1. Cyberattacks are now routine, not the exception
The report's authors leave no room for doubt: only 15% of Polish companies avoided a cybersecurity incident in the last 12 months. As many as 85% of the surveyed organizations had to deal with a cyberattack, with larger companies facing a greater variety of threats and a higher frequency of incidents. The most common types of attacks are phishing (36% of companies), attacks on Wi-Fi networks (28%) and Trojans (19%), but the list also includes DDoS, attacks on cloud services and ransomware. Cybercriminals are increasingly effective at tailoring their techniques to the profile of a company and the "average employee" in a given sector, which makes defence more difficult.
2. Employee confidence is falling and exposure to attacks is increasing
The paradox of modern business is that the more companies invest in digitalization, the less confident employees feel. Only 14% of employees rate their cybersecurity competence as high, which means a drop of 10 percentage points compared with the result from two years ago. Barely half of employees say they know the cybersecurity rules in force in their company well, while the rest operate "in the dark". In practice, this means improvisation instead of predictable behaviour, a culture of hesitation and silence, and a major risk that a minor incident will not be reported in time.
3. AI in employees' hands: efficiency ahead of caution
The report clearly shows that artificial intelligence has become a tool of everyday work - 62% of employees admit that they use AI solutions in their tasks. At the same time, 35% of AI users openly say they would try to bypass company blocks if their employer banned the use of open language models on a work computer. The problem is not only the scale of AI use, but also the knowledge gap around risks: only 8% of employees know and understand the concept of data poisoning, while 43% of respondents understand the term deepfake. Meanwhile, 30% of employees admit they have been fooled by deepfake content, and 57% fear identity theft through AI-supported attacks.
4. AI in organizations: chaos instead of a security policy
From the perspective of cybersecurity teams, the situation looks no better - 59% of experts admit that the pace of AI development makes it harder for them to plan protective measures. Only 27% of companies have a written, formal policy on the use of AI tools (AI Policy), and 28% have a defined list of "trusted" tools that employees are officially allowed to use. Just 38% of companies have invested in corporate AI licenses that guarantee data entered into the system will not be used to train language models. Even fewer (25%) have implemented DLP- or CASB-class tools to monitor network traffic and prevent data leaks to external AI services. The result is the phenomenon of "Shadow AI" - employees use artificial intelligence tools outside the organization's control.
5. Phishing and ransomware: two routes to serious losses
Phishing remains the most commonly experienced type of attack: 36% of companies say they faced such an incident in the last 12 months. Ransomware affected "only" 14% of the surveyed organizations, but the key issue here is the scale of its impact - from operational paralysis to the loss of critical data and the need to report GDPR breaches. The report also shows how strongly AI increases the effectiveness of phishing: 40% of experts fear mass, personalized phishing campaigns generated by AI in the coming year, and 42% of large companies (over 250 employees) see this as one of the main threats. Deepfakes are becoming a real criminal tool used to impersonate colleagues and business partners.
6. Fear and silence - the invisible fuel of cyberattacks
One of the report's most worrying findings is the role of fear in incident escalation. One in six employees who experienced a cyberattack or noticed a security incident on work equipment chose not to report it to their employer. Only 48% of employees say they are well familiar with the rules for responding to cyber threats they encounter, and only 17% know the meaning of the term "ransomware", even though it is one of the most serious threats. Under these conditions, the "Silent Link" syndrome emerges in the organization: a person who has fallen victim to an incident but hides their mistake for fear of the consequences.
7. Training: years of neglect and a self-fulfilling prophecy
The ESET and DAGMA report describes the lack of training as a "self-fulfilling prophecy" - companies save on education and then pay for the consequences of its absence. In the last five years, 58% of employees have not taken part in any cybersecurity training, and this percentage is rising year by year (52% in 2024, 55% in 2025, 58% in 2026). Moreover, 24% of employees are not assessed in any way for their knowledge of current threats, and some companies do not verify the outcomes of training at all, for example through tests, phishing simulations or incident-response exercises. It is no surprise that only 14% of employees rate their cybersecurity competence as high.
8. Regulations and digital sovereignty: pressure that is reshaping the market
Against the backdrop of rising threats, another strong trend is emerging: the growing importance of regulation and the origin of technology. The NIS2 Directive and the Act on the National Cybersecurity System (UKSC) are becoming an important driver of investment - 64% of companies subject to these rules see the new regulations and potential penalties as a key reason for additional spending on cyber protection. 61% of surveyed companies prefer cybersecurity solutions developed by European vendors, guided by factors such as legal compliance, local technical support, geopolitical stability and a lower risk of "backdoors". More than half (53%) plan to increase the share of European technologies in their IT and OT environments over the next two years.
9. Budgets: spend little, pay a lot
An insufficient cybersecurity budget is the most frequently cited investment barrier - mentioned by 35% of experts. Next on the list are the high costs of implementations, the company's focus on other priorities, and low awareness among leaders and employees. At the same time, the report shows that most organizations have only basic tools: strong passwords, firewalls, VPN, antivirus, backups or MFA. They invest far less often in more advanced solutions such as EDR/XDR, DLP, SIEM or comprehensive incident-management processes that genuinely shorten response times and reduce the impact of attacks.
10. What does this mean for management boards and business owners?
From the perspective of a management board or business owner, the key conclusion is this: the threat landscape is growing faster than organizations' competences, policies and budgets. Cybersecurity is no longer the exclusive domain of the IT department - the report clearly indicates that a company's digital resilience depends on organizational culture, strategy, training and conscious risk management. The report's authors emphasize that the foundation is a combination of three elements: simple, understandable rules for employees, consistent regulations and policies (including an AI Policy), and properly selected technological tools. In practice, this means moving away from a "minimum protection" mindset towards a conscious calculation of risk and investment where potential losses would be greatest.
11. The six faces of cybersecurity in your company
One of the most interesting elements of the report is the identification of six personas - archetypes of attitudes towards cybersecurity that the authors observe in Polish organizations. These are not abstract figures, but very real roles that management boards will find in their teams: from lost employees, through innovators who ignore procedures, to managers fighting technological debt. The report lists six "faces" of cybersecurity: the Lost Employee, the Careless Innovator, the Debt Manager, the Silent Link, the Sovereignty Strategist and the Helpless AI Guardian. Each of them embodies a different problem - lack of knowledge, bypassing rules, underfunding, fear of reporting incidents, long-term thinking about digital sovereignty and experts' helplessness in the face of an avalanche of AI-related risks.
- The Lost Employee is a person overwhelmed by the number of threats, relying solely on "what IT will do" and not understanding their own role in cyber defence. This persona is more common in smaller companies, in back-office functions and in teams with a high volume of external document handling, where the lack of training and simple security rules makes them an ideal target for social engineering.
- The Careless Innovatoris valuable from an efficiency perspective - they use AI very effectively, automate tasks and speed up work - but at the same time, they are willing to move company data to private equipment to bypass restrictions and use open LLM models. This persona most often appears in the 18-34 age group, in marketing, PR and analytics departments, and in highly autonomous IT teams, especially in large companies that work remotely.
- The Debt Manager represents security experts who "put out fires" every day while dealing with a chronically insufficient budget and a shortage of specialists. In practice, this means postponing modernization, focusing on patches and basic safeguards, which leads to the accumulation of dangerous technological debt - especially in the SME sector and in organizations with a large share of legacy systems.
- The Silent Link is an employee who has fallen victim to an attack or noticed an incident, but decides to keep quiet because they fear the consequences or because clear procedures are missing. This persona appears more often among new employees, junior staff and in companies that punish mistakes instead of treating rapid incident reporting as a sign of responsibility.
- The Sovereignty Strategist, in turn, is the archetype of a mature decision-maker - usually a CISO, CIO or compliance manager - who consciously focuses on European technologies, local support and compliance with UKSC and NIS2 regulations. Their motivations are pragmatic: reduce geopolitical risk, avoid "backdoors" and build infrastructure that is more resilient and less dependent on global giants.
- The Helpless AI Guardian symbolizes cybersecurity experts who see the "AI tsunami" and the growing number of scenarios in which algorithms are used for attacks, but do not have the right tools or policies. This persona is more common in medium-sized and large companies, in bureaucratic structures where the development of tools for employees cannot keep pace with change, and where there is no written AI Policy or systematic solutions such as DLP, CASB and EDR/XDR.
From the management board's perspective, these personas are a highly useful diagnostic tool - they help name real organizational problems, not just "system implementations". The report encourages companies to view cybersecurity not as a set of technologies, but as an ecosystem of attitudes, tensions and gaps that requires both investment in tools and conscious work with people.
