Poland’s Internal Security Agency (ABW) published its 2024–2025 activity report in May 2026. It recorded more than 40,000 reports of potential information and communication technology (ICT) incidents during the two-year period and documented unauthorised access to water-treatment control systems in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo.[1] Attackers altered equipment parameters, creating a risk to the continuity of local water supplies. Although the Polish and Pakistani contexts differ, the underlying weaknesses, poor credential security, and internet-exposed industrial-control interfaces are not country-specific and could plausibly exist in Pakistan’s critical infrastructure. The Polish case therefore offers relevant lessons for prevention and preparedness.

