Skip to content
Knowledge base Updated: February 5, 2026

Who is Responsible for Implementing the National Cybersecurity System? Responsibilities, Supervision, and Control

Key entities and institutions are responsible for implementing the National Cybersecurity System. Learn who oversees and controls its operations.

Both public authorities and operators of essential services, as well as digital service providers, are responsible for implementing the National Cybersecurity System. Each of these entities is obligated to ensure appropriate protection measures against cyber threats, report incidents, and cooperate with incident response teams (CSIRTs). National cybersecurity authorities supervise the system, monitoring compliance with regulations.

Table of Contents

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

Who bears main responsibility for the National Cybersecurity System?

The main responsibility for implementing and operating the National Cybersecurity System (KSC) lies with the Council of Ministers, as the supreme body of government administration. Through appropriate legal acts and decisions, it shapes the organizational and competence framework of the system. The Prime Minister plays a key role here by appointing the Government Plenipotentiary for Cybersecurity - a central figure coordinating activities in this area.

Beyond the Council of Ministers, significant obligations rest with ministers heading government administration departments, particularly the Minister of Digitalization, Minister of National Defense, and Minister of Internal Affairs and Administration. They are responsible for implementing cybersecurity policy in their areas of competence, supervising their subordinate CSIRT teams, and cooperation within KSC.

The role of essential service operators and digital service providers themselves cannot be overlooked. According to the principle of entity responsibility, they bear the obligation to implement appropriate security measures, report incidents, and cooperate with KSC authorities. Although they operate under supervision, they bear direct responsibility for the cybersecurity of their systems and services.

What role does the Ministry of Digitalization play in KSC implementation?

The Ministry of Digitalization plays a key role in implementing the National Cybersecurity System. As the authority competent for civilian cybersecurity matters, it coordinates the implementation of the KSC law and EU directives in this area.

The Ministry’s main tasks include identifying essential service operators and issuing decisions recognizing an entity as an operator. The Ministry also maintains a register of operators and supervises their fulfillment of statutory obligations, such as implementing security management systems or reporting incidents.

The Ministry of Digitalization is also responsible for cooperation with digital service providers, although in their case, due to the cross-border nature of services, a harmonized regulatory regime applies at the EU level. The Ministry monitors providers’ compliance with security and incident handling requirements.

An important aspect of the Ministry’s activity is coordinating the activities of CSIRT NASK - one of three national-level teams. CSIRT NASK, operating within the Research and Academic Computer Network subordinate to the Ministry, is responsible for handling incidents reported by entities not belonging to government administration and the military sector.

The Ministry of Digitalization actively participates in legislative work, developing draft implementing acts for the KSC law and representing Poland in implementing EU directives. It also conducts information and educational activities, promoting good cybersecurity practices among citizens and entrepreneurs.

What tasks does the Government Plenipotentiary for Cybersecurity have?

The Government Plenipotentiary for Cybersecurity is the central figure in the country’s cybersecurity management system. Appointed and dismissed by the Prime Minister, they are responsible for coordinating government policy in this strategic area.

Key tasks of the Plenipotentiary include primarily analyzing and evaluating the functioning of the National Cybersecurity System. Based on data and indicators obtained from all KSC entities, the Plenipotentiary prepares cyclical reports for the Council of Ministers, containing recommendations for actions to improve the country’s cyber security.

The Plenipotentiary also supervises the risk management process in KSC. In cooperation with administration authorities and CSIRT teams, they identify key threats, assess their potential impact, and propose adequate preventive and corrective measures. They oversee the system’s coherence and effectiveness, eliminating gaps and duplication of competences.

An important aspect of the Plenipotentiary’s work is international cooperation. They represent Poland in contacts with EU and NATO institutions responsible for cybersecurity, participate in developing common standards and good practices. They ensure the interoperability of national solutions with partner systems abroad.

The Plenipotentiary also performs coordination and mediation functions within KSC. They chair the work of the Cybersecurity Committee, a cooperation platform for key institutions. In disputed situations, they act as an arbiter, ensuring the coherence and effectiveness of the system as a whole.

Not insignificant are the Plenipotentiary’s competences in education and awareness-building. They initiate information campaigns, promote knowledge about digital threats among citizens and entrepreneurs. They support the development of cybersecurity sector personnel, cooperating with universities and training centers.

What does the Cybersecurity Committee do?

The Cybersecurity Committee is a key advisory and consultative body in the National Cybersecurity System. Operating under the Council of Ministers, it brings together representatives of the most important institutions responsible for various aspects of the country’s cybersecurity.

The Committee includes ministers competent for internal affairs, national defense, informatization, economy, and public finance, as well as the Head of the Prime Minister’s Chancellery, Head of the Internal Security Agency, and Director of the Government Security Center. It is chaired by the Government Plenipotentiary for Cybersecurity.

The Committee’s main task is ensuring coordination and coherence of actions taken by various administration authorities in cybersecurity. It serves as a platform for information exchange, position alignment, and developing common recommendations.

The Committee reviews key strategic documents, such as the Cybersecurity Strategy of the Republic of Poland or annual action plans of individual ministries. It analyzes the current situation in cyberspace, identifies new threats, and proposes adequate response measures.

An important aspect of the Committee’s work is coordinating actions in crisis situations. In case of a serious cybersecurity incident of national scope, the Committee may recommend that the Council of Ministers introduce heightened readiness states, activate crisis management procedures, or request international support.

