Glossary

Cybersecurity glossary: NIS2, the KSC Act, DORA and penetration testing

This cybersecurity glossary gives short definitions of the terms we use in our articles and on our service pages - from the Polish National Cybersecurity System Act (KSC Act), DORA, OWASP standards and penetration testing practice. Where a topic is covered in more depth on our website, the definition links to it.

Legal definitions are simplified and refer to the relevant provision - only the wording of the Act or regulation is binding. Terms from Polish legislation are given in English, with the original Polish term in brackets. Each term has its own anchor, so you can link straight to a definition, for example the one for CVSS.

B

Black box Also: black-box testing

A penetration test carried out with no knowledge of the system and no user accounts - the tester starts from the position of an external attacker. It shows well what is visible from the internet, but usually does not reach the functions available after logging in.

Black-box, grey-box or white-box

C

CSIRT Also: Computer Security Incident Response Team

A computer security incident response team. The Polish national cybersecurity system includes CSIRT MON, CSIRT NASK and CSIRT GOV, and the amendment to the KSC Act introduces sectoral CSIRTs; significant incidents are reported to them.

CVE Also: Common Vulnerabilities and Exposures

A public identifier of a known vulnerability (e.g. CVE-2021-44228), assigned under the CVE Program. It allows reports, scanners and vendor advisories to refer unambiguously to the same flaw; its severity is usually rated on the CVSS scale.

CVSS Also: Common Vulnerability Scoring System

Common Vulnerability Scoring System - an open standard for rating the severity of vulnerabilities on a scale of 0-10 (from none to critical), based on factors such as the attack vector, the privileges required and the impact on confidentiality, integrity and availability. Pentest reports use version 3.1 or 4.0.

D

DORA Also: Digital Operational Resilience Act

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, applicable from 17 January 2025. It covers ICT risk management, incident reporting, digital operational resilience testing (including TLPT) and ICT third-party risk.

DORA - requirements and support

E

Essential entity (podmiot kluczowy)

The category of entity under the Polish KSC Act with the broadest obligations, corresponding to an essential entity under NIS2. As a rule, this is a large enterprise in a sector listed in Annex 1; regardless of size, the category also covers, for example, qualified trust service providers, critical entities and public entities listed in Annex 1. Among other things, an essential entity must carry out a security audit at least once every 3 years.

G

Gap analysis Also: gap assessment, readiness assessment

An initial assessment of how far an organisation is from meeting a set of requirements - for example, those of the KSC Act: a comparison of the current state with the requirements, a list of gaps and an implementation plan with priorities. It does not replace the statutory security audit under Art. 15.

NIS2 gap analysis - scope and process
Grey box Also: grey-box testing

A penetration test with partial knowledge of the system, usually with user accounts in different roles. It makes it possible to check what cannot be seen from the outside: authorisation, access to other users' data and business logic.

Black-box, grey-box or white-box

H

Head of the entity (kierownik podmiotu) Also: head of an essential or important entity

The head of the unit within the meaning of the Polish Accounting Act - e.g. a company's management board (in NIS2 terms, the management body). They are responsible for fulfilling the obligations under the KSC Act even if they have entrusted them to others, complete cybersecurity training every year and may face a fine of up to 300% of their remuneration.

NIS2 training for the management board

I

IDOR Also: Insecure Direct Object Reference

Insecure Direct Object Reference - a vulnerability in which an application returns or modifies an object (e.g. an invoice, document or account) based on an identifier taken from the request, without checking whether the user is entitled to it. Changing a number in the URL or in an API request is enough to see someone else's data.

Important entity (podmiot ważny)

An entity covered by the Polish KSC Act that is not an essential entity, corresponding to an important entity under NIS2 - as a rule, a medium-sized enterprise in a sector listed in Annex 1, or a medium-sized or large enterprise in a sector listed in Annex 2. It has the same obligations regarding the security management system and incidents, but carries out an audit only when ordered to by the authority.

ISMS (information security management system) Also: information security management system, SZBI

A structured set of policies, procedures, roles and technical measures that an organisation uses to assess risk and protect information. The KSC Act requires one from essential and important entities (Art. 8(1)); ISO/IEC 27001 sets out the requirements for such a system.

K

KSC Act (ustawa o krajowym systemie cyberbezpieczeństwa) Also: National Cybersecurity System Act, KSC 2.0

The Polish National Cybersecurity System Act of 5 July 2018, which sets out how the national cybersecurity system is organised and the obligations of essential and important entities. Since 3 April 2026, it has applied as amended to implement the NIS2 Directive (amending act: Dz.U. 2026 item 252).

NIS2/KSC audit

L

Language model (LLM) Also: LLM, large language model

An artificial intelligence model trained on large volumes of text that generates, summarises and analyses text. It can run as a service in the provider's cloud or locally - on the company's own servers or in its private cloud.

Private LLMs for your business

M

MFA (multi-factor authentication) Also: two-factor authentication, 2FA

A login method that requires at least two independent factors - e.g. a password and an app or a hardware key. The KSC Act lists it among the security measures an entity applies where appropriate (Art. 8(1)(2)(l)).

