started · updated
Poland expands cyber‑security responsibilities and joins EU reserve
Poland has amended its National Cybersecurity System Act to incorporate the EU NIS2 directive, moving cyber‑security oversight from solely IT departments to the entire organization. Board members and senior management must now understand cyber risks, maintain documentation, train staff, and ensure incident‑response plans are in place.
In parallel, the Polish consortium of DC9 Cyber and Efigo has been selected by ENISA for the EU Cybersecurity Reserve. The companies will be on standby for up to 36 months to provide incident‑response services, ransomware mitigation, pentesting and consulting, strengthening Poland’s ability to handle large‑scale attacks. CERT Polska reported 260,783 unique cyber incidents in 2025—a 152 % rise from the previous year—highlighting the growing need for coordinated response capacity.