The Committee also performs advisory functions for the Government Plenipotentiary for Cybersecurity. It supports them in analyzing KSC functioning, identifying areas requiring improvement, and formulating proposals for legislative or organizational changes.

Not insignificant is the Committee’s role in building a coherent cybersecurity culture in administration. Through regular meetings and experience exchange, it contributes to raising competences and operating standards of all involved entities.

Which institutions are crucial for KSC functioning?

The National Cybersecurity System is a complex ecosystem where various institutions play key roles, both at strategic and operational levels. Their smooth cooperation and action coordination are necessary for effective protection of Polish cyberspace.

At the strategic level, the Council of Ministers and its subordinate Government Plenipotentiary for Cybersecurity are of key importance. They, together with the Cybersecurity Committee, shape state policy in this area, define priorities, and coordinate the actions of individual ministries.

Among ministries, a special role is played by the Ministry of Digitalization (as the authority competent for civilian cybersecurity), the Ministry of National Defense (responsible for cyberspace in the military sphere), and the Ministry of Internal Affairs and Administration (supervising services responsible for internal security).

At the operational level, the pillars of KSC are national-level CSIRT teams (Computer Security Incident Response Team): CSIRT NASK (serving the civilian sector), CSIRT GOV (responsible for government administration), and CSIRT MON (securing the military sphere). Operating in 24-hour mode, they monitor cyberspace, detect and analyze incidents, and coordinate threat response.

Sectoral cybersecurity teams, created by essential service operators from individual industries (energy, transport, banking, healthcare, etc.), also play an important role. They ensure information exchange and action coordination within a given sector, closely cooperating with relevant CSIRTs.

The role of special services and law enforcement agencies cannot be overlooked. The Internal Security Agency, through its Department of Teleinformation Security, is responsible for counterintelligence in cyberspace and combating cybercrime. Police and prosecutors conduct proceedings in cyberattack cases, and the Military Counterintelligence Service protects teleinformation systems of the armed forces.

Important links in KSC include the Office of Electronic Communications (regulator of the telecommunications and postal market), the General Inspector for Personal Data Protection (guardian of online privacy), and the Government Security Center (coordinating crisis management).

The role of essential service operators and digital service providers themselves must not be forgotten. By implementing appropriate safeguards and incident response procedures, they create the first line of defense against cyberattacks. Their commitment and responsibility are crucial for the success of the entire system.

What obligations do national-level CSIRT teams have?

National-level CSIRT (Computer Security Incident Response Team) teams are key operational links in the National Cybersecurity System. Operating in 24/7 mode, they stand on the first line of defense of Polish cyberspace, monitoring threats, responding to incidents, and supporting KSC entities in raising security levels.

In Poland, three national-level CSIRTs operate, each responsible for a different area:

  • CSIRT NASK - serves the civilian sector, including essential service operators (except the financial sector), digital service providers, local governments, and individuals.

  • CSIRT GOV - is responsible for cybersecurity of government administration units and critical infrastructure operators.

  • CSIRT MON - secures systems and networks of the Ministry of National Defense and enterprises of particular importance for defense.

The main obligations of CSIRTs include receiving incident reports from supported entities. Teams must provide easy and secure communication channels (e.g., dedicated forms, encrypted email), as well as confirm receipt of reports and inform about actions taken.

After receiving a report, CSIRTs proceed with incident handling. This includes event analysis, identifying causes and effects, classifying by threat level, then implementing adequate remedial measures. Teams provide entities affected by incidents with necessary technical and organizational support, coordinate actions with other CSIRTs (also foreign ones, if the incident is cross-border), and if needed, engage additional resources (e.g., external experts, law enforcement agencies).

CSIRTs also conduct active cyberspace monitoring in search of potential threats. They use various information sources for this purpose - from public (such as social media, hacker forums, news services) to closed (such as intelligence data, cybersecurity company reports). Based on collected data, they prepare regular risk analyses and situation reports for KSC entities.

An important obligation of CSIRTs is early warning about detected threats. Teams develop and distribute to KSC entities alerts, bulletins, and recommendations regarding new vulnerabilities, malware campaigns, or suspicious network activities. They ensure appropriate adaptation of messages to recipients - the language and scope of information will differ for system administrators versus ordinary users.

CSIRTs also play a significant role in raising cybersecurity competences. They organize training, workshops, and exercises for KSC entity employees, participate in conferences and awareness campaigns. They share knowledge and good practices, promote security standards, support building a cyber hygiene culture.

Not insignificant are reporting and analytical tasks. CSIRTs maintain registers of handled incidents, prepare statistics and activity reports. This data serves to assess the country’s cybersecurity state, identify trends and areas requiring improvement, as well as reporting at the EU level (according to NIS directive requirements).

Finally, CSIRTs are active participants in international cooperation in cybersecurity. They exchange threat information with counterparts from other countries (e.g., through the MISP platform), participate in joint exercises and operations. They ensure interoperability of procedures and tools to effectively respond to cross-border incidents.

How do sectoral cybersecurity teams operate?

Sectoral cybersecurity teams are key elements of the National Cybersecurity System, responsible for cooperation and information exchange within individual industries recognized as crucial for state and economy functioning. Their creation and operation are regulated by the law on the national cybersecurity system.

