From Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ... @FIRSTdotorg
From Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 5 hours ago
From Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated TTX Platform

Marcin Fronczak (Cybersecurity Foundation, PL), Miroslaw Maj (Open CSIRT Foundation, NL)

National‑level cybersecurity exercises require precise planning, credible threat modelling, and an understanding of how a country’s cybersecurity system functions in practice. This presentation shares lessons from three editions of Poland’s KSC‑EXE, conducted with the Ministry of Digital Affairs and involving all national cybersecurity actors, including national CSIRTs, competent authorities, sectoral CSIRTs, and operators of essential services. Built on the Polish NIS‑based legal framework, the exercises ensured scenarios and evaluation matched real obligations.

The session outlines how to design national exercises: setting objectives aligned with legislation, creating realistic multi‑sector threat scenarios, balancing participant engagement, integrating real and simulated entities, and using an advanced TTX platform for dynamic injects. It also presents methods for evaluating results and generating actionable improvements for national cyber resilience.

---

Marcin Fronczak - spent 12 years as Chief Information Security Officer in the financial and insurance sectors and performed IT/OT area security audits for a critical infrastructure operator. Prior to that, he spent 5 years as a consultant in the area of technology risk and security. During many audits and consulting projects in Europe, he gained extensive experience and thorough knowledge of risks and auditing of ICT systems, confirmed by obtaining international certifications including CISA, CIA, CRISC, Comptia Security +, ISO 27001 LA. He was the first Pole to earn the CCSK certification in the Cloud Security Area.

Mirosław Maj (Open CSIRT Foundation, Cybersecurity Foundation) has nearly 30 years of experience in ICT security and has played a major role in shaping cybersecurity capabilities in Poland and abroad. He is the co-founder of the Open CSIRT Foundation, responsible for developing SIM3 maturity model and supporting the Trusted Introducer service certifying security teams worldwide, as well as the founder and president of the Cybersecurity Foundation and co-founder of ComCERT.PL. A former head of CERT Polska, he co created CyberBastion - a simulation and training platform powering the multi-edition CyberBastion League.

He advised the Polish Minister of National Defence on cyberdefence development, is a member of the Polish Digitalization Council, and serves as an expert for ENISA, co-authoring numerous European cybersecurity reports. His international work includes major projects in Georgia, CIS countries and the UN, supporting the creation and maturity of national CERTs. He has organized ten editions of Cyber-EXE exercises for key sectors and national-level NIS-based testing. A regular FIRST speaker and founder of the Security Case Study conference, he also lectures on cybersecurity at several universities.
From Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...From CVD to Secure Releases: Automating Security from Source to ReleasesOnly Seeing Stars: Enabling the Open Source Scripting Community with OCSFInside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chairDraugnet: Anonymous Threat Reporting That Actually WorksAutomated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New MalwareAI Interpretability as a Security Control: Introducing the CIRCUIT FrameworkFrom Dork to Diplomat: Communicating Coherently for Vulnerability & Incident Response
FIRST |

From Planning to Impact: Lessons from Poland’s National Cybersecurity Exercises with a Dedicated ...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER