In the era of growing cyber threats, local administrations are becoming increasingly vulnerable to attacks that can disrupt their operations and threaten citizen security. In this article, we will examine why cybersecurity is crucial for local governments, what actions they can take to protect themselves, and what benefits come from investing in modern data protection technologies.
Quick Navigation
- What is the Cybersecure Local Government Program?
- What Are the Main Goals of the Cybersecure Local Government Program?
- Who is the Organizer and Beneficiary of the Program?
- Which Units Can Apply for Support Under the Program?
- What Cybersecurity Areas Does the Program Cover?
- What Specific Actions Can Be Financed from the Program?
- What Is the Funding Amount for Local Governments?
- What Are the Grant Criteria in the Program?
- What Does the Application Process for the Cybersecure Local Government Program Look Like?
- What Are the Project Implementation Deadlines Under the Program?
- What Effects Should the Cybersecure Local Government Program Implementation Bring?
- How Does the Program Fit Into Poland’s Broader Cybersecurity Strategy?
What is the Cybersecure Local Government Program?
The Cybersecure Local Government program is a comprehensive government initiative aimed at strengthening the cybersecurity of local government units in Poland. It was launched in response to growing cyber threats that increasingly affect local administrations. The program offers financial and substantive support for local governments, enabling them to invest in modern technological solutions, employee training, and implementation of effective security procedures.
This initiative is part of a broader strategy for digitization and securing the country’s critical infrastructure. It is based on the assumption that strong and attack-resistant local governments are the foundation of the country’s overall digital security. The Cybersecure Local Government program was designed to address the real needs and challenges faced by local authorities in the digital era.
A key aspect of the program is its comprehensiveness. It is not limited solely to providing equipment or software but also includes building competencies, creating procedures, and raising threat awareness among local government employees. Thanks to this approach, the program has a chance to bring lasting and significant effects in improving digital security at the local level.
What Are the Main Goals of the Cybersecure Local Government Program?
The main goals of the Cybersecure Local Government program focus on comprehensively strengthening the resilience of local government units to cyber threats. The priority is to create solid information security foundations in local governments, which will translate into better protection of resident data and smoother functioning of local administration.
One of the key goals is raising the level of knowledge and competencies of local government personnel in cybersecurity. The program plans to conduct a series of trainings and workshops that will enable local government employees to better understand cyber threats and effectively counter them. It is planned to train at least 10,000 local government employees within the next two years.
Another important goal is implementing or updating Information Security Management Systems (ISMS) in local government units. Thanks to this, local governments will have clearly defined procedures and standards for data protection, enabling more effective response in case of security incidents.
The program also aims to implement advanced technical measures, such as intrusion detection and prevention systems, data backup solutions, and network monitoring tools. It is planned that by the end of 2025, at least 80% of local governments will implement advanced cyberattack protection systems.
An important aspect is also increasing the capacity of local governments to quickly detect and respond to security incidents. The program plans to establish regional cybersecurity centers that will support smaller units in crisis situations.
Finally, the program aims to create a cybersecurity culture in local governments, where threat awareness and responsible practices will be an integral part of daily work. The goal is for at least 95% of local governments to have active cybersecurity awareness programs for employees by 2026.
Who is the Organizer and Beneficiary of the Program?
The organizer of the Cybersecure Local Government program is the Ministry of Digitization in cooperation with the Digital Poland Projects Center (CPPC). The Ministry of Digitization, as the main architect of the country’s digitization policy, is responsible for the strategic directions and goals of the program, while CPPC handles its operational implementation, including managing the application process and distributing funds.
A key role in the program is also played by NASK (Research and Academic Computer Network) - National Research Institute, which provides substantive and technical support. NASK, as the operator of the national cybersecurity system, brings to the program its expert knowledge and experience in cybersecurity.
The main beneficiaries of the program are local government units (LGUs) at all levels - municipalities, districts, and voivodeships. The program covers a total of 2,807 units, including 2,477 municipalities, 314 districts, and 16 voivodeships. Special emphasis is placed on supporting smaller units, which often have limited resources and competencies in cybersecurity.
It is worth emphasizing that indirect beneficiaries of the program are also the residents of these local government units. By strengthening local government cybersecurity, the program contributes to better protection of citizens’ personal data, increased reliability of public services provided electronically, and an overall increase in trust in e-government.
