Purpose: The aim of the article is to examine how companies, listed on the Polish Stock Exchange in the energy sector disclose cybersecurity issues in Management Board Reports and Sustainable Development Reports before and after the implementation of mandatory reporting in accordance with the European Sustainability Reporting Standards (ESRS 2), "General Disclosures" and "Business Conduct" (ESRS G1). The study focuses on identifying changes in the transparency, scope and quality of disclosures. Design/methodology/approach: An analysis of the content of the Management Board Reports and Sustainable Development Reports of companies from the energy sector for 2023 (the period before the implementation of the CSRD) and for 2024 (the period after the implementation of the CSRD) was used. Based on the ESRS guidelines, the company's an author-developed Cybersecurity Disclosure Index was developed, covering four areas: Governance, Strategy, Risk Management and "Metrics and Targets". Findings: The results of the study showed that most of the analysed companies increased the amount and scope of reported information on cybersecurity after the introduction of mandatory ESRS reporting requirements. However, the disclosures still lack several key elements considered essential in this area. Originality/value: The study contributes to expanding the understanding of governance in social responsibility reporting, encompassing cybersecurity. The study analyzes information security in non-financial reporting before and after the implementation of the mandatory provisions of the CSRD Directive and the ESRS standards. To the author's knowledge, this is the first study in Poland on this topic.
Artykuł analizuje możliwości i uwarunkowania wykorzystania sztucznej inteligencji (AI) w operacjach wojskowych w kontekście bezpieczeństwa narodowego Rzeczypospolitej Polskiej. Celem badań było rozpoznanie potencjału, ograniczeń oraz czynników prawnych, organizacyjnych i technologicznych determinujących wdrażanie AI w Siłach Zbrojnych RP. Postawiono hipotezę, że zastosowanie AI wzmacnia bezpieczeństwo narodowe, choć skuteczność jej implementacji zależy od spójnych regulacji i kompetencji personelu. Zastosowano analizę dokumentów strategicznych, piśmiennictwa naukowego oraz metodę analizy i syntezy. Wyniki wskazują, że mimo istniejących krajowych strategii oraz ram NATO i ONZ, tempo implementacji AI w polskiej obronności pozostaje niższe niż u partnerów zagranicznych z uwagi na bariery wykonawcze, brak szczegółowych dokumentów wdrożeniowych oraz ograniczone finansowanie badań. Zidentyfikowano trzy kluczowe kategorie ryzyka: techniczne, operacyjne i cybernetyczne. Rekomenduje się opracowanie krajowych ram prawnych zapewniających kontrolę człowieka nad systemami autonomicznymi, zwiększenie inwestycji w badania i kadry specjalistyczne oraz rozwijanie współpracy międzynarodowej w celu harmonizacji standardów bezpieczeństwa.
EN
The article analyzes the possibilities and conditions of using artificial intelligence (AI) in military operations in the context of Poland’s national security. The study aimed to identify the potential, limitations, and legal, organizational, and technological factors determining the implementation of AI in the Polish Armed Forces. The main hypothesis assumes that the use of AI strengthens national security, although the effectiveness of its implementation depends on coherent regulations and personnel competencies. The research applied the analysis of strategic documents, scientific literature, and the method of analysis and synthesis. The findings indicate that despite existing national strategies and the frameworks of NATO and the United Nations, the pace of AI implementation in Poland’s defense sector remains slower than that of its foreign partners due to operational barriers, the lack of detailed implementation documents, and limited research funding. Three key categories of risks were identified: technical, operational, and cyber. The recommendations emphasize the need to develop national legal frameworks ensuring human control over autonomous systems, increase investments in research and professional training, and strengthen international cooperation to harmonize security standards.
Artykuł przedstawia analizę oraz implementację algorytmu steganografii sieciowej z wykorzystaniem protokołu DNS w strukturze Command and Control. Szczegółowo opisano implementację proponowanego rozwiązania, obejmującą wykorzystanie klucza w celu zwiększenia bezpieczeństwa, implementację odroczonej w czasie transmisji, pasywnego odbioru danych oraz technik segmentacji pakietów w celu zwiększenia przepustowości kanału. Zaprezentowano proof-of-concept weryfikujący funkcjonalność zaproponowanego ukrytego kanału. Analizie poddano zależności pomiędzy przepustowością, poziomem trudności detekcji oraz odpornością na ataki. Ponadto, przeprowadzono ewaluację skuteczności wybranych narzędzi detekcji steganografii sieciowej (PfSense, Snort, Zeek, analiza statystyczna) w kontekście zaimplementowanej metody.
