Sixty kilometres from the Ukrainian border, on Monday 6 July 2026, Bank Gospodarstwa Krajowego (BGK), Poland's state development bank, announced the opening of applications to the lending arm of the Security and Defence Fund (Fundusz Bezpieczeństwa i Obronności, FBiO). The location was not chosen by accident.
Professor Marta Postuła, BGK's first vice-president, launched the programme in Rzeszów, and Teresa Kubas-Hul, the government's representative in the Podkarpackie region (the voivode), recalled that last year her region used almost the entire sum of more than PLN 278m from the Civil Protection and Civil Defence Programme, and that this year it has close to PLN 300m at its disposal, most of it already contracted. Podkarpacie knows how to spend money on security, because for four years it has done little else.
Three days later, on 9 July, at a conference held at the Bielany district office in Warsaw, deputy prime minister and minister for digitisation Krzysztof Gawkowski gave a figure that ought to interest every rural municipality head, every mayor and every municipal company chief executive in Poland: more than PLN 3bn from the Fund could go towards building the digital resilience of local government.
Postuła added a still more interesting detail — the bank has already received several applications, and two of them, filed by a local government unit, concern cybersecurity. Two. In a country where ransomware paralysed four municipal offices in the first half of 2026, and where the deadline for entry in the register of essential and important entities falls on 3 October.
What exactly BGK has launched
The Security and Defence Fund is an instrument worth some PLN 23bn in total, financed from Poland's National Recovery and Resilience Plan (KPO). BGK's chief executive Mirosław Czekaj and the minister of finance and the economy, Andrzej Domański, presented it as one of the largest investment programmes financed from the recovery plan, and Postuła stressed that it is the first mechanism in Europe to redirect recovery money into investments tied directly to national security.
That remark is not merely boasting — it means the instrument was built under time pressure and under the supervision of the European Commission, which translates into rigid conditions, as we shall see in a moment.
The Fund divides into two components. The lending arm, operated by BGK, accounts for around 70 per cent of the money — roughly PLN 16bn. The remaining 30 per cent, about PLN 7bn, forms an equity component run by Chrobry S.A., a company established specifically for the purpose, which will take stakes in undertakings with high growth potential.
Its vice-president Jan Banasiński has announced two portfolios: PLN 500m for early-stage projects and PLN 6.5bn for mature and infrastructure investments, with a declared interest in communications technologies, dual-use and cybersecurity. For local government, however, it is the first component that matters.
Within the lending arm, the largest pool — PLN 11.2bn — has been earmarked for the municipal sector, of which PLN 5.6bn was made available in the first call. The rail sector received PLN 2bn, and undertakings outside those two groups PLN 2.5bn. The municipal call is open to local government units at every level, from the commune to the region, and to companies in which a local authority holds more than half of the shares.
The catalogue of eligible purposes covers the construction and modernisation of collective shelters, threat detection and public warning systems, transport infrastructure supporting military mobility, dual-use rolling stock and — listed expressly, on the same footing as the rest — cybersecurity projects.
The financial terms are unprecedented. Local government units pay 0 per cent interest; municipal companies a fixed rate of 1 per cent. Amounts range from PLN 2m to PLN 500m, the repayment period runs to twenty years, there is a grace period of up to a year from project completion, and there are no handling fees and no own-contribution requirement. Applications go through BGK's regional branches, and the call is open and continuous — running until the allocation is exhausted or the call suspended.
Gawkowski summed it up in a sentence that sounds like an invitation in a minister's mouth and like a warning in a treasurer's ear: this money can be drawn on quickly, without complicated formalities and without any required own contribution.
Three conditions that decide everything
Postuła articulated the first of them in Rzeszów without mincing words: the fund finances new projects only, and there is no question of refinancing investments already under way. For a local authority that started an implementation in 2025 under the Cyber-secure Local Government programme, is halfway through it today and is looking for money to finish, that piece of information closes the subject.
For an authority that has not yet started anything, it is paradoxically good news — but only if it can describe its undertaking as a coherent, new whole rather than as patching up what was left over from the previous programme.
The second condition concerns the write-off, around which a good deal of misunderstanding has already grown up. A write-off of up to 20 per cent of the loan principal for digitisation and cybersecurity services is not available to everyone. It is reserved for units whose income indicators fall below the national average — on BGK's estimate, around 65 per cent of communes and most cities with county status and regions. For investments in the East Shield (Tarcza Wschód) area, the write-off may reach 40 per cent.
The mechanism matters here: a unit that qualifies for the write-off knows it at the moment it signs the agreement — it is aware from the outset that it will repay 80 per cent of the principal. That eliminates the worst-case scenario, in which a unit plans its budget counting on a write-off it will not get.
