Cybersecurity is among the ‘fastest-growing’ business risks for Polish companies, with SMEs increasingly facing growing exposure to cyberattacks and data breaches, according to ERGO Hestia’s nieOdporni report.
Poland ranked first globally for the number of ransomware attacks in the first half of 2025, while remaining one of the least insured markets against cyber risks.
Cyberattacks on the rise
According to the report, some 88% of Polish organisations have experienced a cyberattack or data leak in recent years, while a separate ScamWatchHQ analysis put the proportion experiencing at least one cybersecurity incident at around 69%.
At the same time, a Mastercard survey suggests that many businesses aren’t prepared for a potential cyberattack, with 71% of small businesses considering the risk of a cyberattack to be low, despite one in four having already experienced such an incident.
ScamWatchHQ data also indicates that only three fifths (59%) of Polish companies use basic security software, while more than a third lack basic security measures.
For SMEs, common threats include ransomware, phishing, email compromise, customer data theft and attacks on cloud systems. The consequences can include financial losses, business disruption, data loss, legal and regulatory costs, reputational damage and the loss of customers or business partners.
The cost of an attack can reach hundreds of thousands of Polish zloty and exceed PLN 1 million in serious cases, according to the report, with average ransomware payments reaching approximately PLN 200,000-300,000.
Combined approach
ERGO Hestia says companies should combine technical measures with insurance protection. Basic measures include firewalls, multi-factor authentication, regular backups and up-to-date software. Employee training, security audits, penetration testing and monitoring and incident-response services can also form part of a company’s cybersecurity programme.
“Unlike large corporations, small and medium-sized businesses often lack formal security procedures or advanced security systems,” commented Adam Śliwiński, vice president of Seris Konsalnet Security.
“The lack of specialised IT or security departments makes them easier targets for both physical and cybercriminals. A cyberattack, hack, or theft can not only result in material losses but also business downtime and data loss. Effective protection requires combining monitoring, access control systems, physical and cyber security into a single ecosystem.”
In addition, according to the ERGO Hestia report, the average cost of cyber insurance is around 0.14% of a company’s annual turnover. Cyber insurance can provide additional protection by covering areas including data recovery, forensic investigation, business interruption, legal costs, data protection liabilities and crisis management.
“Protection against cyberattacks isn’t a choice between ‘investing in technology‘ and ‘buying insurance’,” a ERGO Hestia spokesperson said. “It’s both. Technology and procedures reduce the likelihood of an attack occurring. Insurance protects the company in a situation where, despite best efforts, an attack does occur.” Read more here.



