The National Cybersecurity System (NCS) applies to operators of essential services, digital service providers, and public authorities whose task is to ensure the security of critical infrastructure in Poland. The system covers sectors such as energy, transport, healthcare, and administration. Each entity must meet specific requirements regarding risk management, incident reporting, and cooperation with relevant institutions.
Table of Contents
- Who Does the National Cybersecurity System Cover?
- What Entities Are Part of the National Cybersecurity System?
- What Are Operators of Essential Services and What Sectors Do They Represent?
- Who Are the Digital Service Providers Covered by the National Cybersecurity System?
- What Role Do CSIRT Teams Play in the National Cybersecurity System?
- Which Public Administration Bodies Are Part of the National Cybersecurity System?
- What Obligations Does the National Cybersecurity System Impose on Covered Entities?
- How Does the National Cybersecurity System Regulate Personal Data Processing?
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
Who Does the National Cybersecurity System Cover?
The National Cybersecurity System (NCS) covers a wide range of entities whose activities are crucial for the functioning of the state and society in the digital era. This system, established under the Act of July 5, 2018, creates comprehensive frameworks for the protection of the cyberspace of the Republic of Poland.
At the center of the system are operators of essential services, representing strategic sectors of the economy. These include enterprises from industries such as energy, transport, banking, and healthcare. For example, in the energy sector, the NCS covers companies responsible for the generation, transmission, and distribution of electricity, gas, and oil. In transport, the system includes managers of railway, aviation, water, and road infrastructure.
Another important group consists of digital service providers. This category includes entities providing online services, such as internet trading platforms, search engines, and cloud computing services. Their inclusion in the NCS reflects the growing importance of digital services in citizens’ daily lives and the functioning of the economy.
The system also encompasses key state institutions, including public finance sector units, the National Bank of Poland, and Bank Gospodarstwa Krajowego. These entities play a critical role in managing state finances and maintaining economic stability.
It’s worth emphasizing that the NCS is not limited to large organizations only. The system also includes medium-sized enterprises if they meet specific criteria related to their role in the economy or potential impact on state security.
An essential element of the system are the national-level CSIRT (Computer Security Incident Response Team) teams: CSIRT MON, CSIRT NASK, and CSIRT GOV. These specialized units constitute the first line of defense against cyberattacks, monitoring threats and coordinating incident responses.
The NCS also includes authorities competent for cybersecurity matters, which perform regulatory and supervisory functions in individual sectors. Their role is crucial for ensuring consistency and effectiveness of cybersecurity activities.
In summary, the National Cybersecurity System creates a comprehensive network of entities whose cooperation is intended to ensure Poland’s digital security. From critical infrastructure operators, through digital service providers, to state institutions - all these entities have their role in building the country’s cyber resilience.
What Entities Are Part of the National Cybersecurity System?
The National Cybersecurity System (NCS) is a complex structure consisting of a number of entities with diverse roles and responsibilities. This diversity ensures a comprehensive approach to protecting the cyberspace of the Republic of Poland.
Key elements of the NCS are three national-level CSIRT (Computer Security Incident Response Team) teams:
-
CSIRT MON - responsible for the defense sector, subordinate to the Ministry of National Defense.
-
CSIRT NASK - serving the civilian sector, operating within the Research and Academic Computer Network.
-
CSIRT GOV - dealing with government administration, run by the Internal Security Agency.
These teams constitute the first line of defense against cyberattacks, monitoring threats and coordinating incident responses.
Another important group is operators of essential services. These are entities from sectors such as energy, transport, banking, and healthcare, whose IT systems are crucial for the functioning of the state and economy. For example, in the energy sector, companies managing electricity or gas transmission networks belong to the NCS.
The NCS also includes digital service providers, including e-commerce platforms, cloud service providers, and search engines. Their role in the system reflects the growing importance of digital services in citizens’ daily lives and business operations.
An important element is the authorities competent for cybersecurity matters. These are institutions responsible for cybersecurity supervision in individual sectors, such as ministries or regulatory offices.