N

NIS2 Also: NIS2 Directive

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It extends the range of sectors and entities subject to obligations; in Poland it is implemented by the amendment to the KSC Act.

NIS2/KSC audit

O

OWASP ASVS Also: Application Security Verification Standard

Application Security Verification Standard - a catalogue of application security requirements with three verification levels, currently in version 5.0. It serves as a checklist when designing, accepting and testing applications.

OWASP Top 10

A list of the ten most important categories of web application security risks, published by the OWASP Foundation; the current edition is OWASP Top 10:2025. It is a point of reference for teams and auditors, not the full scope of a test.

P

Penetration test (pentest) Also: pentest, penetration testing

A controlled simulation of an attack on a system - an application, API, infrastructure or cloud environment - carried out with the owner's written authorisation. The tester manually searches for and confirms vulnerabilities, assesses their impact and describes in the report how to fix them.

Prompt injection

An attack on an application built on a language model in which the attacker smuggles instructions into the input data - a message, document or web page - so that the model breaks its rules or discloses data. It ranks first in the OWASP Top 10 for LLM Applications 2025.

LLM security testing based on OWASP

R

RAG (Retrieval-Augmented Generation) Also: Retrieval-Augmented Generation

A technique in which, before generating an answer, the application retrieves passages from the company's documents and passes them to the language model as context. The model answers on the basis of current, specified sources - without being fine-tuned on those documents.

Red team Also: red teaming

A team that simulates the actions of a real adversary to achieve a defined goal - e.g. access to a payment system - and to check whether the organisation detects and responds to the attack. Unlike in a typical penetration test, the defenders are usually not aware of the test; TLPT under DORA is based on red teaming.

TLPT under DORA
Register of essential and important entities (wykaz podmiotów kluczowych i ważnych) Also: Wykaz KSC, NIS2 register

The register of entities covered by the KSC Act, kept by the competent authorities in the S46 system (the Wykaz KSC application). An entity must apply for registration within 6 months of meeting the criteria; registration is declaratory - the obligations arise from the Act, not from the entry (Art. 7d(5)).

Retest Also: verification testing

A repeat check of vulnerabilities after fixes have been deployed. It confirms that the flaws have been removed effectively and that the fix has not introduced new bugs - without a retest, the pentest report describes the state before remediation.

S

S46

The ICT system for exchanging information within the Polish national cybersecurity system, provided by the Minister of Digital Affairs (Art. 46 of the KSC Act). It hosts the Wykaz KSC application (wykaz-ksc.gov.pl), and essential and important entities use it to report significant incidents.

Security audit under Art. 15 of the KSC Act (audyt bezpieczeństwa) Also: KSC audit, Article 15 audit

A statutory security audit of the information system that an essential entity must carry out at its own expense at least once every 3 years, with the first one due by 3 April 2028 (for entities that met the criteria on 3 April 2026). It may only be carried out by those who meet the requirements of Art. 15(2) - for example, a team of at least two auditors with certifications or audit experience.

KSC Act audit (Art. 15): who, when and how
Security by design Also: secure by design

An approach in which security is designed in from the start of the development lifecycle - in requirements, architecture, code, testing and deployment - instead of being added at the end of the project.

Secure software - security by design
Shadow AI

Employees' use of AI tools, such as public chatbots, without the organisation's knowledge or consent. It risks leaking customer data and company secrets to external services.

Shadow AI: how to regain control
Significant incident (incydent poważny)

An incident that causes or may cause severe degradation of the quality or interruption of the continuity of a service provided by an essential or important entity, financial losses for that entity or considerable damage to other persons, as defined in the KSC Act (Art. 2(7)); NIS2 uses the same term. An early warning must be submitted within 24 hours and the incident notification within 72 hours of detection.

T

TIBER-EU Also: Threat Intelligence-Based Ethical Red Teaming

The European framework for threat intelligence-based red-team testing in the financial sector (Threat Intelligence-Based Ethical Red Teaming), adopted by the European Central Bank. The requirements for TLPT under DORA (Delegated Regulation (EU) 2025/1190) were developed in line with it.

TLPT under DORA
TLPT Also: threat-led penetration testing

Threat-led penetration testing, the term used in DORA: a red-team test on live production systems of selected financial entities, carried out at least every three years and based on threat intelligence.

TLPT under DORA

V

Vulnerability scan Also: vulnerability scanning

An automated check of systems with a tool that detects known vulnerabilities and misconfigurations. It is fast and repeatable, but it involves no manual verification or business logic testing, so it does not replace a penetration test.

W

White box Also: white-box testing

A test with full knowledge of the system: documentation, architecture and source code. It pinpoints the causes of vulnerabilities most precisely and is often combined with a source code review.

White-box testing and source code review

Sources

  1. Act of 23 January 2026 amending the National Cybersecurity System Act and certain other acts (Dz.U. 2026 item 252) (in Polish) ()
  2. Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector (DORA), OJ L 333, 27.12.2022 ()
  3. Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS 2 Directive) ()

Updated

Related

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877