IT Security · CRP

What Does a CRP Alert Mean?

Remote Admin Security Team·April 15, 2022·4 min read

A CRP alert is an official warning used for cyberspace threat alerts in Poland. It’s announced in the event of a potential threat or a suspected terrorist-style attack, and it primarily concerns critical infrastructure and public administration bodies.

What Is a CRP Alert?

A CRP alert (short for the Polish Cyberspace of the Republic of Poland alert system) is one of the alert levels introduced when terrorism-related incidents may occur or have already occurred. A CRP alert covers the same kind of events, but specifically within the ICT systems of public administration bodies or institutions that form part of critical infrastructure. Critical infrastructure refers to any activity that is at least fundamentally important to how society or the economy functions — hospitals, airports, banks, and gas stations are examples. A CRP alert level can be introduced across the entire country or in specific regions.

Declaring a CRP Alert: Key Characteristics

A CRP alert is designed to make the public aware of a potential threat. Its main purpose is to counter threats in cyberspace, particularly attacks of a terrorist nature. The CRP alert system has several distinct levels, and it’s these levels that determine how likely an attack is considered to be. The warning is meant to protect not only people living in Poland or institutions based there — it also covers Polish citizens abroad and any business or infrastructure operating outside Poland’s borders. The decision to introduce an alert rests with the Prime Minister, who must first consult the minister responsible for internal affairs and the head of the Internal Security Agency (ABW).

Alert Levels in Poland

In line with the NATO framework, the CRP alert system uses a four-level scale, where the first level indicates the lowest risk and the fourth the highest. In Poland, the following alert levels apply:

CRP Alert Level ALFA

ALFA is the first level, carrying the lowest risk of a threat materializing. This warning is typically used when there’s suspicion of an online terrorist-style attack, but without confirmed details of its type or scope. It’s applied in the early stages, when attacks are gaining strength but their intensity isn’t yet clearly visible. ALFA can also be used simply as a precautionary warning that doesn’t necessarily need to be tied to direct indicators of a terrorist threat. Declaring it means stepping up monitoring of ICT systems within critical infrastructure and public administration. While many of us first heard about it in connection with events in February 2022, it had already been used before — for example, during the commemorations of the 80th anniversary of the outbreak of World War II.

CRP Alert Level BRAVO

BRAVO is the second level on the CRP alert scale, used for a moderate level of threat. It’s characterized by a lack of precise knowledge about the target of the attack, though the probability of it occurring is higher than at level ALFA. This level also requires increased security testing and monitoring of the ICT systems of the institutions mentioned above. In Poland, it was introduced, for instance, in 2019 during the European Parliament elections. Until 2022, it was the highest level ever declared in Poland.

CRP Alert Level CHARLIE

The next level is CRP CHARLIE, which already signals a high level of threat. It’s declared after an attempted attack or a well-founded suspicion of a terrorist attack. Another distinguishing feature of CHARLIE is that the target of the attack is already known. This third level can also be introduced upon receiving information about a planned attack. In Poland, it was declared for the first time in 2022, following observations of concerning activity in Polish cyberspace. Because the threat level is high at this stage, a thorough review is carried out of the resources that would be, or have been, used in the attack, and business continuity plans are put into action.

CRP Alert Level DELTA

The final alert level is DELTA, which signals a very high risk of threat. It’s applied when a terrorist-style cyberattack has actually occurred, or when information indicates that such an attack is in its final preparation stage. At DELTA, the state activates previously prepared emergency plans and business continuity restoration processes.

How to Secure Your Company’s Infrastructure

When it comes to CRP alerts, network infrastructure isn’t just the responsibility of public administration — business owners of every kind need to take care of it too. Everyone is exposed when it comes to cyberattacks. The best way to protect yourself against threats is to thoroughly analyze your ICT infrastructure for vulnerabilities. The ReconMore service effectively raises your level of network security by detecting bugs and vulnerabilities before cybercriminals can exploit them. It’s a solution that works well for smaller, medium-sized, and large organizations alike.

Declaring a CRP alert means stepping up security work across the public sector. Its highest level requires stricter requirements for institutions that maintain critical IT systems. When cyberattack threats intensify, all of us should take care of our online security — especially if we run our own business on the internet.