Skip to content
Security incident? Call: +48 732 059 711
Public sector

Security for the institutions citizens rely on

KSC, NIS2, procurement security, citizen data and critical services. We work in the regulatory reality of the Polish public sector — and deliver programs that land.

Who is it for?

  • Central government offices
  • Local authorities (województwa, powiaty, gminy)
  • Public agencies and funds
  • Universities and research institutes
  • Public healthcare and utilities
What we deliver

Outcomes for public bodies

KSC and NIS2 alignment

Act on the National Cybersecurity System (KSC) plus NIS2 obligations — we map both into a single program.

Procurement security

ICT procurement SIWZ / OPZ drafting, supplier evaluation, contract clauses that actually protect you.

Citizen data protection

GDPR and Polish UODO expectations — access control, retention, DPA, breach response.

Critical services continuity

Tabletop exercises with the supervisory board and IT, ransomware and DDoS scenarios.

Budgetable program

We write the program so it fits the annual budget cycle and the public procurement calendar.

Audit coordination

Coordination with NIK, supervisory bodies and sectoral regulators — we prepare the responses.

How we engage

Working inside the public sector reality

  1. 01

    Regulatory scoping

    KSC, NIS2, sectoral acts, internal directives, GDPR — the full regulatory picture.

  2. 02

    Risk assessment

    Asset inventory, critical services mapping, threat modelling (ransomware, DDoS, insider, nation-state).

  3. 03

    Program & procurement

    Program design that fits the budget cycle. Procurement documents drafted with security baked in.

  4. 04

    Delivery & drills

    Policies, training, pentests, tabletops. Annual review and audit coordination.

FAQ

Frequently asked questions

Do you work with public procurement (PZP) processes?
Yes. We help draft SIWZ / OPZ, evaluate suppliers and attend clarification sessions.
Can you coordinate with NASK / CSIRT NASK / CSIRT GOV?
Yes. We know the reporting expectations and have experience liaising with national CSIRTs.
We have very limited budget — what is the minimum viable program?
We prioritise ruthlessly. A minimum viable program usually fits in a single annual budget line if scoped right.
Can you train our staff during working hours?
Yes — we adapt to shift patterns, remote and on-site, and deliver in Polish.
How is this billed?
Typically a fixed-price procurement-compatible contract with clearly defined deliverables.

Start with a public-sector scoping call

30 minutes — we map KSC, NIS2 and sectoral obligations and propose a budgetable program.