Teams are established by essential service operators from a given sector (e.g., energy, transport, banking, healthcare). Membership in the team is mandatory for all operators in the industry, which is to ensure completeness and coherence of information exchange.

The main task of teams is ensuring smooth flow of threat and incident information between operators. Team members are obligated to mutually inform each other about detected vulnerabilities, attacks, suspicious activities. Secure communication channels (e.g., encrypted email, dedicated data exchange platforms) and regular meetings (both on-site and videoconferences) serve this purpose.

Teams also develop common standards and good cybersecurity practices, adapted to the specifics of a given sector. These may include, for example, guidelines for system configuration, incident response procedures, secure software development principles. The goal is to raise and standardize security levels across the entire industry.

An important aspect of team work is identifying interdependencies and potential cascade effects. In today’s closely connected world, an incident at one operator can quickly spread to others, and even beyond the sector. Teams analyze these connections, develop risk scenarios and crisis response plans.

Sectoral cybersecurity teams closely cooperate with CSIRTs at the national level appropriate for a given sector. They pass incident information to them, consult response plans, participate in joint exercises. CSIRTs provide teams with substantive and technical support, and also serve as a link with other KSC entities (e.g., administration authorities, special services).

Not insignificant is the teams’ role in building awareness and cybersecurity competences among operators. They organize training, workshops, staff exchanges. They promote a culture of knowledge sharing, learning from mistakes, continuous improvement.

The effectiveness of sectoral cybersecurity teams largely depends on commitment and trust between members. Breaking natural resistance to sharing information about one’s own weaknesses or incidents is crucial. Confidentiality agreements, clear governance rules, and above all, building relationships and understanding of common goals serve this purpose.

Although formally teams operate within their sectors, they increasingly recognize the need for cross-sectoral cooperation. This results from growing interdependencies between industries - for example, financial system stability depends on reliable energy supplies, which in turn depends on traffic control system security. Therefore, teams establish contacts, exchange experiences, and in some countries even create cross-sectoral working groups.

What does the Single Point of Contact do?

The Single Point of Contact (SPOC) is a key element of the National Cybersecurity System architecture, responsible for ensuring smooth cooperation and information exchange with European Union institutions and other member states in cybersecurity. Its role and tasks are defined by the law on the national cybersecurity system, implementing the EU NIS (Network and Information Security) directive.

In Poland, the SPOC function is performed by the Team for the Single Point of Contact, operating within the Ministry of Digitalization. Its composition includes representatives of key KSC institutions - including the Internal Security Agency, Ministry of National Defense, Ministry of Foreign Affairs, and national-level CSIRT teams.

The main task of SPOC is ensuring effective cross-border cooperation in cybersecurity. It serves as a central point for information exchange between Polish KSC entities and their counterparts in other EU countries. Through it, reports of serious incidents affecting two or more states, requests for support in handling such incidents, and information about identified cross-border threats are transmitted.

SPOC is also responsible for representing Poland in the Cooperation Group established under the NIS directive. This group serves strategic cooperation and information exchange between member states, the European Commission, and ENISA (European Agency for Cybersecurity). SPOC participates in its work, presenting Poland’s position, sharing experiences and good practices, as well as obtaining knowledge and partner support.

An important aspect of SPOC’s activity is coordinating Polish entities’ participation in European and international cybersecurity exercises (such as Cyber Europe or Locked Shields). SPOC is responsible for recruiting participants, ensuring information flow, and after exercises - for analyzing conclusions and recommendations.

SPOC also serves as a contact point for essential service operators and digital service providers regarding reporting serious incidents of cross-border nature. It receives such reports, passes them to appropriate national and foreign CSIRTs, monitors the handling process, and if needed - coordinates cooperation between involved entities.

Not insignificant is SPOC’s role in building awareness and cybersecurity competences at the EU level. It participates in European information campaigns, conferences, training programs. It shares Polish experiences and good practices, while drawing on partner knowledge, promoting best solutions domestically.

The effectiveness of SPOC’s operation largely depends on smooth coordination and information flow within the team itself, as well as between it and other KSC entities. Clearly defining roles and procedures, ensuring secure communication channels, and above all - building a culture of cooperation and trust is crucial.

Although formally SPOC performs the role of a “single” contact point, in practice it closely cooperates with many partners - both at national and European levels. Its effectiveness largely depends on the quality of these relationships, ability to build consensus, and efficient operation in a complex, multi-entity environment.

Who is responsible for cybersecurity in individual sectors?

Responsibility for cybersecurity in individual economic and administration sectors is distributed among many entities, creating a multi-level and multi-entity system defined in the law on the national cybersecurity system.

At the strategic level, authorities competent for cybersecurity matters play a key role. These are ministers heading government administration departments that include individual sectors (e.g., Minister of Climate and Environment for the energy sector, Minister of Infrastructure for the transport sector, Minister of Health for the healthcare sector). They are responsible for implementing cybersecurity policy in their departments, supervising essential service operators, cooperating with CSIRTs and other KSC entities.

At the operational level, main responsibility rests with essential service operators. These are entities, public or private, providing services of key importance for maintaining critical social or economic activity, listed in the law’s annex (e.g., energy enterprises, transport, banks, hospitals). They must implement appropriate technical and organizational measures to ensure security of their information systems, report incidents, cooperate with CSIRTs.

Sectoral cybersecurity teams, established by operators from a given industry, also play an important role. They serve threat information exchange, developing common security standards, coordinating actions in case of incidents. They provide a platform for cooperation and competence building within the sector.

