# Poland cybersecurity capacity building

> Live situation record from CLSTR: https://clstr.news/situations/poland-cybersecurity-capacity-building
> Updated: 2026-08-07T21:08:34.000Z. Sources: 10. Developments: 3.

In late July 2026, Poland announced that its Technical Supervision Office will launch a sector‑specific Computer Security Incident Response Team (CSIRT) on 3 October 2027. The new CSIRT will serve about 38,000 entities across public and private sectors, offering threat identification, incident handling, monitoring, warnings and coordination with other national CSIRTs. At the same time, local authorities began publishing public guidance on common cyber threats and basic protective measures.

A few weeks later, in early August 2026, the Ministry of Digitisation secured 230 million zł from the EU’s Digital Development Fund to create a Joint Cybersecurity Operational Centre (PCOC). The centre will bring together national CSIRTs, special services and other cyber‑security bodies to improve information sharing, threat analysis and rapid response. Additional funding of 30 million zł will support satellite‑signal services for the Main Office of Geodesy and Cartography. Both initiatives are part of a broader effort to strengthen Poland’s digital resilience and align with EU cyber‑security programmes.

On 7 August 2026, security researchers Robert Kruczek and Kamil Szczurowski presented findings at the Def Con conference regarding significant vulnerabilities in Poland's public internet infrastructure. The researchers reported that approximately 250,000 websites belonging to over 10,000 public entities, including hospitals, airports, and government offices, are susceptible to cyberattacks. 

Notably, the researchers found that the websites of approximately 245 courts—nearly two-thirds of the judiciary—were exposed. These vulnerabilities were attributed largely to the use of obsolete software, such as the Pad CMS platform, which allows unauthorized access to over 300 official websites without a password due to its "end of life" status. The researchers cited a lack of vendor updates and bug bounty programs as contributing factors to these systemic risks.

## Timeline

### 2026-08-07: Poland's public infrastructure faces massive cyber vulnerabilities

Researchers discovered that 250,000 Polish public websites, including hospitals, airports, and 245 courts, are vulnerable to cyberattacks due to obsolete software and critical security flaws.

8 sources. https://clstr.news/cluster/polands-courts-hospitals-and-airports-face-critical-web-security-flaws

### 2026-08-03: Poland's Ministry of Digitisation funds 230 million zł Cybersecurity Operational Center

Poland's Ministry of Digitisation will use 230 million zł EU funding to launch the Joint Cybersecurity Operational Centre, supporting 30,000 entities with advanced threat‑analysis tools.

2 sources. https://clstr.news/cluster/polands-ministry-of-digitisation-funds-230-million-z-cybersecurity-operational-center

### 2026-07-22: Poland launches sectoral CSIRT and issues new cyber‑security guidance for residents

Poland’s Technical Supervision Office will create a sectoral CSIRT from Oct 2027 to aid thousands of firms, while local authorities issue public guidance on common cyber threats.

6 sources. https://clstr.news/cluster/poland-launches-sectoral-csirt-and-issues-new-cybersecurity-guidance-for-residents

---
Cite as: Poland cybersecurity capacity building. CLSTR, https://clstr.news/situations/poland-cybersecurity-capacity-building
