SecureHaveNET

Governance Risk Compliance Industrial Cybersecurity

Andrzej Dudek - Information Security / ISMS, ISO/IEC 27001 and TISAX ®.
I connect governance, risk and compliance with practical engineering.

Explore selected work

Systems support people - people create value

Profile

Quality and information security in industrial and automotive environments.

GRC and ISMS grounded in industrial practice

I bring 18 years of experience in automotive, including seven years in information security management. My work spans ISO/IEC 27001, TISAX preparation, risk management and process auditing, combining systems expertise with an understanding of production, IT and OT.

I coordinate assessment preparation, manage process audit programmes and work with process owners and global teams to turn requirements into action. I also develop digital tools that improve everyday work. My background in IATF 16949 and VDA 6.3 connects this work with quality and continuous improvement.

More about me
10 years of experience
Andrzej Dudek

How I work

Understand the process. Connect risks and requirements. Improve through practice.

  1. Problem

    Find what needs to change.

  2. Process

    Understand how work happens.

  3. Risk

    Assess the consequences.

  4. Requirements

    Identify the obligations.

  5. Solution

    Build and validate in practice.

  6. Improvement

    Measure results. Capture lessons. Improve.

Latest articles & projects

Three recent articles and three recent projects, ordered by their latest content update. Zobacz artykuły i projekty po polsku.

For the experience behind this work, read about my professional background and approach.

Competency Areas

Explore five areas of my work, with a practical example and the methods or tools involved.

Requirements into practice

I develop and maintain ISMS documentation, assess gaps and coordinate actions with process owners.

In practice

Connecting ISO/IEC 27001 gap analysis, the Statement of Applicability and supporting evidence with follow-up actions.

ISO/IEC 27001 · IATF 16949 · TISAX®

Interested in exchanging experience on ISMS, risk or industrial cybersecurity? Get in touch.

Approach

Explore how GRC connects information security, automotive quality and OT in my work.

Sculptural GRC core in glass and metal, connected to industrial security, automotive quality and information security

Governance, Risk & Compliance

I work with process owners on risk assessment, mitigation, escalation and contingency planning. I connect these decisions with responsibilities, applicable requirements and evidence of effectiveness.

Select an area on the GRC diagram to explore it.

Select a symbol to explore its role.