The role of digital service providers (such as cloud computing, internet search engines, e-commerce platforms) cannot be overlooked. Although they are not directly assigned to specific sectors, their services are crucial for many industries’ functioning. They are subject to a special regime defined in the law, including the obligation to implement appropriate security measures and report serious incidents.

Sectoral regulators also perform an important function, such as the Office of Electronic Communications (for telecommunications and postal services), the Financial Supervision Authority (for banking and insurance), the Energy Regulatory Office (for electricity and gas). Although they don’t have direct cybersecurity competences, through their general supervisory and regulatory powers, they influence security standards in supervised industries.

Finally, the role of end users - citizens, enterprises, offices using services from a given sector - cannot be overlooked. Through their choices and behaviors (e.g., care for cyber hygiene, incident response), they co-create the overall security level. That’s why educational and awareness-raising activities aimed at a wide audience are so important.

Summarizing, responsibility for cybersecurity in individual sectors is distributed among many entities, connected by a network of dependencies and interactions.

The key to effectiveness is smooth coordination and cooperation between them, based on clear role division, effective information exchange, and continuous competence improvement. Only a holistic, systemic approach can ensure an appropriate level of protection against constantly evolving threats in cyberspace.

What are the obligations of essential service operators?

Essential service operators are entities of particular importance for state and economy functioning, providing services of key importance for maintaining critical social or economic activity. Their list is defined in the annex to the law on the national cybersecurity system and includes, among others, energy enterprises, transport, banks, hospitals.

Due to their critical role, essential service operators are subject to special obligations regarding cybersecurity. Key among them are:

  • Implementation of a security management system in the information system used to provide an essential service. This system must take into account best practices, standards, and recommendations in cybersecurity, be regularly audited and improved.

  • Conducting systematic risk assessments related to cyber threats and implementing adequate preventive and corrective measures. These measures must be proportional to identified risk and compliant with current technical knowledge state.

  • Collecting and registering data on incidents affecting the provided essential service, including their occurrence and detection time, actions taken, and their effects.

  • Immediate reporting of serious incidents (within 24 hours of detection) to the appropriate national-level CSIRT. The report must include, among others, incident description, its effects, remedial actions taken and planned.

  • Cooperation with the appropriate CSIRT in handling reported incidents, including providing necessary information and explanations, following transmitted recommendations and instructions.

  • Participation in sectoral cybersecurity team, including active participation in threat and incident information exchange, developing common standards and good practices.

  • Designating a person responsible for maintaining contacts with national cybersecurity system entities (so-called contact point) and providing them with necessary resources and competences.

  • Conducting regular security audits of the information system used to provide essential service, not less frequently than once every 2 years.

  • Ensuring possibility of inspection by authorities competent for cybersecurity, including making documentation available, providing explanations, demonstrating security measure functioning.

  • Complying with orders, warnings, and recommendations issued by authorities competent for cybersecurity in connection with detected vulnerabilities or incidents.

It’s worth emphasizing that the above obligations are minimal - operators may (and often should) implement additional security measures resulting from their sector’s specifics, scale of operations, or particular risk conditions.

Fulfilling these obligations requires significant investments from operators - in technologies, processes, and above all, in people. Building a cybersecurity culture in the organization, based on threat awareness, responsibility for security, and continuous competence improvement is crucial.

At the same time, consequences of not fulfilling obligations can be severe - from financial penalties, through limitation of service provision possibilities, to loss of reputation and customer trust. Therefore, for essential service operators, cybersecurity must become an integral part of business and operational strategy.

Who supervises digital service providers?

Digital service providers, such as cloud computing, internet search engines, or e-commerce platforms, play an increasingly important role in economy and society functioning. Their services are used by millions of citizens and enterprises, and potential security incidents can have far-reaching consequences. Therefore, they are subject to a special supervision regime in cybersecurity, defined in the law on the national cybersecurity system.

The main authority supervising digital service providers in Poland is the minister competent for informatization (currently the Minister of Digitalization). They are responsible for monitoring provider compliance with the law, including checking their fulfillment of obligations regarding information system security and incident reporting.

The Minister of Digitalization maintains a register of digital service providers subject to statutory obligations. This register is public and available on the ministry’s website. Providers are obligated to register within 30 days of starting service provision.

In case of finding violation of law provisions by a provider, the Minister of Digitalization may apply various supervisory measures - from recommendations and warnings, through imposing obligation to remove identified irregularities, to imposing financial penalties (up to 200,000 PLN).

However, it’s worth noting that due to the cross-border nature of digital services, supervision over their providers is largely European. The law on the national cybersecurity system implements the NIS directive in this respect, which harmonizes security requirements and incident reporting for digital service providers across the EU.

According to the “country of origin” principle, a digital service provider is subject to jurisdiction and supervision of the member state where it has its main seat in the EU (or if it has no seat in the EU - the state where it designated a representative). This means that Polish supervisory authority may have limited possibilities for direct action against providers based in other EU countries.

However, this doesn’t mean such providers are beyond control. Supervisory authorities from different member states closely cooperate, exchange information, and coordinate actions through the NIS Cooperation Group. In case of cross-border incident or regulation violation, the country of origin authority may take action on request or in consultation with authorities of other interested states.

