Insights
Insights
Innovix Insights: practical articles on penetration testing, DORA, software development and AI for IT, security and compliance teams, with sources cited.
Glossary
This cybersecurity glossary gives short definitions of the terms we use in our articles and on our service pages - from the Polish National Cybersecurity System Act (KSC Act), DORA, OWASP standards and penetration testing practice. Where a topic is covered in more depth on our website, the definition links to it.
Legal definitions are simplified and refer to the relevant provision - only the wording of the Act or regulation is binding. Terms from Polish legislation are given in English, with the original Polish term in brackets. Each term has its own anchor, so you can link straight to a definition, for example the one for CVSS.
A penetration test carried out with no knowledge of the system and no user accounts - the tester starts from the position of an external attacker. It shows well what is visible from the internet, but usually does not reach the functions available after logging in.
Black-box, grey-box or white-boxA computer security incident response team. The Polish national cybersecurity system includes CSIRT MON, CSIRT NASK and CSIRT GOV, and the amendment to the KSC Act introduces sectoral CSIRTs; significant incidents are reported to them.
A public identifier of a known vulnerability (e.g. CVE-2021-44228), assigned under the CVE Program. It allows reports, scanners and vendor advisories to refer unambiguously to the same flaw; its severity is usually rated on the CVSS scale.
Common Vulnerability Scoring System - an open standard for rating the severity of vulnerabilities on a scale of 0-10 (from none to critical), based on factors such as the attack vector, the privileges required and the impact on confidentiality, integrity and availability. Pentest reports use version 3.1 or 4.0.
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, applicable from 17 January 2025. It covers ICT risk management, incident reporting, digital operational resilience testing (including TLPT) and ICT third-party risk.
DORA - requirements and supportThe category of entity under the Polish KSC Act with the broadest obligations, corresponding to an essential entity under NIS2. As a rule, this is a large enterprise in a sector listed in Annex 1; regardless of size, the category also covers, for example, qualified trust service providers, critical entities and public entities listed in Annex 1. Among other things, an essential entity must carry out a security audit at least once every 3 years.
An initial assessment of how far an organisation is from meeting a set of requirements - for example, those of the KSC Act: a comparison of the current state with the requirements, a list of gaps and an implementation plan with priorities. It does not replace the statutory security audit under Art. 15.
NIS2 gap analysis - scope and processA penetration test with partial knowledge of the system, usually with user accounts in different roles. It makes it possible to check what cannot be seen from the outside: authorisation, access to other users' data and business logic.
Black-box, grey-box or white-boxThe head of the unit within the meaning of the Polish Accounting Act - e.g. a company's management board (in NIS2 terms, the management body). They are responsible for fulfilling the obligations under the KSC Act even if they have entrusted them to others, complete cybersecurity training every year and may face a fine of up to 300% of their remuneration.
NIS2 training for the management boardInsecure Direct Object Reference - a vulnerability in which an application returns or modifies an object (e.g. an invoice, document or account) based on an identifier taken from the request, without checking whether the user is entitled to it. Changing a number in the URL or in an API request is enough to see someone else's data.
An entity covered by the Polish KSC Act that is not an essential entity, corresponding to an important entity under NIS2 - as a rule, a medium-sized enterprise in a sector listed in Annex 1, or a medium-sized or large enterprise in a sector listed in Annex 2. It has the same obligations regarding the security management system and incidents, but carries out an audit only when ordered to by the authority.
A structured set of policies, procedures, roles and technical measures that an organisation uses to assess risk and protect information. The KSC Act requires one from essential and important entities (Art. 8(1)); ISO/IEC 27001 sets out the requirements for such a system.
The Polish National Cybersecurity System Act of 5 July 2018, which sets out how the national cybersecurity system is organised and the obligations of essential and important entities. Since 3 April 2026, it has applied as amended to implement the NIS2 Directive (amending act: Dz.U. 2026 item 252).
NIS2/KSC auditAn artificial intelligence model trained on large volumes of text that generates, summarises and analyses text. It can run as a service in the provider's cloud or locally - on the company's own servers or in its private cloud.
Private LLMs for your businessA login method that requires at least two independent factors - e.g. a password and an app or a hardware key. The KSC Act lists it among the security measures an entity applies where appropriate (Art. 8(1)(2)(l)).