The program also provides for cooperation with the private sector, particularly with IT and cybersecurity companies that can provide solutions and services for local governments as part of implemented projects. Thanks to this, the program also stimulates the development of the Polish cybersecurity market.
Which Units Can Apply for Support Under the Program?
The Cybersecure Local Government program is aimed at a wide spectrum of local government units in Poland, covering all levels of local administration. Specifically, the following can apply for support under the program:
- Municipalities - both urban, rural, and urban-rural. The program covers all 2,477 municipalities in Poland, from the smallest rural units to the largest cities.
- Districts - all 314 land and urban districts can apply for program funds.
- Voivodeships - all 16 regional governments are eligible to participate in the program.
It is worth emphasizing that the program is available to local government units regardless of their size or level of advancement in cybersecurity. This means that both small rural municipalities just beginning their digitization journey and large cities with extensive IT infrastructure can find appropriate support in the program.
The program also includes organizational units of local governments, such as city and municipality offices, district offices, marshal offices, and other subordinate institutions (e.g., cultural, educational, or social welfare units), provided they are public finance sector units.
An important caveat is the exclusion of healthcare facilities from the program, which have dedicated, separate cybersecurity support programs.
To ensure fair access to funds, the program introduces differentiated funding thresholds depending on the size and wealth of the local government unit. Thanks to this, even the smallest and least resourced municipalities have a chance for significant cybersecurity support.
What Cybersecurity Areas Does the Program Cover?
The Cybersecure Local Government program comprehensively covers three key cybersecurity areas that are essential for creating an effective protection system in local government units. These areas are:
-
Organizational area - focuses on creating and implementing security policies, procedures, and standards. It includes: • Development and implementation of Information Security Management System (ISMS) • Creation of business continuity and disaster recovery plans • Implementation of cybersecurity risk management processes • Establishment of roles and responsibilities in cybersecurity
-
Competency area - focuses on building knowledge and skills of local government employees. Within this area: • Cybersecurity training for all employees • Specialized courses for IT personnel • Cyber threat awareness programs • Security incident exercises and simulations
-
Technical area - covers implementation of modern technological solutions. In this area, the program supports: • Purchase and implementation of malware protection systems • Implementation of network traffic monitoring and analysis solutions • Implementation of data backup and recovery systems • Network infrastructure modernization for security • Implementation of identity and access management solutions
The program emphasizes a balanced approach to these three areas, recognizing that effective cybersecurity requires not only technical tools but also appropriate processes and competent people. Thanks to this comprehensive approach, local governments have a chance to create a coherent and effective protection system against cyber threats.
What Specific Actions Can Be Financed from the Program?
The Cybersecure Local Government program offers a wide spectrum of actions that can be financed under awarded grants. Specific initiatives for which local governments can allocate funds include:
-
In the organizational area: • Development and implementation of information security policies • Conducting security audits and risk analyses • Creating incident response procedures • Developing business continuity and disaster recovery plans • Implementing an information security management system compliant with ISO 27001
-
In the competency area: • Organizing cybersecurity training for employees at all levels • Conducting specialized courses for IT teams • Implementing cyber threat awareness programs • Organizing security incident exercises and simulations • Participation in industry conferences and workshops on cybersecurity
-
In the technical area: • Purchase and implementation of antivirus and anti-malware systems • Implementation of next-generation firewall solutions • Implementation of intrusion detection and prevention systems (IDS/IPS) • Purchase and configuration of data backup and recovery solutions • Network infrastructure modernization, including network segmentation • Implementation of identity and access management (IAM) systems • Implementation of data and communication encryption solutions • Purchase of network traffic monitoring and analysis tools
Additionally, the program enables financing of advisory and consulting services in cybersecurity, which can help local governments identify the best solutions tailored to their specific needs and challenges.
It is worth emphasizing that this list is not exhaustive, and local governments have some flexibility in proposing actions that best suit their individual cybersecurity needs. The key is that proposed actions contribute to achieving the main program goals and comply with guidelines set by the organizers.
What Is the Funding Amount for Local Governments?
