
ISO/IEC 27001 in everyday work
Updated:
How I assess an ISMS in practice: workable procedures, communication between processes, scenario-based training and observation of daily work.
Read more
Risk
Compliance
Industrial Cybersecurity
Andrzej Dudek - Information Security / ISMS, ISO/IEC 27001 and TISAX ®.
I connect governance, risk and compliance with practical engineering.
Quality and information security in industrial and automotive environments.
I bring 18 years of experience in automotive, including seven years in information security management. My work spans ISO/IEC 27001, TISAX preparation, risk management and process auditing, combining systems expertise with an understanding of production, IT and OT.
I coordinate assessment preparation, manage process audit programmes and work with process owners and global teams to turn requirements into action. I also develop digital tools that improve everyday work. My background in IATF 16949 and VDA 6.3 connects this work with quality and continuous improvement.
More about me
Understand the process. Connect risks and requirements. Improve through practice.
Find what needs to change.
Understand how work happens.
Assess the consequences.
Identify the obligations.
Build and validate in practice.
Measure results. Capture lessons. Improve.
Three recent articles and three recent projects, ordered by their latest content update. Zobacz artykuły i projekty po polsku.

Updated:
How I assess an ISMS in practice: workable procedures, communication between processes, scenario-based training and observation of daily work.
Read more

Updated:
My approach to TISAX: customer requirements, coordination, gap analysis, teamwork and responsibility that continues after the assessment.
Read more

Updated:
My approach to GRC: shared management structures, evidence of operation, lasting corrective action and document workflow automation.
Read more

Updated:
Wazuh tests in a private lab: brute force, FIM and VirusTotal, with lessons on configuration, testing and preparing people to use a tool.
Read more

Updated:
A personal ESP32 station with a Nextion panel: information, lighting control and lessons on access control, Security-by-Design and change management.
Read more

Updated:
A private lab: resource monitoring with Zabbix, a clear Grafana dashboard and observations used to improve the server’s operation.
Read more
For the experience behind this work, read about my professional background and approach.
Explore five areas of my work, with a practical example and the methods or tools involved.
I develop and maintain ISMS documentation, assess gaps and coordinate actions with process owners.
Connecting ISO/IEC 27001 gap analysis, the Statement of Applicability and supporting evidence with follow-up actions.
ISO/IEC 27001 · IATF 16949 · TISAX®
Interested in exchanging experience on ISMS, risk or industrial cybersecurity? Get in touch.
Explore how GRC connects information security, automotive quality and OT in my work.
I work with process owners on risk assessment, mitigation, escalation and contingency planning. I connect these decisions with responsibilities, applicable requirements and evidence of effectiveness.
Select an area on the GRC diagram to explore it.
Select a symbol to explore its role.