EN
This study explores the design, implementation, and evaluation of a novel network steganography algorithm based on the DNS protocol, incorporating a Command and Control architecture. The proposed solution is thoroughly implemented and analyzed, demonstrating key usage for enhanced security, delayed transmission mechanisms, passive data reception, and packet segmentation techniques aimed at improving channel throughput. A proof-of-concept implementation confirms the functionality of the covert channel. Furthermore, the work investigates the relationships between channel throughput, detection difficulty, and resistance to countermeasures. The effectiveness of selected network steganography detection tools (PfSense, Snort, Zeek, and statistical analysis) is also evaluated in the context of the developed method.
Sztuczna inteligencja (AI) jest coraz szerzej wykorzystywana w środowiskach krytycznych, takich jak: opieka zdrowotna, automatyka przemysłowa, systemy autonomiczne oraz operacje cyberbezpieczeństwa. Jednocześnie systemy AI stają się celem rosnącej liczby zagrożeń, w tym ataków typu data poisoning, evasion, model extraction, model inversion, a także socjotechniki wspieranej przez modele generatywne. W artykule przedstawiono prace w projekcie cPAID (Cloud-Based Platform- Agnostic Adversarial AI Defence Framework) – chmurową, modularną i niezależną od platformy architekturę ochrony przed zagrożeniami wymierzonymi w systemy AI. W artykule przedstawiono prace projektowe obejmujące analizę luk w systemach AI, wymagania funkcjonalne i niefunkcjonalne dla systemu ochrony, jego architekturę wysokiego poziomu oraz pięć pilotaży walidacyjnych. Proponowane rozwiązanie integruje siedem kluczowych elementów: Data Fabric, Generative Adversarial AI (GenAAI), meta-SIEM (mSIEM), AI-assisted Intrusion Detection and Prevention System (AIPS), Risk Management for AI (RI MA), Adversarial AI Cyber Range oraz metodykę MLPrivSecOps. Architektura systemu jest obecnie walidowana w obszarach monitorowania baterii pojazdów elektrycznych, wykrywania pożarów lasów z dronów, ochrony urządzeń medycznych, autonomii morskiej oraz szkolenia ekspertów cyberbezpieczeństwa. System cPAID stanowi podstawę dla bezpiecznego, wyjaśnialnego, zgodnego z regulacjami i odpornego na ataki wdrażania AI w heterogenicznych środowiskach operacyjnych.
EN
Artificial Intelligence (AI) is increasingly deployed in critical domains such as healthcare, industrial monitoring, autonomous systems, and cybersecurity operations. At the same time, AI-enabled systems are exposed to a broad range of threats, including data poisoning, evasion, model inversion, model extraction, prompt manipulation, and AI-enhanced social engineering. This paper presents cPAID (Cloud-Based Platform- Agnostic Adversarial AI Defence Framework), a modular and cloud-based framework designed to improve the resilience, explainability, compliance, and trustworthiness of AI systems. The paper synthesises cPAID project work by outlining the motivation, requirements engineering process, high-level architecture, and pilot validation strategy. The proposed framework integrates seven main components: Data Fabric, Generative Adversarial AI (GenAAI), meta-SIEM (mSIEM), AI-assisted Intrusion Detection and Prevention System (AIPS), Risk Management for AI (RIMA), Adversarial AI Cyber Range, and the MLPrivSecOps methodology. The cPAID system will be validated through five pilots: in electric vehicle battery monitoring, wildfire detection from drones, ICU medical device protection, maritime autonomy, and cybersecurity expert training. The cPAID framework provides a foundation for secure-by-design, privacy-aware, explainable, and regulation-aligned adversarial AI defence across heterogeneous operational environments.
