Poland's Cybersecurity Forum opens awareness month: how organisations can turn ideas into action
The eighth Cybersecurity Forum and European Cybersecurity Month begin on 30 September. Here is a practical plan for staff and management.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 30 September 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
Poland’s eighth Cybersecurity Forum opens at Warsaw’s Palace of Culture and Science on 30 September. Organised by the Ministry of Digital Affairs and the City of Warsaw, the two-day event is being held for the first time as a standalone forum in the capital. It also marks the opening of European Cybersecurity Month.
The programme covers attacks on institutions and businesses, disinformation, critical-infrastructure protection, emerging technology, regulation, incident response and international cooperation. A public zone offers cyber-hygiene workshops, attack simulations and competitions. The event is a valuable starting point, but attendance alone does not change behaviour or improve resilience.
Bring a decision back, not only conference notes
A familiar post-conference pattern is easy to recognise: an attendee collects a long list of ideas, forwards presentation slides, and everyone returns to established habits a week later. One implemented improvement is more valuable to the organisation than twenty unassigned ideas.
Before arriving, participants should know which questions they want answered. Does the company need a clearer phishing-reporting procedure? Has management ever rehearsed decisions during ransomware? Does procurement assess supplier access? Each question can become a post-event decision with an owner and deadline.
A useful debrief can fit on one page: three relevant observations, one risk for the organisation, one recommended change and the person who should approve it. This turns conference learning into a process rather than a benefit retained by one employee.
Awareness month should be more than a poster campaign
European Cybersecurity Month often produces a sequence of password reminders. Most people do not need another definition of phishing. They need simple behaviours for high-pressure moments: pausing a payment, ending a suspicious call, verifying a bank-account change through another channel, and reporting an accidental click without fearing punishment.
A practical October programme can use four short activities:
- a 15-minute team discussion about one realistic scam;
- a test of the reporting channel so people know where suspicious messages go;
- an out-of-hours contact drill for the incident owner;
- a management simulation in which a security event stops an important service.
The aim is not to catch employees out. It is to determine whether the safe choice is easy, fast and supported by managers. If a person has to locate a 40-page procedure before reporting, inattentiveness is not the only problem.
Different plans for management, staff and IT
Management should rehearse business decisions: who can suspend a service, who communicates with customers, when legal counsel becomes involved, and how the company operates without a core system. IT needs current contacts, access to logs, configuration backups and an agreed way to isolate systems. Employees need a clear reporting route and confidence that early disclosure of an error is encouraged rather than hidden.
These groups should not receive identical training. Sales teams are more likely to face customer impersonation, finance a fraudulent bank-detail change, HR a malicious candidate file, and administrators an attempt to hijack a privileged session. Common foundations are verification through a separate channel, least privilege and rapid escalation.
Five results worth having by 31 October
At the end of the month, an organisation should be able to show more than attendance. Sensible outputs include a functioning reporting channel, current emergency contacts, one completed simulation, remediation of a weakness identified in the exercise, and a plan for role-based training.
Useful measures include time from employee report to response, the number of reports that warranted analysis and the percentage of remediation actions completed on time. A phishing test’s click rate can be misleading on its own. Growth in correct reports may matter more than an unrealistic target of zero clicks.
We develop scenarios for finance, sales, HR and leadership in cybersecurity training for organisations. Management can test decisions in an incident-response tabletop exercise, while staff can reinforce the foundations in the free Breachroad Academy.
Source facts and Breachroad conclusions
The Ministry of Digital Affairs announcement confirms the dates, venue, organisers, opening of European Cybersecurity Month, principal topics and public programme.
The knowledge-transfer plan, proposed exercises and measures are Breachroad recommendations. We do not describe event outcomes because this article is published on the opening day.

