About the interviewee. Jarosław Żelewski is the President of the Management Board (Chief Executive Officer) of Nomad Electric Services sp. z o.o., a company of the Nomad Electric Group specializing in the service and maintenance (O&M) of photovoltaic power plants and energy storage facilities. He took up the position in 2026, having previously served on the company’s Management Board as Operations Director. He has been associated with Nomad Electric since spring 2023. The portfolio of assets under the company’s service care exceeds 3 GW and includes high-voltage facilities in Poland, Germany, Romania and Portugal. The Nomad Electric Group also carries out EPC projects for photovoltaic installations and energy storage facilities, builds grid infrastructure for distribution system operators and develops its own Nomad NX energy monitoring and management system. The Group holds ISO 9001, ISO 14001, ISO 45001, ISO 22301 and ISO/IEC 27001 certificates. Before joining Nomad Electric, Jarosław Żelewski was responsible for service delivery in Poland at technology company Diebold Nixdorf as Country Service Delivery Head, overseeing operations, customer relations and a team of more than 200 people. Previously, as Head of Field Operations, he managed optimization projects there in Central and Eastern Europe. He holds a master’s degree in engineering and is a graduate of the Military University of Technology in Warsaw.
Since when exactly has NIS2 applied to Polish energy companies?
Since April 3, 2026. This is the statutory date. The NIS2 Directive, formally Directive (EU) 2022/2555, does not bind companies by itself. They are bound by a national act, namely the Act of January 23, 2026 amending the Act on the National Cybersecurity System, published in the Journal of Laws under item 252 on March 2, 2026. Article 49 of this Act states that it enters into force one month after its promulgation. Hence April 3.
We are speaking at the end of August, so I will say this directly, because this is the most urgent information in our entire conversation. By October 3, 2026, an application must be submitted for entry into the register of essential and important entities. This deadline is not based on assumptions, but on the announcement of the Minister of Digital Affairs of April 8, 2026, published in the Official Journal of the Minister of Digital Affairs under item 7. The announcement sets the period from May 7 to October 3 for essential entities and exactly the same period for important entities.
There are therefore about five weeks left, and this is the simplest of the obligations imposed by the Act.
Who in the renewable energy industry is an essential entity, and who is an important entity?
Here is the first trap, and I can see that many people in the industry fall into it. Annex No. 1 to the Act, energy subsector electricity, does not talk about megawatts at all. There is no installed capacity threshold there. There is no statement about installations above any particular size.
The Annex lists types of entities and does so in two different ways, which is worth distinguishing because this is where misunderstandings arise.
The first group consists of energy companies holding a licence for the generation, transmission, distribution or trading of electricity. Here, the gateway is the licence. A farm without a generation licence does not enter the energy sector on this basis.
The second group is broader and, in my opinion, less well known. The Annex lists market participants providing services defined in the Energy Law, without any licensing requirement. These include electricity storage from points 59 and 59a, aggregation from point 6e and demand response from point 11j. In addition, this includes the designated electricity market operator from point 28b and operators managing charging points.
Please note what this means for energy storage facilities. An entity providing electricity storage services enters the essential sector without holding any licence, and its status then depends only on the size of the enterprise. This also applies to aggregators. Given the pace at which battery projects are being added in Poland and the development of flexibility services, this is a group that most often does not know that the conversation concerns them at all.
The second criterion is precisely the size of the enterprise. Article 5 of the Act refers to Annex I to Regulation 651/2014, that is, to the EU definition of a small and medium-sized enterprise. An entity from Annex No. 1 that exceeds the medium-sized enterprise threshold is an essential entity. An entity that meets this threshold and is not essential is an important entity. The status is assessed according to the situation as of the date the financial statements are prepared, which follows from paragraph 5 of this Article.
In practice, two neighbouring projects with identical capacity may have a different legal status because they differ in the form in which the business is conducted and in the size of the owner. I know that this sounds worrying. This is, however, what the text of the Act looks like.
