In recent months, Poland has been facing an unprecedented wave of cyber attacks, the sources of which most often point to Russia. As the Minister of Digitalisation and Deputy Prime Minister Krzysztof Gawkowski points out, the number of incidents reaches hundreds per day. Targets range from public administration to the energy and industrial sectors to key water supply infrastructure.
These actions are not random - they are part of a long-term destabilisation strategy, targeting not only Poland, but the entire region. In March 2025 alone, more than a dozen major incidents were reported, including the blockage of IT systems at several utilities. Cyber criminals are increasingly using automation and artificial intelligence to breach security, which presents Polish systems with new challenges.
Critical infrastructure on target
Of particular concern are reports of attacks on systems that manage water supply and industrial automation. In the event of successful sabotage, the consequences could be felt in real terms by citizens - from lack of access to drinking water to disruptions in energy supply.
IT and industrial automation experts are calling for the urgent deployment of advanced protection systems and for greater cooperation between the public and private sectors. What is needed is not only modern technology, but also increased awareness of risks among employees and end-users.
- Unfortunately, but in the European Union, Poland is currently the shining star. Ever since the conflict began across our eastern border, we have been the most frequently attacked country in the community,’ revealed Ryszard Korzeniecki, a cyber security specialist from Softinet, in an interview with Automation Trader.
Cooperation and strategy - the key to defence
The Ministry of Digitalisation announces an intensification of efforts to strengthen the state's cyber resilience. New monitoring and incident response centres are being set up, as well as training for services and public sector employees. The construction of a national cyber security strategy, taking into account both hybrid threats and the need to respond quickly to changing attack techniques, is also an important step.
Increased hacker activity shows that cyber security is no longer just the domain of IT specialists - it has become a matter of strategic importance, affecting every citizen. The responsibility for protecting digital sovereignty now lies with both state institutions and every web user.







