SecureHaveNET

Governance Risk Compliance Industrial Cybersecurity

Andrzej Dudek - Information Security / ISMS, ISO/IEC 27001 and TISAX ®.
I connect governance, risk and compliance with practical engineering.

Explore selected work

Systems support people - people create value

Profile

Governance / GRC → Risk & requirements → Practical engineering & validation.

Governance grounded in engineering

I work as a Quality & Information Security Systems Analyst with a background in automotive quality and process auditing. I connect responsibilities, risks and requirements with solutions people can use in daily operations.

This is how I apply GRC and risk management in industrial and automotive environments: connecting ISO/IEC 27001, TISAX ®, NIS2 and customer requirements with production, IT and OT. My background in IATF 16949 and VDA 6.3 keeps that work grounded in processes.

More about me
10 years of experience
Andrzej Dudek, Quality & Information Security Systems Analyst

How I work

Understand the process. Connect risks and requirements. Improve through practice.

  1. Problem

    Find what needs to change.

  2. Process

    Understand how work happens.

  3. Risk

    Assess the consequences.

  4. Requirements

    Identify the obligations.

  5. Solution

    Build and validate in practice.

  6. Improvement

    Measure results. Capture lessons. Improve.

Competency Areas

I connect experience in quality and information security with an understanding of industrial processes. I turn requirements into actions and build improvements that support everyday work.

Requirements into practice

I translate quality and information security requirements into practical rules, documentation and actions suited to the organisation.

In practice

Structuring self-assessments and supporting evidence to identify gaps and prepare for external assessments.

ISO/IEC 27001 · IATF 16949 · TISAX®

Approach

I start by understanding how the process works and where the risks are. Then I look for practical improvements that meet the requirements.

Sculptural GRC core in glass and metal, connected to industrial security, automotive quality and information security

Governance, Risk & Compliance

I start with the process, assess the risks and identify applicable requirements. I use GRC to connect responsibilities and controls with practical, informed decisions.

Select an area on the GRC diagram to explore it.

Select a symbol to explore its role.

Website Analytics

Selected traffic metrics based on Google Analytics data