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It extends the range of sectors and entities subject to obligations; in Poland it is implemented by the amendment to the KSC Act.
NIS2/KSC auditApplication Security Verification Standard - a catalogue of application security requirements with three verification levels, currently in version 5.0. It serves as a checklist when designing, accepting and testing applications.
A list of the ten most important categories of web application security risks, published by the OWASP Foundation; the current edition is OWASP Top 10:2025. It is a point of reference for teams and auditors, not the full scope of a test.
A controlled simulation of an attack on a system - an application, API, infrastructure or cloud environment - carried out with the owner's written authorisation. The tester manually searches for and confirms vulnerabilities, assesses their impact and describes in the report how to fix them.
An attack on an application built on a language model in which the attacker smuggles instructions into the input data - a message, document or web page - so that the model breaks its rules or discloses data. It ranks first in the OWASP Top 10 for LLM Applications 2025.
LLM security testing based on OWASPA technique in which, before generating an answer, the application retrieves passages from the company's documents and passes them to the language model as context. The model answers on the basis of current, specified sources - without being fine-tuned on those documents.
A team that simulates the actions of a real adversary to achieve a defined goal - e.g. access to a payment system - and to check whether the organisation detects and responds to the attack. Unlike in a typical penetration test, the defenders are usually not aware of the test; TLPT under DORA is based on red teaming.
TLPT under DORAThe register of entities covered by the KSC Act, kept by the competent authorities in the S46 system (the Wykaz KSC application). An entity must apply for registration within 6 months of meeting the criteria; registration is declaratory - the obligations arise from the Act, not from the entry (Art. 7d(5)).
A repeat check of vulnerabilities after fixes have been deployed. It confirms that the flaws have been removed effectively and that the fix has not introduced new bugs - without a retest, the pentest report describes the state before remediation.
The ICT system for exchanging information within the Polish national cybersecurity system, provided by the Minister of Digital Affairs (Art. 46 of the KSC Act). It hosts the Wykaz KSC application (wykaz-ksc.gov.pl), and essential and important entities use it to report significant incidents.
A statutory security audit of the information system that an essential entity must carry out at its own expense at least once every 3 years, with the first one due by 3 April 2028 (for entities that met the criteria on 3 April 2026). It may only be carried out by those who meet the requirements of Art. 15(2) - for example, a team of at least two auditors with certifications or audit experience.
KSC Act audit (Art. 15): who, when and howAn approach in which security is designed in from the start of the development lifecycle - in requirements, architecture, code, testing and deployment - instead of being added at the end of the project.
Secure software - security by designEmployees' use of AI tools, such as public chatbots, without the organisation's knowledge or consent. It risks leaking customer data and company secrets to external services.
Shadow AI: how to regain controlAn incident that causes or may cause severe degradation of the quality or interruption of the continuity of a service provided by an essential or important entity, financial losses for that entity or considerable damage to other persons, as defined in the KSC Act (Art. 2(7)); NIS2 uses the same term. An early warning must be submitted within 24 hours and the incident notification within 72 hours of detection.
The European framework for threat intelligence-based red-team testing in the financial sector (Threat Intelligence-Based Ethical Red Teaming), adopted by the European Central Bank. The requirements for TLPT under DORA (Delegated Regulation (EU) 2025/1190) were developed in line with it.
TLPT under DORAThreat-led penetration testing, the term used in DORA: a red-team test on live production systems of selected financial entities, carried out at least every three years and based on threat intelligence.
TLPT under DORAAn automated check of systems with a tool that detects known vulnerabilities and misconfigurations. It is fast and repeatable, but it involves no manual verification or business logic testing, so it does not replace a penetration test.
A test with full knowledge of the system: documentation, architecture and source code. It pinpoints the causes of vulnerabilities most precisely and is often combined with a source code review.
White-box testing and source code reviewInsights
Innovix Insights: practical articles on penetration testing, DORA, software development and AI for IT, security and compliance teams, with sources cited.
Compliance · NIS2/KSC
NIS2 audit under the Polish KSC Act: who is in scope, deadlines 3 April 2027 and 3 April 2028, duties, the Art. 15 audit and fines. Gap analysis, pentests.
Cybersecurity · Penetration testing
Penetration testing services for web and mobile apps, APIs, infrastructure, cloud and source code. OWASP and PTES, evidence-based reports and retests.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877