At first glance - almost all of them. They have antivirus software, they do backups, someone once deployed a firewall, and once a year there's a "cybersecurity" training. On paper, everything looks fine.
In practice, we've seen the same thing for 15 years across 500+ projects: a backup that "worked" - but hadn't been tested in a year. A server that was supposedly "up to date" had 47 unpatched security updates outstanding. Access rights that were supposedly "revoked" were still active for an employee who had left eight months earlier.
Readiness isn't about having implemented something at some point. It's about knowing - based on regular testing, not belief - that your systems will work at the moment of crisis. That people in the company know what to do, that procedures are documented, not just kept in one person's head.
That's why we don't ask "do you have antivirus". We ask: what will you do when your defences fail?
NIS2 in Poland
Manufacturing, digital services, waste management, and the food sector have joined energy and banking. The scale of this change is unprecedented.
Management is personally liable - financially, not just institutionally. It's not enough to say "we have safeguards in place." You need to prove that IT risk is managed in a documented and verifiable way.
An audit report is the simplest way to have that documentation ready - ready for an inspection, a conversation with your insurer, and questions from the board.
42k
organizations covered by NIS2
€10M
maximum penalty for non-compliance
Most of the incidents we see could have been predicted and prevented. Before anyone even attempts to break into your systems, your organization already has either solid foundations or gaps that will sooner or later be exploited.
Prevention at Engave isn't a one-off purchase or a single training session. It's an audit of the actual state of things (not the declared one), tightening of access controls, identity management policies, network configuration, and regular penetration testing.
Effective response starts with the ability to detect - not after the fact, but in near real time. We deploy monitoring and anomaly detection systems, build incident response procedures, and integrate them with your IT teams. When something happens, you're the first to know - and you know exactly what to do next. Our experience with projects like ZUS means we've worked in environments where mistakes are not an option.
Every company should be able to answer one question: how long would it take to fully get back up and running after a total loss of the production environment? Not "roughly" - but precisely, in hours. We design recovery environments with defined RTO and RPO parameters, test them regularly, and document every scenario.
Every company that has paid a ransom to a hacker had a backup. The problem wasn't the lack of a data copy - it was that the backup was accessible from the same network as the production environment. When ransomware encrypted production, it encrypted the backup too.
Digital Bunker is a physically isolated data recovery environment - inaccessible from the infected network, independent of the internet, and built on the "assume breach" principle: we assume the production environment has been compromised, and design protection so the Bunker stays out of its reach regardless of the scale of the attack.
We designed and implemented this system for Zakład Ubezpieczeń Społecznych - one of the largest cybersecurity projects in Polish public administration. Today, this technology is available on a subscription model - no infrastructure of your own, no multi-million investment required.
ISO certifications are a global standard of excellence, guaranteeing that our company operates effectively, efficiently, and in compliance with regulations.
It's proof that our organization is committed to continuous improvement, taking both quality and customer satisfaction seriously.
Cybersecurity, IT care, digitalisation - whatever the topic, we're happy to talk. Describe your need and the right specialist will get back to you within 24 business hours.
CONTACT:
biuro@engave.pl
+22 863 13 90
Technical support: +48 604 470 151
16 Czarodzieja St., 03-116 Warsaw, Poland