Insights / Data
Cybersecurity in Poland — what the CERT Polska data for 2025 shows
Poland's national CSIRT teams handled 272,941 incidents in 2025 — 144.4% more than the year before. The number that matters most to a company is a different one, though: 97% of the incidents handled by CERT Polska were computer fraud, meaning phishing and investment scams. Not exploits, not zero-days. Messages sent to people.
Scale: 1,800 reports a day
The figures come from the CERT Polska annual report for 2025 and from „The Cyberspace Landscape", the report on the state of Poland's cybersecurity published by the Ministry of Digital Affairs.
| Indicator (2025) | Value | Year-on-year |
|---|---|---|
| Reports to national CSIRTs | 682,245 | — |
| Incidents handled (total) | 272,941 | +144.4% |
| Incidents — CSIRT NASK | 260,783 | +152% |
| Incidents — CSIRT MON | 7,125 | +69% |
| Incidents — CSIRT GOV | 5,033 | +26.1% |
| Reports to CERT Polska | 658,320 | +10% |
Per day that is over 1,800 reports, of which more than 700 are classified as incidents. Note the divergence between two of those numbers — reports rose by 10%, incidents by 152%. That does not mean Poles suddenly started reporting more often. It means the same stream of reports now contains far more genuine attacks.
97% is fraud — that is, an attack on a person
The largest category of incidents handled by CERT Polska remains computer fraud — phishing and investment scams. They account for 97% of all incidents recorded in 2025.
That proportion is also the answer to a question boards often ask: „why train people when we have good antivirus?" Antivirus works against malware, and that is roughly 3,500 incidents a year. Fraud is counted in hundreds of thousands.
Malware and ransomware — smaller numbers, larger single loss
| Category | Incidents in 2025 | Year-on-year |
|---|---|---|
| Malware | close to 3,500 | +81% |
| Ransomware | 179 | +21% |
179 ransomware incidents is roughly one every other day. In this category the count says little — what matters is the cost of a single case: production downtime, restoring from backup, legal handling and notifications to authorities. The 21% year-on-year rise also shows that the criminals' business model still pays.
Automated defence works, but does not replace people
It is worth knowing the scale of the mechanisms running in the background for every user in Poland:
- The Warning List — close to 250,000 domains added in 2025 alone (up 166%), about 670 malicious domains a day. Since 2020 the list has passed half a million entries, and in 2025 it blocked 140 million access attempts.
- The SMS reporting system (number 8080) — over 350,000 messages passed for analysis, more than 80,000 judged malicious, 790 smishing patterns identified and close to 1.88 million malicious SMS messages blocked (27% more than the year before).
These are impressive numbers, but they carry a built-in limitation: every such mechanism reacts to a pattern that has already been recognised. A domain reaches the list after somebody reported it. A campaign aimed at one company, using a domain registered that morning, will pass through those defences — and then the only filter is the person at the keyboard.
What this means for a single company
Three conclusions that translate into a decision:
| Observation from the data | Consequence for the organisation |
|---|---|
| 97% of incidents are fraud | The main vector is email and messaging, not infrastructure, so controls aimed at human behaviour cover a larger share of events than technical safeguards alone. |
| Incidents +144% while reports rose 10% | Attack density is rising, not vigilance. A training programme run once every few years cannot keep pace. |
| Ransomware every other day | Backups and a recovery plan have to be tested, not merely owned. Most ransomware entries start with phishing or compromised credentials. |
Where to report an incident
In December 2025 the cyber.gov.pl portal went live — a single entry point for citizens, companies and public institutions, integrating incident reporting with the S46 system and the moje.cert.pl service. For essential and important entities, reporting to the competent CSIRT is not a courtesy but a statutory duty — and its deadlines are counted in hours, not business days.
Sources
- CERT Polska / NASK — annual report for 2025 (nask.pl, in Polish)
- Ministry of Digital Affairs — „The Cyberspace Landscape: report on the state of Poland's cybersecurity in 2025" (gov.pl, in Polish)
- The cyber.gov.pl portal — incident reporting
Find out how your people handle that 97%
A controlled simulation shows the real click rate in your organisation, and the people who fall for it are assigned training immediately — with no wall of shame and no HR consequences. Tell us your headcount and we will send back the campaign scope and timing.