Insights
Straight answers, without the marketing padding
We write about what people responsible for security and compliance actually ask: what the law requires, what it costs, and what you are allowed to do to your own employees.
All articles
Is security awareness training mandatory?
Articles 8, 8d and 8e of the Polish NIS2 act — what they say, who answers for them and what the fine is.
CostsWhat does security training cost?
Classroom sessions, external workshops and a platform compared — per employee.
LawPhishing simulations and the GDPR
Legal basis, the duty to inform, retention, and the line between a test and employee surveillance.
DataCERT Polska figures for 2025
272,941 incidents, up 144.4%, and 97% of them fraud. What that means for a company.
ComplianceCyber hygiene at work
The act never defines it. Eight areas, the evidence an audit wants, and four mistakes that ruin it.
ComplianceDoes NIS2 apply to my company?
Two conditions together: a covered sector and at least medium size. How to check.
ComplianceWhat are the NIS2 penalties?
A personal fine for the head of up to 300% of pay, plus administrative fines for the entity.
CostsHow much does a phishing simulation cost?
A one-off campaign from about PLN 4,500, or a platform feature from PLN 15 per employee.
TestingPentest vs vulnerability scan
A scan is an automated list; a pentest is a human exploiting the gaps. When to use which.
Who we write for
For the people who have to make a decision and defend it in front of a board or an auditor: security officers, data protection officers, IT managers and owners on whom the Polish NIS2 act placed personal liability.
We do not write „10 tips for a strong password". We write about the things that require a decision: what the provision actually says, what implementation costs, what you may do to employees and how to prove the duty was met.
How we treat the content
- We cite sources — the article number, the journal reference, the date it entered into force. Not „regulations require", but which provision exactly.
- We give numbers — rates, deadlines, fines. A text without a number rarely helps anyone decide.
- We correct myths — including those circulating in industry material, such as the famous „3 October 2026" deadline.
- We write from practice — from the social engineering campaigns and tests we run, not from someone else's summary.
Where to start
„Does this apply to us?"
Start with the training duty in the Polish NIS2 act — it sets out who is covered and what evidence you need to hold.
„What does it cost?"
Read the cost comparison worked through on a 60-person company, with the hidden cost of each option.
„Are we allowed to test like this?"
Check simulations and the GDPR — legal basis, the duty to inform and a checklist before the first campaign.
„How big is the risk?"
See CERT Polska data for 2025 — the scale of incidents in Poland and the share of attacks aimed at people.
„What do we actually implement?"
Go to cyber hygiene at work — eight areas with a defensible minimum and the evidence for an audit.
From knowing to doing
All of these duties can be closed with one tool: training, exam, certificate and a report for the audit. 14 days free, no card.