The NCS also includes sectoral cybersecurity teams, which support operators of essential services in their industries, providing specialized knowledge and support. Entities providing cybersecurity services also participate in the system. These are companies and organizations offering specialized services, such as security audits or penetration testing.
An important role is played by the Single Point of Contact, which ensures information exchange with European Union institutions and member states.
At the top of the NCS structure is the Government Plenipotentiary for Cybersecurity and the Cybersecurity Board. These bodies provide strategic leadership and coordination of activities at the highest state level.
The system also includes public finance sector units, the National Bank of Poland, Bank Gospodarstwa Krajowego, and research institutes, which have their specific roles and obligations in the field of cybersecurity.
This complex NCS structure reflects the multidisciplinary nature of cybersecurity challenges. By integrating diverse entities, the system is able to ensure comprehensive protection of cyberspace, combining technical, operational, and strategic competencies.
What Are Operators of Essential Services and What Sectors Do They Represent?
Operators of essential services are entities that play a critical role in the functioning of the economy and society, and whose IT systems are necessary for providing these services. In the context of the National Cybersecurity System (NCS), operators of essential services represent sectors of strategic importance to the state.
The energy sector is one of the key areas covered by the NCS. Operators in this sector include: • Enterprises involved in electricity generation • Operators of electricity transmission and distribution systems • Companies responsible for natural gas production, transport, and distribution • Entities managing oil infrastructure, including refineries and pipelines
In the transport sector, operators of essential services are: • Railway infrastructure managers • Railway carriers • Entities managing airports and seaports • Air traffic management system operators • Companies managing road infrastructure, including traffic control systems
The banking and financial market infrastructure sector includes: • Credit institutions • Settlement system operators • Stock exchanges • Entities operating payment systems
In the healthcare sector, operators of essential services are: • Healthcare providers, particularly hospitals • Diagnostic laboratories • Blood donation centers • Entities responsible for e-health and medical information systems
The drinking water supply sector includes: • Water supply companies responsible for intake, treatment, and distribution of drinking water • Entities managing water quality monitoring systems
Digital infrastructure, as a key element of the modern economy, is also represented by operators of essential services, including: • DNS (Domain Name System) service providers • Internet exchange point (IXP) operators • Top-level domain (TLD) managers
It’s worth emphasizing that the status of essential service operator is not automatically granted to all entities in a given sector. The recognition of an entity as an essential service operator is determined by criteria such as: • The importance of the provided service for maintaining critical social or economic activity • The actual and potential impact of an incident on public safety, national security, or the economy • The entity’s market share • The geographical scope related to the area that could be affected by an incident
Operators of essential services are subject to special cybersecurity requirements. They must implement appropriate technical and organizational measures, conduct regular security audits, and report serious incidents to the relevant CSIRT. This responsibility reflects the crucial role these entities play in ensuring the continuity of state and economic functioning in the digital era.
Who Are the Digital Service Providers Covered by the National Cybersecurity System?
Digital service providers constitute an important group of entities covered by the National Cybersecurity System (NCS). These are entities that provide services electronically, playing a key role in the functioning of the modern digital economy. In the context of the NCS, digital service providers include three main categories:
-
Online trading platforms: These are e-commerce services that enable consumers and entrepreneurs to conduct transactions online. These platforms act as intermediaries between sellers and buyers, offering technical infrastructure for conducting transactions. Examples may include large marketplaces, auction platforms, or specialized industry websites. The security of these platforms is crucial for protecting the personal and financial data of millions of users.
-
Cloud computing services: Providers of these services offer computing resources, storage space, and other IT services in a cloud model. This includes various service models, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS). Cloud security is critical, as it often stores sensitive data of businesses and public institutions.
-
Search engines: These are tools enabling users to search internet resources. Search engines collect and index enormous amounts of data, making them a potential target for cyberattacks. Their role in shaping access to information makes them a key element of information infrastructure.
It’s worth emphasizing that the NCS covers digital service providers that meet specific size criteria. According to the act, these are entities that employ at least 50 employees or achieve annual net turnover exceeding 10 million euros.