Why can a service company be subject to the Act even though it does not produce electricity?
This issue is practically absent from Polish publications about NIS2 for renewable energy sources, yet it concerns half of our industry.
In Annex No. 1, that is, among the essential sectors, there is a separate item called “ICT service management”. It identifies two types of entities: a managed service provider and a managed cybersecurity service provider. The definition of the former can be found in the new point 4i of Article 2 of the Act. Let us read it slowly. A managed service provider is an entity that “provides services related to the installation, operation or maintenance of ICT products, ICT services, ICT processes or information systems through support or active administration carried out at the service recipient’s premises or remotely”.
Now describe a standard O&M contract with a monitoring centre in these terms. Active administration of an information system at the service recipient’s premises, carried out remotely. The description matches word for word.
A service company can therefore be an essential entity not because it generates energy, but because it administers someone else’s automation systems. I believe this is the most frequently overlooked provision in the entire amendment from the perspective of our industry. I would add that a managed cybersecurity service provider is an essential entity already at the level of a small enterprise, which follows from Article 5 paragraph 1 point 3.
Does belonging to a corporate group determine the status of a special purpose vehicle?
It does not. This is a provision that should land on the desk of every CFO in the industry.
The rule when assessing the size of an enterprise is to add together data from affiliated and partner enterprises. A project structure based on special purpose vehicles could therefore make each of them an essential entity in one move. Article 5, paragraphs 6 and 7, however, introduces an exception. If an entity exceeds the threshold solely because of this aggregation, but its information system is independent of the systems of affiliated or partner enterprises, or it does not provide services jointly with them, then it is neither an essential nor an important entity.
It can be clearly seen here that an architectural decision made several years ago when designing the IT infrastructure now has a legal and financial effect. A shared service catalogue and one domain for the entire group mean one thing. Separated environments mean something else.
I stress that I am speaking as a practitioner, without any legal ambitions. This is not a loophole for avoiding obligations. The separation must be genuine and documented, and the declaration of status is submitted under the penalty of criminal liability.
What did the attack of December 29, 2025 on Polish farms show?
It showed that we are talking about incidents that have already occurred, in our country, at facilities such as those we build and service.
CERT Polska, a team operating within NASK, published a technical report on this incident on January 30, 2026, and an update in August 2026. I encourage you to read both, because they are written without beating around the bush. The coordinated attacks of December 29, 2025 affected at least 30 wind and photovoltaic farms, a large combined heat and power plant supplying nearly half a million customers, a smaller combined heat and power plant serving around 50,000 residents, and a manufacturing company. CERT writes that all attacks had an exclusively destructive objective and compares them to deliberate arson. This happened during low temperatures, just before the New Year.
Energy production was not interrupted, and the stability of the national power system was not threatened. CERT points out, however, that the level of access obtained made it possible to shut down the facilities.
The most important thing, however, is the route of entry, because here each of us should look at ourselves as if in a mirror. At every attacked station, there was a Fortigate device acting as a VPN concentrator and firewall. In every case, the VPN interface was accessible from the internet and allowed login without multi-factor authentication. The report contains a sentence that I read three times: “The interview conducted shows that a common practice in the industry is the use of the same accounts and passwords at multiple facilities.”
It gets even less comfortable from there. Hitachi RTU560 RTUs had default credentials, including an account named “Default”, which has permission to exchange firmware. It was used to upload crafted firmware, causing the devices to enter an endless restart loop. The secure update function was available from version 13.2.1, only it was not enabled on any device. Controllers from another manufacturer failed after logging into the root account over SSH with the default password. Protection controllers had the FTP service enabled with a built-in default account, while an implementation in accordance with the manufacturer’s recommendations would have blocked this account automatically. HMI workstations had a local administrator password set during deployment and never changed.