Artykuł przedstawia aktualne wykorzystanie oraz rozszerzenia dotyczące zakresu stosowania technologii Smart Metering. Szczególną uwagę poświęcono aspektom bezpieczeństwa informatycznego, które stanowią kluczowy element zapewniający stabilność i niezawodność tych systemów. Autorytet zastosowania ochrony, który dotyczy zabezpieczeń fizycznych, jak i sieciowych, jako skuteczna odpowiedź na zagrożenie cybernetyczne. Wykluczono konieczność wystąpienia monitorowania systemów, regularnych audytów oraz edukacji, która jest konieczna, gdy wystąpi ryzyko. W artykule wskazano, że tylko przy zastosowaniu standardów bezpieczeństwa możliwe jest wykorzystanie technologii Smart Metering, bez narażania użytkowników na utratę danych lub zakłócenia w funkcjonowaniu infrastruktury.
EN
The article presents the current use and extensions of the scope of application of Smart Metering technology. Particular attention is paid to IT security aspects, which are a key element in ensuring the stability and reliability of these systems. The authority of protection, which concerns both physical and network security, is presented as an effective response to cyber threats. The need for system monitoring, regular audits and education, which is necessary when risks arise, has been ruled out. The article points out that only by applying security standards is it possible to use Smart Metering technology without exposing users to data loss or infrastructure disruptions.
6
Dostęp do pełnego tekstu na zewnętrznej witrynie WWW
Research objectives and hypothesis/research questions: The primary objective of this study is to identify the key success factors for embedding digital asset protection within the broader framework of corporate governance. The research is founded on the hypothesis that the effectiveness of digital protection is significantly higher in organizations where cybersecurity is managed as a strategic risk rather than a technical cost. Research methods: This study is grounded in Systems Theory and the Socio-Technical Systems (STS) perspective, which views cybersecurity as an interaction between technology, people, and organizational hierarchy. The research procedure was executed in three distinct stages: a systematic review of contemporary literature on the subject, a comparative analysis of international security frameworks (specifically ISO/IEC 27001 and NIST), and the subsequent synthesis of an integrated four-layer management model. The methodology relies on qualitative research methods, specifically qualitative content analysis of academic journals and industry standards. The research instruments utilized include standardized data extraction sheets for thematic coding and the Capability Maturity Model Integration (CMMI) framework to evaluate organizational progress. By employing these qualitative tools, the study identifies the intersection points where technical controls become strategic management assets, ensuring that the resulting model is both theoretically sound and practically applicable to modern organizations. Main results: The research concludes that a lack of executive level engagement and „siloed” IT structures are the primary barriers to effective defense, leading to the development of a four-layer model that integrates governance, end-to-end processes, performance measurement, and maturity-based continuous improvement. Implications for theory and practice: Theoretically, this study shifts the academic focus from infrastructure protection to cybersecurity governance by treating security decisions as fundamental business resource allocations. Practically, it mandates that organizations integrate digital risk into Enterprise Risk Management frameworks, prioritize cyber resilience over simple prevention, and move away from „paper-based” compliance toward a functional security culture.
PL
Cel badań i hipotezy/pytania badawcze: Głównym celem badania jest identyfikacja kluczowych czynników sukcesu w zakresie wdrażania ochrony zasobów cyfrowych w szerszych ramach ładu korporacyjnego. Badanie opiera się na hipotezie, że skuteczność ochrony cyfrowej jest znacznie wyższa w organizacjach, w których cyberbezpieczeństwo jest traktowane jako ryzyko strategiczne, a nie koszt techniczny. Metody badawcze: Badanie opiera się na teorii systemów i perspektywie systemów społeczno-technicznych (STS), która postrzega cyberbezpieczeństwo jako interakcję między technologią, ludźmi i hierarchią organizacyjną. Procedura badawcza została przeprowadzona w trzech odrębnych etapach: systematyczny przegląd współczesnej literatury