Skip to main content
BilgeQor
Back to industries

CTO, IT Director, CISO

Manufacturing & Supplier Portals

Verified CERT Polska reporting context · Poland / NASK

CERT Polska submissions, incidents, fraud, Warning List and SMS filtering — 2025

Market context — not industry-specific evidence

CERT Polska received 658,320 submissions and registered 260,783 unique security incidents in calendar year 2025, of which 97% were classified as computer fraud. Nearly 250,000 domains were added to the Warning List, blocking approximately 140 million attempted visits to dangerous pages. Over 350,000 SMS messages were submitted for analysis and over 80,000 were found harmful; 1.88 million malicious SMS messages were blocked. CERT Polska recorded 179 ransomware incidents in 2025. These figures are CERT Polska 2025 reporting context; they are not total Polish business incident prevalence and not industry-specific evidence.

Poland · CERT Polska 2025 submission, incident, fraud, warning-list, SMS-filtering, and ransomware contextCalendar year 2025

Submissions received by CERT Polska — 2025

Submissions received by CERT Polska
658,320
Unit
submissions received by CERT Polska
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

CERT Polska received 658,320 submissions in calendar year 2025.

Poland CERT Polska 2025 reporting context only. Not total Polish business incident prevalence and not industry-specific evidence.

Unique security incidents registered by CERT Polska — 2025

Unique security incidents registered
260,783
Unit
unique security incidents registered by CERT Polska
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

CERT Polska registered 260,783 unique security incidents in calendar year 2025.

Poland CERT Polska 2025 reporting context only. The 260,783 incidents figure is the same dataset as CSIRT NASK (separate source); CSIRT NASK and CERT Polska are the same entity operated by NASK. Not total Polish business incident prevalence and not industry-specific evidence.

Computer fraud share of registered incidents — 2025

Of registered incidents classified as computer fraud
97%
Unit
percent of registered incidents classified as computer fraud
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

97% of CERT Polska registered incidents in calendar year 2025 were classified as computer fraud.

Poland CERT Polska 2025 reporting context only. Not total Polish business incident prevalence and not industry-specific evidence.

Ransomware incidents recorded by CERT Polska — 2025

Ransomware incidents recorded
179
Unit
ransomware incidents recorded
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

CERT Polska recorded 179 ransomware incidents in calendar year 2025.

Poland CERT Polska 2025 reporting context only. Not total Polish business incident prevalence and not industry-specific evidence.

Domains added to the Warning List — 2025

Domains added to the Warning List (nearly)
250,000
Unit
domains added to Warning List in 2025 (nearly; approximate)
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

Nearly 250,000 domains were added to the CERT Polska Warning List in calendar year 2025.

CERT Polska platform-operation context only. The Warning List domain count is a source-described approximation ("nearly"). Not a measure of Polish business cyber risk and not industry-specific evidence.

Attempted visits to dangerous pages blocked — 2025

Attempted visits to dangerous pages blocked
140,000,000
Unit
attempted visits to dangerous pages blocked
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

Approximately 140 million attempted visits to dangerous pages were blocked via the CERT Polska Warning List in calendar year 2025.

CERT Polska platform-operation context only. Not a measure of Polish business cyber risk and not industry-specific evidence.

SMS messages submitted for analysis — 2025

SMS messages submitted for analysis (over)
350,000
Unit
SMS messages submitted for analysis (minimum)
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

Over 350,000 SMS messages were submitted for analysis in calendar year 2025.

CERT Polska SMS-filtering platform context only. The submitted value is a source-stated minimum ("over"). Not total Polish business SMS threat rates and not industry-specific evidence.

SMS messages found harmful — 2025

SMS messages found harmful (over)
80,000
Unit
SMS messages considered harmful (minimum)
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

Over 80,000 SMS messages were found harmful in calendar year 2025.

CERT Polska SMS-filtering platform context only. The harmful value is a source-stated minimum ("over"). Not total Polish business SMS threat rates and not industry-specific evidence.

Malicious SMS messages blocked — 2025

Malicious SMS messages blocked
1,880,000
Unit
malicious SMS messages blocked
Period
Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Scope
Poland CERT Polska 2025 reporting context

1.88 million malicious SMS messages were blocked in calendar year 2025.

CERT Polska SMS-filtering platform context only. Not total Polish business SMS threat rates and not industry-specific evidence.

Source: NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026

Scope: NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026. The 260,783 unique security incidents figure is the same dataset as CSIRT NASK incidents (separate source); CSIRT NASK and CERT Polska are operated by NASK. The nearly 250,000 Warning List domains is a source-described approximation. The SMS submitted and SMS harmful values are source-stated minimums. These figures do not measure total Polish business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official CERT Polska annual report for calendar year 2025. The 658,320 submissions and 260,783 unique security incidents describe CERT Polska reporting context; the 260,783 figure is the same dataset as CSIRT NASK incidents (separate source) — CSIRT NASK and CERT Polska are the same entity operated by NASK. The 97% computer fraud share describes the composition of registered incidents. The nearly 250,000 Warning List domains is a source-described approximation. The 350,000+ SMS submitted and 80,000+ SMS harmful are source-stated minimums. These figures are Poland CERT Polska 2025 reporting context; they are not total Polish business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification or proof of security.