I want to be precise here, because it is easy to make a mental shortcut. CERT notes that as a result of the destructive actions, it was not possible to recover complete logs from any of the attacked devices, so the method of obtaining the initial access was not ultimately established. It also notes that some of these devices had previously been vulnerable, including to remote code execution. However, everything that could be reconstructed in the subsequent steps was something from the first page of every checklist. Default accounts, lack of a second factor, passwords repeated across facilities.
One more thing. Configuration changes on the operator stations were introduced on December 8, network scanning was recorded on December 25, and the attack took place on December 29. Someone had been sitting in these networks for weeks and nobody saw it. This is precisely why the Act requires continuous monitoring, which we find in Article 8 paragraph 2 point 2 letter g.
How did one router at a wind farm lead the attacker to a combined heat and power plant?
This is the most technically interesting part of the report update and, according to CERT Polska, a vector previously undescribed in known incidents. The analysis took the team more than three months.
Mobile routers with a SIM card operating in a dedicated data transmission network, in the so-called private APN, operated by the distribution system operator, are installed at farms. This is how communication runs between the operator’s SCADA system and the controller at the facility. Operators require this communication to take place over a serial connection. Rightly so, because this limits the risk of transferring an attack to the operator’s network.
Except that, as CERT notes, “there were no requirements as to how the administrative interface of the mobile router should be treated”. At the attacked facility, the router had a second interface connected to a network managed by the previously compromised firewall. The attacker repeatedly logged into this router via SSH and, as CERT cautiously writes, most likely used SSH tunnelling to enter the private APN. From December 18, he scanned this network for remote desktop services and S7 and Modbus industrial protocols. He found a WAGO controller at a completely different facility, with an administration panel exposed from the APN side and the default password for the “admin” account. There he stopped a steam turbine and a water treatment station, interrupting cogeneration.
One detail from this story struck me the most. The implementing company changed the default password on the mobile router, as it should, and CERT still did not establish how the attacker obtained the new one or whether he exploited a vulnerability in the device itself. Changing the password is therefore a necessary condition and nobody should treat it as sufficient.
Taking over one wind farm made it possible to attack a combined heat and power plant because both facilities were connected to the same operator network without isolation between customers.
CERT Polska writes that based on surveys conducted among many entities, such a configuration was common in Poland and is also widely used in other countries. The recommendations are specific: enable isolation between endpoint devices in the APN, treat the private APN as an untrusted network at a level equivalent to the internet, allow only traffic from an allowlist at the interface with the industrial network, monitor deviations from the communication profile, remove all administrative services from the APN-facing interface and include these networks in penetration testing.
I will add one personal observation. For years, the private APN functioned in our industry as a synonym for security because “it is not the internet”. The December incident closes this discussion.
What does this mean for contracts with contractors and service companies?
It means a double bind, and I will call it exactly that.
On the one hand, Article 8 paragraph 2 point 2 letter e requires the security management system to cover “the security and continuity of the supply chain of ICT products, ICT services and ICT processes on which the provision of the service depends, taking into account the relationships between the direct supplier of hardware or software and the entity”. The asset owner must therefore be accountable for what the contractor does at its premises.
On the other hand, the same contractor may itself be subject to the Act as a managed service provider, as we discussed earlier.
In practice, this means that over the next dozen or so months, a wave of contract amendments will move through the market. I expect questions about multi-factor authentication for remote access, separate credentials for each facility, recording of service sessions, the procedure for withdrawing access when personnel rotate, response time in the event of an incident, and who reports an event to whom and within what time. I believe that a company that cannot answer these questions in writing today will, in a year, fall off the shortlists in tenders. Even before anyone imposes the first fine.
How much time is really left and when are fines possible?
I will say something that goes against the majority of materials I have been reading recently. I want this to come across exactly.
The first monetary fine under this Act may be imposed no earlier than April 3, 2028. This is not an opinion, but Article 35 of the amending Act, which states that fines “may be imposed for the first time after 2 years from the date of entry into force of the Act”. Materials threatening millions of euros from autumn 2026 are simply inconsistent with the text of the Act.