przedmiotu, analiza porównawcza międzynarodowych ram bezpieczeństwa (w szczególności ISO/IEC 27001 i NIST) oraz późniejsza synteza zintegrowanego czterowarstwowego modelu zarządzania. Metodologia opiera się na jakościowych metodach badawczych, a konkretnie na jakościowej analizie treści czasopism naukowych i standardów branżowych. Wykorzystane narzędzia badawcze obejmują standardowe arkusze ekstrakcji danych do kodowania tematycznego oraz ramy zintegrowanego modelu dojrzałości organizacyjnej (Capability Maturity Model Integration, CMMI) do oceny postępów organizacyjnych. Dzięki zastosowaniu tych narzędzi jakościowych w badaniu zidentyfikowano punkty przecięcia, w których kontrole techniczne stają się strategicznymi zasobami zarządzania, zapewniając, że powstały model jest zarówno teoretycznie uzasadniony, jak i praktycznie zastosowalny w nowoczesnych organizacjach. Główne wyniki: Badania wykazały, że brak zaangażowania kadry kierowniczej oraz „silosowe” struktury IT stanowią główne przeszkody dla skutecznej ochrony, co doprowadziło do opracowania czteropoziomowego modelu integrującego zarządzanie, kompleksowe procesy, pomiar wydajności oraz ciągłe doskonalenie oparte na dojrzałości. Implikacje dla teorii i praktyki: Teoretycznie badanie to przesuwa akademickie zainteresowanie z ochrony infrastruktury na zarządzanie cyberbezpieczeństwem, traktując decyzje dotyczące bezpieczeństwa jako podstawowe alokacje zasobów biznesowych. W praktyce nakazuje organizacjom integrację ryzyka cyfrowego z ramami zarządzania ryzykiem przedsiębiorstwa (ERM), priorytetowe traktowanie odporności cybernetycznej zamiast prostej prewencji oraz odejście od „papierowej” zgodności na rzecz funkcjonalnej kultury bezpieczeństwa.
W artykule omówiono najważniejsze elementy charakteryzujące wymiar i zakres cyberbezpieczeństwa. Określono istotę cyberprzestrzeni w kontekście jej informacyjnego charakteru. Odniesiono się do zagrożeń cyberprzestrzeni i sklasyfikowano je w trzech głównych obszarach: informacyjnym, informatycznym i kinetycznym. Przedstawiono obszary cyberbezpieczeństwa w odniesieniu do zagrożeń i elementów składowych cyberprzestrzeni.
EN
The article identifies the most important elements determining the dimension and scope of cybersecurity. It defines cyberspace in the context of its informational nature, and Cyberspace threats are classified into three main areas: informational, IT, and kinetic. Cybersecurity areas are presented in relation to threats and components of cyberspace.
9
Dostęp do pełnego tekstu na zewnętrznej witrynie WWW
The article analyzes the growing role of artificial intelligence (AI) in modern command and control (C2) systems within the armed forces. The author discusses AI’s impact on decision-making processes, operational management, and cybersecurity, highlighting benefits such as faster data analysis and resource management optimization. Simultaneously, it addresses challenges related to AI integration, legal responsibility, and ethical concerns. The article emphasizes the need to develop interoperable AI systems, adapt legal regulations, and ensure effective human-machine cooperation.
PL
W artykule przeanalizowano rolę sztucznej inteligencji (AI) w nowoczesnych systemach dowodzenia i kontroli (C2) w siłach zbrojnych. Omówiono wpływ AI na procesy decyzyjne, zarządzanie operacjami oraz cyberbezpieczeństwo. Wskazano na korzyści płynące z wykorzystania AI, takie jak przyspieszenie analizy danych czy optymalizacja zarządzania zasobami. Zwrócono uwagę na wyzwania związane z integracją AI, odpowiedzialnością prawną i zagrożeniami etycznymi. Podkreślono konieczność rozwijania interoperacyjnych systemów AI, dostosowania regulacji prawnych oraz zapewnienia efektywnej współpracy człowieka z maszyną.
Z punktu widzenia spółki wodociągowo-kanalizacyjnej ten rok powinien być potraktowany jak ostatni moment na przejście od myślenia reaktywnego do systemowego. Nie chodzi o kupienie jednego firewalla, jednego programu antywirusowego czy jednego „pakietu cyber”. Chodzi o zbudowanie porządku.
W zakładach przemysłu spożywczego utrzymanie ruchu funkcjonuje w warunkach innych niż w większości gałęzi przemysłu. Dostęp do maszyn bywa ograniczony reżimem higienicznym, interwencje techniczne często kolidują z planami mycia i dezynfekcji, a wiele usterek objawia się nie gwałtowną awarią, lecz stopniową utratą stabilności procesu. W tym środowisku zdalna diagnostyka staje się narzędziem codziennej pracy automatyka i służb UR, pozwalającym wcześniej wychwycić symptomy problemów oraz ograniczyć liczbę wejść na linię produkcyjną.
