Estimated reading time: 6 minutes
Microsegmentation. Poland’s cyberwar. AI-powered attackers. The blast radius that decides your cyber insurance premium. New podcast episode.
Poland absorbed 270,000 cyberattacks in the past year. That’s 2.5 times more than the year before, according to Deputy Digital Affairs Minister Paweł Olszewski. Russia tripled its military intelligence resources aimed at Polish targets in 2025, per Digital Affairs Minister Krzysztof Gawkowski. December brought a coordinated strike that hit more than 30 wind and solar farms, plus a heat plant serving half a million homes.
For Piotr Kupisiewicz, none of this is abstract. He’s the CTO of Elisity, a network microsegmentation vendor with roots in Kraków. He joined the Cyber Insurance News & Information podcast to talk segmentation strategy. Poland’s war kept intruding instead, and he let it.”The distance does not really matter,” he said, describing how American executives tend to view Poland’s cyber conflict as remote. It isn’t. Poland’s government runs a civilian cyber-defense corps called Cyber Legion. It had drawn over 2,000 volunteers by late 2025, according to Defense Minister Władysław Kosiniak-Kamysz. Kupisiewicz was careful with the label. Not a militia, he said, but a structured government program for citizens with real security skills.
His point for a global audience: oceans don’t stop packets. Hybrid warfare that looks distant on a map arrives at the same speed everywhere.
Get The Podcast At These Spots
YouTube
Spotify
Apple
Amazon
What Microsegmentation Actually Solves
Traditional network security worked like a single locked gate around an entire property. Once an attacker got inside, they moved freely. Most breaches today start from within: a compromised laptop, a stolen credential, one infected machine spreading sideways through the network.
Kupisiewicz’s preferred analogy is a submarine. Naval architects assume a hull breach will happen eventually. Watertight compartments seal off flooding before the whole vessel goes down. Microsegmentation applies the same logic to a corporate network. It walls off critical systems so one infection can’t reach everything at once.
Retrofitting an existing network into segments is harder than designing it that way from day one, Kupisiewicz said. It isn’t impossible. Elisity has spent years building tools to add compartments to networks that were never designed with any.
AI Is Speeding Up Both Sides
Attackers used to need real technical skill. Kupisiewicz says AI removed that requirement. The industry used to call amateurs running exploits they didn’t understand “script kiddies.” Kupisiewicz says AI turned that insult into an option for everyone. It “allows everyone kind of to be a script kiddie nowadays,” he said.
He believes it cuts the same way for defenders, calling AI a force multiplier on both sides of the fight.
Accountability is where Elisity draws a hard internal line. Kupisiewicz recalled his CEO’s warning to staff. Using AI to build a slide deck doesn’t change who owns the numbers on it. An AI-generated excuse doesn’t fly, in his telling. Companies that ban AI outright just push the behavior underground. Employees will use personal devices, or photograph their screens, rather than lose access to a tool that saves them hours.
The Boring Stuff Still Wins
Most breaches don’t involve custom malware or nation-state tradecraft. Kupisiewicz points to a water utility breach as the clearest example. Attackers didn’t write anything sophisticated. They used a default password nobody had bothered to change.
That kind of gap tends to open around one overworked IT generalist covering multiple facilities alone, Kupisiewicz said. That person handles everything from printer support to firewall configuration. He’s done that job himself. A password reset falls through the cracks when one person is stretched across five buildings.
Security leadership carries its own version of this fatigue. Industry surveys have long put average CISO tenure between two and three years. Newer 2025 compensation data shows that number stretching toward three and a quarter years. Nobody in the conversation tried to prove why the job burns people out this fast. Kupisiewicz’s working theory, offered without much hedging: nobody notices security until it fails. “If you don’t have an active breach, people might not appreciate the security teams,” he said.
What This Means for Underwriters and Boards
None of the above changes because a company buys a cyber policy. Poland’s attack volume doesn’t drop. AI doesn’t stop lowering the bar for attackers. Someone, somewhere, still hasn’t changed a default password. What a policy changes is who absorbs the financial impact when one of these risks lands.
His advice to CISOs trying to justify a security budget is simple. Quantify the worst case in numbers a board can act on. Elisity built what it calls a zero trust score. It’s a rating from zero to 100 of how contained a company’s network actually is, benchmarked against similar businesses. Pair that with a specific blast radius, a device count, and a list of what’s exposed if one zone gets hit. A board stops debating abstractions and starts pricing a real number.
Segmentation vendors, Elisity included, point to lower cyber insurance premiums as one payoff of shrinking blast radius this way. Underwriters do generally view tighter segmentation as a favorable control. How much that moves an individual quote depends on the carrier and the policy. It also depends on the rest of a company’s posture, not on any single vendor’s tooling.
Kupisiewicz suggests a simple question for every executive to ask their CISO. What’s the most pessimistic scenario, and what happens the day it occurs? That conversation, more than any product, tends to surface what a company’s actual blast radius is worth.
A Team Sport, Even While Competing
Kupisiewicz has spent almost two decades in cybersecurity and doesn’t pretend it’s all grim. He described a, perhaps, surprising rapport among rival vendors. Even fierce competitors will cooperate against a shared attacker. “Cybersecurity is… a team sport,” he said, meaning it as an observation about the whole industry, not a slogan.
The closing question was the simplest one in the episode. What’s the worst thing you could wake up to on a Monday morning? Is your company ready to deal with it? This industry spends most of its time selling protection against things that haven’t happened yet. That question is the only one that actually matters.
FAQ – Microsegmentation Cyber Insurance
Microsegmentation divides a network into small, isolated zones so a single compromised device can’t reach the rest of the system. It contains attacks instead of trying to block every intrusion outright.
Poland borders the war in Ukraine and has become one of Russia’s most targeted NATO members. The country absorbed roughly 270,000 cyberattacks over the past year, more than double the prior year’s total.
Underwriters generally view tighter segmentation as a positive risk control. Whether it moves a specific premium depends on the carrier and the rest of a company’s security posture, not on any single product.
Cyber Legion is a government-run program that trains civilian volunteers with cybersecurity skills to support national cyber defense. Officials describe it as structured service, not informal hacking.
Kupisiewicz recommends starting with the most pessimistic scenario: what system, if lost, would stop the business entirely, and what’s actually protecting it today.
Episode Transcript – Confirm elements against the recording
Related Cyber Insurance Posts
- Ransomware Accelerated 60% in Six Months. The Exposure Outlived the Claim
- Does Cyber Insurance Cover Scams? It Depends(Opens in a new browser tab)
- The Underwriting Network(Opens in a new browser tab)