Polish companies still tend to underestimate the risk of cyberattacks, even though the scale of the threat is rising rapidly. According to data from CERT Polska, 260,800 cybersecurity incidents were recorded in 2025, while a Mastercard study shows that small businesses in particular still too often regard this risk as limited. According to the survey, one in four small companies and one in two large organizations in Poland has already experienced a cyberattack or digital security breach.
“We conducted a study among Polish entrepreneurs – small, medium-sized, and large – to assess their awareness of cybercrime and the need for protection against cyberattacks. What surprised us was the lack of awareness of the threats,” Małgorzata Domagała, Vice President and Director of Products and Solutions at Mastercard for Poland, the Czech Republic, and Slovakia, told Newseria. “Among small businesses, only 5% are concerned about cyberattacks.”
Last year alone, CERT Polska handled more than 260,000 incidents – 152% more than a year earlier. Despite this, Mastercard’s study shows that 71% of respondents representing small businesses assess the risk of a cyberattack on their company as low or rather low. Only 5% perceive the cyber threat to their organization as very high. Large companies are far less optimistic in this respect – 18% see the risk of an attack as very high or high.
“Awareness of threats is correlated not only with the size of the organization, but also with the company’s experience. Organizations that have already been attacked are more likely to recognize potential risks in the future. In Poland, one-quarter of small firms, 44% of medium-sized firms, and more than 50% of large firms have already experienced such a cyberattack,” Małgorzata Domagała points out.
According to small businesses, the areas seen as most vulnerable to cybercriminal activity are customer data (46%) and financial and accounting data (41%). Medium-sized and large organizations more often point to internal IT systems, databases, employee data, and strategic documents.
“Based on analyses and information from specialized cybersecurity organizations, we see that the most frequently targeted assets are those related to customer data and employee data,” says Mastercard’s Director of Products and Solutions for Poland, the Czech Republic, and Slovakia.
Companies in manufacturing are most often the victims of cybercriminals (49%), followed by trade-related businesses (38%) and e-commerce firms (34%).
“Entrepreneurs underestimate the scale of attacks. There are more threats than they realize, while at the same time companies declare a higher level of readiness and better security than they actually have in reality,” the expert says.
The greatest underestimation of threats concerns the smallest businesses. The study shows that many of them assume cybercriminals focus mainly on large organizations. However, the findings indicate that smaller firms are also frequent targets of attacks, among other things because of their lower level of security and their access to customer or business partner data.
“Cybercrime is now the world’s third-largest economy – its value is USD 10.5 trillion per year. Therefore, if a small company has sufficiently attractive assets, whether in the form of a customer database or its own data, it can be attacked,” Małgorzata Domagała argues.
The most common forms of attack are ransomware and social engineering. In the first case, cybercriminals block access to systems and demand a ransom; in the second, they use manipulation to gain access to data or infrastructure. The scale of this type of threat is also visible in CERT Polska’s data – in 2025 alone, more than 140 million attempts to enter malicious websites were blocked, many of which impersonated banks, courier companies, or public services.
“Sometimes cybercriminals impersonate supervisors and create a sense that ‘something’ must be done immediately and that quick action is necessary. They trigger fear and instinctive reactions in employees, which causes people not to think rationally,” the Mastercard expert explains.
Mastercard’s study shows that the human factor remains one of the key elements of risk. At the same time, the actions companies take after incidents are focused mainly on removing the effects of an attack. Long-term solutions, such as systemic risk management or regular employee education, are implemented less frequently.
Large and medium-sized companies, as well as those that have experienced a cyberattack in the past, are more likely to have an incident response plan in place. Among small businesses, only 18% have such a document. The same applies to employee training – 64% of large organizations train employees in cybersecurity at least once a year, while more than half of small businesses have never conducted this type of training.
“If we consider that manipulation is one of the key elements of attacks, then it is easy to imagine that the main and best solution is employee education. Yet only a small share of attacked companies inform employees about incidents and provide instructions on what should be done and how to protect against such cyberattacks. We see a huge education gap, and in our view, awareness and employee education could go a long way toward supporting the digital resilience of companies,” Małgorzata Domagała emphasizes.





