The cyber threat landscape
CERT Polska's annual report for 2025 shows a scale that is hard to overlook: 658,320 reports and 260,783 registered incidents — 152 per cent more than the year before. That is an average of more than 1,800 reports a day, of which over 700 are classified as incidents.
The composition of those events says more than the headline figure. Computer fraud accounted for 97.1 per cent of all incidents, and phishing alone for 78,391 cases, or 30 per cent of events. The brands most often impersonated were OLX (28,462 cases) and Allegro (22,513). Ransomware was recorded 179 times, against 163 the year before.
The conclusion for a company planning its first steps: the dominant threat is not a sophisticated attack on the infrastructure but fraud exploiting the trust of an employee or a customer.
The second reference point is the statistics of Poland's data protection authority (UODO). In 2025 the authority received 22,435 personal data breach notifications and 12,986 complaints — against 8,056 complaints the year before. It imposed 32 fines totalling roughly PLN 64.4 million.
Read together, these two sources give a realistic picture of the risk facing a mid-sized company: it is far more likely that trouble will start with a click on a link or a compromised mailbox than with an intrusion through a software flaw. And that it will end on two fronts — the operational and the regulatory.
The three pillars of cybersecurity
Building an effective cybersecurity programme does not require small companies to implement everything at once. Instead, they should focus on three pillars: technology, processes and people.
Enabling MFA reduces the risk of account compromise by as much as 99.9 per cent.
On the technology side, multi-factor authentication (MFA) is a key element of protection. According to Microsoft's data, enabling MFA reduces the risk of account compromise by as much as 99.9 per cent. Endpoint protection, meanwhile — installing modern antivirus software and an endpoint detection and response (EDR) tool — should be a priority for every company, whatever its size.
Processes and monitoring
The second pillar — processes — includes deploying a basic security information and event monitoring capability (SIEM). For small companies this need not be an advanced enterprise product; initial logging and analysis can be handled with open-source tools or managed services. What matters is that the company has visibility of what is happening on its network — which devices are connecting, what data is being transferred, and which anomalies might indicate a breach. The change management process should be clearly defined, particularly where it concerns rolling out security updates, which should be tested in a non-production environment before being deployed to production systems.
Engaging employees
The third pillar — people — is notoriously undervalued and yet constitutes the real line of defence. Involving employees in cybersecurity through regular security awareness training reduces the risk of a phishing attack by as much as 45 per cent, according to Kaspersky research. Phishing attacks remain one of the most popular access vectors for cybercriminals — the Verizon Data Breach Investigations Report 2024 indicates that phishing was the entry point in 29 per cent of confirmed data breaches.
Phishing was the entry point in 29 per cent of confirmed data breaches.
Beyond these three pillars, a company should develop and test a cyber incident response plan. The plan should set out the roles and responsibilities of individual team members, procedures for internal and external communication, and the steps to be taken to contain the incident and restore normal operations. Experience shows that companies with a documented incident response plan can reduce their recovery time objective (RTO) by 40 per cent compared with companies that have no such plan.
Awareness is built through a programme, not a one-off presentation — how to design and measure one is covered in our piece on cybersecurity training.
Where to start — seven steps for a small or mid-sized company
The order matters, because the first three steps cost nothing but time and yet cut off most realistic attack scenarios.
Step 1: take stock of what you have. A list of systems, accounts and data — who uses what, where the personal data sits, who holds administrative access. Without it, every subsequent step is guesswork. It is also a formal requirement: GDPR requires a record of processing activities, and ISO 27001 an inventory of assets.
Step 2: switch on multi-factor authentication everywhere you can. Email, banking, cloud systems, the website's admin panel. This is the single change with the best ratio of effect to cost — a stolen password stops being enough for an attacker.
Step 3: tidy up access rights. Accounts of former employees, service accounts with administrator privileges, shared passwords to line-of-business systems. A review of access rights every six months catches more than many a technical audit.