Accessible data table
Verified Poland CERT Polska 2025 reporting and platform context data from NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026, reporting period Calendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context.
MetricValueSourceScopeReporting period
Submissions received by CERT Polska658,320 submissions received by CERT PolskaNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Unique security incidents registered260,783 unique security incidents registered by CERT PolskaNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Of registered incidents classified as computer fraud97% percent of registered incidents classified as computer fraudNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Ransomware incidents recorded179 ransomware incidents recordedNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Domains added to the Warning List (nearly)250,000 domains added to Warning List in 2025 (nearly; approximate)NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Attempted visits to dangerous pages blocked140,000,000 attempted visits to dangerous pages blockedNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
SMS messages submitted for analysis (over)350,000 SMS messages submitted for analysis (minimum)NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
SMS messages found harmful (over)80,000 SMS messages considered harmful (minimum)NASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context
Malicious SMS messages blocked1,880,000 malicious SMS messages blockedNASK / CERT Polska, Raport CERT Polska za 2025 rok, 8 April 2026Poland CERT Polska 2025 reporting contextCalendar year 2025 CERT Polska submission, incident, fraud, warning-list, SMS-filtering, and ransomware context

Verified national CSIRT reporting context · Poland / Ministerstwo Cyfryzacji

National CSIRT reports and handled incidents — Poland 2025

Market context — not industry-specific evidence

The Ministerstwo Cyfryzacji Krajobraz cyberprzestrzeni 2025 report records 682,245 reports received by national-level CSIRT teams and 272,941 handled incidents in calendar year 2025 — a 144.4% year-on-year increase in handled incidents. CSIRT NASK handled 260,783 incidents, CSIRT MON handled 7,125, and CSIRT GOV handled 5,033. The 144.4% figure reflects growth in CSIRT-handled incident counts and does not measure a per-business incident rate. These figures are Poland national CSIRT reporting context; they are not total Polish business incident prevalence and not industry-specific evidence.

Poland · Ministerstwo Cyfryzacji 2025 national CSIRT reporting and handled-incident contextCalendar year 2025

Reports received by national CSIRT teams — 2025

Reports received by national CSIRT teams
682,245
Unit
reports received by national-level CSIRT teams
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context

National CSIRT teams received 682,245 reports in calendar year 2025.

Poland national CSIRT reporting context only. Not total Polish business incident prevalence and not industry-specific evidence.

Handled incidents by national CSIRT teams — 2025

Handled incidents
272,941
Unit
handled incidents
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context

National CSIRT teams handled 272,941 incidents in calendar year 2025.

Poland national CSIRT reporting context only. Not total Polish business incident prevalence and not industry-specific evidence.

Year-on-year increase in CSIRT-handled incidents — 2025

Year-on-year increase in handled incidents
144.4%
Unit
percent year-on-year increase in handled incidents
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context

CSIRT-handled incidents increased 144.4% in calendar year 2025 compared with 2024.

Poland national CSIRT reporting context only. The 144.4% is a year-on-year increase in CSIRT-handled incident counts and does not measure a per-business incident rate. Not total Polish business incident prevalence and not industry-specific evidence.

Handled incidents by national CSIRT team — 2025

CSIRT NASK — 260,783
260,783
Unit
incidents handled by CSIRT NASK
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context
CSIRT MON — 7,125
7,125
Unit
incidents handled by CSIRT MON
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context
CSIRT GOV — 5,033
5,033
Unit
incidents handled by CSIRT GOV
Period
Calendar year 2025 national CSIRT reporting and handled-incident context
Scope
Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting context

Poland national CSIRT team incident context only. The CSIRT NASK 260,783 figure is the same dataset as CERT Polska unique security incidents (separate source); CSIRT NASK and CERT Polska are the same entity operated by NASK. Not total Polish business incident prevalence and not industry-specific evidence.

Source: Ministerstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026

Scope: Ministerstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026. The 682,245 reports and 272,941 handled incidents describe national CSIRT team reporting context for 2025. The CSIRT NASK 260,783 figure is the same dataset as CERT Polska unique security incidents (separate source); CSIRT NASK and CERT Polska are the same entity operated by NASK. These figures do not measure total Polish business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official Ministerstwo Cyfryzacji Krajobraz cyberprzestrzeni 2025 report. The 682,245 reports and 272,941 handled incidents describe national-level CSIRT team reporting context for calendar year 2025. The 144.4% figure is a year-on-year increase in handled incident counts and does not measure a per-business incident rate. The 260,783 CSIRT NASK figure is the same dataset as the 260,783 unique security incidents reported by CERT Polska (separate source); CSIRT NASK and CERT Polska are the same entity operated by NASK. These figures are national CSIRT reporting context only; they are not total Polish business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification or proof of security.

Accessible data table
Verified Poland national CSIRT 2025 reporting and handled-incident context data from Ministerstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026, reporting period Calendar year 2025 national CSIRT reporting and handled-incident context.
MetricValueSourceScopeReporting period
Reports received by national CSIRT teams682,245 reports received by national-level CSIRT teamsMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context
Handled incidents272,941 handled incidentsMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context
Year-on-year increase in handled incidents144.4% percent year-on-year increase in handled incidentsMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context
CSIRT NASK — 260,783260,783 incidents handled by CSIRT NASKMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context
CSIRT MON — 7,1257,125 incidents handled by CSIRT MONMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context
CSIRT GOV — 5,0335,033 incidents handled by CSIRT GOVMinisterstwo Cyfryzacji, Krajobraz cyberprzestrzeni 2025, 16 April 2026Poland Ministerstwo Cyfryzacji 2025 national CSIRT reporting contextCalendar year 2025 national CSIRT reporting and handled-incident context

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Supply Chain Attacks
  • Data Exfiltration
  • Ransomware

Digital surfaces in scope

Vendor PortalsSupply Chain DashboardsOrder Management

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.