KS-CYBER_

Insights / Data

Cybersecurity in Poland — what the CERT Polska data for 2025 shows

Updated: August 2026 · about 7 min read

Poland's national CSIRT teams handled 272,941 incidents in 2025 — 144.4% more than the year before. The number that matters most to a company is a different one, though: 97% of the incidents handled by CERT Polska were computer fraud, meaning phishing and investment scams. Not exploits, not zero-days. Messages sent to people.

Scale: 1,800 reports a day

The figures come from the CERT Polska annual report for 2025 and from „The Cyberspace Landscape", the report on the state of Poland's cybersecurity published by the Ministry of Digital Affairs.

Indicator (2025)ValueYear-on-year
Reports to national CSIRTs682,245
Incidents handled (total)272,941+144.4%
Incidents — CSIRT NASK260,783+152%
Incidents — CSIRT MON7,125+69%
Incidents — CSIRT GOV5,033+26.1%
Reports to CERT Polska658,320+10%

Per day that is over 1,800 reports, of which more than 700 are classified as incidents. Note the divergence between two of those numbers — reports rose by 10%, incidents by 152%. That does not mean Poles suddenly started reporting more often. It means the same stream of reports now contains far more genuine attacks.

97% is fraud — that is, an attack on a person

The largest category of incidents handled by CERT Polska remains computer fraud — phishing and investment scams. They account for 97% of all incidents recorded in 2025.

What that means operationally. If 97 in every 100 incidents begin with a message that someone opened, clicked or replied to, then a security budget spent exclusively on the technical layer protects the minority of cases. A spam filter will stop most of it, but it is the few per cent that get through where the recipient's reaction decides the outcome.

That proportion is also the answer to a question boards often ask: „why train people when we have good antivirus?" Antivirus works against malware, and that is roughly 3,500 incidents a year. Fraud is counted in hundreds of thousands.

Malware and ransomware — smaller numbers, larger single loss

CategoryIncidents in 2025Year-on-year
Malwareclose to 3,500+81%
Ransomware179+21%

179 ransomware incidents is roughly one every other day. In this category the count says little — what matters is the cost of a single case: production downtime, restoring from backup, legal handling and notifications to authorities. The 21% year-on-year rise also shows that the criminals' business model still pays.

Automated defence works, but does not replace people

It is worth knowing the scale of the mechanisms running in the background for every user in Poland:

  • The Warning List — close to 250,000 domains added in 2025 alone (up 166%), about 670 malicious domains a day. Since 2020 the list has passed half a million entries, and in 2025 it blocked 140 million access attempts.
  • The SMS reporting system (number 8080) — over 350,000 messages passed for analysis, more than 80,000 judged malicious, 790 smishing patterns identified and close to 1.88 million malicious SMS messages blocked (27% more than the year before).

These are impressive numbers, but they carry a built-in limitation: every such mechanism reacts to a pattern that has already been recognised. A domain reaches the list after somebody reported it. A campaign aimed at one company, using a domain registered that morning, will pass through those defences — and then the only filter is the person at the keyboard.

What this means for a single company

Three conclusions that translate into a decision:

Observation from the dataConsequence for the organisation
97% of incidents are fraud The main vector is email and messaging, not infrastructure, so controls aimed at human behaviour cover a larger share of events than technical safeguards alone.
Incidents +144% while reports rose 10% Attack density is rising, not vigilance. A training programme run once every few years cannot keep pace.
Ransomware every other day Backups and a recovery plan have to be tested, not merely owned. Most ransomware entries start with phishing or compromised credentials.

Where to report an incident

In December 2025 the cyber.gov.pl portal went live — a single entry point for citizens, companies and public institutions, integrating incident reporting with the S46 system and the moje.cert.pl service. For essential and important entities, reporting to the competent CSIRT is not a courtesy but a statutory duty — and its deadlines are counted in hours, not business days.

A practical note. The „Incident reporting" module should be known by every employee, not only the IT team. The most expensive incidents are the ones the security team hears about several days late, because somebody preferred not to admit they clicked.

Sources

  • CERT Polska / NASK — annual report for 2025 (nask.pl, in Polish)
  • Ministry of Digital Affairs — „The Cyberspace Landscape: report on the state of Poland's cybersecurity in 2025" (gov.pl, in Polish)
  • The cyber.gov.pl portal — incident reporting

Find out how your people handle that 97%

A controlled simulation shows the real click rate in your organisation, and the people who fall for it are assigned training immediately — with no wall of shame and no HR consequences. Tell us your headcount and we will send back the campaign scope and timing.

How a simulation works

Prefer to talk now: +48 535 740 973 · kontakt@ks-cyber.pl