DistantNews
Support us
Poland's Critical Infrastructure Faces Serious Cybersecurity Gaps, Watchdog Warns
๐Ÿ‡ต๐Ÿ‡ฑ Poland /Energy & Infrastructure

Poland's Critical Infrastructure Faces Serious Cybersecurity Gaps, Watchdog Warns

From Rzeczpospolita · () Polish

Translated from Polish and summarized by DistantNews. Read the original for the full story.

At a glance

News Sources not specified Context piece
  • Poland's Supreme Audit Office (NIK) has identified serious cybersecurity gaps in the nation's critical infrastructure, including rail, water, and energy sectors.
  • The audit revealed that operators often ignored critical security alerts, and state oversight was insufficient.
  • These vulnerabilities pose a significant risk, as cyberattacks on infrastructure like water systems or power grids could have severe real-world consequences.

Poland's critical infrastructure is alarmingly vulnerable to cyberattacks, according to a new report by the Supreme Audit Office (NIK). The watchdog agency has highlighted significant security flaws in key sectors such as rail transport, water supply, and energy, warning that the state's oversight has been inadequate.

The control revealed serious gaps in the security of rail transport, water, and drinking water supplies.

โ€” NIKSummarizing the findings of the cybersecurity audit.

The NIK's audit, covering the period from January 2021 to February 2026, found that none of the eight audited operators ensured their systems were resilient against breaches affecting data confidentiality, integrity, availability, and authenticity. Alarmingly, six of these operators systematically ignored critical alerts generated by their monitoring and security systems. In some extreme cases, operators did not even conduct basic monitoring, leaving them unaware of potential attacks.

This lack of vigilance is particularly concerning given the increasing sophistication and frequency of cyber threats. The NIK pointed out that Poland has been one of the most frequently targeted countries globally by cybercriminals. The report emphasizes that the mechanisms of the National Cybersecurity System (KSC), established over seven years ago, have failed to effectively ensure that operators fulfill their security obligations.

The oversight of cybersecurity in these sectors by the ministers of energy and infrastructure was insufficient.

โ€” NIKHighlighting the lack of governmental supervision.

The consequences of successful cyberattacks on critical infrastructure could be devastating. The NIK cited examples such as manipulating water quality by increasing chlorine levels, posing a direct threat to public health, or gaining control of power grids, leading to widespread and prolonged blackouts. With the number of cyber incidents in Poland rising dramatically, nearly 273,000 incidents were handled by national response teams in 2025, a 144.4% increase from the previous year, these vulnerabilities represent a clear and present danger.

It is all the more worrying that more than seven years have passed since the creation of the KSC, and in 2025 Poland was one of the countries most frequently attacked by cybercriminals in the world.

โ€” NIKExpressing concern over the persistent vulnerabilities despite existing systems.
About this summary

Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.