Skip to content
Knowledge base

Cyber threat landscape 2026: a report for Polish companies in the NIS2 era

CERT Poland registered a record 260,783 incidents in 2025 (+152% YoY), and the amendment to the KSC act implementing NIS2 took effect on 3 April 2026. See what really threatens Polish companies and where to start preparing.

Poland is today the most digitally attacked country in the European Union — that is how Polish decision-makers describe their situation, and the data confirms it. CERT Poland registered a record 260,783 incidents in 2025 (a 152% year-on-year increase), and state-aligned actors linked to Russia are increasingly striking critical infrastructure. At the same time, on 3 April 2026 the amendment to the act on the national cybersecurity system (KSC) implementing the NIS2 directive took effect, imposing hard obligations and personal management accountability on tens of thousands of companies.

This report organizes the 2026 cyber threat landscape for Polish companies: it shows the scale in numbers, the three most dangerous attack vectors, the situation in critical infrastructure, and where to realistically begin preparations.

Methodological note. Below we compile data from various sources (CERT Poland/NASK, ENISA, Verizon DBIR, CrowdStrike, Gartner, Check Point, Recorded Future). Some indicators are comparisons of periods or projections rather than established facts — we flag this at the relevant figures. We present attack attributions as they differ between sources.

1. The scale of threats in numbers

Poland

According to the annual report by CERT Poland (NASK), in 2025 the team received 658,320 reports (a 10% YoY increase) and registered 260,783 unique incidents — a 152% increase over the 103,449 incidents in 2024. That is about 700 incidents handled per day.

The threat structure was dominated by:

  • computer fraud — 97% of all events (phishing, investment scams), up 158% YoY;
  • malware — 3,438 incidents (+81% YoY), including 179 ransomware attacks (+21% YoY);
  • vulnerable services — 1,732 incidents.

These figures should be read with context: the head of CERT Poland stressed that the 152% increase stems partly from better detection (proactive discovery of criminal infrastructure), not solely from more attacks — the number of reports themselves rose by 10%. The CERT Warning List blocked about 140 million attempts to access malicious sites in 2025; nearly 250,000 domains were added (+166% YoY).

The drop in serious incidents in the financial sector (by 68%) is attributed by CERT to the implementation of the DORA regulation and the shift of reporting to CSIRT KNF. Incidents at public entities, however, rose by 48%.

Europe

ENISA Threat Landscape 2025 (an analysis of 4,875 incidents from July 2024 to June 2025) indicates that 79.4% of incidents were ideologically motivated (mainly hacktivist DDoS), 13.4% financially, and 7.2% involved cyber espionage. Phishing remains the dominant entry vector (about 60% of cases), and public administration was the most frequent target (38.2% of incidents). Importantly for regulation — 53.7% of the organizations attacked are “essential” entities in the sense of EU law.

The world

The Verizon Data Breach Investigations Report 2025 (an analysis of 22,052 incidents and 12,195 breaches) confirms global trends: ransomware present in 44% of breaches (up 32%), stolen credentials the main entry vector (22%), exploitation of vulnerabilities — 20%. Third-party involvement in breaches doubled from 15% to 30%. The median ransom paid fell to USD 115,000 (from USD 150,000 the year before), and 64% of victims refused to pay. The human element was present in about 60% of breaches.

2. The three most dangerous vectors of 2026

Three vectors that define 2026 emerge from this data.

Ransomware — more dangerous despite fragmentation

The ransomware ecosystem has undergone deep reconfiguration. After Operation Cronos (the takedown of LockBit) and the collapse of RansomHub, Qilin (known as Agenda) and Akira lead the way. Qilin was the most active group of 2025 — it exceeded 1,000 victims on its leak site. According to a joint FBI/CISA advisory, Akira had reportedly obtained an estimated USD 244.17 million by the end of September 2025. Double extortion (stealing data before encryption) has become the standard.

In Poland, CERT recorded 179 ransomware attacks (companies — 129, public institutions — 30, private individuals — 20). The flagship example of the consequences remains the RA World group’s attack on ALAB Laboratoria (November 2023) — the largest leak of medical data in Polish history. More on the mechanism and defense: what ransomware is and how to protect yourself and cyber trends in ransomware.

AI-supported attacks

AI has become a defining element of the threat landscape. According to ENISA, more than 80% of observed social engineering campaigns used AI-generated or AI-enhanced content in early 2025. Deepfakes, voice cloning and AI-generated phishing lower the barrier to entry, and attacks on AI systems themselves (prompt injection, data poisoning) become a separate category. We devote a separate article to this threat: deepfake, vishing and CEO fraud — how to protect your company from AI-powered scams.

Supply chain compromises

Third-party involvement in breaches doubled from 15% to 30%. The loudest case of 2025/2026 was the self-replicating Shai-Hulud worm in the npm ecosystem, and the attack on Collins Aerospace showed the cascading nature of such incidents (paralysis of check-in at European airports). Supply chain security is one of the pillars of NIS2. See: software supply chain attacks and ICT supply chain security and vendor audit under NIS2.

3. Critical infrastructure and OT under pressure

The most serious incident of 2025 was the coordinated attack on Polish energy on 29–30 December 2025 — against at least 30 renewable energy farms and a combined heat and power plant serving about 500,000 customers. The attackers used a wiper (data-destroying software), and the entry vector was a lack of MFA on VPN gateways. Attribution differs between sources: ESET pointed to the Sandworm group (GRU), CERT Poland — to an overlap of infrastructure with the Static Tundra/Berserk Bear cluster (linked to the FSB), without a definitive attribution. We analyze this incident separately: DynoWiper and the attack on Polish energy — wiper versus ransomware.

