Romania has put the Cyber Alliance for Regional Resilience among its cybersecurity priorities for 2026.

The alliance was created in February, when the Romanian National Cyber Security Directorate, Ukraine's National Cybersecurity Coordination Center and Moldova's Cybersecurity Agency signed a trilateral memorandum. The agenda was practical from the beginning: information exchange, joint training, stronger protection of critical infrastructure and coordinated responses to cyber and hybrid threats.

Now the focus is shifting from setting up the framework to making it work.

In August, Romania's National Cyber Security Directorate said it wanted to increase activity under the alliance and continue its operationalisation. That follows several months in which the three countries have already moved beyond declarations and into exercises and technical cooperation.

For Andrei Joroveanu, a graduate in Global Security and Strategy at the Brussels School of Governance and Assistant and Writer at EPIS Thinktank, the alliance's size may be one of its main advantages. His view is that a smaller regional format can move faster than a large multinational mechanism and give Romania more direct access to lessons Ukraine has accumulated during the war.

Key takeaways

  • Romania can use the trilateral format to strengthen its own cyber capabilities and train personnel using practical lessons developed by Ukraine under sustained wartime pressure.
  • Its strongest immediate value may be in early warning and coordinated responses to hybrid campaigns, where faster communication between neighbouring institutions matters.
  • Exercises already give the alliance practical content. A deeper shift would come with permanent mechanisms, clearer common policies and closer integration of the three national cyber systems.

A smaller format can do things differently

Romania already has access to much larger cybersecurity structures through NATO and the European Union.

NATO provides political consultation, information sharing, exercises and mutual assistance. Its Virtual Cyber Incident Support Capability is designed to help Allies during significant malicious cyber activity. The EU Cybersecurity Reserve offers trusted incident-response services to Member States and eligible partner countries. Ukraine was authorised to receive support from the Reserve in June 2026, while Moldova had been included earlier.

So the case for the trilateral alliance is not that NATO or EU mechanisms are missing.

The difference is in how quickly a smaller group can work and how directly it can organise cooperation around a shared regional problem.

Large institutions come with procedures, mandates and overlapping responsibilities. Research on the EU cybersecurity framework has repeatedly pointed to fragmentation, uneven implementation and coordination problems. More recent work also describes growing institutional complexity even as European capabilities expand. Those problems do not make larger structures ineffective, but they can make them slower and harder to navigate.

Joroveanu sees space here for a smaller arrangement. Romania can work directly with Ukrainian and Moldovan institutions instead of having every initiative shaped first by the procedures and membership architecture of a larger organisation.

That matters because the three countries do not sit in the same institutional position. Romania belongs to both NATO and the EU. Ukraine and Moldova do not, even though both are increasingly involved in European cybersecurity mechanisms.

In Joroveanu's assessment, the alliance can therefore work in two directions at once. Romania can develop its own cyber capabilities more quickly, while helping its neighbours strengthen their resilience through direct regional cooperation. It can also use Ukrainian experience to train personnel and improve practices that Romania would otherwise encounter mainly through exercises rather than repeated exposure to real attacks.

The learning has already started.

The Resilient Trident exercise in Bucharest brought specialists from Romania, Ukraine and Moldova together for practical scenarios in April. Ukrainian officials said the exercise was meant to improve coordinated responses to cross-border cyber incidents and give the alliance practical substance.

Further training in May used scenarios based on real Ukrainian experience, including digital forensics, incident response and critical-infrastructure protection. Ukrainian and Romanian teams also trained together in another exercise later that month.

The alliance's advantage will not be that it replaces NATO or the EU, but that three neighbouring states may be able to learn and react together before a larger mechanism needs to move.

Ukraine brings experience the others cannot reproduce

Ukraine enters the partnership with an experience neither Romania nor Moldova would want to acquire in the same way.

Its cyber infrastructure has been under sustained pressure throughout the full-scale war. CERT-UA reported an average of roughly 15 cyber incidents a day in 2025 and identified Russia as the main source of attacks. Ukrainian authorities recorded almost 6,000 cyberattacks that year, targeting critical infrastructure, government systems and the military.

The character of those attacks has also changed.

