Local Cybersecurity Centres – 269 million zlotys for local authorities to strengthen cybersecurity
On 31 July 2026, a call for proposals was announced for the establishment of Local Cybersecurity Centres (LCCs) – an initiative aimed at strengthening local government bodies in the face of ever-increasing cyber threats.
The LCCs are designed to support local authorities in protecting themselves against cyber-attacks and other digital threats. As the Minister for Digitalisation pointed out, local government is one of the most frequently targeted areas of public administration. In 2025, 3,249 incidents involving local authorities were recorded by the National Computer Security Incident Response Team (CSIRT NASK).
Over 269 million zloty is to be allocated to the implementation of the projects.
Project objective – joint cybersecurity centres
The main objective of the project is to support the creation of inter-municipal cybersecurity centres, which will serve groups of local government bodies and their organisational units, such as local authorities, schools and social welfare centres.
Key project objectives
- Establishment of multi-municipal centres
Technologically advanced units and specialised experts will support smaller and organisationally weaker local authorities.
- A new standard of response
Instead of fragmented activities and isolated solutions, a professional, regional operational layer will be established, covering, amongst other things, monitoring and rapid incident response.
- Consolidation of expertise
Pooling dispersed IT resources in specialised centres is intended to help address the shortage of cybersecurity specialists in smaller local authorities.
Who can benefit?
The programme is aimed at Local Government Units (LGUs), namely:
- municipalities,
- districts,
- and cities with district status.
Organisational units of local authorities, such as schools, social welfare centres and cultural institutions, may also participate in the project.
A key element of the programme is cooperation between several local authorities. Instead of establishing separate cybersecurity infrastructure for each municipality, local authorities can pool their resources to create a shared centre, infrastructure and team of specialists.
What conditions must be met?
For an application to be approved, certain requirements must be met.
- Partnership
Before submitting an application, a partnership must be established involving at least two local government bodies.
- Minimum of 1,000 endpoints
As part of the project, the LCC’s support must cover at least 1,000 endpoints belonging to the applicant and its partners.
- Relevant qualifications
As of the date of submission, the applicant’s organisation must employ, under an employment contract, at least one person holding:
- a certificate featured on the list of 80 recognised certificates, including CISSP, CISA, OSCP, CEH or an ISO/IEC 27001 lead auditor,
or
- a degree, postgraduate qualification or MBA in the field of cybersecurity.
- Provision of the full scope of LCC services
The LCC must carry out all tasks specified in the minimum scope, covering 7 areas, as set out in Annex 4 to the Act on the National Cybersecurity System.
These include, amongst others:
- incident response,
- asset management and the Information Security Management System (ISMS),
- software updates,
- access rights management,
- data protection and backups,
- email security,
- training and promoting cyber hygiene.
Failure to meet the requirements concerning, amongst other things, appropriate competencies and the provision of the full range of LCC services may result in the application being rejected.
What can the funds be spent on?
The funds are primarily intended to increase the actual level of cybersecurity in local authorities.
Funding may cover, amongst other things:
Threat monitoring and detection
- SIEM systems,
- EDR/XDR solutions,
- network and system monitoring,
- cyber-threat analysis tools.
Cyber-attack response
- incident handling and analysis,
- support from cyber-security specialists,
- organisation of a SOC team,
- threat response services.
Security measures
- multi-factor authentication (MFA),
- Zero Trust solutions,
- IT infrastructure security,
- network and device protection systems.
Experts and services
- security audits,
- vulnerability testing and analysis,
- consultancy services,
- technical support,
- training for local authority staff.
Infrastructure and software
- IT hardware,
- software and licences,
- the infrastructure necessary for the LCC to operate,
- the adaptation or use of suitable premises.
A major advantage of the LCC model is the ability to share hardware, software and specialists amongst several local authorities. This model also allows for the consolidation of procurement and services related to cybersecurity.
Why is it worth working together?
Cybersecurity is one of the most significant challenges facing local government today. Smaller local authorities often do not have their own SOC team or a sufficient number of specialists.
The LCC model allows the resources of several local authorities to be pooled to create a shared technological and expert base. As a result, local authorities do not have to fund the entire infrastructure, licences and specialist teams separately.
This is an opportunity not only to acquire modern technologies, but above all to establish a permanent system for monitoring, protecting against and responding to cyber threats.
Deadline for applications
Applications may be submitted until 30 October 2026.
Given the need to establish partnerships, meet infrastructure and competence requirements, and prepare the entire LCC concept, it is advisable to begin work on the project as soon as possible.
Support for cybersecurity development
Andersen recognises the growing need to develop expertise and solutions in the field of cybersecurity, including within the public sector and local government bodies.
The development of Local Cybersecurity Centres is not merely an investment in technology and infrastructure. It also requires appropriate organisational, legal and procurement preparations, as well as the proper definition of the rules governing cooperation between the local authorities involved.
KONTAKT
E: tomasz.srokosz@pl.Andersen.com
T: +48 32 731 68 52
M: +48 512 286 226