Moreover, some aspects of digital service provider activities may be subject to supervision by other authorities, depending on service specifics. For example, personal data processing by providers is subject to supervision by the President of the Personal Data Protection Office regarding GDPR compliance.

Finally, the role of digital service users themselves cannot be overlooked. Through their choices and reactions (e.g., reporting incidents, choosing providers caring for security), they can exert pressure on providers to prioritize cybersecurity issues.

Summarizing, supervision over digital service providers in cybersecurity is exercised at many levels - from national, through European, to market. The key to effectiveness is close cooperation and action coordination between all involved entities, based on clear rules and procedures.

What role do cybersecurity authorities play?

Authorities competent for cybersecurity are key institutions in the country’s cybersecurity management system, responsible for implementing state policy in this area at the sectoral level. Their role and tasks are defined by the law on the national cybersecurity system.

Competent authorities are generally ministers heading government administration departments that include individual economic sectors crucial for state and citizen security (e.g., Minister of Climate and Environment for energy sector, Minister of Finance for banking sector, Minister of Health for healthcare sector). In some cases, this function is performed by central government administration authorities (e.g., Financial Supervision Authority for financial market infrastructure sector).

A key task of competent authorities is identifying essential service operators in sectors they supervise. Through administrative decisions, they recognize a given entity as an essential service operator, taking into account criteria defined in the law (including dependency of a given service on information systems, negative effects of its provision disruption for public safety, health, security, and public order).

After designation, competent authorities exercise ongoing supervision over essential service operators. They monitor their fulfillment of statutory obligations, such as implementing security management systems, reporting incidents, participating in sectoral cybersecurity teams. In case of finding irregularities, they may issue recommendations, impose obligation to remove deficiencies, and ultimately - impose financial penalties.

An important power of competent authorities is the ability to conduct inspections at essential service operators. They may request documentation presentation, explanations, and even demonstration of information system and security measure functioning. The inspection’s purpose is verifying law compliance and assessing actual cybersecurity level.

Competent authorities also play a key role in incident management. They receive reports of serious incidents from operators, assess their impact on essential service provision, supervise the incident handling process by appropriate CSIRTs. In case of incidents of sectoral or national significance, they coordinate actions of various entities and cooperate with the Plenipotentiary for Cybersecurity.

No less important is the regulatory function of competent authorities. Within their competences, they may issue regulations and guidelines specifying statutory requirements, adapted to a given sector’s specifics. For example, they may define detailed criteria for recognizing incidents as serious, report formats, minimum requirements for security management systems.

Competent authorities are also engaged in building competence and cybersecurity awareness in their sectors. They organize training, workshops, conferences for essential service operators. They promote good practices, standards, recommendations. They support development of sectoral cybersecurity teams as platforms for knowledge and experience exchange.

Finally, competent authorities represent their sectors in national and international dialogue on cybersecurity. They participate in the work of the Cybersecurity Committee, cooperate with the Plenipotentiary, CSIRTs, other competent authorities. At the EU forum, they take part in the NIS Cooperation Group work, sharing Polish experiences and drawing on good practices of other member states.

Summarizing, authorities competent for cybersecurity perform the role of cybersecurity “hosts” in individual economic sectors crucial for state and citizen security. Through their regulatory, supervisory, and coordination activities, they ensure implementation of uniform high cybersecurity standards, adequate to a given sector’s specifics. They are a key link connecting the strategic level (state policy) with the operational level (individual entity actions).

What does cybersecurity responsibility look like at the organizational level?

Although the National Cybersecurity System creates legal and institutional frameworks for cyberspace protection at the state level, ultimately it’s at the level of individual organizations - companies, offices, institutions - that the daily battle for information system and data security is fought. It’s there that specific safeguards, procedures, and good practices are implemented. And it’s there that potential incidents have the most direct consequences.

According to the principle of entity responsibility, each organization is itself responsible for the security of its systems and services. In case of essential service operators and digital service providers, these obligations are additionally defined in the law on the national cybersecurity system. But even entities not covered by the law are not exempt from responsibility - it results at least from general provisions on personal data protection (GDPR), trade secrets, or due diligence.

At the organizational level, responsibility for cybersecurity is usually divided between different roles and functions. Ultimate responsibility lies with management (board, general director), which must ensure that cybersecurity is treated as an integral element of risk management and business strategy. It’s at this level that key decisions regarding security investments, acceptable risk level, and incident response priorities are made.

Direct supervision over cybersecurity is usually exercised by a designated member of management (e.g., Chief Information Security Officer - CISO). They are responsible for developing and implementing security policy, supervising the IT security team, reporting to the board, and contacts with external entities (e.g., supervisory authorities, CSIRTs).

The IT security team, consisting of specialists such as system administrators, security analysts, penetration testers, plays a key role. On a daily basis, they monitor systems for threats, respond to incidents, implement technical and organizational security measures. In large organizations, such a team may number dozens of people and be divided into specialized sub-teams (e.g., SOC - Security Operations Center, incident response team, vulnerability management team).

However, cybersecurity cannot be reduced to just the IT department. Other functions also play an important role, such as risk management, internal audit, compliance, personal data protection, business continuity, training. Their engagement is necessary to ensure a comprehensive, integrated approach to cybersecurity throughout the organization.

Finally, the responsibility of each individual employee, regardless of position, cannot be overlooked. It’s often their actions - clicking suspicious links, using weak passwords, carelessness when processing data - that are the starting point for incidents. That’s why regular training, building threat awareness, and promoting good cyber hygiene practices are so important.

It’s also worth emphasizing that an organization’s responsibility doesn’t end with its own systems. Increasingly, key processes are implemented in supply chains, engaging many external partners, subcontractors, suppliers. The organization must ensure that security requirements are met at every stage of this chain, through appropriate contract provisions, audits, tests.

Summarizing, at the organizational level, responsibility for cybersecurity is distributed among many roles and functions, from management to individual employees. The key to effectiveness is clear division of responsibilities, smooth communication and coordination, and above all - building a cybersecurity culture where everyone feels responsible for protecting common information assets. This is a difficult task, requiring constant attention and commitment, but absolutely necessary in the era of advancing digitalization.

Who in companies and institutions is responsible for implementing KSC requirements?

Implementing National Cybersecurity System requirements in companies and institutions recognized as essential service operators or digital service providers is a complex process, engaging many people and functions in the organization. Ultimate responsibility rests with top management, but practical implementation is usually delegated to lower levels.

A key figure here is the person responsible for maintaining contacts with national cybersecurity system entities, colloquially called “cybersecurity liaison officer.” The KSC law imposes on essential service operators and digital service providers the obligation to designate such a person and report their data to the appropriate supervisory authority.

The liaison officer serves as a single contact point for CSIRTs, competent authorities, and other KSC entities. They transmit reports of serious incidents, receive warnings and recommendations, coordinate cooperation with external entities in cybersecurity. They must have appropriate knowledge, competences, and authorizations to effectively perform this function.

However, merely designating a liaison officer is not enough. They must have support and engagement from the entire organization. Top-level management (board, general director) plays a key role here. Ultimate responsibility for KSC regulation compliance and providing necessary resources - human, technical, financial - rests with them. They must ensure that KSC requirements are included in the organization’s security strategy and policy, and their implementation is treated as a priority.

Direct supervision over KSC requirement implementation is usually exercised by the Chief Information Security Officer (CISO) or another person responsible for cybersecurity in the organization. Together with their subordinate team, they develop an implementation plan, assign tasks, monitor progress, report to management. They must closely cooperate with the liaison officer, providing them with necessary substantive and organizational support.

Implementing individual KSC requirements requires engagement from many departments and specialists. The IT team is responsible for implementing technical security measures, such as malware protection systems, firewalls, intrusion detection systems. The legal department analyzes statutory requirements and develops necessary internal regulations. HR organizes training and builds awareness among employees. Internal audit and compliance monitor compliance with regulations and standards.

The role of external partners cannot be forgotten either. Many organizations use services of consulting, legal, technological firms when implementing KSC requirements. Their expertise and experience can be invaluable, especially for entities that don’t have extensive own resources. However, even with external support, ultimate responsibility always remains with the organization.

Finally, the role of rank-and-file employees cannot be overlooked. Through their daily actions, they implement the organization’s security policy. They must be aware of KSC requirements, understand their obligations, know how to recognize and report incidents. Without their engagement, even the best procedures and technologies will be ineffective.

Summarizing, implementing KSC requirements in companies and institutions is a task for the entire organization, from top management to individual employees. It requires clear division of roles and responsibilities, smooth coordination, and above all - organizational culture change, where cybersecurity becomes a priority for everyone. This is a process requiring time, resources, and constant commitment, but necessary to meet the challenges of contemporary cyberspace.

What obligations do designated cybersecurity contact persons have?

Persons designated for cybersecurity contacts, colloquially called “cybersecurity liaison officers,” perform a key role in ensuring smooth communication and cooperation between essential service operators or digital service providers and National Cybersecurity System entities. Their obligations are defined in the law on the national cybersecurity system.

The basic task of a liaison officer is performing the function of a single contact point for national, sectoral, and own level CSIRTs, as well as for authorities competent for cybersecurity. This means that all communication between these entities and the organization should go through the liaison officer.

In practice, the liaison officer is responsible for transmitting to appropriate CSIRTs reports of serious incidents that affected the organization’s information systems. They must do this immediately, no later than within 24 hours of incident detection. The report must contain information specified in the law, such as incident description, its effects, remedial actions taken and planned.

But communication also works the other way. The liaison officer receives warnings, orders, and recommendations from CSIRTs and competent authorities regarding cybersecurity. They must ensure these reach the appropriate people in the organization (e.g., IT department, board) and are properly handled. In case of orders from competent authorities (e.g., order to remove vulnerability), they must supervise their execution and report back.

The liaison officer is also responsible for coordinating the organization’s cooperation with CSIRTs and competent authorities regarding incident handling. They must ensure that CSIRTs receive all necessary information and support from the organization, and at the same time, that CSIRT actions are appropriately understood and implemented in the organization.

An important obligation of the liaison officer is also maintaining current and complete organization contact data in registers maintained by CSIRTs and competent authorities. They must report any changes to this data (e.g., address change, person performing officer function) within the statutory 14-day period.

The liaison officer should also actively participate in sectoral cybersecurity team work, if one was created for the industry in which the organization operates. This means participating in meetings, exchanging threat and incident information, cooperating in developing common standards and good practices.

No less important is the liaison officer’s role within the organization. They should act as a cybersecurity ambassador, promoting threat awareness and good practices among employees. They should closely cooperate with the IT department, information security department, internal audit, ensuring coherent and effective implementation of KSC requirements.

