Mateusz Dominik joins as new Partner in the NewTech/Cybersecurity practice

According to data from CERT Polska, over 260,000 cybersecurity incidents were recorded in Poland in 2025, compared to ‘only’ just over 100,000 the year before. And although we are only halfway through the current year, the figures are already rising exponentially – by the end of July, over 190,000 incidents had been recorded. Among the most common phishing attacks are also those with the most serious consequences for any organisation’s operations, such as ransomware attacks. As threats continue to escalate, so does the volume of regulation in the field of cybersecurity.

That is why we are strengthening our NewTech team with Mateusz Dominik, a new Partner in the area of Cybersecurity. He is a specialist with experience gained on both sides of the fence – in law firms and consulting firms, as well as in the heavily regulated environment of international financial institutions and global technology providers.

Mateusz takes a holistic view of EU regulations such as DORA, NIS2, CER, CRA, the AI Act and the Data Act, and in this rapidly evolving regulatory landscape, he recognises both the regulatory pressure bearing down on businesses and the opportunity to build a competitive advantage or a high level of resilience. That is why, in his practice, he strongly emphasises the importance of identifying the common threads running through individual regulations – an approach that enables the optimal use of existing processes and their effective development.

2

A lawyer with an insider’s understanding of both technology and the law

The appointment of Mateusz Dominik represents a strategic strengthening of the NewTech and Cybersecurity practice and an important step in the development of unique hybrid services within our portfolio.

As an expert who combines legal knowledge with a practical understanding of technology and the realities of implementation projects, Mateusz effectively bridges the communication gap between the regulatory world and the technical community, seamlessly translating legal requirements and compliance standards into the language of technical specifications, and complex technological and business considerations into sound legal frameworks. With this combination of skills, we will be better placed to support organisations’ end-to-end regulatory compliance processes and our clients’ complex IT projects. Mateusz’s knowledge and experience will also help to accelerate roll-outs, minimise operational risks and deliver genuine digital security for clients wherever technology meets the law.

When asked how he views the role of a lawyer in transformation projects, Mateusz is direct – there is no point in overcomplicating things. Above all, he focuses on navigating converging regulations confidently and translating their intricacies into terms the business can understand.

For example, when implementing an AI-based solution, compliance with the AI Act alone will rarely be the only consideration. It will frequently be necessary to verify compliance with provisions governing aspects of the contractual relationship with the technology provider (falling under civil law or outsourcing requirements), as well as competition and consumer protection rules, intellectual and industrial property rights protection, data (including personal data) protection aspects, cybersecurity regulatory requirements, and more.

A thorough understanding of the regulatory framework should also extend to knowledge of market standards and supervisory practice, including the guidelines, recommendations and Q&A materials issued alongside successive pieces of legislation. It is precisely these that shape an organisation’s ability to build processes resilient to adverse opinions or decisions by supervisory authorities – together with their business and technical consequences. Identifying these interdependencies is the legal adviser’s responsibility, and it can determine the success of an entire project.

Another key challenge is communicating these complex and intricate matters in a way that enables the business to properly understand and assess the risks. A specialist lawyer is able to tailor the message to the audience – be it a Chief Information Officer, a security specialist or a network architect.

For example, it is the lawyer’s role to explain why implementing a solution designed to monitor employees’ emotions in the workplace is not the most advisable approach from a regulatory standpoint, whereas a similar solution for assessing customers’ emotions may be acceptable (provided that XYZ steps are taken).

Or why the ‘principle of proportionality’, invoked across numerous European legislative instruments, cannot give rise to arbitrary interpretation of the rules – and why, for instance, the implementation of a cybersecurity incident management system cannot simply be forgone, even where the organisation has not previously been affected by such incidents.

1

Mateusz Dominik champions ‘compliance by design’

A defining characteristic of regulation is that it virtually never keeps pace with reality. One need only look at the AI Act, which had not yet fully entered into force before it already urgently required amendment – not least in the context of the proliferation of ‘nudifier’ applications. Such regulatory gaps can sometimes present an opportunity, however, for those who take a conscious and mature approach to compliance, or who are subject to close regulatory oversight, regulatory inflation and the constant flux of the legislative landscape remain a considerable challenge.

Mateusz sees the antidote to the rapid pace of technological and regulatory change in the ‘compliance by design’ approach – that is, embedding compliance considerations from the very outset of developing a solution, a business model or a new feature.

This is the hallmark of mature organisations that manage the full, complex lifecycle of ICT solutions and understand that any other approach is likely to prove extremely costly.

It is easy to envisage a scenario in which a solution that is both commercially desirable and technologically feasible turns out, once it goes live, to constitute a high-risk system, or even a prohibited practice, under the AI Act. Its use would have to be suspended, at least until the necessary technological or business modifications have been made, and its actual deployment brought into conformity with extensive regulatory requirements. The risk of substantial penalties must also not be overlooked. These are very real costs of deferring compliance.

Highly specialised advisory services in cyber law

Mateusz is a practitioner with considerable experience in working with clients from heavily regulated sectors. In recent years, he has supported clients on projects involving the implementation or application of new regulations, including the EBA Guidelines on outsourcing, the DORA Regulation, the NIS2 Directive and the Act on the National Cybersecurity System (UKSC), regulatory recommendations and positions on technology, as well as projects to adapt to changes in the area of regulated outsourcing.

These experiences will strengthen our cyber-law practice.

In the field of cybersecurity, we are not so much standing on the threshold of change as we have already been part of it for some considerable time. The number of cyber threats and cyber incidents is growing exponentially; their vectors and sources are shifting (as in the case of so-called APT attacks); attacks on entities within supply chains are becoming increasingly frequent; more advanced technologies – such as frontier AI – are being exploited, as are vulnerabilities inherent in those technologies – such as prompt injections. Recent times have also seen a wave of new regulations, generating additional requirements addressed to a wide range of market participants, including critical infrastructure operators. Yet this is no longer a topic of exclusive interest to security specialists. This combination of shifts in cyberspace and in the legal framework is driving growing demand for highly specialised cyber-law advisory services. New areas of support and new business needs are emerging, emphasises Mateusz Dominik.

The priority must be a thorough understanding of the specific needs and characteristics of a given business, the particularities of its industry, and the business implications of the legal risks identified.

An (even) stronger NewTech practice at Kochański & Partners

Mateusz Dominik joins the team of Piotr Kochański, Monika Maćkowska-Morytz and Natalia Kotłowska-Wochna, a group that today comprises over a dozen outstanding specialists.

Mateusz brings to our organisation something the market is currently in great demand for – a lawyer who genuinely understands technology from the inside, rather than merely describing it from the outside. His experience in financial institutions and on the technology provider side offers our clients tangible value and real insight into what a project looks like from the perspective of every stakeholder involved. This is a genuine boost – and it has been felt from day one, emphasises Piotr Kochański, Managing Partner.

Do you have questions about UKSC, DORA, NIS2, a qualification opinion or other areas of cybersecurity and data protection? Get in touch with us


Contact us:

Piotr Kochański

Piotr Kochański

Advocate / Senior Managing Partner / New Tech / Nuclear Energy / Media / Defence / Head of the Arbitration & Dispute Resolution Practice Group

+48 602 218 217

p.kochanski@kochanski.pl

Mateusz Dominik

Mateusz Dominik

Attorney-at-law / Partner / NewTech / Cybersecurity

+48 883 323 457

m.dominik@kochanski.pl