Digital service providers covered by the NCS have a number of obligations, including:
• Implementing appropriate and proportionate technical and organizational measures for risk management • Taking actions to prevent and minimize the impact of incidents on provided services • Reporting serious incidents to the relevant CSIRT • Ensuring service continuity or its fastest possible restoration after an incident
Importantly, digital service providers are subject to less rigorous requirements than operators of essential services. This stems from the assumption that digital services are inherently cross-border and subject to less sector regulation.
The inclusion of digital service providers in the NCS reflects the growing importance of these entities in the digital economy. Their security has a direct impact on millions of users and thousands of businesses using their services. By covering them with the cybersecurity system, the NCS aims to increase the resilience of the entire digital ecosystem in Poland.
What Role Do CSIRT Teams Play in the National Cybersecurity System?
CSIRT (Computer Security Incident Response Team) teams play a key role in the National Cybersecurity System (NCS), constituting the first line of defense against cyber threats. In Poland, three main national-level CSIRT teams operate: CSIRT MON, CSIRT NASK, and CSIRT GOV, each with its own area of responsibility and specialization.
-
Threat monitoring: CSIRTs conduct continuous cyberspace monitoring in search of potential threats. They use advanced analytical tools and early warning systems to identify new types of attacks, malicious software, or system vulnerabilities. This proactive attitude allows for quick response to emerging threats.
-
Incident handling coordination: In case of detecting a serious incident, CSIRT teams coordinate the actions of various entities involved in its handling. They ensure information flow, provide technical support, and help develop response strategies. This role is crucial for ensuring coherent and effective response to attacks.
-
Incident analysis and classification: CSIRTs conduct detailed analysis of reported incidents, determining their scale, potential effects, and source. Based on this, they classify incidents and prioritize remedial actions. This analytical work is fundamental for understanding the nature of threats and developing effective defense strategies.
-
Incident response: CSIRT teams provide direct support in responding to serious cybersecurity incidents. This includes technical assistance, advice on attack mitigation, and support in restoring normal system functioning. Their expertise is often crucial for minimizing damage and quickly restoring normal operations.
-
Information exchange: CSIRTs play a key role in exchanging information about threats and incidents between various NCS entities, as well as at the international level. They cooperate with similar teams in other countries, which allows for quick response to global threats. This information exchange is necessary for building collective resilience to cyber threats.
-
Awareness building: CSIRT teams engage in educational and awareness-raising activities, organizing trainings, workshops, and conferences on cybersecurity. They also publish alerts and warnings about new threats. These activities contribute to raising the overall level of cybersecurity in the country.
-
Development of tools and methodologies: CSIRTs work on developing new tools and methodologies in the field of cybersecurity. This includes creating proprietary solutions for malware analysis or intrusion detection systems. This innovative work allows maintaining technological advantage over cybercriminals.
-
Technical support: Teams offer specialized technical support for NCS entities, helping with security implementation, risk assessment, or conducting penetration tests. This support is particularly valuable for smaller organizations that may not have their own expert resources.
The role of CSIRT teams in the NCS is multidimensional and crucial for the effectiveness of the entire system. Their work not only helps in defending against current threats but also contributes to building Poland’s long-term cyber resilience. Thanks to their specialization and advanced competencies, CSIRT teams constitute a center of expertise in the field of cybersecurity, supporting both state institutions and the private sector in facing increasingly sophisticated cyber threats.
Which Public Administration Bodies Are Part of the National Cybersecurity System?
The National Cybersecurity System (NCS) includes a number of public administration bodies that play key roles in ensuring state cybersecurity. These entities create a comprehensive structure of supervision, coordination, and support in the area of cyberspace protection of the Republic of Poland.
-
Minister competent for computerization: Plays a central role in the NCS, responsible for coordinating activities and implementing government policy in the field of cybersecurity. Supervises the functioning of the system and represents Poland in cybersecurity matters on the international forum.
-
Government Plenipotentiary for Cybersecurity: This is a key figure responsible for coordinating activities in the field of cybersecurity at the government level. The Plenipotentiary supervises the implementation of NCS goals and ensures consistency of actions of various ministries.
-
Cybersecurity Board: This is an advisory and consultative body on cybersecurity matters. It consists of representatives of key ministries and services, providing a platform for strategic discussion and coordination of activities at the highest level.
