
&lt;p&gt;Before any choice of tool, the company has to answer a single question: what categories of information do we have, and where is each of them allowed to go?&lt;/p&gt;
&lt;p&gt;For an SME, three levels are enough:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Public or internal with no risk.&lt;/strong&gt; Marketing copy, general documentation, internal procedures with no personal data. Can be used with any tool the company has approved.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Confidential.&lt;/strong&gt; Quotes, contracts, financial data, information about clients and employees. Can only be used in tools the company administers, where the data is not used to train the model and there is access control.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Restricted.&lt;/strong&gt; Sensitive personal data, health data, information covered by specific confidentiality clauses, data subject to EU residency obligations. Does not go into any tool without a separate assessment.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This classification is not bureaucracy. It is what lets you tell a client, with an argument behind it, what happens to their data. And it is the only way you can train your people without asking them to guess.&lt;/p&gt;
&lt;h2 id=&quot;step-2-not-everyone-needs-the-same-access&quot; tabindex=&quot;-1&quot;&gt;Step 2: not everyone needs the same access&lt;/h2&gt;
&lt;p&gt;The second common mistake is to treat AI as a single thing. It isn&#39;t.&lt;/p&gt;
&lt;p&gt;A chat where a person asks questions and gets answers is one thing. A tool that is given access to the company&#39;s files, email or calendar and carries out tasks is something else entirely. An automated process that runs on its own, with no human in the loop, is a third category.&lt;/p&gt;
&lt;p&gt;The risk grows from one level to the next, and the control should grow with it. Someone in marketing needs the first level. Someone in operations who delegates recurring reports may need the second. The third level is only switched on where there is a clear use case, a named person accountable for it, and a defined limit on what the system is allowed to do.&lt;/p&gt;
&lt;p&gt;Tiered access also solves a problem of a different nature: it puts an end to the “why does he get it and I don&#39;t” conversations. The answer becomes a rule, not the manager&#39;s personal decision.&lt;/p&gt;
&lt;h2 id=&quot;step-3-a-company-account-not-personal-accounts&quot; tabindex=&quot;-1&quot;&gt;Step 3: a company account, not personal accounts&lt;/h2&gt;
&lt;p&gt;This is where it is decided, in practice, whether AI adoption is under control or not.&lt;/p&gt;
&lt;p&gt;Personal accounts, free or paid, have three fundamental problems. The data can be used to train the model, depending on each user&#39;s own settings, which the company cannot see. Nobody can administer anything: neither grant access nor withdraw it when an employee leaves. And when the person leaves, the conversations leave with them.&lt;/p&gt;
&lt;p&gt;Our recommendation is clear: if the company uses AI, use a team plan. Both major providers, Anthropic (Claude) and OpenAI (ChatGPT), have plans of this kind, with central administration and with data excluded from training. The difference in cost compared with individual accounts is small relative to what it solves.&lt;/p&gt;
&lt;p&gt;We work on Claude, both internally and in the implementations we do for clients, and we recommend it. Not because its answers read more nicely, but for three things that matter in a company:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The knowledge belongs to the company, not to each individual.&lt;/strong&gt; Shared projects have a common knowledge base and common instructions: the procedures, the tone, the company context are set up once and the whole team works from them. Nobody has to explain the company from scratch every single time. Conversations stay private, the knowledge is shared.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;You can delegate work, not just ask questions.&lt;/strong&gt; Cowork allows a task across files and applications (a recurring report, a consolidation of documents, a compliance check over a set of contracts) to be delegated rather than carried out manually by copy-pasting out of a chat. This is where the real productivity difference lies, and this is where the second level of access above makes sense.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Control belongs to the administrator.&lt;/strong&gt; Domain verification and blocking of new personal accounts created on the company domain, single sign-on (SSO) through the company&#39;s existing identity, a spending cap, data excluded from training by default. Taking over personal accounts that already exist on the domain is only possible on the Enterprise plan. And the team plan starts at two users, so there is no minimum threshold that shuts out small companies.&lt;/p&gt;
&lt;p&gt;In a company that already has Microsoft 365 or Google Workspace, integration with the existing identity means that access to AI is granted and withdrawn the same way as access to email. When the person leaves the company, they leave AI too. That is what “under control” means.&lt;/p&gt;
&lt;h2 id=&quot;step-4-a-one-hour-training-session-and-a-one-page-guide&quot; tabindex=&quot;-1&quot;&gt;Step 4: a one-hour training session and a one-page guide&lt;/h2&gt;
&lt;p&gt;Nobody reads a ten-page policy. What works is a one-page guide, with concrete examples of “yes” and “no”, and a short session in which people see how the work is done properly on their own real cases.&lt;/p&gt;
&lt;p&gt;The guide has to answer the questions people actually have: can I put in a client quote? (yes, in the company account, not in your personal one), can I put in a CV received through recruitment? (no, not without the candidate&#39;s consent), can I ask it to rewrite an email for me? (yes), can I let AI send the email? (no, not without checking it).&lt;/p&gt;
&lt;p&gt;The wording matters as much as the content. A rule that sounds like somebody&#39;s personal decision gets negotiated. A rule that is company policy gets respected.&lt;/p&gt;
&lt;h2 id=&quot;step-5-review-after-three-months&quot; tabindex=&quot;-1&quot;&gt;Step 5: review after three months&lt;/h2&gt;
&lt;p&gt;The setup is not an event. After three months, you need to know who is using it, for what, and where situations came up that the guide did not cover. They almost always do. A good use case was discovered by someone in accounting, a rule turned out to be too strict and people went around it, a level of access needs to be extended.&lt;/p&gt;
&lt;p&gt;The review is what keeps the policy precise. And a precise policy is the only kind that gets respected.&lt;/p&gt;
&lt;h2 id=&quot;what-a-properly-built-setup-looks-like&quot; tabindex=&quot;-1&quot;&gt;What a properly built setup looks like&lt;/h2&gt;
&lt;p&gt;In concrete terms, for an SME, a properly built setup means: the data classification agreed together with the leadership team, the team plan configured on the company domain and tied to the existing identity (Microsoft 365 or Google Workspace), the access levels defined by role, the shared projects built with the company&#39;s knowledge, the one-page guide written around the team&#39;s real cases, and a training session. Plus the review at three months.&lt;/p&gt;
&lt;p&gt;That is exactly what we do, both for our own company and for our clients. If AI is already being used in your company but nobody can say exactly how, where and with what data, this is the right moment for a conversation.&lt;/p&gt;
</content:encoded>
      <category>AI &amp; Automation</category>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Tiberiu Grigorescu</dc:creator>
    </item>
  </channel>
</rss>
