Insights / Compliance
Cyber hygiene at work — what the act requires and how to prove it
The Polish Act on the National Cybersecurity System lists „basic cyber hygiene practices" among the mandatory measures, but nowhere defines them. That is not an oversight by the legislator — the content is deliberately left to the organisation. Below is a concrete scope you can implement and show to an inspector.
Where exactly the duty sits
In Article 8(1)(2) of the act, in the list of technical and organisational measures that the information security management system of an essential or important entity must cover:
(j) „basic cyber hygiene practices"
These are two separate points and it is worth noticing, because they get conflated. Education is an activity — you train people. Cyber hygiene is a state maintained day to day: a set of habits and settings that apply regardless of when the last training took place. Demonstrating one does not discharge the other.
Both come from the NIS2 directive — its Article 21(2)(g) requires „basic cyber hygiene practices and cybersecurity training". The directive's recitals hint at what that covers: zero-trust principles, software updates, device configuration, network segmentation, identity and access management, and user awareness, including training on phishing and social engineering techniques.
Eight areas that make up cyber hygiene
The scope below is not a quotation from the act — it is a practical expansion of the directive's guidance in a form you can put into a policy and tick off during an audit.
| Area | A defensible minimum | Evidence for an audit |
|---|---|---|
| Authentication | MFA on email, VPN and privileged accounts; a password manager instead of reused passwords | MFA coverage report from the identity directory |
| Updates | Automatic patching of systems and browsers; a maintenance window for servers | Compliance report against the patching policy |
| Access management | Least privilege, access reviews at least once a year, immediate revocation on departure | Review register, offboarding checklist |
| Backups | An offline or immutable copy; a test restore, not merely a backup taken | A dated record of a test restore |
| Device configuration | Disk encryption, screen lock, USB media control, MDM for phones | Policy export from the management console |
| Email and domain | SPF, DKIM and DMARC in enforcing mode; external mail tagging | DNS record export and DMARC reports |
| Incident reporting | One known channel, known to every employee; a no-blame reporting culture | The procedure plus statistics on employee reports |
| Awareness | Recurring training with knowledge verification and regular phishing simulations | Completion register, campaign results |
Why this is not a list for the IT department
Half of the items above depend on the behaviour of ordinary users, not on a server configuration. MFA is bypassed through notification fatigue, not by breaking cryptography. A password manager does not help if the master password is on a sticky note. A reporting channel does not work if people are afraid to admit they clicked.
How often to refresh it
The act gives no frequency for staff cyber hygiene — it gives one only for management: Article 8e(1) requires training once every calendar year, and paragraph 3 adds that participation must be documented. For everyone else, a sensible rhythm that stands up as „appropriate and proportionate to the risk" looks like this:
| Activity | Frequency | Rationale |
|---|---|---|
| Onboarding training for a new employee | on hiring | The highest risk sits with people who do not know the procedures |
| Refresher training for staff | once a year | Consistent with the management cycle in Art. 8e |
| Short thematic modules | quarterly | Sustains alertness between annual sessions |
| Phishing simulation | quarterly | Measures the actual state, not the declared one |
| Management training | once every calendar year | An explicit requirement — Art. 8e(1) and (3) |
Four mistakes that ruin the evidence
- A policy with no acknowledgement. A document on the intranet proves nothing about anyone having read it. Article 8d(4) speaks of ensuring that personnel „are aware" — an obligation of result.
- Training without knowledge verification. An attendance list shows who was in the room. A test score shows who understood.
- Treating a simulation as employee surveillance. A public list of who clicked destroys the reporting culture and creates employment-law risk. See phishing simulations and the GDPR.
- A one-off push before an audit. Cyber hygiene is a continuous state — one session from three years ago demonstrates nothing except that the subject was once noticed.
Where to start if there is nothing
The order that buys the most coverage for the least cost:
- Week 1 — MFA on email and administrative accounts. The single change that eliminates the most account-takeover scenarios.
- Week 2 — one channel for reporting suspicious messages, plus a clear message that reporting never ends in consequences.
- Month 1 — baseline training for all staff with a knowledge test and a named completion register.
- Month 2 — a first phishing simulation as a baseline measurement, without communicating individual results.
- Month 3 — management training covering the scope in Art. 8e(2), and completing the documentation.
Cyber hygiene with the evidence included
The platform delivers the training, verifies knowledge with a test and generates named, dated certificates — separately for staff and for management. Tell us how many employees you have and in which roles, and we will send back a proposed training path with a quote.