Poland’s Ministry of Digitalization opened a competition Thursday for at least 30 shared regional cybersecurity centers serving the country’s 2,800-plus fragmented local governments — a structural redesign driven by a damning national audit released eleven days earlier that found Warsaw could not confirm whether a prior 1.475 billion złoty (approximately $395 million USD) municipal cybersecurity grant program actually improved anyone’s security. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski opened the launch conference with a declaration that has become his governing premise for every defensive investment Poland is making: “We are in a digital war with Russia.”

The new program — Lokalne Centra Cyberbezpieczeństwa, or Local Cybersecurity Centers, known as LCC — will distribute approximately 270 million złoty (roughly $72 million USD) to fund shared professional-grade cybersecurity operations centers serving consortia of municipalities, counties, and regional bodies. Applications are open now through October 30, 2026, according to the official program announcement on gov.pl.

Poland Faces 4,000 Attacks Daily — and Most Hit Its Weakest Layer

The numbers driving this investment are not abstract. Poland currently absorbs roughly 4,000 cyberattacks per day, and Gawkowski told Thursday’s launch conference that 2025 produced more than 279,000 classified cyber incidents across Polish public institutions, per CyberDefence24’s coverage of the event. Among those, local government units — municipalities, county offices, school districts, social service agencies, and the like — logged 3,249 confirmed incidents, a 60 percent increase from 2,027 in 2024, according to the official LCC program launch announcement.

The December 2025 attack on Poland’s energy grid, now formally attributed to Russia’s FSB Center 16 by the United Kingdom and European Union, illustrated the catastrophic upper bound of what inadequate local-level defenses can invite. That attack struck around 30 energy infrastructure facilities simultaneously during a period of frost and came close enough to triggering a blackout that, had it succeeded, would have left approximately 500,000 citizens without power in midwinter temperatures that reached −15°C (5°F). UK Foreign Secretary Yvette Cooper described the Russian state as “striking Poland’s energy grid in the depths of winter” as part of what she called “increasingly reckless attempts to sow chaos across Europe.” Attacks against Poland grew 144 percent year-on-year in 2025, Gawkowski told the Defence24 Days conference in Warsaw in May.

The vulnerability Russia is exploiting most systematically at the local level is not a technical one — it is an organizational one. Poland’s 2,800-plus JSTs (jednostki samorządu terytorialnego — local government units), most of which include schools, social service offices, and utility operators under the same administrative umbrella, lack the resources to sustain professional cybersecurity operations independently. The typical small municipality has a single IT generalist managing multiple sites, responsible simultaneously for printers, payroll systems, citizen-facing databases, and whatever security tooling the institution has purchased. That person cannot simultaneously function as a 24/7 threat analyst.

Why Grants Without Baselines Cannot Fix Cybersecurity

The structural problem with Poland’s first major attempt to address this gap has now been quantified by NIK — the Najwyższa Izba Kontroli, Poland’s constitutional supreme audit institution, equivalent in function to the US Government Accountability Office. On July 20-21, 2026, NIK published the findings of its audit of the Cyberbezpieczny Samorząd (Cybersecure Local Government) program, the prior initiative that distributed individual grants to municipalities beginning in 2023.

The scale of that program was significant. In 2023 alone, 2,614 JSTs applied for grants, and by 2024 a total of 2,497 grant agreements worth 1.475 billion złoty (approximately $395 million USD) had been signed with municipalities and counties. The problem, NIK found, was that the program was designed to measure activity rather than outcomes.

Specifically: the program’s administering body, the Center for Digital Poland Projects (CPPC), neither required municipalities to undergo a standardized security audit before receiving a grant nor established any mechanism to verify whether the money actually made them more secure afterward. The program measured success by counting devices purchased and employees trained — not by assessing whether organizations could now detect and respond to a real attack. “In the majority of audited offices, irregularities in information security were found,” NIK concluded. Despite having participated in the grant program, more than half of audited units still had not implemented SZBI — the System Zarządzania Bezpieczeństwem Informacji, Poland’s ISMS requirement under the National Interoperability Framework (KRI) — which is the foundational security management system that national regulations have required all public entities to operate since 2018.