Step 4: backups that somebody has actually tested. A backup from which nobody has ever restored data is an assumption, not a control. At least one copy should be isolated from the production network — the only effective answer to ransomware.
Step 5: updates as a process, not a burst of effort. A set rhythm for updating systems and applications, with a named owner and a record of what was updated and when.
Step 6: training on recognising fraud. Given that 97 per cent of incidents are fraud, that is where the greatest return on training lies. Not a lecture on cybersecurity — concrete examples of the messages that reach your industry.
Step 7: a procedure for when an incident happens. Who takes the decisions, who we notify, by when, who talks to clients. A single page that everyone knows is worth more than a hundred-page policy in a drawer.
How long you have to report an incident
This question catches companies out more often than any other, because the deadlines run in parallel under two regimes and start from different moments.
GDPR: notification of a personal data breach to the President of UODO within 72 hours of becoming aware of the breach (Article 33). Where the breach is likely to result in a high risk to the rights and freedoms of individuals, those individuals must additionally be notified without undue delay (Article 34).
The KSC Act: essential and important entities report a significant incident in three stages — an early warning within 24 hours, the incident notification within 72 hours, and the final report within one month.
These deadlines do not substitute for one another. A company subject to both regimes that suffers a leak of personal data as a result of a security incident discharges both obligations in parallel — to two different authorities, in different formats.
The practical consequence is simple: 24 hours is not enough time to work out who decides whether to report. That has to be settled in advance.
The most common mistakes at the outset
Years of working with companies starting to get their security in order reveal the same few patterns.
Buying a tool instead of understanding the problem. The company buys an EDR product or a password management system before establishing where its data actually is and who has access to it. The tool starts working, but it protects a portion of a picture nobody has drawn the outline of.
A security policy written for the auditor. A document nobody in the organisation has read, describing processes that do not exist in the company. At the first incident it turns out to be useless, and at an inspection it becomes incriminating, because it exposes the gap between what was declared and what is done.
Security entrusted to one person with no mandate. An IT specialist responsible for everything from printers to cybersecurity cannot at the same time enforce the rules on the board. Without formal authority and direct access to senior management, the role is a fiction.
No separation of administrative and ordinary accounts. The same person works on an account with domain administrator privileges, reads email on it and browses the internet. One click is enough to hand an attacker the highest privileges on the network.
Backups on the same network as production data. Ransomware encrypts network shares along with the backups. If the backup is reachable from the same account the user works on, it is not a backup.
Treating compliance as the goal. GDPR, KRI and ISO 27001 are frames of reference, not ends in themselves. A company that is formally compliant but has no working incident response passes the exam and loses the match.
How to talk to the board about this
Technical arguments rarely convince the people who make budget decisions. Three framings work better.
Business continuity. Not "we have a vulnerability in system X", but "in a scenario where the file server is encrypted, we are back at work after so many hours, and for that period we are not invoicing". Boards understand downtime.
Personal liability. Following the amendment to the KSC Act, responsibility for cybersecurity rests with the management body, and a penalty can fall on the head of the entity personally. That changes the nature of the conversation.
Customer requirements. More and more procurement processes and framework agreements contain security requirements — from security questionnaires to a requirement for certification. Security ceases to be a cost and becomes a condition of market access.
Regulatory requirements
In Poland, in addition, every company should be aware of the GDPR requirements, particularly Article 33, which obliges organisations to notify UODO within 72 hours of becoming aware of a personal data security breach. The NIS2 provisions, which take effect in Poland in the second half of 2025, impose additional requirements on so-called essential and important entities — these also cover more rigorous requirements on cyber risk management and incident reporting.
Deciding to work with a cybersecurity specialist — such as a consultancy offering comprehensive support in operational security — allows a company to have an information security audit carried out. That audit identifies gaps in the current state of security, assesses the threats and recommends remedial action tailored to the company's specific circumstances and capacity. For a company in 2025, investing in cybersecurity is no longer a luxury — it is a business necessity.
The starting point for assessing where you actually stand is an IT security audit — only that will show which of these requirements are met on paper alone.