The third condition is written not in the programme rules but in the Public Finance Act. A loan is not a grant. Zero interest and a twenty-year repayment period make it an exceptionally cheap instrument, but it remains a liability that has to be disclosed, serviced and accommodated within the individual debt ratio under article 243 of the Act of 27 August 2009 on public finance — unless a specific provision states otherwise.
This is the first question in the whole matter that should reach the treasurer rather than the IT specialist, and it is best asked before the commune invests three weeks of work in preparing documentation. Experience with earlier repayable instruments teaches that the answer "we'll check that at the contract stage" tends to be the most expensive sentence in the entire process.
The clock that ticks louder than the call
The call is open and continuous, so it is easy to fall into the illusion that there is plenty of time. There is not — except that the pressure comes not from BGK but from the Polish NIS-2 implementing act (the KSC Act). The amended act, which transposes the NIS-2 Directive, has been in force since 3 April 2026. The self-registration window in the register of essential and important entities, kept in the system available at wykaz-ksc.gov.pl, opened on 7 May and closes on 3 October 2026.
Some entities — public bodies, telecommunications undertakings, digital service providers and former operators of essential services — were entered ex officio by the minister for digitisation by 6 May, but most municipal companies have to do it themselves, after conducting their own analysis of sector and size thresholds.
The consequences of inaction are quantifiable. An essential entity faces a fine of up to EUR 10 million or 2 per cent of total worldwide annual turnover; an important entity up to EUR 7 million or 1.4 per cent. The act also provides for a separate, personal financial penalty for the head of the entity, reaching six times their remuneration calculated on the basis used for holiday pay equivalents.
Part of the sanctions regime is covered by a transition period, and it is worth verifying that against your own situation rather than taking on trust one interpretation or another heard at an industry conference. The direction of the construction, however, is unambiguous: liability has ceased to be purely institutional.
We described that mechanism in detail in connection with the ransomware attack on the Nowa Ruda town hall (in Polish), where for the first time it became something more than an academic curiosity for Polish local government officials.
And here the arithmetic appears that the press releases do not show. From today to 3 October there are roughly two months left. Preparing a loan application, running a procurement procedure, signing contracts with suppliers and starting an implementation is, in the realities of a public finance sector body, a process counted in quarters, not weeks.
The FBiO money will not build resilience before the registration deadline — and it does not have to, because entry in the register is an information obligation, not a certificate of maturity. But anyone planning to use the call as a way of catching up with the act should understand that what they are buying is at most a year, and then only if they start from the right end.
Why fourteen water utilities gave the money back
Before anyone concludes that the problem of Poland's municipal sector can be solved by a bank transfer, it is worth recalling a story from a month ago. On 15 May 2026 the Digital Poland Projects Centre (CPPC) updated the ranking list for the Cyber-secure Water Utilities programme. It turned out that fourteen entities, despite their applications having been assessed positively, did not sign a funding agreement and between them returned more than PLN 12.6m out of a pool of PLN 627m.
Not because they did not need the protection — between 2024 and 2025 the water and sewerage sector was the most frequent target of pro-Russian hacktivist groups in Poland. They gave the money back because they did not fit within the de minimis aid ceiling, because VAT was excluded from eligible costs and a small commune had nothing to cover it from, and because the delivery deadline was so short that an administration of a few staff could not have run the procurements in time.
We described the whole story, together with the responses of the individual utilities, in our analysis of the withdrawals from the Cyber-secure Water Utilities grant programme (in Polish).
The lesson from that episode is brutally simple, and it maps onto FBiO one for one: the availability of money is not the same thing as the ability to spend it. A programme with excellent terms can bypass precisely those entities it was designed for, if its formal construction collides with the organisational realities of a small body.
Włodzimierz Woźniak summed it up at the time in a sentence that still holds: there are large undertakings, and there is the rest of the world. A large municipal company has a legal department, a budget reserve and a consciously managed grant portfolio. The municipal services company (zakład gospodarki komunalnej) in a commune of four thousand residents has none of those three things — and it is that company which operates the water treatment plant somebody has already tried to shut down remotely.
FBiO has three advantages over Cyber-secure Water Utilities that are worth recording honestly: no required own contribution, a twenty-year repayment period that spreads the cost over time, and an open, continuous call that does not force you to file an application within a month.
It also has one structural weakness — it is a repayable instrument, and taking on a liability requires a resolution of the authority's decision-making body, an opinion from the regional audit chamber (RIO) on the ability to repay, and a place in the multi-year financial forecast. Enthusiasm cannot shorten that process.
The first question is not "what to buy"
The most common mistake we see in local government after every support programme is announced looks the same each time: the unit first asks suppliers what can be bought for the sum available, then tries to fit a justification around it, and writes the risk analysis last, to close off the documentation. That order is the reverse of what the act requires and of what makes economic sense.
