Risk management. We identify key threats to the organization's business continuity.
KSC, NIS2 and ISO 27001 audits. We assess security levels, identify vulnerabilities and draw up an action plan.
Documentation and procedures. We draw up security policies, incident response procedures and the required records.
Implementation and ongoing supervision. We help implement security measures, train employees, and develop a security management system.
The complete process of preparing an organisation
We are building a mature cybersecurity system that supports compliance, business continuity and organisational resilience.
Preparing your organization for KSC, NIS2 and ISO/IEC 27001
HOW IT WORKS?
From analysing responsibilities to implementing safeguards
Analysis of responsibilities and the current level of security
To begin with, we assess the requirements applicable to the organisation and identify which areas need to be reorganised. We analyse the company’s operations, the systems it uses and the biggest risks. On this basis, we point out any gaps and set priorities for further action.
Documentation and allocation of responsibilities
We prepare documentation adjusted to the company’s actual operating conditions. We define security rules, access management, incident handling, backup procedures and cooperation with suppliers. We also establish the scope of responsibilities and a schedule for reviews, tests and training sessions.
Implementation of technical safeguards
Based on the results of the analysis, we introduce security measures in the areas most at risk. We organise accounts and access rights, and strengthen the security of devices, email, networks and remote access. We also set up backups, event monitoring and centralised configuration management.
Frequently asked questions
Short answers alleviate the most common concerns: whether the audit will disrupt work, whether documentation is needed, and whether the client will receive specific recommendations.
Can an audit disrupt a company's operations?
+
We agree on the scope and method of the tests in advance. We only carry out potentially sensitive activities once they have been approved.
Do we need full network documentation?
+
No. If the documentation is incomplete, we treat it as part of the audit and help reconstruct the environment.
Will we receive specific recommendations?
+
Yes. The report includes a description of the problems, priorities, and recommendations for action for IT and management.
Do you help implement changes?
+
Yes. After the audit, we can help you plan and implement the most important improvements.
Failure to comply with KSC obligations may result in administrative fines. This includes failure to be listed on the KSC register, failure to implement an information security management system, failure to conduct risk analysis, failure to report incidents, failure to conduct a required audit, or obstructing an inspection.
The amount of the penalty may be:
for a key entity – from PLN 20,000 to EUR 10 million or 2% of the revenues from business activities achieved in the previous financial year;
for a major entity – from PLN 15,000 to EUR 7 million or 1.4% of the revenues from business activities achieved in the previous financial year;
in the event of a breach causing a particularly serious threat – up to PLN 100 million.
Liability may also extend to the entity's manager. A fine imposed directly on the manager may amount to up to 300% of their remuneration, calculated according to the principles specified in the Act. Merely delegating responsibilities to the IT department or an external provider does not exclude management's liability.
It depends primarily on the sector of activity, the type of services provided, the size of the organization and its importance for the operations of other entities.
In Poland, regulations cover key and important entities, and a company subject to the Act may be required to independently register on the KSC list. The assessment should also take into account capital ties and exceptions provided for in the regulations.
NIS2 is a European Union directive defining common requirements for cybersecurity risk management, incident management, oversight, and accountability. In Poland, these requirements are implemented through the National Cybersecurity System Act.
ISO/IEC 27001 is an international standard specifying requirements for an information security management system. It can be implemented by organizations regardless of whether they are subject to the KSC.
No. ISO/IEC 27001 helps structure risk management, accountability, documentation, and continuous security improvement, so it can provide a good foundation for preparing an organization.
However, the KSC may impose additional obligations arising directly from the regulations, for example, regarding registration, incident reporting, cooperation with competent authorities, or specific oversight procedures. Each of these obligations must be verified separately.
Yes. We combine the preparation of procedures and policies with the configuration of actual security measures.
We can, among other things, streamline user access, implement multi-factor authentication, secure email and devices, segment the network, prepare backups, and implement monitoring. This ensures that the documentation reflects the actual operation of the infrastructure.
After implementation, we can conduct periodic reviews of security, permissions, backups, and documentation. We also help update risk analysis following changes to infrastructure, company structure, or service delivery.
Ongoing cooperation may also include monitoring, incident handling, training, data recovery testing and monitoring the implementation of the adopted action plan.
Let's start with a conversation
A quick conversation is the first step to better decisions. Fill out the form and we'll get back to you at a time convenient for you, or book a meeting online now ->