-
Ministry of National Defense: Responsible for cybersecurity in the defense sector. Within the MON, CSIRT MON operates, one of the three main computer incident response teams in the country.
-
Internal Security Agency: ABW plays a key role in protecting the state’s cyberspace. CSIRT GOV operates within its structures, responsible for cybersecurity of government administration and critical infrastructure.
-
Research and Academic Computer Network - State Research Institute (NASK-PIB): NASK runs CSIRT NASK, which is responsible for cybersecurity in the civilian sector.
-
Authorities competent for cybersecurity matters: These are ministers heading government administration departments: energy, transport, maritime economy, inland navigation, computerization, and the Financial Supervision Authority. They perform regulatory and supervisory functions in their sectors.
-
Single Point of Contact: Functions within the structure of the Ministry of Digitization and is responsible for cooperation with authorities competent for cybersecurity matters in other EU member states.
-
Office of Electronic Communications: Plays an important role in supervising the telecommunications sector, which has a direct impact on the cybersecurity of the country’s communication infrastructure.
-
Government Security Center: Responsible for crisis management at the national level, including coordination of activities in case of serious cybersecurity incidents.
-
Police and prosecutor’s office: Play a key role in prosecuting computer crimes and cybercrime.
-
Military Counterintelligence Service: Responsible for protection against cyber threats in the defense area.
-
National Police Headquarters: Within its structures operates the Bureau for Combating Cybercrime, specializing in fighting crime in cyberspace.
-
Ministry of Foreign Affairs: Plays a role in shaping international cybersecurity policy and representing Poland on international forums in this regard.
It’s worth emphasizing that the NCS structure is dynamic and may evolve in response to changing threats and needs in the field of cybersecurity. Cooperation between these bodies is crucial for effective protection of the Republic of Poland’s cyberspace. Each of these entities brings its specialized knowledge and competencies, creating a comprehensive defense system against cyber threats.
What Obligations Does the National Cybersecurity System Impose on Covered Entities?
The National Cybersecurity System (NCS) imposes a number of important obligations on covered entities, aimed at ensuring a high level of cybersecurity in key sectors of the economy and public administration. These obligations differ depending on the entity category but generally aim to create a comprehensive system of protection against cyber threats.
-
Operators of essential services: • Conducting regular risk assessments, at least once every 2 years • Implementing appropriate and proportionate technical and organizational measures • Implementing an information security management system (e.g., compliant with ISO/IEC 27001 standard) • Reporting serious incidents to the relevant CSIRT within 24 hours of detection • Maintaining cybersecurity documentation • Designating a person responsible for contacts with NCS entities • Conducting regular security audits
-
Digital service providers: • Implementing appropriate technical and organizational measures for risk management • Reporting incidents having a significant impact on service provision • Ensuring service continuity at the level specified in the act • Applying measures to prevent and minimize the impact of incidents on information system security
-
Public entities: • Designating a person responsible for cybersecurity • Reporting incidents to the relevant CSIRT • Ensuring incident management • Applying technical and organizational measures appropriate to the estimated risk
-
National-level CSIRT teams: • Monitoring cybersecurity threats and incidents at the national level • Assessing risks associated with disclosed cybersecurity threats • Communicating information about incidents and risks to other NCS entities • Responding to reported incidents • Classifying incidents, including serious incidents, and coordinating serious incident handling
-
Sectoral cybersecurity teams: • Accepting incident reports • Supporting incident handling • Analyzing incidents • Supporting operators of essential services in fulfilling obligations arising from the act
-
Authorities competent for cybersecurity matters: • Conducting cybersecurity analyses and assessments at the sectoral level • Supervising operators of essential services and digital service providers • Cooperating with CSIRT and other competent authorities
-
All NCS entities: • Cooperating with law enforcement and judicial authorities in prosecuting perpetrators of crimes and offenses • Participating in cybersecurity exercises organized by competent entities • Complying with recommendations and guidelines issued by competent authorities
It’s worth emphasizing that these obligations are not static. The NCS provides mechanisms for continuous improvement and adaptation to changing threats. Entities covered by the system must be prepared for regular updates of their procedures and systems in response to new challenges in cyberspace.
Meeting these obligations requires organizations to make significant investments in infrastructure, processes, and human resources. However, given the growing cyber threats, these requirements are necessary to ensure the security not only of individual entities but of Poland’s entire digital ecosystem.
How Does the National Cybersecurity System Regulate Personal Data Processing?
The National Cybersecurity System (NCS) introduces specific regulations regarding personal data processing, which must be compliant with general data protection principles, including the General Data Protection Regulation (GDPR). The NCS takes into account the special nature of data processed in the context of cybersecurity, balancing between the need to protect privacy and the necessity of effective response to cyber threats.
-
Legal bases for processing: The NCS provides a legal basis for processing personal data in the context of cybersecurity. This particularly applies to data related to security incidents, threat information, or data necessary for risk analysis. The basis for processing is the performance of tasks in the public interest, which is consistent with Article 6(1)(e) GDPR.
-
Scope of processed data: The NCS precisely defines the scope of personal data that may be processed by individual system entities. This includes, among others, contact details of persons responsible for cybersecurity in organizations, incident-related data (e.g., IP addresses, login data), or information about users of systems affected by an incident.
-
Purpose limitation principle: The system introduces the principle of purpose limitation for data processing. Personal data may be processed exclusively for the purpose of performing tasks related to cybersecurity, such as detecting and analyzing incidents, risk assessment, or coordinating defensive actions.
-
Data retention period: The NCS specifies maximum retention periods for personal data related to security incidents. For example, incident data may be retained for a period necessary to perform tasks, but no longer than 5 years from the moment of receiving the incident report.
-
Data disclosure principles: The system regulates the principles of disclosing personal data between NCS entities. Such disclosure is limited to situations where it is necessary to perform cybersecurity tasks. Mechanisms for controlling and recording disclosures have also been introduced.
-
Information obligations: NCS entities are obliged to inform data subjects about processing their data in the context of cybersecurity. However, in some cases, when this could threaten the effectiveness of defensive actions, this obligation may be limited.
-
Security measures: The NCS imposes on entities the obligation to apply appropriate technical and organizational measures to protect processed personal data. This includes, among others, data encryption, access control, or regular security audits.
-
Reporting personal data breaches: The system introduces the obligation to report personal data breaches that may affect information system security. These reports are made in parallel to the relevant CSIRT and to the supervisory authority for personal data protection.
-
Cooperation with the supervisory authority: The NCS provides for close cooperation of system entities with the President of the Personal Data Protection Office in the field of protecting data processed in the context of cybersecurity.
-
Pseudonymization and anonymization: The system promotes the use of pseudonymization and anonymization techniques when full identification of persons is not necessary for processing purposes.
-
Training and awareness building: The NCS imposes on entities the obligation to conduct regular training for personnel in the field of personal data protection in the context of cybersecurity.
-
Data protection impact assessment: For some data processing operations within the NCS, conducting a data protection impact assessment (DPIA) is required, especially when processing may cause high risk of violating the rights and freedoms of natural persons.
In summary, the NCS introduces comprehensive regulations regarding personal data processing, which take into account the specifics of cybersecurity activities. The system aims to ensure a balance between effective cyberspace protection and respect for the right to privacy. Entities covered by the NCS must therefore not only meet general GDPR requirements but also adapt to specific regulations arising from the national cybersecurity system act. This requires organizations to implement advanced processes and tools for managing personal data in the context of cybersecurity.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- CSPM (Cloud Security Posture Management) — CSPM (Cloud Security Posture Management) is a category of cloud security tools…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
Learn More
Explore related articles in our knowledge base:
- Who Does the National Cybersecurity System Cover? Entities, Operators, Providers and Authorities
- Who is Responsible for Implementing the National Cybersecurity System? Responsibilities, Supervision, and Control
- National Cybersecurity System Act - Objectives, Definitions, Regulations and Roles
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
- NIS2 for hospitals — implementation and funding
- Security Audit Pricing Calculator
- NIS2 for hospitals — compliance