Article 8 of the KSC Act obliges essential and important entities to implement an information security management system whose core is the systematic assessment and treatment of risk. That means the scope of the investment is to follow from the risk identified, not the risk from the equipment purchased.
A unit that spends borrowed money on a solution that does not address its real threats commits two errors at once: it fails to build resilience, and it breaches the elementary principle that public expenditure must serve a purpose — a principle an inspection will sooner or later ask about. The illustrated version: an armoured gate mounted in a plasterboard wall is expensive, impressive and completely useless.
A risk analysis done properly takes a few weeks and costs a fraction of the cheapest element of an implementation. It answers questions no product catalogue will ask: which of the services this unit delivers are critical for residents, and how long can they be unavailable before the effect becomes irreversible; where the data physically sits and who has access to it; which suppliers have remote entry into the infrastructure, and on what terms.
And whether there is a backup from which anyone has ever restored the system under test conditions. The answers to those questions build the scope of the application. Without them, the application is a shopping list with a justification written in afterwards.
What the loan cannot buy
An FBiO loan finances investment. Cybersecurity, however, is in large part not an investment but a running cost — and that is the most serious trap in the whole mechanism.
The Fund's money will buy network segmentation, backup systems with an offline copy on the three-two-one model, multi-factor authentication, EDR-class endpoint protection, log collection and correlation systems, the replacement of controllers and the separation of the operational technology environment from the office one. All of it makes sense and all of it is needed. But none of these elements works on its own.
A log collection system with nobody to read the logs is a hard drive recording a break-in that nobody will ever hear about. A backup nobody has restored under test conditions is a declaration, not a safeguard — the Nowa Ruda attack showed how quickly the difference between the two is put to the test.
A procedure for reporting an incident to the relevant CSIRT within 24 hours of detection, and a report within 72, will not work if the person who first sees the encryption message does not know who to call at one in the morning on a Saturday.
Maintenance, monitoring, reviews, training and restore tests are recurring costs that an investment loan will not cover, and that will weigh on the unit's budget for the whole life of the solution — and for most of the twenty-year repayment period.
This leads to a conclusion that sounds less impressive than an announcement about billions, but is the only honest advice: when planning the size of the loan, you have to plan at the same time a line in the operating budget for maintaining what the loan will buy.
If that line is missing, the unit is financing a five-year illusion of security on a twenty-year credit. Economically that is worse than doing nothing, because to the absence of protection you add the servicing of a liability and the false sense that the matter has been dealt with.
A municipal company is not a commune
The terms of the call draw a clear distinction between local government units and municipal companies — the first get 0 per cent, the second 1 per cent at a fixed rate. That difference is not a whim of the bank but a consequence of the fact that a municipal company, even one wholly owned by the commune, remains under EU law an undertaking operating on a market.
Financing on terms better than the market's is potentially State aid, and that means checking under which regime it is being granted and whether it exhausts the ceilings the company already has in play.
This is exactly what defeated fourteen water utilities in the grant programme. The municipal services company in Nowa Sarzyna had around PLN 200,000 of free de minimis headroom for the next three years, because at the end of 2025 it had signed another funding agreement worth more than a million.
MPWiK Warszawa — the capital's water and sewerage utility, a company that can hardly be accused of lacking competence or budget — was able to apply for exactly PLN 735,890, because that was what remained of its ceiling, and it financed the rest from an earmarked reserve of the Warsaw City Security Centre.
The legal construction of FBiO differs from that competition, and conclusions should not be carried across automatically, but the question stays the same and has to be asked before the application is filed, not after the agreement is signed: under which aid regime is this financing granted, and how much room does the company have left in the relevant ceiling?
The second issue is VAT. In the water utilities programme the tax was excluded from eligible costs, which for the Wietrzychowice commune meant finding around PLN 300,000 from its own resources, and for the municipal services company in Mielnik meant withdrawing altogether: as a budgetary unit operating within centralised VAT settlement, it did not obtain the commune office's consent to cover that cost.
The eligibility rules for FBiO have to be checked in the call documentation, but the lesson itself is universal: the structure of tax settlements between a commune and its units can overturn an application that was faultless on the merits. Establishing this takes one meeting between the treasurer and the company's accounts department. Not establishing it has already cost the Polish water and sewerage sector PLN 12.6m.
An application you will not have to hand back
A good loan application for a cybersecurity undertaking differs from a weak one in four respects, and none of them concerns the brand of equipment.
First, it describes the starting position in numbers, not adjectives. Not "outdated infrastructure", but: twenty-three servers, seven of them without vendor support; a single backup taken daily to an array in the same server room; no multi-factor authentication on remote access for four suppliers of line-of-business systems.
