Polish companies are increasingly developing structures and procedures related to data protection, yet their subjective sense of resilience to threats is declining. According to KPMG’s “Digital Business Transformation Monitor 2025” and “Cybersecurity Barometer”, 56% of companies already have dedicated cybersecurity departments, but only 40% of leaders believe their organizations are sufficiently protected. Large enterprises most often experience intensified attempts of cyberattacks.
October – observed as European Cybersecurity Month – provides a timely opportunity to examine the condition of Polish businesses in this area.
Cybersecurity Index Rising, Confidence Falling
The cybersecurity and risk index in this year’s Digital Business Transformation Monitor reached 5.9 points – one point higher than in the previous edition. In 2025, 56% of companies declared having a dedicated cybersecurity department, up 16 percentage points year-on-year. At the same time, fewer organizations reported having formalized security management procedures – down 13 p.p. to 59%. The financial sector remains the most prepared, with 82% of companies having procedures and 73% with dedicated structures.
Companies are declaring larger investments: the share of businesses planning a significant increase in cybersecurity spending in the next 12 months rose by 20 p.p. year-on-year. Nevertheless, only 40% of leaders believe their organizations are adequately protected – a 17 p.p. drop compared to last year.
The scale and complexity of cyberthreats are growing faster than companies’ digital competencies. Although the cybersecurity index improved, organizational maturity remains incomplete. Only 59% of companies have formalized security management procedures, despite the rising number of incidents, increasingly sophisticated attacks, regulatory pressure, and greater awareness among business leaders.
– Cybersecurity is no longer just the domain of IT departments. It has become a strategic discipline that must be embedded in organizational culture, investment decisions, and everyday processes. The pace of technological change requires flexibility – not only in responding to incidents but also in adapting strategies, integrating security with digital transformation, and raising employee awareness – said Michał Kurek, Partner and Head of Cybersecurity at KPMG in Poland and Central and Eastern Europe.
Attacks, Failures, and New Risks
The 2025 Cybersecurity Barometer report shows that in 2024, only 17% of companies reported no cybersecurity incidents – the lowest level in the study’s history. Large enterprises saw the highest surge in attack attempts: 55% reported an increase or significant increase, compared to 38% of medium-sized firms and 40% of small firms. The most frequently cited threat was malware, particularly data leaks caused by malicious software.
The Digital Business Transformation Monitor also highlights growing concerns over failures of external providers’ systems and internal infrastructure. While cyberattacks were placed at the bottom of the list, 64% of organizations still view them as a threat with at least a moderate impact on digital transformation (28% see them as having a high or very high impact).
About the Reports
The KPMG report “Digital Business Transformation Monitor” was based on a CATI survey conducted in March 2025 among 180 respondents responsible for digitalization in their companies – managers, directors, board members, and CEOs. The sample represented small, medium, and large enterprises across eight sectors: construction & real estate; energy, mining & utilities; life sciences; automotive; consumer goods; financial sector; IT, media & communications; and transport & logistics. Companies with fewer than 10 employees were excluded.
Source: CEO.com.pl