Cyberbezpieczeństwo przemysłowe w Europie weszło w fazę dojrzałości regulacyjnej. To, co jeszcze kilka lat temu funkcjonowało jako zbiór zaleceń i dobrych praktyk, dziś przyjmuje formę obowiązków prawnych, których niewypełnienie oznacza realne konsekwencje finansowe, operacyjne i reputacyjne.
Zaciera się dziś granica między IT, OT i telekomunikacją, a cały system staje się programowalny i rozproszony. W efekcie powstaje jednak też nowa powierzchnia do potencjalnego ataku.
14
Dostęp do pełnego tekstu na zewnętrznej witrynie WWW
The article addresses the problem of multi-criteria optimisation of configuration parameters for an information protection system (IPS) within an enterprise or company. The problem lies in the difficulty of allocating a company’s limited resources among the various components of the information security system (ISS) when there are conflicting requirements regarding security and performance. To address this challenge, it is proposed to integrate an analytical risk assessment model with the NSGA-II evolutionary algorithm. This results in the formation of a 3D Pareto front, which will enable the decision-maker to select a security configuration based on a visual analysis of five dimensions: reliability, performance, scalability, cost and compliance. This will eliminate the subjectivity inherent in methods that rely on a priori weighting coefficients. During the computational experiments, the influence of algorithm parameters on the formation of the solution set was examined, and Pareto fronts were visualised using the Plotly library. The trade-offs between the considered criteria were analysed. The results obtained confirmed the effectiveness of the proposed approach for selecting the optimal configuration of the protection system.
PL
Artykuł porusza problem wielokryterialnej optymalizacji parametrów konfiguracyjnych systemu ochrony informacji (IPS) w przedsiębiorstwie lub firmie. Problem polega na trudnościach związanych z alokacją ograniczonych zasobów firmy pomiędzy różne elementy systemu bezpieczeństwa informacji (ISS) w sytuacji, gdy występują sprzeczne wymagania dotyczące bezpieczeństwa i wydajności. Aby sprostać temu wyzwaniu, proponuje się połączenie analitycznego modelu oceny ryzyka z algorytmem ewolucyjnym NSGA-II. Efektem tego jest utworzenie trójwymiarowej powierzchni Pareto, która umożliwi decydentowi wybór konfiguracji zabezpieczeń w oparciu o wizualną analizę pięciu wymiarów: niezawodności, wydajności, skalowalności, kosztu i zgodności z przepisami. Pozwoli to wyeliminować subiektywność charakterystyczną dla metod opartych na a priori ustalonych współczynnikach ważenia. W trakcie eksperymentów obliczeniowych zbadano wpływ parametrów algorytmu na tworzenie się zbioru rozwiązań, a fronty Pareto zwizualizowano przy użyciu biblioteki Plotly. Przeanalizowano kompromisy między rozpatrywanymi kryteriami. Uzyskane wyniki potwierdziły skuteczność proponowanego podejścia w wyborze optymalnej konfiguracji systemu zabezpieczeń.
Niniejszy artykuł poświęcony jest praktycznym możliwościom wdrożenia Dy-rektywy UE 2022/2555 (NIS2) w małych i średnich jednostkach samorządu terytorialnego w Polsce o ograniczonych zasobach finansowych i kadrowych. Problematyka poruszona w pracy obejmuje kluczowe wyzwania, przed którymi stoją małe i średnie jednostki samorządu terytorialnego (JST) chcące zapewnić zgodność z wybranymi wymaganiami omawianej dyrektywy w zakresie zarzą-dzania ryzykiem oraz gotowości na cyberincydenty. Szczególną uwagę zwrócono na ryzyka związane z próbą jednoczesnego i pełnego wdrożenia wszystkich wymagań, co w realiach samorządowych może prowadzić do przeciążenia organizacji, nieefektywnego ekonomicznie wydatkowania środków oraz wdrażania zabezpieczeń dających jedynie pozorne poczucie bezpieczeństwa. W odpowiedzi na te wyzwania przyjęto tezę, że skuteczne wdrożenie NIS2 w JST wymaga podejścia etapowego, opartego na priorytetyzacji zasobów krytycznych, uproszonych mechanizmów zarządzania ryzykiem oraz wykorzystaniu rozwiązań open-source i programów wsparcia.
