Security versus digital risks is now a need for organizations, not an alternative

Startups

Warsaw, POLAND – Cyber risks are presently amongst the fastest-growing organization dangers dealt with by Polish business, according to information from CERT Polska and analyses provided in ERGO Hestia’s “nieOdporni” (“nonResilient”) report. The growing variety of security events CERT Polska records each year shows that cybersecurity is no longer an issue exclusively for big corporations, however likewise for little and medium-sized business.

Poland amongst the nations especially susceptible to cyberattacks

Poland is presently amongst the nations especially susceptible to cyberattacks. In the very first half of 2025, it ranked initially on the planet in regards to the variety of ransomware attacks. At the exact same time, it stays among the marketplaces with the most affordable level of cyber threat insurance protection. The scale of the danger is likewise highlighted by current events. One such event was an attack on software application coming from a business specialising in electronic medical records. The taken information included info worrying, for instance, prescriptions and the health of as numerous as 19 million individuals.

Information from the “nieOdporni” report, Mastercard and other analyses pointed out by ERGO Hestia reveal that cyberattacks and information breaches have actually impacted a substantial percentage of Polish business.

Cybersecurity of Polish services in figures

                                                                                
Indicator             Small businesses     Medium-sized    Large businesses   
                                           businesses                           
  
Experienced a           25%                  44%                 50%         
cyberattack                                                                    

Have not provided       54%                  14%                  4%                 
cybersecurity                                                                  
training                                                                       

Have an incident        18%                  -                   78%                
response plan                                                                  

Consider the risk        5%                  21%                 18%                
of a cyberattack to                                                            
be high*                                                                       
                                                                                

Information are drawn from the report entitled “Historia niejednego ataku, czyli cyberbezpieczeństwo w polskich firmach– wyniki badania Mastercard” (“A Tale of Many Attacks: Cybersecurity in Polish Companies– Mastercard Survey Results”).

* Among services that have actually currently experienced a cyberattack, this portion increases to 25%.

According to the “nieOdporni” report, 88% of Polish organisations have actually experienced a cyberattack or information breach over the last few years. At the very same time, an analysis by ScamWatchHQ pointed out in the report suggests that roughly 69% of companies in Poland have actually experienced a minimum of one cybersecurity occurrence. The distinction in between these figures arises from the various scope and method of the research studies.

Awareness of the threat is not constantly matched by readiness

Mastercard’s information expose a clear space in between the real scale of the danger and how it is viewed. An overall of 71% of small companies think about the threat of a cyberattack versus their organisation to be low, although one in 4 has actually currently experienced such an attack.

Throughout the marketplace as an entire, the issue likewise worries standard security procedures. The ScamWatchHQ report worries that just roughly 59% of Polish organizations utilize standard security software application, while more than one-third do not even have fundamental safeguards in location.

The scale of the danger is additional highlighted by information from the BIK 2025 Anti-Fraud Report. Practically 32% of SMEs experienced tried monetary scams in 2025, while 19.2% came down with a hacker attack or dealt with the threat of internal scams.

What cyber hazards impact SMEs and what are their effects?

The most typical dangers consist of ransomware attacks that obstruct access to information and systems, phishing that results in user accounts being jeopardized, Business Email Compromise (BEC) scams, the theft of client information and invasions into cloud systems.

The results of cyberattacks are multidimensional and impact practically every location of a business’s operations. The repercussions of cybersecurity breaches in the SME sector are monetary, functional, legal and reputational. The most considerable consist of:

  • monetary losses– the expenses of fixing the results of an attack, recuperating information and handling organization disturbance, along with any ransom payments in case of ransomware attacks;

  • company interruption– the momentary unavailability of IT systems might lead to the suspension of production, sales or the arrangement of services;

  • information loss– the disclosure or damage of client and worker information and service details might have long-lasting repercussions for the operation of business;

  • loss of track record and client trust– a security breach weakens a business’s trustworthiness and might result in the loss of company partners and decreased competitiveness;

  • legal and regulative effects– individual information breaches might lead to a commitment to report the event and the imposition of administrative fines under information security legislation;

  • interruption of service relationships– organization partners might restrict their cooperation with a business that stops working to guarantee a suitable level of details security;

  • theft of copyright– the loss of technical documents, styles, knowledge or trade tricks might deteriorate a business’s competitive benefit;

  • increased operating expense– following an event, companies frequently sustain extra expense on system upgrades, security audits and worker training;

  • in severe cases, a severe cybersecurity breach might threaten the ongoing operation of business.

  • restoring security software application licences;

  • preserving network and server facilities;

  • security tracking and occurrence reaction services (SOC/MDR);

  • routine system updates;

  • security audits and penetration screening;

  • cybersecurity training for workers;

  • the reimbursement of IT experts or costs for outsourced security services.

Just how much does a cyberattack expense, and just how much does cybersecurity expense?

The expense of a cyberattack might total up to numerous countless zlotys and, when it comes to severe events, surpass PLN 1 million. Analyses by cyber insurance coverage brokers (“Cyber Insurance for Small Businesses in Poland– Key Statistics 2025”, Kelot, 2025) show the list below typical loss levels depending upon the size of business:

                                                                                
Size of business                       Average loss following a cyberattack  
 
Small businesses                       PLN 50,000–200,000                     
Medium-sized businesses                PLN 200,000–500,000                    
Large businesses                       More than PLN 1 million                
                                                                                

The scale of financial investment and the repaired expenses related to keeping and enhancing cybersecurity systems in the SME sector depend mainly on the size of business, its level of digitalisation and suitable regulative requirements. For the majority of little and medium-sized business, such expense represents a substantial product in the IT budget plan.

Cybersecurity expense increases with the size of business, while the yearly spending plan for fundamental security is often times lower than the typical ransom payment of around PLN 200,000– 300,000.

The most considerable repaired expenses consist of:

Cybersecurity expense is typically approximated to represent in between 5% and 15% of the overall IT spending plan, and might reach as much as 20– 25% in higher-risk sectors such as financing and health care.

How can a service be safeguarded versus a cyberattack?

“Unlike big corporations, little and medium-sized services frequently have neither official security treatments nor innovative security systems. The lack of specialised IT or security departments makes them a much easier target for both standard crooks and cybercriminals. A cyberattack, burglary or theft might result not just in product losses, however likewise in company disturbance and information loss. Reliable defense needs tracking, gain access to control systems and physical and cyber safeguards to be incorporated into a single environment,” states Adam Śliwiński, Vice-President of the Management Board of Seris Konsalnet Security, as priced estimate in the ERGO Hestia report.

According to Tomasz Dolata, a cyber insurance coverage professional at ERGO Hestia, the most efficient method to restrict the repercussions of a cyberattack is to invest all at once in extensive insurance coverage cover and the advancement of significantly robust IT facilities. “This makes it possible both to minimize the probability of events happening and to reduce their monetary and functional repercussions,” he stresses.

The professionals priced quote in the ERGO Hestia report tension that cyber insurance coverage does not change technical safeguards such as multi-factor authentication (MFA), backups or worker training. It does, nevertheless, supply an extra layer of security that assists an organization limitation the repercussions of an occurrence when an attack is successful regardless of the safeguards in location.

What should cyber insurance coverage cover?

  1. attacks, consisting of ransomware, phishing, user account compromise and information security breaches;

  2. information healing and system remediation, in addition to digital forensics expenses;

  3. losses arising from organization disruption;

  4. liability towards clients and service partners, consisting of the settlement of claims brought by clients or partners as an outcome of an information breach or service interruption;

  5. legal expenses;

  6. expenses connected with breaches of information security legislation;

  7. crisis management, consisting of crisis interactions, interaction with clients, helpline services and procedures to restrict reputational damage;

  8. 24-hour access to occurrence reaction experts.

  9. the scope of cover and the list of threats covered, for instance whether it safeguards information saved in the cloud and covers remote working and mobile phones;

  10. exemptions from cover, for instance whether cover likewise uses when an event arises from a staff member mistake;

  11. the insured quantities and liability limitations for specific kinds of loss;

  12. the possibility of extending the cover as business establishes;

  13. the schedule of help services;

  14. the treatment and time needed for claims settlement;

  15. the quantity of the insurance policy holder’s contribution to a claim (the excess).

In addition to extensive insurance coverage cover, the policy likewise covers the services of digital forensics professionals. This is a very crucial element of cyber insurance coverage since, following an event, a company should not just restrict its repercussions, however likewise rapidly identify the source of the attack and maintain proof.

What should be thought about when picking cyber threat insurance coverage?

What should insurance coverage for little and medium-sized business consist of?

An ideal insurance coverage plan need to mainly consist of security for business home (structures, home furnishings, equipment and electronic devices), third-party liability insurance coverage, service disturbance insurance coverage, electronic devices cover, company help, legal defense and extensive cyber insurance coverage covering both the monetary effects of an occurrence and professional assistance.

Cyber insurance coverage as an extra layer of defense

As the authors of the “nieOdporni” report mention, a cyber insurance coverage supplies a monetary buffer that allows a company to make it through the effects of an effective attack by covering a ransom payment, moneying skilled support, bring back systems and covering possible fines.

“Protection versus cyberattacks is not an option in between ‘purchasing innovation’ and ‘purchasing insurance coverage’. Both are essential. Innovation and treatments decrease the probability of an attack happening in the very first location. Insurance coverage safeguards business if, in spite of its best shots, an attack however takes place,” the ERGO Hestia specialists state.

Cyber insurance coverage is likewise easily offered today, consisting of to smaller sized market individuals. According to the report gotten ready for ERGO Hestia, cyber insurance coverage is provided by a growing variety of significant insurance providers running on the Polish market, and the offered items likewise cover little and medium-sized business. The requirements troubled companies looking for cyber insurance coverage are attainable: standard safeguards such as a firewall program, multi-factor authentication (MFA), routine backups and making use of current software application supported by its producer are normally adequate.

Cyber insurance coverage does not need to be pricey. According to the ERGO Hestia report, the typical expense of cyber insurance coverage is roughly 0.14% of a business’s yearly turnover, representing just roughly 1.8% of the expenses that a company might sustain following an effective cyberattack. In practice, this suggests that the expense of the policy is typically incomparably lower than the expenditures connected with organization disruption, information loss, crisis management or liability towards clients.

Source of info: PAP MediaRoom

Contact details:

Marcin Żebrowski

[email protected]

+48 727 024 270

News release dispersed by Pressat on behalf of news aktuell, on Monday 14 September, 2026. For additional information subscribe and follow https://pressat.co.uk/


Discover more from PMN S.P.O.R.T.S - A PRIME MEDIA NETWORK BRAND

Subscribe to get the latest posts sent to your email.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here