NIS2 in Poland · KSC · fractional CISO

Fractional CISO: ongoing NIS2 support in Poland, with a clear scope

A KSC implementation ends on the day the controls work. Then someone has to keep them working: review risks, answer customer questionnaires, rehearse incidents and keep the evidence current. We do that every month as your fractional CISO.

// In short

A fractional CISO is a role, not a headcount

An experienced member of our team acts as your CISO for an agreed number of days a month. They run the risk register, keep you ready for incidents, answer customer questionnaires, maintain the evidence and report to the board quarterly. It suits essential and important entities under NIS2 in Poland that have no CISO of their own, or whose CISO needs support.

// Rhythm

Every month, every quarter and once a year

A fixed calendar instead of work on call. The number of days per month is set in the contract.

Every month

  • Review of the risk and obligations register with the owners
  • Evidence check: logs, backups and access reviews with a current date
  • Answers to customer security questionnaires
  • Assessment of new suppliers and contract changes
  • Advice for IT and the board at agreed hours

Every quarter

  • Board report: risks, incidents, state of the evidence and decisions needed
  • Short incident scenario exercise with the team
  • Sample review of administrator accounts

Once a year

Incident readiness, rehearsed in advance

  1. Who decides to report

    A named person and a deputy, with a phone number outside office hours. Every quarter we check that the details are current.

  2. Early warning within 24 hours

    Criteria for when an event is a serious incident, and a prepared form with the data you know straight away.

  3. Notification within 72 hours

    Who gathers information on impact and cause, where the logs come from and who approves the notification.

  4. Final report within one month

    A report within one month of the notification, with cause, impact and remediation. The template is ready before the incident, not written during it.

  5. Timeline and evidence

    Decisions, times and logs recorded as you go. You will need them for the final report, the audit and your customers.

We are not a SOC

We do not monitor your systems 24/7. We prepare the procedure and rehearse it with you, and if you have a SOC provider, we agree the reporting path with them. How to limit the damage of a leak is covered in our article on data breaches.

// First step

The first month, then ongoing support

We start with a fixed 6-week scope. Afterwards, you decide whether you want ongoing support and at what level.

  1. 01Start

    Current state and a 12-month plan

    We check what already works and set the calendar of reviews, exercises and reports.

    • Review of the risk and Article 8 obligations register
    • Incident reporting procedure with contacts
    • List of customer questionnaires and requirements
    • 12-month calendar

    First step, 6 weeks

    KSC ongoing support kick-off

    • Status of Article 8 obligations with owners
    • Calendar of reviews, exercises and reports
    • Incident procedure with contacts

    Key deliverable: the first board report with a list of decisions to take

    Request the first step
  2. 02Ongoing

    A fractional CISO at an agreed level

    One person runs your support, and cover is set in the contract. The knowledge stays in your documentation, not in our heads.

    • Days per month written into the contract
    • Short monthly summary of the work
    • Documentation in your systems
    • Polish criminal record certificates (KRK) for our team members (Article 8f)
    Independence rules

// Scope

What is in scope and what is not

Scope, days and contact hours are agreed in writing before we start.

In scope

  • The fractional CISO role for an agreed number of days
  • Risk and Article 8 obligations register with owners and dates
  • Incident readiness: procedure, exercises, report templates
  • Answers to customer questionnaires and supplier assessments
  • Evidence upkeep and a quarterly board report

Out of scope

  • 24/7 monitoring and SOC services
  • Administering your systems and networks
  • Formal KSC audits under Article 15: we don't perform them
  • Decisions on behalf of the board: we prepare them, the head of the entity takes them
  • Reselling tool licenses

We don't perform formal KSC audits. The auditor has to be independent of whoever runs your controls: it cannot be anyone who performs Article 8 or 9-13 tasks at the entity, or did so in the year before the audit (Article 15(2a)). As of 24 September 2026, source: Dz.U. 2026 item 252 (in Polish).

// FAQ

Questions about a fractional CISO

How is ongoing support different from a KSC implementation?

An implementation has a start and an end: from gap analysis to controls that work. Ongoing support starts after that and keeps the controls working and the evidence current. You can order both, or only ongoing support if someone else did the implementation.

How many days a month does a fractional CISO work?

As many as we write into the contract after the first month. It depends on the number of systems, suppliers and customer questionnaires. If a month needs more, for example after an incident, we agree it with you before we start the work.

Can you perform our KSC audit later?

No. We don't perform formal KSC audits. The auditor also cannot be anyone who performs Article 8 or 9-13 tasks at the entity, or did so in the year before the audit (Article 15(2a)). We help you prepare for an audit that an independent auditor performs.

What happens if there is an incident?

The procedure we rehearsed together kicks in: early warning within 24 hours, notification within 72 hours and a final report within one month of the notification. During the hours set in the contract we help you assess the event and prepare the reports. We do not provide 24/7 monitoring.

Do your team members have a Polish criminal record certificate?

Yes. Under the KSC Act, people who do Article 8 or 11 work at essential and important entities must provide a certificate from the Polish National Criminal Register, KRK (Article 8f). We have it ready before we start.

What stays with us if we end the contract?

Everything. The risk register, procedures, evidence index and reports live in your systems from day one. At the end we hand a list of open items to whoever takes over the role.

From the blog: keeping security running

Let's talk about ongoing KSC support

In 30 minutes we look at what already works, what you need every month and where the first month should start.

Book a 30-minute call

Prefer to start in writing?

Tell us who is responsible for cybersecurity at your company today, and we will send you the scope and date of the first step. We reply within one business day.

Request the first step