Not sure whether a message is a scam? CERT Polska has launched a new knowledge base
The new wiedza.cert.pl portal offers practical guidance for individuals and organisations. Here is when to use it—and when to report an incident immediately.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 3 September 2026
- READING TIME
- 7 min read
- TOPIC
- Human Security
A suspicious text message usually arrives at the worst possible moment. A parcel is waiting, an account is about to be locked, or a tiny extra payment is supposedly due. At that point, people do not need a lecture about cybersecurity. They need one trustworthy place that answers a simple question: what should I do now?
On 2 September 2026, CERT Polska announced the launch of wiedza.cert.pl. The portal brings together practical guidance on threats, incident response and prevention. It is intended not only for administrators, but also for business owners, decision-makers and everyday internet users.
What is in the new portal?
At wiedza.cert.pl, resources are organised around situations rather than product names. There are sections on personal security, incident handling, good practice, policies and procedures, and infrastructure resilience. The service launched with dozens of articles and is intended to grow over time.
For anyone who does not work in security, the personal security section is a useful starting point. It includes guidance on protecting phones and social media accounts and recognising phishing. It is a sensible page to bookmark or add to a company intranet.
This does not mean people must investigate every suspicious message themselves. The knowledge base can help someone understand the situation and choose a next step. Reports still go through incydent.cert.pl, while a suspicious Polish text message containing a link can be forwarded to 8080.
Three moments when it can help
Before anything goes wrong. Read a few guides with your family or team and agree where unusual messages should be reported. Learning calmly is much easier than searching for help under pressure.
When a message does not feel right. Do not click the link simply to “see what happens”. Open the knowledge base yourself in a new tab, compare the warning signs with its phishing guidance, and contact the claimed sender through a channel you already trust.
After clicking or sharing information. Do not wait until you are certain it was a scam. CERT Polska’s official phishing response guide recommends steps based on what was exposed: contacting the bank, changing passwords, signing out active sessions, enabling multi-factor authentication and, when Polish identity-document data was shared, restricting the PESEL identity number. Financial loss should be reported to the police.
Guidance does not replace a fast response
A common reaction after clicking a suspicious link is: “I will wait and see whether anything happens.” Reporting a concern is not an admission of guilt, nor an accusation against a particular person. It gives a bank, employer or response team information they can use to limit the damage.
Organisations should separate two needs. A public knowledge base explains how to recognise a situation and what action may be appropriate. An internal procedure must also say whom to call inside the organisation. The simplest version fits in one sentence: if a message involves money, a password or an urgent change of details, pause and report it through the named phone number or mailbox.
Do not make employees prove a message is malicious before they report it. That is the receiving team’s job. A colleague should be able to raise a concern without being mocked for a “false alarm”.
Source facts and Breachroad’s conclusion
The launch date, intended audiences, initial volume of material and plan to expand the portal come from CERT Polska’s announcement. Its published pages provide the section structure, reporting route and response steps after phishing.
Breachroad’s conclusion is that the portal’s greatest value is not the number of articles but one memorable, trusted address. Pair it with a short internal response path and practise using real-life examples instead of expecting people to memorise technical terms.
Our guide to recognising phishing is a useful next read. If you want these principles to become everyday team habits, our cybersecurity training for employees focuses on safe responses to messages, calls and payment requests.