The audit also found quality-control failures in how grants were settled. Of 15 grant settlement requests examined, 13 were officially approved by NASK (the state research institute that administered applications) despite containing serious errors, defective documentation, or missing required attachments. In several offices, grant money was spent on security software installed on the same servers as operational government systems — a configuration that NIK found explicitly violates KRI regulations and creates resource conflicts that can degrade the security tools’ reliability. Some municipalities, NIK also documented, used grant-funded servers for non-security operational work entirely.

The result is a 1.475 billion złoty (~$395 million USD) program whose administrators cannot confirm produced any improvement in the resilience of the institutions it was supposed to protect. NIK’s formal conclusion: it is impossible to say to what degree subsidized offices actually increased their resistance to cyberattacks.

What the LCC Program Builds Instead

The LCC program’s design is a direct architectural response to that documented failure. Rather than giving each municipality a grant to spend individually, the LCC requires at least two local government units to form a consortium before they can apply — and the consortium’s purpose is to build and operate a shared cybersecurity center that serves all member entities professionally.

State Secretary Paweł Olszewski outlined the minimum operational requirements each center must fulfill: detection and response to cyberattacks and incidents; current inventory of hardware and software across all member organizations; monitoring for software and security patch compliance; access management and privilege control; data protection and backup; email and communications security; and regular staff training, per CyberDefence24’s conference report. These are mandatory baselines, not aspirational guidelines. Centers that exceed them — integrating with Poland’s National Cybersecurity System (KSC) and CSIRT coordination infrastructure, offering additional services — receive additional scoring points in the competition.

The architectural difference between the LCC model and the prior program is the difference between buying a fire extinguisher for every individual office and hiring a professional fire department that covers the whole district. An estimated 9 million złoty (roughly $2.4 million USD) per center — the approximate per-hub budget at 30 centers across 270 million złoty — is sufficient to staff a professional security operations team with 24/7 monitoring capability shared across dozens of municipalities that could not individually afford it. The same 9 million złoty distributed across those municipalities as individual grants would produce more unverifiable device purchases and unmonitored security tools.

“We encourage local governments to join forces,” Olszewski said at Thursday’s conference. “The more local governments, the more money, the more citizens covered under cybersecurity.”

NASK is available to assist municipalities that find the application process complex. Documentation is available through the Center for Digital Poland Projects, and the application window runs through October 30, 2026.

Poland’s Broader Defensive Investment

The LCC program is one element of a much larger defensive posture Poland has been building since the December 2025 grid attack demonstrated that infrastructure disruption — not just espionage — is now a core Russian objective. Warsaw has set a defense budget target of 200 billion złoty (approximately $53.5 billion USD) for 2026, representing 4.83 percent of GDP and the highest defense spending share in NATO, according to an analysis from Harvard’s Epicenter publication. More than 4 billion złoty (approximately $1.07 billion USD) was allocated to cybersecurity specifically in 2025, as Gawkowski announced.

Gawkowski has been explicit about the stakes. At the Defence24 Days conference in May, he asked his audience: “If someone launched a bomb at a power plant in Warsaw — and it just so happens that the bomb failed to detonate — wouldn’t that act by another country be considered an act of war?” The December 2025 attack, he noted to the Defence24 Days conference, was timed to coincide with the coldest period of winter and the New Year holiday — a deliberate design intended to maximize civilian harm and erode public trust in government.

CERT Polska’s description of the December attacks as “purely destructive in nature” — designed to damage rather than surveil — marked a documented escalation in Russia’s objectives. Polish intelligence agency ABW separately disclosed in May 2026 that it had documented five separate compromises of municipal water infrastructure in 2025, including one that nearly caused a city to lose its water supply. Small utilities and local governments are, as ABW described it, proving especially vulnerable.

