KSC Forum is a three-day industry conference organized since 2019 devoted to the practical implementation of Act on the National System Cybersecurity(UKSC) and the EU NIS2 directive. The event is organized by Evention, and its permanent location is Hotel Crystal Mountain in Wisła. The 8th edition will be held in 2026, gathering approximately 400 participants and 80 speakers representing business, public administration and regulatory bodies.
What is KSC Forum
KSC Forum functions as a platform for dialogue between business and public administration in the area of cybersecurity. CISO and security managers from large enterprises, representatives of CSIRTs and supervisory offices, as well as legal experts interpreting the requirements KSC 2.0 and NIS2.
The conference program includes plenary sessions, technical workshops, discussion panels and a networking part. The three-day formula allows you to combine regulatory topics with practical implementation solutions, exchange of experience between sectors and direct contact with regulators.
The conference has been held regularly since 2019, and its scope is systematically growing as the catalog of entities covered by KSC regulations is expanded.
KSC Forum 2026
The eighth edition of the KSC Forum will be held on August 26–28, 2026 at the Crystal Mountain Hotel in Wisła. The organizers expect approximately 400 participants and 80 speakers – including representatives of public administration, CISOs of large enterprises from the energy, gas and health sectors andlegal experts co-creating new regulations.
This year’s edition falls at the moment when amendment of UKSC and implementation of NIS2 move from the stage of interpretation of regulations to the stage of real implementation obligations and management responsibility. The group of entities covered by the regulation is expanding from the existing key entities to a wide group of important entities, including medium and large enterprises, service operators and supply chain participants. Many of these organizations are now facing risk management and incident reporting obligations for the first time.
Legal advisor Jerzy Muszyński and partner of the digital law firm Marcin Serafin talked about the implementation of KSC in practice
The 2026 program also refers to specific events from recent months, including the December attack on over thirty renewable energy installations and a heat and power plant in Poland (DynoWiper incident), analyzed as an example of the growing scale of cyber sabotage targeting NATO’s critical infrastructure. Special guests included: former operator of the GROM Military Unit and state security experts, relating experiences from Ukraine to building organizational resilience in Poland.
Conference topics
KSC Forum covers a permanent set of issues, updated every year with new regulatory requirements and implementation experiences of participants. The core of the program is the analysis of the UKSC amendment and its relationship with other European regulations – NIS2, DORA and CER – including differences in terms of validity, implementation deadlines and sanctions for non-compliance.
A separate thematic block concerns operational obligations of key and important entities: risk management, reporting security incidents, maintaining business continuity and certification of ICT products and services. The conference also regularly addresses the role of sector CSIRTs and information analysis and exchange centers (ISACs) in the early detection of threats and coordination of responses to incidents.
The responsibility of the management board and management staff for meeting cybersecurity requirements remains an important part of the program – a topic that is gaining in importance as CISO competences in organizational structures are growing. This is complemented by labor market issues: deficit of cybersecurity specialists, competence development paths and possibilities of financing implementations from KPO funds and European Funds for Digital Development.
Who participates in the KSC Forum
KSC Forum participants are divided into three groups that rarely meet in one place on such a scale:
- representatives of public administration and regulators,
- management staff and security departments of large organizations,
- cybersecurity technology and service providers.
The conference’s Program Board includes, among others: CISO and cybersecurity directors from ENEA, ORLEN Termika, GAZ-SYSTEM, Polska Grupa Lotnicza, Centrum e-Health and Polska Spółka Gazownictwa – which reflects the industry profile of the event, focused on the energy, transport, health and municipal sectors, most affected by the amendment to the UKSC.
The substantive and social patronage of the event is provided by industry organizations such as ISACA Warsaw Chapter, ISSA Polska, (ISC)² Poland Chapter and CSO Council, which additionally expands the group of participants to include independent experts and practitioners from outside corporate structures.
Organizations just entering the KSC and NIS2 field gain the opportunity to compare their own implementation stage with the experience of entities that have been subject to regulations for a long time.
Frequently asked questions about KSC Forum
When is KSC Forum 2026 held?
KSC Forum 2026, the 8th edition of the conference, takes place on August 26–28, 2026.
Where is the KSC Forum held?
The conference is held periodically at the Crystal Mountain Hotel in Wisła, as a three-day onsite event.
Who organizes the KSC Forum?
The organizer of the KSC Forum is Evention, and the event is held under the honorary patronage of the Ministry of Digitization, the Government Center for Security and UKE.
Who is the KSC Forum intended for?
The conference is intended for people responsible for cybersecurity in organizations covered by UKSC and NIS2 – CISOs, management boards, public administration representatives and specialists implementing regulatory requirements.