Table of Contents
This is an inevitable negative consequence of the ongoing digitization of business processes, the development of online banking, mobile applications, contactless payments, and other IT services provided over the Internet and in the cloud (cloud computing).

The cyber threat increases with technological advancement. The development of the pandemic has further accelerated this process due to the transfer of various forms of "traditional" activities to the online world, particularly as more and more people work remotely from home, which has allowed businesses to survive in difficult times while simultaneously giving rise to new, additional threats.
The sale of products and services online has also developed extremely dynamically, proving to be a natural solution under various restrictions on movement and physical contact between individuals.
The Number of Cybersecurity and Data Protection Incidents is Rising
The operations of any modern company rely on data of varying degrees of sensitivity, the vast majority of which are currently processed in digital form. When some of this data is lost or inaccessible, its operations often become impossible. Therefore, cybersecurity should be an important element of the operational strategy of any organization that possesses information that may be valuable to cybercriminals. The financial sector is particularly vulnerable, as it not only processes sensitive data but also deals with money.
It is estimated that cybercriminals earn over half a trillion dollars annually worldwide, which is even more than drug dealers in the international drug market. Cybercrime is also on the rise because there are no borders on the Internet, and a hacking attack can be carried out from anywhere, with minimal risk and high profitability. According to the annual report of CERT Polska – an institution established within NASK to respond to incidents in the field of cybersecurity, in 2020 "both the scale of cybercriminal activities and the effects felt by the victims of attacks, increasingly dependent on IT systems, noticeably increased."
Last year, CERT Polska registered 10,420 cybersecurity incidents (a 60.7% increase compared to the previous year). Phishing accounted for as much as 73% of all handled incidents. The number of such reports increased by 116% year on year.
The Biggest Cyber Threats to Data Protection
The history of hacking, understood as any actions aimed at gaining access to devices, systems, or even entire computer networks, began with innocent attacks that were characterized as youthful fun. For a long time, hacking had a positive connotation, with separate terms being distinguished – hacking was good, while cracking was "the bad one," but over the years, all of this transformed into a criminal enterprise worth billions of dollars, utilizing sophisticated techniques and even offering specific tools for less advanced criminal users. The catalog of types of cyberattacks is extensive, continually evolving, and includes, among others, phishing, ransomware, distributed denial of service (DDoS), deepfake, and other methods utilizing various types of viruses, trojans, worms, or rootkits.
The aim is to disrupt operations, damage or destroy computer systems, but also to collect, modify, or steal data and documents that may be used for further criminal activities, such as transferring funds to a fraudulent bank account or blackmail. Sometimes, it may involve gaining recognition within the hacker subculture, but more often, the underlying motive for these actions is primarily financial. Occasionally, cyberattacks serve political purposes within the framework of so-called hybrid warfare, the promotion of fake news, interference in elections, and the disintegration of societies and state structures, as we have witnessed in recent years.
During the pandemic and remote work, the number of phishing attacks has increased significantly, where the essence is to impersonate trusted and familiar entities to the recipient. The content of the message is formulated in such a way that it suggests a connection to our current activities and/or professional work. Clicking on a link or downloading an attachment activates a hidden weapon, which most often leads to the theft of our data and, consequently, to the depletion of a bank account or identity theft.
A significant threat is posed by ransomware. After infecting a computer system, the key data of the organization is encrypted, and the criminals leave instructions on how to pay the ransom – sometimes using cryptocurrencies. After the ransom is paid, they offer to provide decryption keys to unlock the infected files. The ransom paid does not guarantee a solution to the problem; moreover, data theft may be associated with further blackmail. It happens that corporate data is made public if companies refuse to pay the ransom because they have recovered data from backup copies.
On the other hand, distributed denial of service (DDoS) involves blocking access to server services, websites, or networks by generating artificial internet traffic, usually using many other computers that have previously been taken over. As a result of excessive strain on system resources, a given service or website ceases to function, leading to potential customers abandoning the service.