The Cybersecure Local Government program offers significant financial support for local government units, with funding amounts adapted to the size and needs of individual local governments. The funding amount is differentiated and depends on several key factors:
-
For municipalities: • Minimum funding amount is PLN 200,000 • Maximum funding amount reaches PLN 850,000 • Exact amount depends on population and the municipality’s tax income indicator
-
For districts: • Minimum funding amount is also PLN 200,000 • Maximum amount can reach PLN 850,000 • Grant amount depends on district population
-
For voivodeships: • All regional governments can apply for the maximum funding amount of PLN 1,000,000
It is worth emphasizing that the program assumes a flexible approach to financing, taking into account specific needs and challenges of different types of local governments. For example, smaller rural municipalities, which often have limited own resources, can count on a higher percentage of funding relative to total project value.
The funding level can reach up to 100% of eligible project costs for the smallest and least wealthy municipalities. For larger local government units, a certain own contribution is required, the amount of which depends on the tax income indicator per capita.
The program also provides for additional funds for cybersecurity activities under other initiatives, such as the Digital Poland Operational Program. The total pool of funds allocated for the Cybersecure Local Government program and related initiatives amounts to approximately PLN 1 billion.
Importantly, local governments can apply for funds to implement comprehensive projects covering both technical infrastructure investments and soft activities such as training or security audits. This flexibility allows adapting projects to individual needs and priorities of each local government unit.
What Are the Grant Criteria in the Program?
Grant criteria in the Cybersecure Local Government program are carefully developed to ensure effective and fair distribution of funds. Here are the key criteria considered when evaluating applications:
-
Project comprehensiveness: • Evaluated whether the project covers all three key areas: organizational, competency, and technical • Projects proposing a balanced approach to these three areas are preferred
-
Adequacy to needs: • The project should address real cybersecurity needs and challenges of the given local government • A preliminary needs and risk analysis is required
-
Cost effectiveness: • The relationship between proposed actions and their cost is evaluated • Projects offering the best quality-to-price ratio are preferred
-
Innovation and modernity of solutions: • Projects proposing implementation of modern, proven cybersecurity solutions are rated higher
-
Sustainability of results: • The project should guarantee long-lasting effects extending beyond the implementation period • The local government’s ability to maintain and develop implemented solutions is evaluated
-
Readiness for implementation: • Well-prepared projects with clearly defined schedules and division of responsibilities are preferred
-
Project team competencies: • Qualifications and experience of persons responsible for project implementation are evaluated
-
Compliance with standards: • The project should comply with applicable cybersecurity norms and standards, such as ISO 27001 or NIST guidelines
-
Cooperation and experience sharing: • Projects assuming cooperation between local governments or exchange of good practices receive additional points
-
Impact on local development: • The project’s potential impact on digital and economic development of the given region is evaluated
It is worth emphasizing that the application evaluation process is two-stage. In the first stage, formal correctness of the application and meeting basic eligibility criteria is checked. Applications that pass this verification positively are then subjected to detailed substantive evaluation by a team of experts.
These criteria aim to ensure that program funds are used most effectively, bringing real benefits in improving local government cybersecurity. At the same time, the evaluation system takes into account the diversity of needs and capabilities of different types of local government units, from small rural municipalities to large cities.
What Does the Application Process for the Cybersecure Local Government Program Look Like?
The application process for the Cybersecure Local Government program was designed to be transparent and accessible to all eligible local government units. Here are the key stages of this process:
-
Call announcement: • The Ministry of Digitization and CPPC publish an official announcement of the application call • Application deadline is specified, usually lasting 30 to 60 days
-
Application preparation: • Local governments prepare applications according to program guidelines • A preliminary cybersecurity needs and risk analysis is required • Development of a detailed action plan and project budget
-
Application submission: • Applications are submitted electronically through a dedicated web portal • All necessary documents must be attached, including declarations and technical annexes
-
Formal evaluation: • CPPC conducts preliminary formal evaluation of applications • Documentation completeness and meeting basic eligibility criteria is checked • In case of minor deficiencies, applicants have the opportunity to supplement documentation within a specified deadline
-
Substantive evaluation: • Applications that passed formal evaluation positively are subjected to detailed substantive evaluation • Evaluation is performed by a team of independent cybersecurity experts • Applications are evaluated according to previously established criteria, using a point system
-
Results announcement: • The ranking list of projects recommended for funding is published on the program website • Applicants are individually informed about evaluation results
-
Appeal procedure: • Local governments whose applications were not qualified have the right to appeal • Appeals are considered by an independent commission
-
Contract signing: • Grant contracts are signed with local governments whose projects were qualified for funding • Contracts specify detailed project implementation conditions, including schedule and budget
-
Project implementation start: • After signing contracts, local governments can begin implementing planned activities
The entire process, from call announcement to contract signing, usually takes 3 to 6 months. It is worth emphasizing that at every stage of the process, local governments can count on support and consultations from the Cybersecure Local Government program team.
