KS-CYBER_

Insights

Straight answers, without the marketing padding

We write about what people responsible for security and compliance actually ask: what the law requires, what it costs, and what you are allowed to do to your own employees.

Who we write for

For the people who have to make a decision and defend it in front of a board or an auditor: security officers, data protection officers, IT managers and owners on whom the Polish NIS2 act placed personal liability.

We do not write „10 tips for a strong password". We write about the things that require a decision: what the provision actually says, what implementation costs, what you may do to employees and how to prove the duty was met.

How we treat the content

  • We cite sources — the article number, the journal reference, the date it entered into force. Not „regulations require", but which provision exactly.
  • We give numbers — rates, deadlines, fines. A text without a number rarely helps anyone decide.
  • We correct myths — including those circulating in industry material, such as the famous „3 October 2026" deadline.
  • We write from practice — from the social engineering campaigns and tests we run, not from someone else's summary.

Where to start

If you ask

„Does this apply to us?"

Start with the training duty in the Polish NIS2 act — it sets out who is covered and what evidence you need to hold.

If you ask

„What does it cost?"

Read the cost comparison worked through on a 60-person company, with the hidden cost of each option.

If you ask

„Are we allowed to test like this?"

Check simulations and the GDPR — legal basis, the duty to inform and a checklist before the first campaign.

If you ask

„How big is the risk?"

See CERT Polska data for 2025 — the scale of incidents in Poland and the share of attacks aimed at people.

If you ask

„What do we actually implement?"

Go to cyber hygiene at work — eight areas with a defensible minimum and the evidence for an audit.

From knowing to doing

All of these duties can be closed with one tool: training, exam, certificate and a report for the audit. 14 days free, no card.