Commonly used fake news proliferate thanks to deepfake technology – utilizing artificial intelligence techniques for image and sound manipulation, which can be used for abuses and financial fraud, compromising specific individuals (sometimes public figures in high positions), information manipulation, and social engineering.
How to increase a company's resilience to the risk of data loss?
However, it should be noted that despite the increase in the number of cyberattacks, as much as 92.5% of cyber incidents and 84.7% of data breach cases are unintentional or accidental. This is according to research by the International Association of Privacy Professionals (IAPP). It appears that people are the weakest link in cybersecurity and data protection. How can we make them a stronger link?
Cybersecurity is a shared responsibility, within which every individual associated with the organization can play a positive role. First and foremost, it is essential to provide employees, collaborators, and contractors with knowledge about cyber threats, model and test appropriate behaviors, and then monitor them in practice to prevent leaks and/or loss of information. It is extremely important to do this continuously and systematically. Changes in the business model, the development of IT services, including cloud data processing, mean that security systems must be constantly improved, as solutions that were effective yesterday may not be sufficient today.
Cybersecurity should be integrated with risk management, and control measures must be adequate to the level of risk for a given company. Extremely important aspects include risk analysis, identification of critical data, and the confidentiality, integrity, and availability of data. It is crucial to define and implement appropriate procedures, technical measures, and tools that will ensure the organization's resilience to attacks, a deterrent function, rapid detection of attacks, and minimization of potential losses.
The American National Institute of Standards and Technology (NIST) distinguishes five pillars of a comprehensive and effective cybersecurity program in the context of identifying organizational assets, managing risk, and responding to threats: Identify, Protect, Detect, Respond, and Recover. Timely detection of incidents and monitoring of damages are extremely important. Rapid detection and quick response increase the organization's resilience to subsequent cyber threats.
In this context, an interesting solution is the infrastructure, isolated from the local network and appropriately secured, referred to as a „Honeypot” (loosely translated as a pot of honey), which aims to lure cybercriminals in order to observe how they conduct their attacks. It serves as a trap, simultaneously acting as a deterrent – criminals, knowing that the company employs such measures, prefer not to risk detection.
Due to the increasing complexity and scale of cyber threats, organizations utilize artificial intelligence and machine learning (AI/ML) for early detection, which can significantly reduce potential damages. It is becoming standard practice to consider the risk of data breaches at the design stage of IT solutions (so-called security by design), which aligns with the principle of data protection by design stipulated in the GDPR, obliging data controllers to incorporate data protection at every stage of the creation and operation of technologies related to their processing.
Cybersecurity and Personal Data Protection
The minimum cybersecurity requirements include compliance with the GDPR, appropriate contractual clauses, risk assessment, access control, and security monitoring. Cybersecurity primarily involves the protection of data, including personal data. The Data Protection Officer (DPO) is a key stakeholder and partner in the area of cybersecurity within the company. This is one of the most important functions in the organization, and the most crucial when it comes to personal data protection. The DPO informs, advises, and trains senior management and employees, conducts audits, and continuously assesses the organization's compliance with personal data protection regulations, identifying areas for improvement. If necessary, the DPO serves as a point of contact – both for the supervisory authority and for individuals whose data is processed by the data controller. The Data Protection Officer should participate in the planning and modification of all processes related to personal data.
Training employees in information security awareness is crucial for preventing and mitigating risks, as it helps them understand the important role they can play in combating breaches. Such training significantly enhances information security at relatively low costs. Employees of the organization should be aware that security is everyone's responsibility. They should "live security" – in this way, a so-called "firewall of people" will be created. A good solution is to hire a specialized external company that will provide not only appropriate training but also comprehensive practical and substantive support in the field of personal data protection and information security. Because you never know when something might happen...
Check what you remember - for the correct answer reward!
Indicate the mechanism that allows for the implementation of adequate, and thus effective IT security measures:




