NIS2 in Poland · KSC · fractional CISO
Fractional CISO: ongoing NIS2 support in Poland, with a clear scope
A KSC implementation ends on the day the controls work. Then someone has to keep them working: review risks, answer customer questionnaires, rehearse incidents and keep the evidence current. We do that every month as your fractional CISO.
// In short
A fractional CISO is a role, not a headcount
An experienced member of our team acts as your CISO for an agreed number of days a month. They run the risk register, keep you ready for incidents, answer customer questionnaires, maintain the evidence and report to the board quarterly. It suits essential and important entities under NIS2 in Poland that have no CISO of their own, or whose CISO needs support.
// Rhythm
Every month, every quarter and once a year
A fixed calendar instead of work on call. The number of days per month is set in the contract.
Every month
- Review of the risk and obligations register with the owners
- Evidence check: logs, backups and access reviews with a current date
- Answers to customer security questionnaires
- Assessment of new suppliers and contract changes
- Advice for IT and the board at agreed hours
Every quarter
- Board report: risks, incidents, state of the evidence and decisions needed
- Short incident scenario exercise with the team
- Sample review of administrator accounts
Once a year
- Article 8e management training
- ISMS and policy review, with an approval date
- Business continuity plan test
- Pre-audit review when an Article 15 audit is coming up
Incident readiness, rehearsed in advance
Who decides to report
A named person and a deputy, with a phone number outside office hours. Every quarter we check that the details are current.
Early warning within 24 hours
Criteria for when an event is a serious incident, and a prepared form with the data you know straight away.
Notification within 72 hours
Who gathers information on impact and cause, where the logs come from and who approves the notification.
Final report within one month
A report within one month of the notification, with cause, impact and remediation. The template is ready before the incident, not written during it.
Timeline and evidence
Decisions, times and logs recorded as you go. You will need them for the final report, the audit and your customers.
We are not a SOC
We do not monitor your systems 24/7. We prepare the procedure and rehearse it with you, and if you have a SOC provider, we agree the reporting path with them. How to limit the damage of a leak is covered in our article on data breaches.
// First step
The first month, then ongoing support
We start with a fixed 6-week scope. Afterwards, you decide whether you want ongoing support and at what level.
01Start
Current state and a 12-month plan
We check what already works and set the calendar of reviews, exercises and reports.
- Review of the risk and Article 8 obligations register
- Incident reporting procedure with contacts
- List of customer questionnaires and requirements
- 12-month calendar
Request the first stepFirst step, 6 weeks
KSC ongoing support kick-off
- Status of Article 8 obligations with owners
- Calendar of reviews, exercises and reports
- Incident procedure with contacts
Key deliverable: the first board report with a list of decisions to take
02Ongoing
A fractional CISO at an agreed level
One person runs your support, and cover is set in the contract. The knowledge stays in your documentation, not in our heads.
- Days per month written into the contract
- Short monthly summary of the work
- Documentation in your systems
- Polish criminal record certificates (KRK) for our team members (Article 8f)
// Scope
What is in scope and what is not
Scope, days and contact hours are agreed in writing before we start.
In scope
- The fractional CISO role for an agreed number of days
- Risk and Article 8 obligations register with owners and dates
- Incident readiness: procedure, exercises, report templates
- Answers to customer questionnaires and supplier assessments
- Evidence upkeep and a quarterly board report
Out of scope
- 24/7 monitoring and SOC services
- Administering your systems and networks
- Formal KSC audits under Article 15: we don't perform them
- Decisions on behalf of the board: we prepare them, the head of the entity takes them
- Reselling tool licenses
We don't perform formal KSC audits. The auditor has to be independent of whoever runs your controls: it cannot be anyone who performs Article 8 or 9-13 tasks at the entity, or did so in the year before the audit (Article 15(2a)). As of 24 September 2026, source: Dz.U. 2026 item 252 (in Polish).
// FAQ
Questions about a fractional CISO
How is ongoing support different from a KSC implementation?
An implementation has a start and an end: from gap analysis to controls that work. Ongoing support starts after that and keeps the controls working and the evidence current. You can order both, or only ongoing support if someone else did the implementation.
How many days a month does a fractional CISO work?
As many as we write into the contract after the first month. It depends on the number of systems, suppliers and customer questionnaires. If a month needs more, for example after an incident, we agree it with you before we start the work.
Can you perform our KSC audit later?
No. We don't perform formal KSC audits. The auditor also cannot be anyone who performs Article 8 or 9-13 tasks at the entity, or did so in the year before the audit (Article 15(2a)). We help you prepare for an audit that an independent auditor performs.
What happens if there is an incident?
The procedure we rehearsed together kicks in: early warning within 24 hours, notification within 72 hours and a final report within one month of the notification. During the hours set in the contract we help you assess the event and prepare the reports. We do not provide 24/7 monitoring.
Do your team members have a Polish criminal record certificate?
Yes. Under the KSC Act, people who do Article 8 or 11 work at essential and important entities must provide a certificate from the Polish National Criminal Register, KRK (Article 8f). We have it ready before we start.
What stays with us if we end the contract?
Everything. The risk register, procedures, evidence index and reports live in your systems from day one. At the end we hand a list of open items to whoever takes over the role.
From the blog: keeping security running
Let's talk about ongoing KSC support
In 30 minutes we look at what already works, what you need every month and where the first month should start.
Book a 30-minute callPrefer to start in writing?
Tell us who is responsible for cybersecurity at your company today, and we will send you the scope and date of the first step. We reply within one business day.
Request the first step