Second, it ties every element of the scope to a specific risk from the analysis and to a specific statutory requirement — segmentation as the answer to the risk of encryption spreading from the office network into the operational one, an offline copy as the condition of restoring the service within the assumed time, monitoring as the condition of meeting the incident reporting deadline.
Third, it contains a realistic timetable that allows for the procurement procedure, and a reserve against price increases — PPU Propol of Osiek gave up its grant partly because IT market prices rose above the budget assumed in the application, and the materials were not in the suppliers' warehouses.
Fourth, it identifies who on the unit's side will own the result, and out of what the maintenance will be financed once the project ends.
It is also worth planning from the outset the thing usually added at the end: how the effect will be documented. Both an audit of the use of KPO funds and any inspection activity by the competent authority under the KSC Act will ask not what was bought, but what of it works.
A record of a backup restore test, a report from a segmentation test, a report from an access rights review, a list of alerts handled by the monitoring team — those are evidence. An invoice is evidence of nothing beyond the fact that money left the account.
Two months, two applications and the rest of Poland
Let us go back to the figure we started with. Two cybersecurity applications filed by a local government unit in the first week of the call, against an allocation of PLN 11.2bn for the municipal sector and more than PLN 3bn which, on the digitisation minister's own account, could go towards digital resilience.
That disproportion does not come from an absence of need — the first half of 2026 brought ransomware attacks on the town halls in Obrazów, Myszków, Lewin Kłodzki and Nowa Ruda, and earlier years brought a series of incidents at water treatment plants and sewage works.
It comes from the fact that between the availability of money and the ability to use it stand several weeks of analytical work, for which the typical commune has neither a spare post nor the habit.
The situation does, however, have one feature the earlier programmes lacked, and it is worth exploiting. The call is open and continuous. That means a unit which begins with a risk analysis now, in August, will file a sensible application in the autumn — and still has a chance of the money, provided the allocation is not exhausted first.
The advantage therefore belongs not to the fastest but to those who know what they are applying for. In grant programmes with short deadlines, reflexes were rewarded. Here preparation is rewarded — and that is the change Poland's municipal sector has been waiting years for, even if it does not yet know it.
Why Fib.Code for an FBiO application
Fib.Code combines three competences that have to come together in this process, and which on the market usually come apart. We know the requirements of the KSC Act and of ISO/IEC 27001 from the auditor's side, so we can translate a legal obligation into a concrete, defensible project scope.
We know the realities of local government and municipal infrastructure — OT networks in water utilities and district heating plants, line-of-business systems in town halls, suppliers' remote entry points — so our risk analysis does not stop at the office network. And we know the language of project documentation, so the result of the analysis can be carried straight into the application, the description of the subject matter of the contract and the timetable, instead of being translated a second time in another room.
We work to three principles we do not negotiate. We start from risk, not from a catalogue — we do not sell equipment and we have no interest in a scope larger than the threats warrant. We write documents that survive inspection, because they are written for evidence rather than for length.
And we say plainly when we believe a planned expenditure will not increase security, even if it falls within the eligibility catalogue — because a twenty-year loan taken out for something that does not work is worse than not taking it out at all.
The end product is a complete set you can take to the bank and to the authority's decision-making body: a risk analysis together with a treatment plan, a project scope tied to risks and to legal provisions, the substantive justification for the application, a timetable that accounts for procurement procedures, and an estimate of maintenance costs for the years ahead.
On top of that, if the unit needs it, support with self-identification and entry in the register before 3 October — because these two processes are best run in parallel, drawing on the same analysis.
What to do in the first week of August
One meeting, four people, ninety minutes: the head of the commune or the company's chief executive, the treasurer or chief accountant, the person responsible for IT, and the information security officer if one has been appointed. The agenda consists of five questions, and you have to leave the meeting either with an answer to each or with the name of the person who will bring it by the end of the week.
Are we already entered in the register of essential or important entities, and if not — who will carry out the self-identification before 3 October, and by when? Do we have a current risk analysis meeting the requirements of article 8 of the KSC Act, or only a document from years ago signed for the purposes of a different audit?
Does the loan liability fit within our debt ratio, and what resolution and what opinion from the regional audit chamber (RIO) will it require? Under which aid regime will we receive this financing, if the applicant is a company, and how much room is left in our ceiling? And finally: out of what will we finance the upkeep of what we buy, in 2028 and 2029 — and is that line already in the multi-year financial forecast?
If any of those questions has no answer, the loan application is premature. If all five have answers, preparing a complete set of documentation will take four to six weeks and will be ready before the autumn.
Book a free consultation: l.grabowski@fibcode.com | fibcode.com/en/contact. Directly related material: why 14 water utilities gave back PLN 12.6m for cybersecurity (in Polish), self-identification and entry in the register before 3 October and what the KSC amendment changed after 3 April — money, obligation and deadline are three sides of the same sheet of paper in this matter.