In parallel, attacks on the water and sewage sector were recorded (including access to SCADA systems via internet-exposed interfaces and weak passwords). According to ENISA, OT threats account for 18.2% of all categories. This underlines why IT/OT segmentation and cutting management interfaces off from the internet are a priority today — see an OT security audit in manufacturing and OT/ICS security: protecting industrial infrastructure.

4. Other significant threats

  • DDoS and pro-Russian hacktivism. The most active hacktivist attacking Poland remains the NoName057(16) group (DDoS against banks, the stock exchange, the transport sector). Globally, Cloudflare blocked 47.1 million DDoS attacks in 2025 (+121% YoY). See: what a DDoS attack is and anti-DDoS protection.
  • Infostealers and session theft. According to Recorded Future/Flashpoint, in 2025 infostealers infected 11.1 million machines and produced 3.3 billion stolen credentials. This is a growing, underestimated vector that bypasses even MFA by stealing cookies and tokens — we describe it in the article infostealers and session theft.
  • APT. CERT Poland recorded an intensification of APT group attacks aimed at Polish institutions, companies and individuals connected with politics, administration and academia. See: what APT attacks are and APT attacks on energy infrastructure.

5. Regulatory context: NIS2 and the amendment to the KSC act

The NIS2 directive (EU 2022/2555) took effect on 16 January 2023; the transposition deadline passed on 17 October 2024. Poland implemented it late: the amendment to the KSC act (the act of 23 January 2026) was published on 2 March 2026 and took effect on 3 April 2026 after a one-month vacatio legis.

  • Scope of entities. The act expands the scope from a few hundred operators of essential services to about 38,000 entities (Ministry of Digital Affairs estimate; other sources cite ~42,000). Entities are divided into essential (usually >250 employees or >EUR 50 million turnover) and important (50–249 employees, EUR 10–50 million turnover). Notably, managed cybersecurity service providers (MSSPs) are subject to the act already from the small-enterprise threshold.
  • Obligations. An information security management system (ISMS), risk management, supply chain security, incident reporting and personal management accountability, including mandatory board training. Reporting a serious incident (the S46 system): early warning within 24h of detection, notification within 72h, a final report within a month.
  • Deadlines. 6 months to register in the entity list (by 3 October 2026), 12 months to implement the ISMS (by 3 April 2027), 24 months for the first audit of an essential entity (by 3 April 2028). Administrative penalties are not to be imposed during the first 2 years (until 3 April 2028).
  • Penalties. Per available analyses: an essential entity — up to EUR 10 million or 2% of revenue, an important entity — up to EUR 7 million or 1.4% of revenue, the entity’s manager — a penalty tied to remuneration. The exact wording and amounts should be verified against the text of the act (Journal of Laws 2026).

We cover this in detail in the articles: the KSC/NIS2 2026 amendment — deadlines and obligations, a KSC/NIS2 readiness audit — a practical guide for CISOs and does my company fall under NIS2/KSC — a self-identification test.

6. Where to start — priorities for 2026

Combining the threat landscape with the regulatory requirements, the order of actions is fairly clear:

  1. Determine whether you fall under KSC/NIS2 — account for all PKD (business activity) codes, not just the predominant activity, and file an application for entry in the list within 6 months. MSSPs — remember the lowered threshold. A KSC/NIS2 readiness audit — a CISO guide will help.
  2. Deploy phishing-resistant MFA on all VPN gateways, edge devices and privileged accounts — the lack of MFA on VPN was the attack vector against Polish energy.
  3. Verify OT/ICS exposure — cut SCADA/HMI management interfaces off from the internet, introduce IT/OT segmentation, check device visibility in search engines such as Shodan.
  4. Onboard the board into its new, personal accountability — conduct mandatory management training and test the reporting process against the 24h deadline.
  5. Deploy immutable, offline backups and regularly test recovery — this is the key defense against ransomware and wipers.
  6. Introduce supplier due diligence (MSP/MSSP/SaaS) and contractual provisions on supply chain security; pin and verify open source dependencies (SBOM, signatures).

Summary

2026 combines two trends that reinforce each other: an unprecedented scale and sophistication of attacks (ransomware, AI, supply chain, wipers in critical infrastructure) and the hard regulatory requirements of NIS2/KSC with personal board accountability. For Polish companies this is not an either-or choice: regulatory compliance and real operational resilience are two sides of the same coin.

The overview above is informational. The interpretation of KSC/NIS2 provisions depends on a company’s profile, and the figures come from various industry reports. If you want to assess whether your organization is subject to the regulation and how to close resilience gaps, the nFlo team will conduct a readiness audit and help set implementation priorities.

Sources and reference materials

  • CERT Poland (NASK) — annual report on the state of cyberspace security of the Republic of Poland 2025
  • ENISA Threat Landscape 2025
  • Verizon Data Breach Investigations Report (DBIR) 2025
  • Check Point Research; CrowdStrike 2025 Global Threat Report; Recorded Future / Flashpoint
  • Act on the national cybersecurity system (amendment) — Journal of Laws 2026

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist