The “Cybersecure Local Government” program is an initiative supporting local governments in Poland in improving cybersecurity. It offers financial and substantive support for implementing solutions to secure IT infrastructure and training for employees. The project’s goal is to protect sensitive data and local government systems against growing cyber threats while increasing awareness of cyber risks.
What is the National Cybersecurity System?
The National Cybersecurity System (NCS) is a comprehensive solution aimed at ensuring a high level of security in Polish cyberspace. This system was established under the National Cybersecurity System Act, which came into force on August 28, 2018. The NCS integrates the activities of many entities, such as operators of essential services, digital service providers, CSIRT (Computer Security Incident Response Team) teams, cybersecurity authorities, and the single point of contact for cybersecurity matters. All these entities cooperate with each other, exchanging information and coordinating activities to effectively prevent, detect, and respond to cybersecurity incidents.
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
What are the Main Goals of the National Cybersecurity System?
The overarching goal of the National Cybersecurity System is to achieve and maintain a high level of resilience of national IT systems to threats from cyberspace. The system aims to minimize the effects of cybersecurity incidents, thereby ensuring the uninterrupted functioning of key services for society and the economy. Among the specific goals of the NCS are:
-
Ensuring continuity of essential services and digital services.
-
Achieving an appropriate level of security of information systems used to provide essential services and digital services.
-
Effectively preventing cybersecurity incidents and, in the event of their occurrence, responding promptly and minimizing negative effects.
-
Effective coordination of handling reported cybersecurity incidents.
-
Raising awareness and competencies in cybersecurity among all system participants.
Who Makes Up the National Cybersecurity System?
The National Cybersecurity System comprises many different entities whose cooperation and commitment are crucial for the effective operation of the entire system. The main elements of the NCS are:
-
Operators of essential services - entities providing services of key importance for maintaining critical social or economic activity, such as energy supply, transport, healthcare, water supply, or digital infrastructure.
-
Digital service providers - entities providing cloud computing services, internet search engines, and e-commerce platforms.
-
National-level CSIRT teams - CSIRT GOV, CSIRT NASK, and CSIRT MON, responsible for handling cybersecurity incidents in various areas.
-
Sectoral cybersecurity teams - dedicated teams operating in individual economic sectors, supporting operators of essential services.
-
Entities providing cybersecurity services - companies offering services such as security audits, penetration tests, or incident response.
-
Cybersecurity authorities - ministers heading government administration departments, the Head of the Internal Security Agency, the Director of the Government Security Center, and other bodies responsible for cybersecurity in their areas.
-
Single point of contact - the body responsible for cooperation with other EU Member States and European-level CSIRTs.
How Does Cooperation Between Entities Within the System Work?
Cooperation between entities of the National Cybersecurity System is based on several key principles and mechanisms. First of all, entities are obliged to exchange information about cybersecurity threats, vulnerabilities, and incidents. This exchange takes place through the S46 platform, which is used for reporting and analyzing incidents and sharing knowledge about threats.
CSIRT teams at the national level play a key role in coordinating activities. They cooperate both among themselves and with operators of essential services, digital service providers, and public administration bodies. CSIRTs exchange information about threats and vulnerabilities and coordinate the handling of reported incidents. They also provide support to NCS entities in responding to incidents and implementing preventive measures.
Cybersecurity authorities supervise the functioning of the NCS in their areas of responsibility. They cooperate with CSIRT teams, providing them with information about identified threats and incidents and coordinating activities in case of serious incidents.
The single point of contact serves as a liaison for cooperation with the European Union and other Member States. It is responsible for transmitting information about serious cross-border incidents and coordinating activities with foreign partners.
How are Cybersecurity Threats Identified?
Identification of cybersecurity threats within the NCS occurs at many levels and using various sources of information. CSIRT teams monitor threats and vulnerabilities nationwide, analyzing data from IT systems, incident reports, information exchange with domestic and foreign partners, and intelligence sources.
Operators of essential services and digital service providers are required to implement information security management systems and monitor threats in their systems. They must identify vulnerabilities, assess risks, and implement adequate security measures. Information about identified threats and incidents is forwarded to the appropriate CSIRT teams.
An important element of threat identification is information exchange within the NCS. CSIRT teams, relevant authorities, and other system entities share knowledge about new threats, malware campaigns, vulnerabilities, and indicators of compromise (IoC). This exchange takes place through the S46 platform and direct communication channels.
International cooperation also plays an important role, particularly within the CSIRT and FIRST (Forum of Incident Response and Security Teams) networks. It allows for early identification of global threats, such as new ransomware campaigns or attacks targeted at specific sectors.
What Does the Incident Reporting and Handling Process Look Like?
The process of reporting and handling cybersecurity incidents within the NCS is regulated by the provisions of the National Cybersecurity System Act. According to these provisions, operators of essential services and digital service providers are required to report serious incidents to the appropriate national-level CSIRT team within 24 hours of their detection.
Incident reports are received by CSIRTs via a dedicated website, email, and a 24-hour telephone hotline. The report must contain information about the nature of the incident, its effects, actions taken, and contact details of the reporting party.
Upon receiving a report, the CSIRT team performs an initial analysis and classification of the incident in terms of its criticality and potential effects. It then takes actions appropriate to the threat level, such as:
-
Incident handling coordination - CSIRT cooperates with the reporting entity and other involved parties to effectively respond to the incident.
-
Technical support - the CSIRT team can provide support in incident analysis, cause identification, effect removal, and system security restoration.
-
Information exchange - CSIRT transmits incident information to other CSIRT teams, relevant authorities, and foreign partners if the incident is cross-border.
-
Communication - the CSIRT team maintains constant contact with the reporting entity, providing information about the incident handling status and actions taken.
In case of high-criticality incidents that may have serious consequences for state security or critical infrastructure operation, crisis response procedures are triggered. The Government Crisis Management Team and the minister responsible for informatization then play a leading role. The priority becomes minimizing incident effects, restoring system continuity, and identifying and eliminating incident causes.
What Role Do National-Level CSIRT Teams Play?
CSIRT (Computer Security Incident Response Team) teams at the national level play a key role in ensuring Poland’s cybersecurity. They are responsible for handling cybersecurity incidents, coordinating activities in this area, and cooperating with domestic and foreign entities.
Three national-level CSIRT teams operate in Poland:
-
CSIRT GOV - operating at the government administration level, handling incidents in public administration IT systems.
-
CSIRT NASK - run by the Research and Academic Computer Network, handling incidents in the private sector and in the digital services area.
-
CSIRT MON - operating in the state defense area, handling incidents in the Polish Armed Forces IT systems.
The main tasks of CSIRT teams include:
-
Monitoring cybersecurity threats and identifying vulnerabilities in IT systems.
-
Receiving and handling cybersecurity incident reports from operators of essential services, digital service providers, and other entities.
-
Analysis and classification of incidents in terms of their criticality and potential effects.
-
Coordination of incident handling activities, including cooperation with reporting entities, relevant authorities, and other CSIRT teams.
-
Technical support in responding to incidents, removing their effects, and restoring system security.
-
Publishing warnings and communications about identified threats and cybersecurity recommendations.
-
Conducting preventive and educational activities aimed at raising awareness and competencies in cybersecurity.
-
Cooperation with other CSIRT teams domestically and abroad, including exchange of information about threats and incidents.
CSIRT teams work closely together, ensuring a coherent and comprehensive cybersecurity incident management system nationwide. They exchange information about threats, coordinate activities in case of serious incidents, and jointly develop standards and best practices in cybersecurity.
How Does the Threat Information Exchange System Work?
Effective exchange of cybersecurity threat information is fundamental to the effective operation of the National Cybersecurity System. The main tool for this purpose is the S46 platform, which enables reporting and analyzing incidents and sharing knowledge about threats between NCS entities.
The S46 platform is available to all CSIRT teams, operators of essential services, digital service providers, and other authorized entities. Through it, they can report incidents, provide information about identified threats and vulnerabilities, and gain access to the cybersecurity knowledge base.
CSIRT teams use the S46 platform to exchange information about threats and indicators of compromise (IoC). They share data about new malware campaigns, phishing, botnets, and other threats. This information is analyzed and used to update threat detection systems, block malicious domains and IP addresses, and warn potential attack targets.
Direct operational cooperation between CSIRT teams and key entities, such as telecommunications operators, internet service providers, or security teams of large organizations, is also an important element of the information exchange system. This cooperation includes regular meetings, exercises, and experience exchange, as well as rapid communication channels in case of serious incidents. This enables efficient transfer of critical information and coordination of activities in crisis situations.
The cybersecurity threat information exchange system also extends beyond national borders. CSIRT teams cooperate with their foreign counterparts within the CSIRT, FIRST networks, and bilateral agreements. Information exchange at the international level allows for early detection of global cyberattack campaigns and coordinated response to them.
How is Cybersecurity Risk Management Implemented?
Risk management is fundamental to effective protection against threats from cyberspace. Within the National Cybersecurity System, uniform standards and methodologies for assessing and addressing cybersecurity risk are implemented.
Operators of essential services are required to regularly conduct risk analyses for their IT systems. They must identify key assets, assess potential threats and vulnerabilities, and estimate potential incident effects. Based on risk analysis results, they implement adequate and proportionate security measures, such as malware protection systems, access control mechanisms, or incident response procedures.
Digital service providers must also manage cybersecurity risk, although the requirements for them are less stringent than for operators of essential services. They are required to implement basic security measures, such as malware protection, system updates, or data confidentiality assurance.
At the national level, cybersecurity risk is assessed by cybersecurity authorities and CSIRT teams. This assessment is based on incident data, intelligence information, security audit results, and analysis of trends and new threats. Risk assessment results are used to update the national cybersecurity strategy, plan preventive activities, and allocate resources.
Cooperation between NCS entities is also an important element of risk management. Operators of essential services and digital service providers provide information about identified threats and incidents to CSIRT teams, which in turn share knowledge and best practices for assessing and addressing risk. Relevant authorities coordinate risk management activities nationwide, ensuring consistency and adequacy of measures taken.
What Does the Critical Incident Response Process Look Like?
Critical incidents are cybersecurity events of the highest threat level that may have serious consequences for state security, critical infrastructure operation, or key services for society. When such an incident occurs, special crisis response procedures are triggered, engaging the highest state bodies.
The critical incident response process begins with their detection and reporting by the operator of essential services or another entity to the appropriate CSIRT team. This team performs an immediate incident analysis and assesses its criticality. If the incident is deemed critical, CSIRT immediately informs the relevant cybersecurity authority (usually the minister responsible for a given sector or the Head of the Internal Security Agency) and the Government Security Center.
At the national level, crisis management procedures are triggered, coordinated by the Government Crisis Management Team. This team includes representatives of key ministries, special services, and cybersecurity experts. This team is responsible for strategic decisions regarding incident response, resource allocation, and communication with the public and foreign partners.
At the operational level, activities are directed by the minister responsible for informatization or another designated body. Main tasks include:
-
Coordination of cooperation between entities involved in incident handling (CSIRT teams, operators of essential services, special services, law enforcement agencies, etc.).
-
Providing necessary resources and technical support for teams responding to the incident.
-
Monitoring incident progress and evaluating the effectiveness of actions taken.
-
Communication with the public and media to minimize negative incident effects and prevent panic.
The priority in responding to critical incidents is minimizing their effects and restoring normal system and service operation as quickly as possible. Depending on the incident nature, activities may include disconnecting infected systems, restoring data from backups, updating security, or cooperating with telecommunications operators to block malicious traffic.
After response activities are completed, a detailed incident analysis is conducted to identify its causes, evaluate the effectiveness of actions taken, and formulate conclusions and recommendations for the future. These conclusions are used to update crisis response procedures, improve security systems, and plan long-term activities in cyberspace protection.
What are the Mechanisms for Coordinating Activities in Crisis Situations?
Effective response to serious cybersecurity incidents requires efficient coordination of activities of many entities at various levels. The National Cybersecurity System Act provides for a number of coordination mechanisms to ensure consistency and effectiveness of activities in crisis situations.
The Government Crisis Management Team (GCMT) plays a key role, responsible for coordinating public administration activities and cooperating with owners and holders of critical infrastructure objects, installations, or devices. In case of a critical incident, GCMT makes strategic decisions regarding response directions and methods, resource allocation, and crisis communication.
At the operational level, coordination is handled by the minister responsible for informatization or another body designated by the Prime Minister. Its tasks include ensuring cooperation between CSIRTs, administration bodies, and operators of essential services and digital service providers. The minister is also responsible for exchanging information with foreign partners and international organizations such as ENISA or NATO.
The government plenipotentiary for cybersecurity also plays an important role, responsible for coordinating government policy and activities in this area. The plenipotentiary chairs the Cybersecurity Council, which serves as a platform for cooperation and information exchange between key public administration bodies.
At the technical level, coordination is ensured by CSIRT teams that work closely together in exchanging information, analyzing threats, and jointly responding to incidents. CSIRTs maintain 24-hour communication channels and regularly meet to exchange experiences and best practices.
Crisis management centers at the national and departmental levels, such as the Government Security Center or the National Cybersecurity Center, also play an important role in coordinating activities. These centers aggregate data from various sources, monitor crisis situation development, and provide an overall picture of the situation for decision-makers.
Coordination mechanisms are regularly tested and improved through crisis management exercises such as Cyber-EXE or Locked Shields. These exercises allow identifying potential gaps and weaknesses in procedures and developing effective cooperation models between various entities.
How are Preventive and Educational Activities Conducted?
Prevention and education are key elements in building resilience to threats from cyberspace. The National Cybersecurity System provides for a number of activities in this area, addressed both to entities covered by the act and to the general public.
One of the main prevention tools is recommendations and best practices in cybersecurity, developed by CSIRT teams and relevant authorities. These documents contain practical guidance on secure system configuration, update management, access control, or incident response. Recommendations are published on CSIRT websites and distributed to operators of essential services and digital service providers.
CSIRTs also conduct active threat monitoring and regularly publish warnings about new malware campaigns, vulnerabilities, or attack techniques. This information allows organizations and users to take appropriate preventive measures, such as system updates or password changes.
Training and exercises in cybersecurity are also an important element of prevention. CSIRTs and commercial training service providers offer a wide range of courses, workshops, and simulations addressed to various target groups - from IT specialists to management staff. These trainings aim to raise competencies in identifying and responding to incidents, as well as promoting good security practices.
At the national level, information and educational campaigns are conducted targeting the general public. Their goal is to raise awareness of cyberspace threats and promote safe behaviors, such as caution in opening attachments, regular software updates, or using strong passwords. These campaigns use various communication channels, including traditional media, the internet, and social media.
Initiatives targeting children and young people, such as the “Digital Starter Kit” program or the “CyberSafe.pl” project, also play an important role in education. Their goal is to shape good online security habits from an early age and prepare young people for conscious and responsible use of digital technologies.
Preventive and educational activities within the NCS are continuous and constantly adapted to the changing threat landscape. Their effectiveness is regularly evaluated, and conclusions are used to plan further initiatives. The key to success is close cooperation between all system entities and involvement of the whole society in building a cybersecurity culture.
How Does International Cooperation Within the System Work?
In an era of globalization and mutual dependencies, effective cyberspace protection requires close cooperation in the international arena. Poland actively engages in cybersecurity initiatives at the European Union, NATO forums, and within bilateral relations with key partners.
The basis for cooperation within the EU is the NIS Directive (Network and Information Security), which establishes legal and organizational frameworks for ensuring a high level of network and information system security. Poland implemented the directive’s provisions through the National Cybersecurity System Act. National CSIRT teams work closely with CSIRTs of other Member States and with ENISA (European Union Agency for Cybersecurity) in exchanging information about threats, coordinating cross-border incident response, and sharing best practices.
Poland also actively participates in EU projects and initiatives, such as Cyber Rapid Response Teams (CRRTs) - rapid response teams for cybersecurity incidents of European importance, or Cyber Europe crisis management exercises regularly organized by ENISA.
Within NATO, Poland participates in the work of the Cooperative Cyber Defence Centre of Excellence (CCD COE) in Tallinn, which is responsible for developing the alliance’s cybersecurity capabilities. Polish experts participate in center trainings, exercises, and research projects, as well as in developing NATO cyber defense doctrines and standards. Poland is also an active participant in Locked Shields exercises - the world’s largest and most advanced cybersecurity exercises organized annually by CCD COE.
At the bilateral level, Poland develops cybersecurity cooperation with key partners such as the USA, United Kingdom, Germany, or Israel. This cooperation includes regular political consultations, intelligence information exchange, joint exercises and trainings, as well as research and development projects. Cooperation with the United States is particularly intensive, with which Poland concluded a bilateral cybersecurity cooperation agreement in 2018.
Global organizations and initiatives, such as the Global Forum on Cyber Expertise (GFCE) or the International Telecommunication Union (ITU), are also important forums for cooperation. Poland actively engages in the work of these bodies, sharing its experiences and best practices and participating in developing global cybersecurity standards and guidelines.
International cooperation within the NCS is multidimensional and constantly developing in response to evolving threats. Efficient information exchange, building mutual trust, and sharing knowledge and resources are of key importance here. Only through close cooperation with partners can Poland effectively counter cyberspace threats and build a secure future in the digital age.
How is the System’s Effectiveness Evaluated?
Evaluating the effectiveness of the National Cybersecurity System is a complex process that covers many aspects and requires continuous monitoring. The system undergoes regular reviews and audits aimed at identifying areas requiring improvement and formulating recommendations for further development.
One of the key evaluation tools is annual reports submitted by cybersecurity authorities. These reports contain information about the state of cybersecurity in individual sectors, the number and nature of reported incidents, actions taken, and cooperation with other entities. Reports are submitted to the minister responsible for informatization, who prepares a consolidated report on the state of the national cybersecurity system based on them.
Security audits conducted by CSIRT teams at operators of essential services and digital service providers are also an important element of evaluation. These audits aim to verify compliance of applied security measures with the act’s requirements and identify potential weaknesses and risk areas. Audit results are used to formulate recommendations and plan corrective actions.
System effectiveness is also evaluated through analysis of actual incidents and conclusions from crisis management exercises. Each serious incident is analyzed in detail in terms of causes, course, and effectiveness of actions taken. Conclusions from these analyses serve to identify gaps in response capabilities, training needs, or necessary procedure changes. Similarly, conclusions from exercises allow identifying areas requiring improvement and testing the effectiveness of existing solutions.
At the strategic level, NCS effectiveness is evaluated in the context of achieving goals set in the Cybersecurity Strategy of the Republic of Poland. This strategy is regularly updated based on changing conditions and emerging new challenges. Progress in implementing the strategy is monitored by the Cybersecurity Council, and conclusions are used to plan further activities.
System effectiveness evaluation also takes into account benchmarking and international comparisons. Poland actively participates in initiatives such as the National Cyber Security Index, which allows evaluating the country’s preparedness level against other states. Results of these comparisons are used to identify best practices and areas requiring improvement.
It should be emphasized that NCS effectiveness evaluation is a continuous process that must keep up with the dynamically changing threat environment. Openness to new ideas, readiness to learn from mistakes, and constant pursuit of improvement are the keys to success. Only through continuous adaptation and strengthening of the system can Poland effectively respond to the challenges of the digital age.
What are the Plans for Developing and Improving the National Cybersecurity System?
The National Cybersecurity System is a dynamic structure that must constantly evolve to keep up with the changing threat landscape and growing expectations of the digital society. Development and improvement plans for the system include a number of legislative, organizational, and technological initiatives.
One of the key directions is adapting the NCS to the requirements of the NIS 2 directive, which will enter into force in 2024. This directive significantly expands the scope of entities covered by cybersecurity regulations, including public administration, critical infrastructure, and key ICT service and product providers. Implementation of NIS 2 will require amending the National Cybersecurity System Act and issuing a number of executive regulations.
An important aspect of NCS development is strengthening the operational capabilities of CSIRT teams and relevant authorities. Planned are increases in human and financial resources of these entities, as well as investments in modern tools and infrastructure for detecting and responding to incidents. The project to build the National Cybersecurity Center - a central competence and coordination center that will ultimately integrate the activities of all NCS entities - is of key importance.
System development also includes improving cooperation and information exchange mechanisms. Planned is the implementation of advanced platforms for automatic threat intelligence data exchange and further development of the S46 system as a central incident reporting and analysis tool. Strengthening cooperation with the private sector, particularly with critical infrastructure operators and key cybersecurity service providers, is also an important direction.
In the strategic dimension, updating the Cybersecurity Strategy of the Republic of Poland for 2024-2029 is of key importance. The new strategy will need to take into account the dynamics of changes in the threat environment, technological progress (e.g., artificial intelligence development, quantum computing technologies), and the evolution of the geopolitical environment. Integration of cybersecurity goals with broader state digital transformation goals will also be an important aspect.
NCS development plans also place great emphasis on strengthening research and development potential and innovation in cybersecurity. Planned are dedicated grant programs, support for startups and SMEs developing innovative cybersecurity solutions, and strengthening cooperation between the scientific environment and administration and business.
Continuous improvement of cybersecurity competencies and awareness among all participants is an important element of system improvement. Intensive educational and training activities are planned, addressed both to professionals (e.g., certification programs, advanced exercises) and to the general public (information campaigns, school education).
NCS development is a continuous process requiring the commitment and cooperation of all stakeholders. Only through openness to change, investment in innovation and human capital, and close cooperation at the national and international level can Poland build a cybersecurity system that will effectively protect citizens, the economy, and the state in the digital revolution era.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
Learn More
Explore related articles in our knowledge base:
- How to Wisely Choose a Partner for the Cybersecure Local Government Program?
- Applying for a Cybersecure Local Government Grant? Why an Audit is the Key First Step to Success
- What Is the Cybersecure Municipality Project? - A Guide
- Cybersecurity Threats and Strategies for Local Governments - Comprehensive Guide
- Who Does the National Cybersecurity System Cover? Entities, Operators, Providers and Authorities
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Related topics
See also:
- NIS2 for local government — implementation
- NIS2 Funding Calculator for Local Government
- EDR vs XDR vs NDR — comparison