This does not mean, however, that we can relax. Obligations are already running, and the calendar is packed. Application for entry by October 3, 2026. Joining the S46 system and implementing the obligations of Chapter 3 of the Act, including the information security management system, by April 3, 2027. The first security audit for essential entities by April 3, 2028.
There is also a provision that changes the way we think about registration. Article 7d paragraph 5 states that entry in the register “is a material and technical action and is declaratory in nature”. The status of an essential entity arises by operation of law when the conditions are met, and not at the time of entry in the register. An entity that does not report itself does not cease to be an essential entity. It simply is one without an entry in the register, while also having failed to fulfil the obligation.
I treat these two years as a window for doing things properly. The security measures we discussed in connection with the December attack cost weeks of work. They also have nothing to do with the amount of the fine.
What is the management board president personally responsible for?
For everything. Compared with the previous legal framework, this is a systemic change.
Article 8c paragraph 1 states that the head of an entity is responsible for fulfilling cybersecurity obligations. Paragraph 2 adds that in the case of a multi-person body, if no responsible person has been designated, all members of the management board are responsible. Paragraph 3 closes the most convenient loophole by stating that the head is also responsible when he or she has entrusted the duties to someone else with his or her consent.
Article 8d lists what specifically belongs to the head. I will point out point 2 because it shows the legislator’s way of thinking. The head “plans adequate financial resources for the fulfilment of cybersecurity obligations”. Lack of a budget has ceased to be a defence argument and has become a description of a violation.
Article 8e introduces a training obligation for the head once in each calendar year, with documented participation. Article 8f requires a person admitted to tasks related to the security management system or incident handling to present in advance information from the National Criminal Register confirming no convictions for offences against the protection of information. A person convicted by a final judgment may not perform such tasks. I suspect that this is currently the least-known obligation in the entire Act, and it directly affects HR and recruitment processes.
There is also a sanction. Article 73a paragraph 4 provides for a penalty for the head of up to 300 percent of the remuneration received, calculated according to the rules for determining holiday pay. This penalty is independent of the penalty imposed on the entity itself. The company itself is liable for up to EUR 10 million or 2 percent of revenue as an essential entity, with the higher amount applying. An important entity is liable for up to EUR 7 million or 1.4 percent.
And one more detail that makes the biggest impression on me. The application for entry in the register contains a declaration by the head submitted under the penalty of criminal liability under Article 233 paragraph 6 of the Criminal Code. The president personally signs that the data is true.
How is a serious incident reported and within what time?
There are three deadlines, and in the Polish Act they have two features that are often forgotten.
The early warning goes immediately, no later than within 24 hours. The serious incident notification within 72 hours. The final report no later than one month from the date of notification, not from the date of detection. In addition, there is an interim report if the incident response team requests one.
The first feature I mention. The Polish deadlines run from the moment the incident is detected, which follows from Article 11 paragraph 1 points 4 and 4a. The second feature concerns the recipient. The notification is received by the competent sectoral CSIRT, that is, the team established by the authority competent for the given sector. For energy, this authority is the minister responsible for energy. The notification therefore goes to a specific team in one’s sector.
In addition, Article 11 paragraphs 2a and 2b imposes an obligation to inform service recipients about a serious cyber threat and about an incident if it adversely affects the provision of services.
I want to emphasize one thing from the CERT report update because I consider it the most important organizational lesson from the entire December event. The combined heat and power plant we talked about initially assumed that the turbine shutdown was an error by the subcontractor’s engineers during maintenance work. It reported the event for information purposes only. CERT took up the case as an attack only because it knew about similar events elsewhere. The team writes directly: “This shows how important it is to report not only confirmed incidents, but also unexplained failures.”
I believe this sentence should hang in every dispatch room in this country. An unexplained failure reported too early costs an hour of work. An unreported one costs three months of laboratory analysis, as in this case.