Additionally, before the official call, information webinars and workshops are organized to help local governments prepare high-quality applications. The program also offers technical support for using the electronic application submission system.
What Are the Project Implementation Deadlines Under the Program?
Project implementation deadlines under the Cybersecure Local Government program are carefully planned to enable local governments to effectively implement planned activities while ensuring timely use of funds. Here is key information regarding deadlines:
-
Project implementation period: • Minimum project duration is 12 months • Maximum implementation time is 24 months • Local governments have some flexibility in determining project length within these limits, depending on the scope of planned activities
-
Project start date: • Projects can start at the earliest on the day of signing the funding agreement • It is recommended to start project implementation no later than 3 months from the contract signing date
-
Project completion date: • All projects must be completed by December 31, 2025 • This is related to the schedule for spending EU funds
-
Milestones: • Within the project, local governments are required to define key milestones • Typical milestones include: completion of security audit, implementation of key systems, completion of training cycle
-
Reporting: • Local governments are required to submit quarterly progress reports • Final reports must be submitted within 30 days of project completion
-
Flexibility: • The program provides for the possibility of minor schedule modifications during project implementation • Significant changes require approval from the program managing institution
-
Financial settlement: • Final financial settlement of the project must occur by March 31, 2026
-
Sustainability period: • Local governments are required to maintain project effects for at least 5 years after completion
It is worth emphasizing that these deadlines are correlated with the broader implementation schedule of the National Recovery Plan and other EU-funded programs. Therefore, it is so important that local governments plan their activities precisely and adhere to established deadlines.
The program also provides for support mechanisms for local governments that may encounter difficulties meeting deadlines. These include expert advice, the possibility of schedule modification (in justified cases), and support in accelerating delayed activities.
Adherence to these deadlines is crucial not only for the success of individual projects but also for achieving nationwide goals in local government cybersecurity.
What Effects Should the Cybersecure Local Government Program Implementation Bring?
Implementation of the Cybersecure Local Government program should bring a number of significant effects, both at the local and nationwide level. Expected results include:
-
Increased cyber resilience: • 90% of local governments participating in the program are expected to significantly raise their level of protection against cyberattacks • Predicted 70% reduction in successful attacks within the first two years after implementation
-
Increased employee competencies: • Planned training of at least 50,000 local government employees in cybersecurity • 80% increase in cyber threat awareness among personnel
-
Standardization of security processes: • Implementation of Information Security Management System compliant with ISO 27001 in 60% of participating local governments • Unification of incident response procedures nationwide
-
IT infrastructure modernization: • Replacement of outdated equipment and software in 70% of local governments • Implementation of advanced protection systems in 80% of units
-
Improved business continuity: • 60% reduction in downtime caused by security incidents • Implementation of effective business continuity plans in 85% of local governments
-
Increased citizen trust: • 40% increase in trust in e-services provided by local governments • 50% increase in residents using e-government
-
Stimulation of local IT market: • Creation of at least 1,000 new jobs in the cybersecurity sector • 30% increase in investments in local IT companies specializing in security
-
Development of inter-local government cooperation: • Establishment of 16 regional cybersecurity competency centers • 200% increase in threat information sharing between local governments
-
Improved personal data protection: • 80% reduction in incidents related to personal data leaks • Full GDPR compliance in 95% of local governments
-
Increased innovation: • Implementation of innovative cybersecurity solutions in 40% of local governments • Increase in patents and innovations in the security area
In summary, the Cybersecure Local Government program should bring comprehensive and lasting effects extending beyond just increasing IT security. It is expected to contribute to digital transformation of local governments, increased citizen trust in e-government, and stimulation of local IT and cybersecurity sector development. Program success will be measured not only by technical indicators but also by the satisfaction level of residents and local government employees and overall improvement in local administration efficiency.
How Does the Program Fit Into Poland’s Broader Cybersecurity Strategy?
The Cybersecure Local Government program is an integral part of Poland’s broader cybersecurity strategy, fitting into key priorities and goals defined at the national level. Here is how this program connects with the overall strategy:
-
Implementation of Poland’s Cybersecurity Strategy: The program directly implements goals contained in Poland’s Cybersecurity Strategy for 2019-2024, particularly in the area of strengthening resilience of public administration information systems. It contributes to achieving the strategic goal of raising resilience to cyber threats and increasing the level of information protection in the public sector.
-
Strengthening the national cybersecurity system: Cybersecure Local Government is a key element in building a comprehensive cyberspace protection system for Poland. By strengthening security at the local level, the program contributes to overall improvement of the country’s cybersecurity level. Local governments, as an important link in public administration, become more resistant to attacks, which translates into increased security of the entire system.
-
Development of competencies in cybersecurity: The program fits into the strategic goal of workforce development and increasing social awareness in cybersecurity. Through training and building competencies of local government employees, the program contributes to creating a broad base of cybersecurity specialists throughout the country.
-
Cross-sectoral cooperation: Cybersecure Local Government promotes cooperation between the public and private sectors, which is one of the priorities of the national cybersecurity strategy. The program encourages partnerships with local IT companies and scientific institutions, thereby supporting the development of the Polish cybersecurity sector.
-
Protection of critical infrastructure: Many local governments manage elements of critical infrastructure at the local level. The program contributes to better protection of these resources, which is a key element of the national cybersecurity strategy.
-
Standardization and harmonization of procedures: Through implementing uniform standards and procedures in local governments, the program supports the strategic goal of unifying the approach to cybersecurity in public administration at all levels.
-
Support for digital transformation: The Cybersecure Local Government program is closely linked to the broader country digitization strategy. By supporting secure digitization of public services at the local level, the program contributes to achieving the goals of the Integrated State Informatization Program.
-
Implementation of international obligations: The program supports implementation of Poland’s obligations arising from EU and NATO membership in cybersecurity, including NIS Directive implementation at the local level.
-
Building resilience to hybrid threats: By strengthening local government cybersecurity, the program contributes to increasing the country’s resilience to hybrid threats, which is one of the priorities of the national security strategy.
-
Stimulating innovation: The program encourages implementation of innovative cybersecurity solutions, thereby supporting the strategic goal of developing Polish technologies in this field.
In summary, the Cybersecure Local Government program is a key element in implementing Poland’s broader cybersecurity strategy. By strengthening security at the local level, the program contributes to building a comprehensive cyberspace protection system, developing competencies, stimulating innovation, and implementing international obligations. It constitutes practical implementation of strategic assumptions at the local government level, which is essential for effective protection of the country’s digital infrastructure.
Read Also
- How Does the Cybersecure Local Government Program Work? Goals, Amounts, and Evaluation Criteria
- What is a Forensic Audit? Definition, Methodology, Application, and Impact on Organizational Security
- How Does the Cyberbezpieczny Samorząd Program Work? Goals, Funding Amounts and Evaluation Criteria
Develop Your Skills
This article is related to the training Cyber security for employees of Local Government Units (LGUs). Check the program and sign up to develop your skills with EITT experts.
Read also
- How Does the Cybersecure Local Government Program Work? Goals, Amounts, and Evaluation Criteria
- How Does the Cyberbezpieczny Samorząd Program Work? Goals, Funding Amounts and Evaluation Criteria
Frequently Asked Questions
What is the total budget allocated for the Cybersecure Local Government program?
The total pool of funds allocated for the Cybersecure Local Government program and related initiatives amounts to approximately PLN 1 billion. Individual grants range from PLN 200,000 to PLN 850,000 for municipalities and districts, while voivodeships can apply for up to PLN 1,000,000.
Can small rural municipalities apply for the program?
Yes, the program is specifically designed to be inclusive of all local government units regardless of size. Smaller and less resourced municipalities can benefit from differentiated funding thresholds and may receive up to 100% coverage of eligible project costs, ensuring fair access to cybersecurity support.
How long do local governments have to implement their cybersecurity projects?
Projects under the program must last between 12 and 24 months, with all projects required to be completed by December 31, 2025. Local governments are also obligated to maintain project effects for at least 5 years after completion, ensuring lasting cybersecurity improvements.
Does the program cover employee training in addition to technical infrastructure?
Yes, the program takes a comprehensive approach covering three key areas: organizational, competency, and technical. The competency component includes cybersecurity training for all employees, specialized courses for IT personnel, awareness programs, and security incident exercises and simulations.