
Moreover, the dynamics of changes occurring in cyberspace, their innovativeness, and their connection with the latest technologies have led to the emergence of a legal gap – a significant scope of activity, carrying legal and economic consequences, has not been fully accounted for in legal systems – both national and international. Unfortunately, in addition to undeniable benefits, the development of cyberspace has also brought about many new types of crimes. Fraudsters, thieves, and terrorists have quickly begun to exploit modern technologies in their activities.
Receive a package of free GDPR guides and micro-trainings
In this context, the report by the Supreme Audit Office (NIK) titled Implementation of Tasks Related to the Protection of the Cybersecurity of the Republic of Poland by State Entities is alarming, as it indicates that the state administration has not yet taken the necessary actions to ensure Poland's cybersecurity. Despite the fact that an increasing portion of significant aspects of social and economic life is currently conducted online or using IT systems, Poland's security is still perceived in a conventional manner. It seems that those in charge of the most important public institutions do not recognize this new category of threats and are unaware of the dangers and the new tasks associated with them for the administration.
The fact that the topic of new technologies and the associated threats can no longer be treated in such a manner is evidenced by the report of the Government Computer Incident Response Team CERT.GOV.PL on the state of cybersecurity in Poland from 2014. It highlights a significant increase in the dynamics of attacks on IT networks. The attackers were no longer just individuals, but also specialized groups, and the year 2014 turned out to be record-breaking in terms of the number of reports received and incidents handled – a total of 12,017 reports were registered, of which 7,498 were classified as incidents. Moreover, compared to 2013, the number of incidents in the category of Social Engineering increased by as much as 350%, and as indicated by PwC research, the global number of information security incidents in companies and institutions rose by over 25% within a year.
Conducted campaigns often exploited the image of well-known companies, entities engaged in online sales, or intermediary firms, such as courier companies, auction and booking services, banks, telecommunications operators, etc.
Polish companies are also not faring well in this regard. As many as 22% of the surveyed entities lack knowledge about the number of security incidents in their organization – this is 4 percentage points higher than the global benchmark. Interestingly, very often – in as many as 75% of cases – the aim of hacking attacks is not even to obtain specific information, but to demonstrate vulnerabilities in the security systems of individual entities. While this may not result in direct financial losses (e.g., there is no theft of a customer database for resale to competitors), the reputational damage is nonetheless serious. The non-financial consequences of an information security incident primarily include loss of reputation and personnel decisions, most often concerning company management. Research shows that Polish entrepreneurs and management almost completely disregard these issues. They are also unaware of the actual costs of such an incident (as a result, the loss of a good reputation is always associated with future financial losses) or estimate it at… 50,000 PLN.