A 2025 assessment by Ukraine's State Service of Special Communications found that Russian-linked operations had moved away from the early emphasis on large destructive attacks and increasingly focused on espionage, intelligence collection and information operations. The overall number of recorded cyber incidents still continued to rise.

For the alliance, that experience is useful well beyond technical training.

Joroveanu expects the trilateral format to be most valuable in early warning and responses to coordinated hybrid campaigns. His reasoning is fairly straightforward: if the three cyber authorities communicate quickly and follow the same threat environment, information from an attack in one country may help the other two prepare before the same technique is used against them.

Ukraine is the obvious place for many of those warning signals to appear first.

If Romanian and Moldovan institutions receive information about recent intrusions into Ukrainian networks, they may be able to identify techniques, sectors or types of infrastructure likely to be targeted next. Joroveanu sees particular value for Romania and Moldova in learning from attack patterns already observed in Ukraine instead of waiting to encounter the same methods independently.

Moldova brings a different kind of experience.

Russian pressure there has not been limited to technical cyber operations. Studies of Moldova's security environment describe political influence, economic pressure, energy dependency, propaganda and disinformation as parts of a wider hybrid strategy.

That gives the alliance three fairly different starting points. Ukraine brings intensive wartime cyber experience. Moldova has long dealt with hybrid interference. Romania brings EU and NATO membership, stronger institutional capacity and access to much larger cyber ecosystems.

The value may come from how those different strengths fit together.

Exercises are only the beginning

The Cyber Alliance is already more than the memorandum that created it.

Resilient Trident gave the three national systems a practical setting in which to work together. Romanian, Ukrainian and Moldovan institutions have also held consultations on priorities, trained specialists together and discussed mechanisms for dealing with large-scale cyber incidents. Some of that cooperation began before the alliance itself, with joint crisis-response exercises already taking place in 2025.

Still, an exercise has a beginning and an end. An operational mechanism has to work between exercises too.

That is where Joroveanu places the real threshold.

The first sign would be deeper integration of the three countries' cyber capabilities. In practical terms, that could mean standing structures able to assist during serious incidents, somewhat similar in function, though not necessarily in scale or design, to NATO's Virtual Cyber Incident Support Capability.

The second would be a clearer common policy framework.

NATO's 2021 Comprehensive Cyber Defence Policy gives political, military and technical cooperation a shared direction and ties cyber defence to the Alliance's wider deterrence and defence posture. Joroveanu argues that the trilateral alliance will eventually need its own clearer statement of objectives, responsibilities and mechanisms if cooperation is to become predictable rather than depend on individual initiatives.

That does not mean copying NATO.

A Romania-Ukraine-Moldova mechanism would be much smaller and would have to work across three different legal, institutional and alliance relationships. But the practical questions are similar.

Who calls whom first when one country detects a serious attack? What information can be shared immediately? Can specialists or technical assistance move quickly enough to make a difference? And can an attack on one country change the defensive posture of the other two before they are targeted themselves?

Those answers will show whether the alliance is becoming operational.

Romania's current push to increase activity under the format suggests that this phase is beginning. The three countries have already shown they can exercise together. Ukraine has experience worth transferring, Moldova has a clear need for resilience against hybrid pressure, and Romania can connect regional cooperation with larger Euro-Atlantic structures.

The next stage is less visible than an exercise or a new memorandum.

It will be found in permanent channels, common procedures and faster mobilisation around shared threat information. If those appear, the Cyber Alliance could give the three countries something that neither their national systems nor larger organisations provide in quite the same way: a regional layer built around threats they already face together.

If they do not, the alliance may still produce useful exercises and exchanges. But it will remain a cooperation framework rather than the operational security tool its members are now trying to build.

Expert contribution

This analysis draws on a written exchange with Andrei Joroveanu, a graduate in Global Security and Strategy at the Brussels School of Governance and Assistant and Writer at EPIS Thinktank. His assessments are attributed throughout the article.

Share

Share this analysis

Mara Ionescu

Mara Ionescu

Research Contributor

Information resilience, foreign influence narratives, and regional security in Romania, Ukraine, and the Republic of Moldova.

View contributor profile