New regulations force universities to implement Cybersecurity Systems requirements
Polish universities must comply with new cybersecurity requirements by April 3, 2027, but experts warn that many institutions may be unprepared. Under the amended National Cybersecurity System Act, universities must implement information security management systems, conduct risk assessments, establish incident-reporting procedures, and reorganize responsibilities. Rectors will be directly accountable for cybersecurity and cannot delegate that responsibility. Łukasz Faber of AGH University says effective security systems take years, not months, to develop. Smaller and nontechnical institutions may lack sufficient staff and funding, increasing the risk of buying solutions that meet formal requirements without improving protection.
Universities must also overcome decentralized structures and treat cybersecurity as an organization-wide issue involving technology, law, risk management, procedures, and employee training.
(wnp.pl)