Does an implemented ISO 27001 standard settle the matter?
It gives an advantage at the start, and I say this as a person who has this certificate in his company. But it does not settle the matter, and I believe it is worth saying this loudly before someone buys such a promise from a consultant.
The overlap is real. Article 8 paragraph 2 lists twelve areas, from risk assessment policies, through human resources security and access control, to cryptography. Whoever operates a system compliant with ISO/IEC 27001 already has most of them described, implemented and, more importantly, audited by a third party. Similarly, ISO 22301 overlaps with letter f, that is, business continuity and disaster recovery plans.
However, the Act adds things that are not included in the standard. The 24- and 72-hour deadlines to the competent sectoral CSIRT. Entry in the register with a declaration under criminal liability. Verification of personnel’s criminal record in the National Criminal Register. Annual documented training of the head. Separate statutory liability of the management board. The standard describes how to manage information security. The Act additionally says to whom and within what time you explain yourself about it.
So I formulate it this way. The certificate shortens the road perhaps by half and organizes the internal conversation within the company. It is not a certificate of compliance with the Act, and nobody should sell it as such.
Where to start if the company has not done anything yet?
I would arrange it into six steps and deliberately start with the cheapest things.
- Establish the status. Check licences, the size of the enterprise according to the financial statements, capital relationships and whether the company is perhaps a managed service provider. Record the result with justification because the declaration is made under criminal liability.
- Submit the application for entry through the ICT system, signed with a qualified electronic signature, trusted signature or qualified electronic seal. The deadline is October 3, 2026.
- Inventory remote access. Every external entry into the facility, every service account, every VPN concentrator. Disable login without a second factor. Eliminate shared passwords between facilities. CERT described exactly this list in the report.
- Review default credentials on controllers, operator stations, mobile routers and protection controllers. Enable secure firmware updating wherever the manufacturer provides it.
- Examine the interface with the private APN and treat it as an untrusted network, in accordance with the recommendation of CERT Polska.
- Designate contact persons, launch the reporting path and train the management board. The training obligation applies to the head personally and must be documented.
Only then comes the construction of the full information security management system, for which the Act provides time until April 3, 2027. The audit deadline is April 3, 2028.
What mistake do you consider the most costly in this whole matter?
The belief that this is a legal project.
I have already seen several approaches in which a company orders an opinion, receives a binder, enters itself in the register and considers the matter closed. Meanwhile, the CERT Polska report does not indicate that anything in December 2025 failed because of a lack of documentation. It failed because of a default password, an exposed administration panel and the lack of a second factor when logging in. Formal compliance and technical resilience are two different undertakings, and the Act requires both.
The second mistake, less obvious, concerns the division of roles between the asset owner and the contractor. Remote access to a facility usually involves several entities at once: the general contractor, the service company, the controller supplier, sometimes the inverter manufacturer, and also the grid operator. If nobody maintains one register of these accesses, it does not matter how good the policies written separately by each party are.
Do you see anything more here than a cost?
I do, and I am saying it without forced enthusiasm.
The renewable energy market in Europe is entering a phase in which the value of an asset is determined by the predictability of its operation over 20 years. The price of building it in a year means less today. Financing institutions and insurers are beginning to ask about operational resilience in the same tone in which they have long asked about performance. The amendment gives this a common language and a common calendar.
Let me also remind you what happened on February 24, 2022, when the attack on Viasat satellite modems deprived 5,800 Enercon wind turbines in Germany, with a total capacity of around 11 gigawatts, of remote monitoring and control. The turbines were operating, only the operator could not see them. Nobody directed this attack at wind energy. It simply happened to be connected to the same infrastructure.
Over the course of a decade, our industry has built a distributed system of thousands of unattended facilities, remotely controlled and connected through someone else’s links. It is a huge engineering achievement and at the same time an attack surface that did not exist twenty years ago. I treat NIS2 as a belated response to something that nevertheless had to be done.