Rising Number of Cyberattacks in Poland: Time for Radical Legal and Security Reforms

SECURITYRising Number of Cyberattacks in Poland: Time for Radical Legal and Security Reforms
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Eliminating regulatory chaos, accelerating the legislative process in Poland, implementing Zero Trust security architecture, mandatory cybersecurity training for public and private sector employees, and requiring digital solutions to be designed according to the “Secure by Design” principle. These are among the key recommendations published in the Roadmap for Strengthening Poland’s Cyber Resilience, prepared by the Digital Poland Association (Związek Cyfrowa Polska).

The document sets out a package of proposals and recommendations which, if implemented swiftly, could significantly boost Poland’s digital security. Experts warn that Poland remains a prime target of coordinated attacks by hostile states and cybercriminals, while the national response system is still fragmented, reactive, and too slow. Data show that in 2024, Poland was the most frequently attacked country in Europe in the context of Russian disinformation campaigns and cyberattacks. More than 600,000 incidents were reported over 12 months, a year-on-year increase of 29 percent. At the same time, actual readiness to counter these threats—both in the public and private sectors—remains insufficient.

“We must be clear: Poland is a frontline country. Yet in many offices, staff still use public email accounts and sign IT contracts without security clauses. This is a real threat to the state and its citizens,” said Michał Kanownik, President of Digital Poland. “Our response is a concrete roadmap—ready-to-use cybersecurity measures for the government, local administrations, institutions, and companies. Either we act now, or soon we will be paying the price—political, economic, and social.” The roadmap was presented publicly for the first time at the Economic Forum in Karpacz.


What Needs to Change Immediately?

The roadmap emphasizes several urgent measures:

  • Unified cybersecurity regulations: Experts call for harmonization of rules at both EU and national levels. Currently, fragmented interpretation of NIS2, DORA, and CRA directives across member states creates major barriers for companies implementing new technologies. A coherent legal framework would increase predictability, reduce compliance risks, and strengthen infrastructure security across the EU.
  • Faster legislation in Poland: The pace of lawmaking must match the evolving threat landscape. “When cybercriminals update their techniques weekly, we cannot afford a system where legal interpretations take months,” Kanownik stressed. The experts highlight the need to modernize Poland’s National Cybersecurity System (KSC), which dates back to 2018 and no longer reflects today’s geopolitical or technological context.
  • Zero Trust architecture: Digital Poland urges widespread adoption of Zero Trust, which assumes no user or device is inherently trusted, even inside an organization. Continuous identity verification, activity monitoring, and access segmentation are seen as essential against sophisticated external and insider threats.
  • Mandatory training: Employees remain the weakest link in cybersecurity. Digital Poland calls for compulsory training on phishing, social engineering, and password management for civil servants and critical-sector staff.
  • “Secure by Design” standards: Security must be built into systems and devices from the outset. Without regulatory requirements, vendors will continue delivering products with known vulnerabilities, leaving users exposed.

The roadmap also addresses individual users, stressing the importance of securing mobile devices, which are now the primary point of contact with the internet. Recommendations include the use of Mobile Threat Defense, VPNs, MFA, and regular updates. Broad-based public education is also highlighted as the cheapest and most effective way to strengthen digital resilience nationwide.


A Call to Action

The roadmap will now be submitted to Polish policymakers as a foundation for future work on strengthening cyber resilience. Digital Poland has pledged to continue supporting the implementation of its recommendations through legislative initiatives, educational programs, and cooperation with the tech sector and international institutions.

“This document is only the beginning. Poland has the chance to become a leader in digital security in the region—but only if we want it. We are presenting a set of ready-to-use solutions that could bring us closer to that goal,” Kanownik said.

He reminded policymakers that cyber resilience is not a one-off project but a continuous process:

“It requires consistency and cooperation. Only through joint effort by government, business, academia, and citizens can we build a digital Poland that is safe not only today but also a decade from now. I urge decision-makers at all levels: treat this report as a call to action.”


Source: CEO.com.pl

Check out our other content
Related Articles
The Latest Articles