Finally, the liaison officer should constantly monitor the threat landscape, follow new trends and technologies in cybersecurity, participate in training and conferences. They must care for their continuous professional development to effectively perform their function in a dynamically changing environment.

Summarizing, the role of person designated for cybersecurity contacts is multidimensional and demanding. It requires not only technical knowledge but also communication, coordination, and even diplomatic skills. This is a role of key importance for ensuring smooth organization functioning within the National Cybersecurity System.

Who controls and enforces KSC regulation compliance?

Control and enforcement of compliance with the law on the national cybersecurity system (KSC) is a key element of ensuring the entire system’s effectiveness and coherence. Authorities competent for cybersecurity, indicated in the law, are primarily responsible for these tasks.

For most sectors, competent authorities are ministers heading government administration departments that include given sectors. For example, for the energy sector, the competent authority is the Minister of Climate and Environment, for the transport sector - the Minister of Infrastructure, and for the healthcare sector - the Minister of Health. In some cases, the function of competent authority is performed by central government administration authorities, e.g., the Financial Supervision Authority for the banking and financial market infrastructure sector.

Competent authorities have broad control powers over essential service operators and digital service providers in sectors they supervise. They may conduct planned inspections (according to annual inspection plan) and ad hoc inspections (in response to incidents or other signals of potential irregularities).

During inspection, authority representatives have the right to enter premises, view documents, request explanations, conduct information system inspections. They may also commission external expertise if inspection specifics require it. The operator or provider is obligated to ensure conditions and means necessary for smooth inspection conduct.

If inspection finds irregularities (e.g., lack of implementing appropriate security measures, failure to report serious incident), the competent authority may apply various corrective measures and sanctions. Depending on violation severity, these may be:

  • Post-inspection recommendations, with deadline for removing irregularities.

  • Order to remove vulnerability within specified time.

  • Order to suspend, limit, or cease digital service provision or essential service implementation.

  • Financial penalty up to 200,000 PLN.

It’s worth noting that financial penalties may be imposed not only on legal entities but also on individuals performing managerial functions, if their negligence led to regulation violation.

Beyond inspections, competent authorities also monitor KSC regulation compliance through analysis of documentation and reports submitted by operators and providers (e.g., incident reports, security audit results). In case of doubts or incomplete data, they may request additional explanations or initiate ad hoc inspection.

National-level CSIRTs also play an important role in enforcing KSC regulations. Although they don’t have formal control powers, in practice they’re often the first point where irregularities are detected (e.g., failure to report incident, non-compliance with issued recommendations). In such situations, CSIRTs refer the matter to the appropriate authority to initiate inspection proceedings.

The role of the Government Plenipotentiary for Cybersecurity cannot be overlooked either. Although they don’t have direct control powers, they supervise and coordinate the entire KSC functioning. They may request information and reports from competent authorities, analyze their control action effectiveness, propose legislative and organizational changes to improve the regulation enforcement system.

Finally, external auditors, hired by operators and providers to conduct mandatory security audits, may play a certain role in controlling KSC regulation compliance. Although formally they’re not part of the state control system, in practice they often identify irregularities and formulate recommendations, which then become the subject of interest for competent authorities.

Summarizing, the KSC regulation control and enforcement system is multi-level and engages many entities, with competent authorities playing a key role. Its effectiveness depends on clear competence division, smooth information exchange, and above all - determination in law enforcement. Only consistent and proportional application of corrective measures and sanctions can ensure that KSC requirements are taken seriously by all system entities.

What control powers do cybersecurity authorities have?

Authorities competent for cybersecurity, indicated in the law on the national cybersecurity system (KSC), have broad control powers over essential service operators and digital service providers in sectors they supervise. These powers are a key tool for ensuring law compliance and maintaining high cybersecurity levels in systems of critical importance for state and economy functioning.

The basic power is the ability to conduct planned and ad hoc inspections. Planned inspections are carried out according to annual inspection plan, developed by the competent authority. This plan should take into account risk analysis results and prioritize entities and systems of greatest significance or highest threat level. Ad hoc inspections are conducted as needed, in response to incidents, complaints, media reports, or other signals of potential irregularities.

During inspection, authorized authority representatives have the right to:

  • Enter premises, facilities, and systems of the inspected entity.

  • View documents, data, and information related to inspection subject, regardless of storage medium.

  • Request oral and written explanations from inspected entity employees.

  • Conduct inspections of information systems, infrastructure, devices, data carriers.

  • Commission external expertise if inspection specifics require it (e.g., malware analysis, penetration tests).

The inspected entity is obligated to ensure conditions and means necessary for smooth inspection conduct, including making documents available, providing explanations, ensuring system access. Hindering or thwarting inspection may itself constitute law violation and basis for imposing sanctions.

Beyond on-site inspections, competent authorities also have the right to request from operators and providers transmission of specific cybersecurity-related information and documents, such as:

  • Internal security audit results.

  • Risk assessment documentation and risk management plans.

  • Security policies and procedures.

  • Incident register.

  • Business continuity and disaster recovery plans.

Authorities may also conduct explanatory proceedings in case of suspected law violation, summon witnesses, seek expert opinions.

If inspection or explanatory proceedings find irregularities, the competent authority may apply a range of corrective measures and sanctions, from post-inspection recommendations, through orders to remove vulnerabilities or suspend service provision, to financial penalties. Measure choice depends on violation severity, its potential cybersecurity effects, and inspected entity’s attitude.

