Digging the Latest Small Business News

Businesses must prioritize protection against digital threats as a necessity, not a choice

Warsaw, POLAND – Cyber threats are currently among the fastest-growing business risks faced by Polish enterprises, according to data from CERT Polska and analyses presented in ERGO Hestia’s “nieOdporni” (“nonResilient”) report released on Monday 14 September, 2026. The report highlights the growing number of security incidents recorded by CERT Polska each year, demonstrating that cybersecurity is no longer a concern solely for large corporations, but also for small and medium-sized enterprises.

Poland is currently among the countries particularly vulnerable to cyberattacks. In the first half of 2025, it ranked first in the world in terms of the number of ransomware attacks. At the same time, it remains one of the markets with the lowest level of cyber risk insurance coverage. The scale of the threat is also illustrated by recent incidents, such as the attack on a company specializing in electronic medical records. The stolen data contained sensitive information concerning prescriptions and the health of as many as 19 million people.

Data from the “nieOdporni” report, Mastercard, and other analyses cited by ERGO Hestia show that cyberattacks and data breaches have affected a significant proportion of Polish enterprises. According to the report, 88% of Polish organizations have experienced a cyberattack or data breach in recent years. An analysis by ScamWatchHQ cited in the report indicates that approximately 69% of businesses in Poland have experienced at least one cybersecurity incident. The difference between these figures results from the different scope and methodology of the studies.

Despite the growing awareness of the risk, many businesses are not adequately prepared to handle cyber threats. According to data from the “nieOdporni” report, only 25% of small businesses, 44% of medium-sized businesses, and 50% of large businesses have experienced a cyberattack. Additionally, 54% of small businesses, 14% of medium-sized businesses, and 4% of large businesses have not provided cybersecurity training to their employees. Only 18% of large businesses have an incident response plan in place, while smaller businesses lag behind at 0% for medium-sized businesses and 78% for small businesses. Furthermore, only 5% of small businesses, 21% of medium-sized businesses, and 18% of large businesses consider the risk of a cyberattack to be high.

The consequences of cyberattacks are multidimensional and affect almost every area of a company’s operations. The most significant include financial losses, business disruption, data loss, loss of reputation and customer trust, legal and regulatory consequences, disruption of business relationships, theft of intellectual property, increased operating costs, and in extreme cases, a serious cybersecurity breach may threaten the continued operation of the business.

To protect against cyberattacks, businesses must invest in comprehensive insurance cover and the development of increasingly robust IT infrastructure. According to Tomasz Dolata, a cyber insurance expert at ERGO Hestia, this dual approach is the most effective way to limit the consequences of a cyberattack. “This makes it possible both to reduce the likelihood of incidents occurring and to minimize their financial and operational consequences,” he emphasizes.

ERGO Hestia offers comprehensive cyber insurance coverage that includes protection against attacks, data recovery and system restoration, business interruption, liability towards customers and business partners, legal costs, and crisis management, among other things. The policy also covers the services of digital forensics specialists, which is an essential component of cyber insurance as it enables businesses to quickly determine the source of an attack and preserve evidence.

When choosing cyber insurance, businesses should carefully consider the scope of coverage, exclusions, insured amounts and liability limits, the possibility of extending the cover, assistance services, claims settlement procedures and timeframes, and the amount of the policyholder’s contribution to a claim. The ERGO Hestia report also recommends that businesses invest in other forms of insurance, such as property, liability, business interruption, electronic equipment, business assistance, legal protection, and comprehensive cyber insurance.

Unlike large corporations, small and medium-sized businesses often lack formal security procedures and advanced security systems, making them an easy target for both conventional criminals and cybercriminals. As a result, ERGO Hestia recommends that businesses invest in both technology and insurance to effectively protect themselves from cyber threats. “Technology and procedures reduce the likelihood of an attack occurring in the first place. Insurance protects the business if, despite its best efforts, an attack nevertheless occurs,” the report states.

Cyber insurance is readily available today, including to smaller market participants. The average cost of cyber insurance is approximately 0.14% of a company’s annual turnover, representing only approximately 1.8% of the costs that a business may incur following a successful cyberattack. In practice, this means that the cost of the policy is usually incomparably lower than the expenses associated with business interruption, data loss, crisis management, or liability towards

Share this article
0
Share
Shareable URL
Prev Post

Synalogik Secures Pre-Series A Investment and Names Peter Irvine as Chief Business Officer

Next Post

Iranian Citizens Awarded 2026 Freedom Prize

Read next
0
Share