EN
This article is devoted to the practical possibilities of implementing Directive (EU) 2022/2555 (NIS2) in small and medium-sized local government units in Poland under conditions of limited financial and human resources. The issues addressed in the paper concern the key challenges faced by local government entities seeking to ensure compliance with selected requirements of the Directive in the areas of risk management and cybersecurity incident preparedness. Particular attention is given to the risks associated with attempting the simultaneous and comprehensive implementation of all requirements, which in the context of local administration may lead to organizational overload, economically inefficient allocation of funds, and the deployment of safeguards that provide only an illusory sense of security. In response to these challenges, the article advances the thesis that the effective implementation of NIS2 in local government units requires a phased approach based on the prioritization of critical assets, simplified risk management mechanisms, and the use of open-source solutions and available support programs.
Contemporary armed conflicts have confirmed that Command Posts (CPs) have become one of the most vulnerable elements of the C2 system, particularly under conditions of integrated kinetic, cyber, and electromagnetic effects. The experiences of Ukraine from 2022–2025 demonstrate that traditional, static, and high-emission Command Posts are incapable of survivability in an environment saturated with ISR sensors and automated targeting systems. The aim of this article is to analyze the determinants of CP protection and cybersecurity in multi-domain operations and to identify key factors for their survivability. Results indicate that effective protection requires a systems approach combining mobility, dispersion, electromagnetic signature reduction, active cyber defense, and the integration of MILDEC and OPSEC. The importance of nodal ADC2 architecture, the utilization of fixed infrastructure and cloud environments, as well as the reorganization of staff processes, has also been confirmed.
PL
Współczesne konflikty zbrojne potwierdziły, że Stanowiska Dowodzenia (SD) stały się jednym z najbardziej wrażliwych elementów systemu C2, szczególnie w warunkach zintegrowanych efektów kinetycznych, cybernetycznych i elektromagnetycznych. Doświadczenia Ukrainy z lat 2022–2025 pokazują, że tradycyjne, statyczne i wysokoemisyjne Stanowiska Dowodzenia nie są w stanie przetrwać w środowisku nasyconym czujnikami ISR i zautomatyzowanymi systemami celowniczymi. Celem niniejszego artykułu jest analiza czynników determinujących ochronę SD i cyberbezpieczeństwo w operacjach wielodomenowych oraz identyfikacja kluczowych czynników wpływających na ich przetrwanie. Wyniki wskazują, że skuteczna ochrona wymaga podejścia systemowego łączącego mobilność, dyspersję, redukcję sygnatur elektromagnetycznych, aktywną cyberobronę oraz integrację MILDEC i OPSEC. Potwierdzono również znaczenie węzłowej architektury ADC2, wykorzystania infrastruktury stacjonarnej i środowisk chmurowych, a także reorganizacji procesów sztabowych. Wnioski dowodzą, że jedynie zintegrowany, wielowarstwowy model ochrony umożliwia utrzymanie ciągłości dowodzenia i ogranicza podatność PK na skoordynowane działania przeciwnika.
Artykuł podejmuje problematykę cyber-deterrence w kontekście bezpieczeństwa państwa, koncentrując się na rozwiązaniach przyjmowanych w Finlandii oraz w pozostałych państwach nordyckich. Punktem wyjścia jest założenie, że cyberprzestrzeń stała się trwałym elementem środowiska bezpieczeństwa, a zakłócenia w tej domenie mogą bezpośrednio wpływać na funkcjonowanie administracji publicznej, usług publicznych oraz kluczowych procesów państwowych. W tym ujęciu odstraszanie w cyberprzestrzeni nie jest rozumiane wyłącznie jako reakcja na incydenty, lecz jako element szerszej strategii opartej na prewencji, odporności instytucjonalnej i ciągłości działania. Analiza pokazuje, że w Finlandii cyber-deterrence jest ściśle powiązane z koncepcją bezpieczeństwa kompleksowego i nie opiera się na logice odwetu. Zamiast tego akcentowane są zdolności państwa do identyfikowania zagrożeń, ograniczania ich skutków oraz utrzymania kontroli nad kluczowymi procesami w warunkach długotrwałej presji. Szczególna uwaga została poświęcona uwarunkowaniom społecznym i instytucjonalnym cyberbezpieczeństwa, w tym roli administracji publicznej, samorządu terytorialnego oraz współpracy międzysektorowej. W rezultacie fiński model cyber-deterrence ukazany został jako systemowy i pośredni mechanizm odstraszania, którego skuteczność wynika z odporności państwa, a nie z demonstracji siły w cyberprzestrzeni.