An important power of competent authorities is also the ability to publicly warn about detected cybersecurity threats, if it’s in the public interest. They may publish information about incidents, vulnerabilities, attacks, along with recommendations for users and system administrators. They must care for sensitive information confidentiality and not disrupt ongoing proceedings.

Finally, competent authorities have the right and obligation to cooperate with other KSC entities, particularly CSIRTs and the Plenipotentiary for Cybersecurity, as well as with law enforcement and judicial authorities. They may pass information about detected incidents and violations to them, coordinate control actions, exchange experiences and good practices.

Summarizing, control powers of authorities competent for cybersecurity are broad and give them powerful tools for enforcing KSC regulations. However, with this power comes great responsibility. Authorities must use their powers proportionally, without excessive burden on inspected entities, respecting their rights and legitimate interests. They must care for obtained information confidentiality, avoid conflicts of interest, act transparently and subject to control. Only this way can they build trust and partnership relations with supervised sectors, which is key to the entire cybersecurity system’s effectiveness.

Who can impose penalties for non-compliance with KSC requirements?

The law on the national cybersecurity system (KSC) provides for the possibility of imposing financial penalties on entities that don’t comply with its provisions. This is one of the strictest tools for enforcing obligations by essential service operators, digital service providers, and other KSC entities. However, due to potentially severe financial and reputational consequences, it’s also a tool that must be used with great caution and within strictly defined legal frameworks.

According to the law, financial penalties may be imposed by authorities competent for cybersecurity. These are, let’s recall, ministers heading government administration departments that include individual economic sectors crucial for state and citizen security (e.g., Minister of Climate and Environment for energy sector, Minister of Infrastructure for transport sector), and in some cases - central government administration authorities (e.g., Financial Supervision Authority for banking sector).

Competent authorities may impose a financial penalty by administrative decision, after conducting inspection or explanatory proceedings. A penalty may be imposed if the authority finds that the entity doesn’t fulfill obligations specified in the law, such as:

  • Implementing effective information security management systems.

  • Reporting serious incidents within statutory timeframe.

  • Removing vulnerabilities and complying with competent authority orders.

  • Cooperating with CSIRTs and sectoral cybersecurity teams.

  • Conducting security audits.

  • Ensuring conditions for inspection by competent authorities.

Penalty amount is specified in the law and may be up to 200,000 PLN. When determining penalty amount, the competent authority must take into account several factors, such as:

  • Violation severity and its potential cybersecurity effects.

  • Violation duration.

  • Actions taken by entity to remove violation and prevent similar violations in future.

  • Previous violations of law provisions by given entity.

  • Entity’s cooperation with competent authority during inspection and proceedings.

Importantly, penalties may be imposed not only on entities (legal persons) but also on individuals performing managerial functions, if their negligence led to regulation violation. This applies to, for example, board members, directors responsible for IT or information security.

An appeal to higher authority (e.g., to appropriate minister, if penalty was imposed by central administration authority) is available against penalty decision. Appeal must be filed within 14 days of receiving decision. In case decision is upheld, entity may still file complaint to provincial administrative court.

It’s worth noting that imposing financial penalty doesn’t exclude other corrective measures and sanctions provided in the law, such as order to remove vulnerabilities or limit service provision. Competent authorities have great freedom in selecting tools adequate to the situation.

Summarizing, the right to impose financial penalties for non-compliance with KSC regulations lies with authorities competent for cybersecurity. This is a powerful tool that can significantly impact KSC entity functioning and finances. That’s why it’s so important that authorities apply it thoughtfully, proportionally, and transparently, with full respect for inspected entity rights.

On the other hand, the very possibility of imposing severe penalties is an important factor motivating entities to treat statutory obligations with utmost seriousness. In a world where cyber threats evolve at breakneck speed, and incident consequences can be catastrophic, there’s no room for treating cybersecurity as an optional add-on. It must be an integral element of risk management, business continuity, and every organization’s responsibility.

Competent authorities, by imposing penalties, send a clear signal that the state takes cybersecurity seriously and expects the same from essential service operators and digital service providers. At the same time, reasonable penalty application, combined with advice, support, and positive motivation, can build a cybersecurity culture based on cooperation and trust between administration and private sector.

It’s a delicate balance, requiring from competent authorities not only formal competences but also wisdom, sensitivity, and relationship-building skills. Penalties should be a last resort, used when other measures fail. Priority should be preventing violations, education, supporting entities in continuously improving their security systems.

It’s also worth remembering that penalties alone, though necessary, won’t solve the cyber threat problem. This is a complex challenge requiring a comprehensive approach - from education and awareness-building, through investments in technologies and people, to international cooperation and good practice exchange. KSC creates a framework for such an approach, but its effectiveness depends on all participants’ engagement - administration, business, scientific communities, citizens.

In this context, the right to impose penalties appears as an important but only one element of a larger puzzle. Elements that must work together, creating synergy and building cybersecurity culture as shared responsibility.

This is a responsibility from which there’s no escape. In a world where almost every aspect of our lives depends on digital technologies, ensuring cyberspace security becomes a matter of state, a condition of sovereignty and prosperity of the state and citizens. KSC, with its control and enforcement mechanisms, including financial penalties, is an important tool for implementing this responsibility. A tool that must be used wisely but firmly, in the name of common good.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist