KS-CYBER_

Insights / Compliance

Cyber hygiene at work — what the act requires and how to prove it

Updated: August 2026 · about 7 min read

The Polish Act on the National Cybersecurity System lists „basic cyber hygiene practices" among the mandatory measures, but nowhere defines them. That is not an oversight by the legislator — the content is deliberately left to the organisation. Below is a concrete scope you can implement and show to an inspector.

Where exactly the duty sits

In Article 8(1)(2) of the act, in the list of technical and organisational measures that the information security management system of an essential or important entity must cover:

(i) „cybersecurity education for the entity's personnel"
(j) „basic cyber hygiene practices"

These are two separate points and it is worth noticing, because they get conflated. Education is an activity — you train people. Cyber hygiene is a state maintained day to day: a set of habits and settings that apply regardless of when the last training took place. Demonstrating one does not discharge the other.

Both come from the NIS2 directive — its Article 21(2)(g) requires „basic cyber hygiene practices and cybersecurity training". The directive's recitals hint at what that covers: zero-trust principles, software updates, device configuration, network segmentation, identity and access management, and user awareness, including training on phishing and social engineering techniques.

Eight areas that make up cyber hygiene

The scope below is not a quotation from the act — it is a practical expansion of the directive's guidance in a form you can put into a policy and tick off during an audit.

AreaA defensible minimumEvidence for an audit
Authentication MFA on email, VPN and privileged accounts; a password manager instead of reused passwords MFA coverage report from the identity directory
Updates Automatic patching of systems and browsers; a maintenance window for servers Compliance report against the patching policy
Access management Least privilege, access reviews at least once a year, immediate revocation on departure Review register, offboarding checklist
Backups An offline or immutable copy; a test restore, not merely a backup taken A dated record of a test restore
Device configuration Disk encryption, screen lock, USB media control, MDM for phones Policy export from the management console
Email and domain SPF, DKIM and DMARC in enforcing mode; external mail tagging DNS record export and DMARC reports
Incident reporting One known channel, known to every employee; a no-blame reporting culture The procedure plus statistics on employee reports
Awareness Recurring training with knowledge verification and regular phishing simulations Completion register, campaign results

Why this is not a list for the IT department

Half of the items above depend on the behaviour of ordinary users, not on a server configuration. MFA is bypassed through notification fatigue, not by breaking cryptography. A password manager does not help if the master password is on a sticky note. A reporting channel does not work if people are afraid to admit they clicked.

The national data confirms it: 97% of incidents handled by CERT Polska in 2025 were computer fraud — phishing and investment scams. See the full CERT Polska figures.

How often to refresh it

The act gives no frequency for staff cyber hygiene — it gives one only for management: Article 8e(1) requires training once every calendar year, and paragraph 3 adds that participation must be documented. For everyone else, a sensible rhythm that stands up as „appropriate and proportionate to the risk" looks like this:

ActivityFrequencyRationale
Onboarding training for a new employeeon hiring The highest risk sits with people who do not know the procedures
Refresher training for staffonce a year Consistent with the management cycle in Art. 8e
Short thematic modulesquarterly Sustains alertness between annual sessions
Phishing simulationquarterly Measures the actual state, not the declared one
Management trainingonce every calendar year An explicit requirement — Art. 8e(1) and (3)

Four mistakes that ruin the evidence

  • A policy with no acknowledgement. A document on the intranet proves nothing about anyone having read it. Article 8d(4) speaks of ensuring that personnel „are aware" — an obligation of result.
  • Training without knowledge verification. An attendance list shows who was in the room. A test score shows who understood.
  • Treating a simulation as employee surveillance. A public list of who clicked destroys the reporting culture and creates employment-law risk. See phishing simulations and the GDPR.
  • A one-off push before an audit. Cyber hygiene is a continuous state — one session from three years ago demonstrates nothing except that the subject was once noticed.

Where to start if there is nothing

The order that buys the most coverage for the least cost:

  • Week 1 — MFA on email and administrative accounts. The single change that eliminates the most account-takeover scenarios.
  • Week 2 — one channel for reporting suspicious messages, plus a clear message that reporting never ends in consequences.
  • Month 1 — baseline training for all staff with a knowledge test and a named completion register.
  • Month 2 — a first phishing simulation as a baseline measurement, without communicating individual results.
  • Month 3 — management training covering the scope in Art. 8e(2), and completing the documentation.
Disclaimer. This text is an informational summary based on the Polish Act on the National Cybersecurity System (Journal of Laws 2026, item 252) and Directive (EU) 2022/2555, and is not legal advice. The scope of the duties depends on the entity's classification and its assessed risk.

Cyber hygiene with the evidence included

The platform delivers the training, verifies knowledge with a test and generates named, dated certificates — separately for staff and for management. Tell us how many employees you have and in which roles, and we will send back a proposed training path with a quote.

I'd rather look around first

Prefer to talk now: +48 535 740 973 · kontakt@ks-cyber.pl