EN
This article addresses the issue of cyber deterrence in the context of national security, focusing on solutions adopted in Finland and the other Nordic countries. The starting point is the assumption that cyberspace has become a permanent element of the security environment, and disruptions in this domain can directly impact the functioning of public administration, public services, and key state processes. In this approach, cyber deterrence is not understood solely as a response to incidents, but as part of a broader strategy based on prevention, institutional resilience, and business continuity. The analysis shows that in Finland, cyber deterrence is closely linked to the concept of comprehensive security and is not based on the logic of retaliation. Instead, the emphasis is on the state's ability to identify threats, mitigate their effects, and maintain control over key processes under conditions of sustained pressure. Particular attention is paid to the social and institutional conditions of cybersecurity, including the role of public administration, local government, and cross-sectoral cooperation. As a result, the Finnish cyber-deterrence model was presented as a systemic and indirect deterrence mechanism whose effectiveness stems from the state's resilience, not from the demonstration of force in cyberspace.
W artykule dokonano analizy ekonomicznej roli cyberbezpieczeństwa w kontekście cyfryzacji współczesnej gospodarki. Celem artykułu jest próba przedstawienia wyników analizy i roli cyberbezpieczeństwa w gospodarce, ze szczególnym uwzględnieniem ekonomicznych determinant inwestycji w bezpieczeństwo informacji, struktury kosztów związanych z zabezpieczaniem systemów teleinformatycznych oraz ich zróżnicowania w zależności od wielkości przedsiębiorstw. W artykule przeprowadzono przegląd literatury z dziedzin ekonomii, finansów, zarządzania ryzykiem oraz bezpieczeństwa informacji, przedstawiono przyjęte ramy teoretyczne i metodologiczne; a także zaprezentowano wyniki analiz dotyczących wpływu nakładów cyberbezpieczeństwa na procesy decyzyjne w przedsiębiorstwach. Artykuł kończą wnioski rekomendujące wzmacnianie kompetencji z zakresu zarządzania cyberbezpieczeństwem, rozwijanie standaryzacji procesów ochronnych oraz tworzenie narzędzi finansowych wspierających.
EN
In this article, an economic analysis of the role of cybersecurity is conducted in the context of the digitalization of the modern economy. The objective of this paper is to present the results of this analysis and to examine the role of cybersecurity in the economy, with particular emphasis on the economic determinants of investments in information security, the cost structure associated with protecting teleinformatic systems, and the variation of these costs depending on the size of the enterprise. The article includes a literature review in the fields of economics, finance, risk management, and information security, introduces the theoretical and methodological framework employed, and presents the results of analyses regarding the impact of cybersecurity expenditure on decision-making in firms. The article concludes with recommendations to strengthen cybersecurity management competencies, develop standardization of protection processes, and create financial tools to support the smallest entities in particular in improving their cyber resilience.
The growing role of artificial intelligence (AI) in cybersecurity presents both opportunities and challenges. While AI strengthens detection and defense systems, it also enables cybercriminals to launch sophisticated, adaptive, and large-scale attacks. This paper reviews key AI-powered cyber threats, including deepfake deception, AI-driven phishing campaigns, automated vulnerability exploitation, and the autonomous generation of malware. It also examines emerging techniques such as prompt injection, model stealing, and data poisoning, which compromise the integrity of AI-based systems. In response, the study explores advanced defense strategies such as explainable AI (XAI), multimodal detection models, content watermarking, and AI-enhanced honeypots. It further considers regulatory frameworks and ethical concerns surrounding dual-use AI. By analyzing current research and real-world incidents, this study supports a deeper understanding of evolving threats and outlines recommendations for proactive and collaborative cybersecurity efforts in the age of AI.
JavaScript jest wyłączony w Twojej przeglądarce internetowej. Włącz go, a następnie odśwież stronę, aby móc w pełni z niej korzystać.