Warsaw, Poland

AI and security advice from people who publish in the field.

We work where artificial intelligence, data governance and cybersecurity meet. What we recommend, we have run ourselves — certification programmes, regulatory audits and security functions inside regulated businesses.

18
Peer-reviewed publications
29
Conference and invited talks
20
Years in IT, fourteen leading teams
~200
Students through AWS Academy since 2024

What we do

Three services. Each is backed by work done inside regulated businesses, not advised on from outside.

Security & Compliance

Certification programmes, policy frameworks, and the evidence trail that holds up when an external auditor pulls on it.

  • Cyber risk assessment and security posture review, with a prioritised remediation plan
  • ISO/IEC 27001:2022 — gap analysis through to the certification audit
  • SOC 2 and ISAE 3402 readiness, Type I and Type II — scoping the trust services criteria, closing the gaps, and standing beside you through the auditor's fieldwork
  • Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance
  • GDPR and Swiss FADP programmes: records of processing, technical and organisational measures, policy exceptions
  • Audit preparation for regulators and clients: evidence packs, control narratives, dry runs
  • Outsourced DPO under the GDPR, or DPA under the Swiss FADP

Talks and training

Security awareness people actually remember, and technical training that leaves a certification behind.

  • Security awareness for mixed technical and non-technical audiences
  • AI literacy for leadership teams
  • Cloud and machine-learning courses with a certification path
  • Conference keynotes and invited lectures

Applied research and development

Machine learning on difficult signals — speech, gaze, language, network data — built to be reproduced, not demonstrated once.

  • Feasibility studies and proofs of concept with an honest verdict
  • ML pipelines that run on-premise or in a public cloud
  • Data quality, validation and enrichment
  • Joint research and grant collaborations with universities

How we work

Small engagements are welcome. So is being told the answer is no.

Remote by default

Workshops, interviews and reviews over video. On-site in Warsaw, or at your offices, when the work genuinely needs to be in the room — audit walkthroughs and training usually do.

Scoped or hourly

A fixed-scope piece with a defined deliverable — a gap assessment, a policy set, a readiness review — or hours drawn down as you need them. Whichever fits the problem.

Two regimes at once

Data protection under the GDPR and under the revised Swiss FADP, held simultaneously in a current role. Useful if your entities straddle the EU and Switzerland, which is where most of the awkward questions live.

We will tell you no

If the work needs a larger firm, a different specialism, or nothing at all, we will say so at the first conversation rather than the third invoice.

The reasoning is public

Four papers, chosen because each maps onto a service rather than because it is the most cited. The complete list — 18 publications and 29 talks — is kept current on Karol's academic site.

  1. 2026 — The dual-use dilemma of generative artificial intelligence in cybersecurity. Security and Defence Quarterly, 52(4), 4–22. DOI
  2. 2025 — Enhancing dementia and cognitive decline detection with large language models and speech representation learning. Frontiers in Neuroinformatics, 19. DOI
  3. 2023 — Neural Simulation Pipeline: enabling container-based simulations on-premise and in public clouds. Frontiers in Neuroinformatics, 17. DOI
  4. 2023 — Migrants vs. stayers in the pandemic: a sentiment analysis of Twitter content. Telematics and Informatics Reports, 10. DOI

All 18 publications and 29 talks →

Who we are

Karol Chlasta

PhD in Engineering and Technical Sciences Founder

PhD from the Polish-Japanese Academy of Information Technology, specialising in artificial intelligence methods; the dissertation was defended summa cum laude in 2023. Over twenty years in IT, fourteen of them in leadership positions, having pivoted from systems development to cybersecurity. Currently Head of Data Governance and Compliance at Wyden and Assistant Professor at Kozminski University. ISO/IEC 27001:2022 Lead Implementer, Data Protection Officer under the GDPR and Data Protection Advisor under the Swiss FADP.

Piotr Struzik, MSc

Cloud and platform

Cloud engineering across OpenStack, GCP and AWS, with containerisation in Docker and Kubernetes and infrastructure defined as code. Experience in government cloud architecture, monitoring and QA automation. MSc from Cracow University of Technology.

Paweł Sochaczewski, MSc

DevOps and infrastructure

DevOps for financial systems on AWS, after years building life insurance and electricity billing platforms. Teaches at Kozminski University and WSP ZNP. MSc from the Faculty of Mathematics, Informatics and Mechanics, University of Warsaw.

Tell us what you are facing

A short description of the problem is enough to start. We will say plainly whether it is something we can help with.

karol.chlasta@warsawiq.com
Consulting, talks and training, applied research
WarsawIQ Karol Chlasta
al. Jana Pawła II 43A/37B
01-001 Warsaw, Poland
NIP 8732876227 · REGON 522787378
Elsewhere
LinkedIn · GitHub · karol.chlasta.pl