Services
Servicesarrow Organization security
Organization security

National Cybersecurity System

The entry into force of the act on the national cybersecurity system poses a huge challenge for entities providing key services and digital services. It is the first legal act in Poland that treats the area of security in an extremely comprehensive and efficient manner. Security in a wide range.

Security of Key / Digital Services is “achieving an appropriate level of security of information systems used to provide services and to ensure incident handling” (quotation from Art. 3 of the Act).

Therefore, we must be aware of all the areas necessary to ensure security.

We can definitely say what cybersecurity is not:

  • is not an implementation of the SIEM system,
  • is not an establishment of a SOC / CSIRT,
  • it is not the implementation of advanced security monitoring tools,
  • is not establishing attack vectors and reaction procedures,
  • it is not any single activity referred to so far in the literature on the implementation of the NIS Directive.

Unfortunately, very often the implementation of the NIS directive (and thus the Cyber Act) is understood as an effective implementation of the company’s Security Operations Center (SOC).

This is one of the threads of effective cybersecurity. Certainly, a new one in our country, as well as the fact that institutions and companies, often competing with each other, share information with trustworthy entities about dangerous incidents.

It will certainly take a long time just to convince all interested parties to show their weaknesses. Hence, it seems to us simplifying the topics contained in the Cybersecurity Act.

Meanwhile, the first paragraph of Chapter 3 of the Cyber Act specifies the obligations of operators of essential services as follows: “The operator of the key service implements a security management system in the information system used to provide the key service” [Art. 8 of the Act]. Then there is what is meant by that.

It is required: implementation of risk management principles, implementation of security appropriate and proportionate to the risk, incident management, use of secure means of communication, secure management of systems, monitoring of information on threats and vulnerabilities.

Bezpieczeństwo przemysłu
The biggest bugs in cybersecurity

The scale and complexity of cyber attacks increases every year. This is confirmed by data from the Cybersecurity Barometer survey conducted by KPMG. In 2017, 82% of enterprises operating in Poland experienced at least one security incident. According to Cisco, 45% of cyber attacks in our country have caused losses of more than $ 100,000. Interestingly, most companies were optimistic about the maturity of their security measures, which may result from underestimating the risk.
The most common mistakes that expose businesses to cyber attacks include: too many cybersecurity systems, too few security specialists cybersecurity and too much freedom of employees, non-compliance with corporate cybersecurity rules and practices, no backups and disaster recovery policies , no access to archival cybersecurity data.

How to protect yourself from cybercrime?

According to specialists in data protection, the occurrence of acts of cyberterrorism are closely related to employee mistakes, failure to implement adequate security and the use of technologies, including cloud technologies, without much reflection in the field of security. Therefore, it is worth developing procedures and considering what to do in the event of a cyber attack on the company, the processed data, the network as well as data protection strategies and organizational structures. In a crisis situation, a quick response is important, so it is advisable to design and implement early warning systems, taking into account the activity of all employees and departments. Cybersecurity is a multi-level process and it is worth taking into account appropriate risk management and raising awareness of all members of the organization in the same way.

 

Are you looking for additional information?
Visit the site arrow
Are you getting support at KSC?
contact us arrow
Service implementation process
1
Zero audit
2
Strategy and concept
3
Conducting a risk analysis
4
Development of documentation for the Security System
Do you have questions about this service?
Write to us arrow
Additional materials