What do we offer?
We provide comprehensive support in meeting the requirements of the National Cybersecurity System Act. With years of expert experience, we will thoroughly assess your organization’s organizational and technical capabilities to ensure the proper level of security for the digital services you offer. We will conduct an audit to identify and assess risks, analyze the applied security measures, IT systems, risk management methods, and communication models. The result of our experts’ and auditors’ efforts will be a complete report, including the current situation assessment, recommendations, and potential changes—everything will be included in the final documentation required by the law.
With our support, you will gain a full understanding of whether your organization meets the requirements of the KSC Act. You will receive, among other things, a risk register with the likelihood of their occurrence, allowing you to counteract them and ensure business continuity, helping you maintain the reputation of a partner who cares about the security of your service.
Take advantage of our experience and raise your cybersecurity standards.
How do we work?
1. Audits
We will gather, analyze, and assess the current situation in your organization, considering the level of security and the safeguards applied to the systems used for providing digital services. The security audit of the digital service will be conducted according to international standards, including ISO 19011, 27001, 22301, and with an assessment of cybersecurity process maturity using COBIT. We will thoroughly examine the service, IT systems, tools, administration, incident management processes, and communication. We will also review the internal cybersecurity structure, including the team, and assess risks and incidents that could impact the continuity of operations. At the end, you will receive an audit report with findings, an overview of any non-compliance with requirements, and recommendations along with the scope of necessary changes to ensure that your organization meets the requirements of the KSC Act.
2. Impact analysis and risk assessment
We will identify the assets necessary for the uninterrupted provision of your digital service and conduct a business impact analysis in terms of risk analysis and business continuity (according to ISO 22301, ISO 31000, and ISO 27005). We will define the risk analysis methodology, assess the likelihood of threats, and identify critical areas that may impact the continuity of your service. Then, together with your team, we will prepare an action plan that includes risk avoidance, management, and acceptance strategies. Finally, you will receive a report from us with a description of identified risks, their categorization, and a register of assets and threats.
3. Organizational and technical changes
Based on the prepared audit and security analysis reports for the systems used to provide digital services, we will create a list of necessary changes that your organization should implement to meet the requirements of the KSC. These changes will relate to risk management methods and communication models, including both internal and external communication channels. The recommendations will be tailored to the needs and specifics of your organization.
4. Documentation of the security management system
We will prepare the required documentation for your organization regarding the cybersecurity of the information system used to provide the digital service and the protection of related infrastructure. We will create new documents and, if necessary, update existing ones, focusing on risk management processes and business continuity strategy. The provided documentation will complement the existing standards in your organization and be tailored to its specific operations.
5. Training for digital service providers
We provide training and workshops that will equip your staff with knowledge of the national cybersecurity system and the skills necessary to ensure the security of the digital services provided, in line with the developed documentation. At the end of the training or course, each employee will receive a relevant certificate and educational materials.
Let's talk about your project! Fill out the form
What else do we offer?
We will help implement cybersecurity in your organization or its individual components. Check out our offer for other services related to cybersecurity.
Cybersecurity implementation
Learn about the service scopeCybersecurity audit
Learn about the service scopeVulnerability audit
Learn about the service scopeCybersecurity risk analysis
Learn about the service scopeIncident management
Learn about the service scopeSupport in implementing NIS 2
Learn about the service scopeAssessment of the organization's readiness for implementing the NIS2 directive
Learn about the service scopeImplementation of DORA
Learn about the service scopeCyber support
Learn about the service scopeComprehensive NIS2 compliance consulting
Learn about the service scopeCybersecurity documentation
Learn about the service scopeCybersecurity consulting
Learn about the service scopeSupport for key service operators
Learn about the service scopeCybersecurity training
Learn about the service scopeNIS2 directive: training for the board
Learn about the service scopeImplementation of DORA with ICT service providers
Learn about the service scopeTesting resilience according to NIS2
Learn about the service scopeWhy us?
Knowledge and experience
Tailored services
Favorable conditions
We work as equals!
They trusted us
Get to know more
Why should a digital service security analysis be conducted?
Ensuring an adequate level of security for digital services is required by law. These requirements are outlined in the Act on the National Cybersecurity System, which came into force on July 5, 2018, and implements the EU Directive 2016/1148(1). This is the first comprehensive legal act that defines the tasks and obligations necessary to create a national cybersecurity system.
Who is the support for meeting the requirements of the KSC Act intended for?
The service is aimed at digital service providers (DSPs) – such as e-commerce platforms, cloud processing services, and search engines. Due to the international nature of these entities, their obligations are governed by the EU regulatory framework and the Polish KSC Act, which imposes a requirement on these companies to ensure a level of security proportional to the risk to which the security of the digital services they provide is exposed.
Ustawa o krajowym o systemie cyberbezpieczeństwa obejmuje również operatorów usług kluczowych (UOK), dla których przygotowaliśmy odrębną ofertę – sprawdź: Analiza ryzyka cyberbezpieczeństwa.
What is the scope of support for digital service providers?
The service includes checking vulnerabilities and threats that may affect the operation of the IT system, and consequently the availability of the digital service. Support includes conducting an audit, analysis, and preparation of documentation in line with the requirements of the National Cybersecurity System Act. We will verify whether your organization meets the organizational and technical obligations of a digital service provider. We will also conduct an impact analysis and risk assessment regarding the security of the service. Finally, we will prepare and update the required documentation as specified in the KSC Act. Additionally, we will train your staff, raising awareness of potential threats and providing strategies for risk management and crisis situations.
Benefits of cybersecurity risk analysis
The audit and security analysis of digital services aim to ensure that your organization meets the required level of security for the networks and information systems used to deliver services, as mandated by the law. With the comprehensive support provided by PBSG, you will understand the goals and requirements placed on digital service providers and align your security measures, risk management practices, communication, and documentation with the National Cybersecurity System Act. This will ensure that your organization complies with the obligations of digital service providers under the law, while also offering secure services, which is crucial for building a competitive advantage.
How much does analysis and support for a digital service provider cost?
The cost of the audit and analysis regarding the security of a digital service and support for the provider depends on factors such as the size of the organization and its IT systems, the nature of its operations, the market environment, and the complexity of the processes involved. Each service is individually priced, taking into account the scope of work and the preferred timeline.
How long does the audit and risk analysis take for a digital service provider?
Each stage has a defined duration, but the entire process can typically be completed within a few weeks. The timeline depends on the size of the organization and the specifics of the project. We adjust the work schedule to meet the individual needs of your organization.