The LCC program’s ambition is to address that vulnerability not by funding individual tooling purchases that produce unverifiable outcomes, but by creating shared professional infrastructure that local governments can access without having to independently staff and sustain it. Gawkowski framed the goal in terms of equity: “The point is to equalize the cybersecurity status of local Poland.”

Whether the LCC program’s structural redesign will deliver better outcomes than the Cyberbezpieczny Samorząd’s individual grants cannot yet be answered. What can be said is that NIK identified the specific flaw — no security baselines, no post-program audit, activity metrics rather than resilience metrics — and that the LCC’s consortium model, mandatory operational minimums, and KSC integration are all direct structural responses to those findings. NIK’s recommendation to future programs: require standardized security audits before and after, and link grant eligibility to measurable security improvement rather than to the number of devices purchased. By requiring consortium-based professional operations centers rather than per-municipality equipment grants, the LCC program puts accountability into the architecture rather than hoping it emerges from individual implementation.

Frequently Asked QuestionsWhy did Poland’s previous municipal cybersecurity grant program fail to show measurable results?

NIK’s July 2026 audit found that the Cyberbezpieczny Samorząd program, which distributed 1.475 billion złoty (~$395 million USD) in grants to nearly 2,500 municipalities, was built around activity-based metrics rather than security outcomes. The program’s administering body required no standardized security audit before grants were issued and established no mechanism to verify whether recipients became more secure after spending the money. The program counted devices purchased and employees trained rather than whether organizations could detect and respond to real attacks. As a result, NIK concluded it is impossible to determine whether the 1.475 billion złoty program improved anyone’s actual cybersecurity posture. See the NIK audit findings for the complete audit.

How is the new LCC program structurally different from the individual grants Poland issued before?

The key architectural difference is the consortium requirement and the shared-SOC model. Rather than distributing grants to individual municipalities to purchase their own equipment, the LCC requires at least two local governments to form a partnership and apply jointly to fund a shared cybersecurity center that professionally monitors and defends all member organizations. The estimated 9 million złoty (~$2.4 million USD) per hub supports a professional team with 24/7 monitoring capability — something small municipalities cannot independently sustain. This shifts the model from buying individual fire extinguishers to operating a shared fire department. See CyberDefence24’s coverage of the launch conference for details on minimum operational requirements.

Why are local governments specifically targeted in Russia’s cyber campaign against Poland?

Municipal governments, school systems, water utilities, and county offices are attractive targets precisely because they are fragmented and under-resourced. Poland’s 2,800-plus JSTs collectively logged 3,249 cyber incidents in 2025 — a 60 percent increase from 2024 — while most operate with a single IT generalist covering multiple sites. That person cannot simultaneously serve as a 24/7 threat analyst. The December 2025 energy grid attack, now attributed to Russia’s FSB Center 16, demonstrated that adversaries are willing to exploit the gap between national-level defenses and local-level vulnerabilities. Polish intelligence agency ABW documented five separate compromises of municipal water infrastructure in 2025, including one that nearly caused a city to lose its water supply, according to a report from Industrial Cyber. See also the official LCC program announcement for the 2025 incident count.

What does mandatory SZBI compliance actually require of Polish municipalities?

SZBI (System Zarządzania Bezpieczeństwem Informacji) is Poland’s term for an Information Security Management System, the structured framework for identifying, managing, and reviewing an organization’s information security risks. The KRI (National Interoperability Framework) regulation has required all Polish public entities to operate a compliant SZBI since 2018 and to conduct annual independent security audits. NIK’s 2026 audit found that despite years of this legal requirement — and despite the 1.475 billion złoty grant program — more than half of audited municipalities still had not implemented a compliant SZBI, and 47 percent had not conducted the mandatory annual security audit in 2023 or 2024. The full findings are available in the NIK audit report.