AI and security advice from people who publish in the field.
We work where artificial intelligence, data governance and cybersecurity meet.
What we recommend, we have run ourselves — certification programmes, regulatory audits
and security functions inside regulated businesses.
Three services. Each is backed by work done inside regulated businesses, not
advised on from outside.
Security & Compliance
Certification programmes, policy frameworks, and the evidence trail that holds up when
an external auditor pulls on it.
Cyber risk assessment and security posture review, with a prioritised remediation plan
ISO/IEC 27001:2022 — gap analysis through to the certification audit
SOC 2 and ISAE 3402 readiness, Type I and Type II — scoping the trust services
criteria, closing the gaps, and standing beside you through the auditor's fieldwork
Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance
GDPR and Swiss FADP programmes: records of processing, technical and organisational
measures, policy exceptions
Audit preparation for regulators and clients: evidence packs, control narratives,
dry runs
Outsourced DPO under the GDPR, or DPA under the Swiss FADP
Talks and training
Security awareness people actually remember, and technical training that leaves a
certification behind.
Security awareness for mixed technical and non-technical audiences
AI literacy for leadership teams
Cloud and machine-learning courses with a certification path
Conference keynotes and invited lectures
Applied research and development
Machine learning on difficult signals — speech, gaze, language, network data — built to
be reproduced, not demonstrated once.
Feasibility studies and proofs of concept with an honest verdict
ML pipelines that run on-premise or in a public cloud
Data quality, validation and enrichment
Joint research and grant collaborations with universities
How we work
Small engagements are welcome. So is being told the answer is no.
Remote by default
Workshops, interviews and reviews over video. On-site in Warsaw, or at your offices,
when the work genuinely needs to be in the room — audit walkthroughs and training
usually do.
Scoped or hourly
A fixed-scope piece with a defined deliverable — a gap assessment, a policy set, a
readiness review — or hours drawn down as you need them. Whichever fits the problem.
Two regimes at once
Data protection under the GDPR and under the revised Swiss FADP, held simultaneously
in a current role. Useful if your entities straddle the EU and Switzerland, which is
where most of the awkward questions live.
We will tell you no
If the work needs a larger firm, a different specialism, or nothing at all, we will
say so at the first conversation rather than the third invoice.
The reasoning is public
Four papers, chosen because each maps onto a service rather than because it is
the most cited. The complete list — 18 publications and 29 talks — is kept current on
Karol's academic site.
2026 — The dual-use dilemma of generative artificial intelligence
in cybersecurity. Security and Defence Quarterly, 52(4), 4–22.
DOI
2025 — Enhancing dementia and cognitive decline detection with
large language models and speech representation learning.
Frontiers in Neuroinformatics, 19.
DOI
2023 — Neural Simulation Pipeline: enabling container-based
simulations on-premise and in public clouds.
Frontiers in Neuroinformatics, 17.
DOI
2023 — Migrants vs. stayers in the pandemic: a sentiment analysis
of Twitter content. Telematics and Informatics Reports, 10.
DOI
PhD from the Polish-Japanese Academy of Information Technology, specialising in
artificial intelligence methods; the dissertation was defended summa cum laude
in 2023. Over twenty years in IT, fourteen of them in leadership positions, having
pivoted from systems development to cybersecurity. Currently Head of Data Governance and
Compliance at Wyden and Assistant Professor at Kozminski University. ISO/IEC 27001:2022
Lead Implementer, Data Protection Officer under the GDPR and Data Protection Advisor
under the Swiss FADP.
Piotr Struzik, MSc
Cloud and platform
Cloud engineering across OpenStack, GCP and AWS, with containerisation in Docker and
Kubernetes and infrastructure defined as code. Experience in government cloud
architecture, monitoring and QA automation. MSc from Cracow University of Technology.
Paweł Sochaczewski, MSc
DevOps and infrastructure
DevOps for financial systems on AWS, after years building life insurance and electricity
billing platforms. Teaches at Kozminski University and WSP ZNP. MSc from the Faculty of
Mathematics, Informatics and Mechanics, University of Warsaw.
Tell us what you are facing
A short description of the problem is enough to start. We will say plainly
whether it is something we can help with.