ATAILA Newsroom · Budapest · 2026-08-28
Ninety percent passed the audit. Ten percent could prove it.
Hungary's first mandatory cybersecurity audit round is complete. According to SZTFH figures reported by Telex, 2,194 organisations finished the audit by the extended 30 June deadline, close to 90% met the requirements — and only 10% earned the top rating, “met with negligible risk”. Both numbers are worth reading carefully, and the second one is the interesting one.
The article we are responding to
„A hazai cégek 90 százaléka átment az első kiberbiztonsági auditon”
telex.hu · 2026-08-26
What the numbers actually say
One clarification the headline invites and the body text corrects: this is 90% of those who completed the audit, not 90% of Hungarian companies. The in-scope population is larger — SZTFH has put it above 2,500 — and a significant number never fulfilled the registration obligation at all and had to be called on by the authority. The 90% is a pass rate among the compliant, not a portrait of the country. Fines for failing to register or to have the audit carried out reach HUF 150 million.
Credit where it is due: a first mandatory round that pulls more than two thousand organisations through a real audit is a genuine result, and the sector deserves it. Our interest is in the gap the same dataset exposes.
The distance between passing and proving
Nine in ten met the requirements. One in ten was found to carry negligible risk. That is not a contradiction, and it is not a scandal. It is the ordinary distance between having controls and being able to demonstrate them.
The single systemic weakness named in the results makes the point better than we could: organisations had prioritised solutions for remote access to company systems, but the documentation of those systems was frequently inadequate. Not the controls. The documentation of the controls.
Anyone who has been through an audit knows why. Documentation written for the audit is accurate on the day it is written and starts decaying the following Monday, because the estate keeps changing and the document does not. Two years later somebody rewrites it from memory. That cycle is our best explanation for the distance between the two numbers — our reading, not an SZTFH finding.
What we do instead, and why it is not a clever trick
Our estate is built from code — the same Terraform and Ansible that creates a network, a database or a GPU node is the record of what exists. Access goes through one identity system, so “who can reach this remotely” is a query rather than a recollection. Changes reach production through a gated pipeline that logs who promoted what and when.
None of that is clever. It is simply the ordinary way to run infrastructure when you operate it yourself rather than assembling it once and hoping. The audit benefit is a side effect, and we should be honest about its size. Drift still happens — somebody always fixes something by hand at two in the morning. What changes is where it surfaces: as a difference against the code the next time the pipeline runs, rather than as a surprise two years later. Reconciling it becomes a change request instead of an archaeology project.
Controls you can describe are compliance. Controls the system can prove on its own are operations. The two-year cycle only punishes the first kind.
The part nobody audited in June
This next bit is our argument, not a finding in the report — we flag that plainly, because the report does not say it.
Almost none of those 2,194 organisations had an AI estate in scope in June. In two years, many will: a model store, GPU nodes, an inference gateway, prompt and output logs, an agent with credentials of its own. That surface asks every question NIS2 already asks, plus several it does not have vocabulary for yet. Which model version answered that query. Who could reach the inference endpoint. Where the weights came from and whether that source still exists. Whether a human ever reviewed an automated decision, and whether that review was recorded.
If the documentation of remote access was the weak point in 2026, the documentation of AI systems is a fair candidate for 2028 — and it is much easier to build a system that answers those questions by itself than to reconstruct the answers under audit.
The question worth asking internally
Not “did we pass?” but: if the auditor came back unannounced next Tuesday, how much of the answer would the systems produce, and how much would a person have to write? The ratio between those two is the honest score, and it is the one that will still be true in 2028.
Source: A hazai cégek 90 százaléka átment az első kiberbiztonsági auditon — telex.hu, 2026-08-26
← Back to the Newsroom Press inquiries: contact us