SecureHaveNET

Governance Risk Compliance Industrial Cybersecurity

Making GRC work in industrial environments.
Insights on ISO/IEC 27001, TISAX ®, governance and security practices based on practical experience in production and OT contexts.

Read articles

Systems support people — people create value

Profile

Understand the problem. Assess the risk. Apply the requirements. Build what works.

Integrated GRC and Quality Approach

I start with the problem and how the process works in practice. I assess the risk, identify applicable requirements, and look for a proportionate solution that people can use in daily operations.

This is how I apply GRC and risk management in industrial and automotive environments: connecting ISO/IEC 27001, TISAX ®, NIS2 and customer requirements with production, IT and OT. My background in IATF 16949 and VDA 6.3 keeps that work grounded in processes.

More about me
10 years of experience
Andrzej Dudek, Quality and Information Security Systems Analyst

How I work

Understand the process. Connect risks and requirements. Improve through practice.

  1. Problem

    Find what needs to change.

  2. Process

    Understand how work happens.

  3. Risk

    Assess the consequences.

  4. Requirements

    Identify the obligations.

  5. Solution

    Build what works in practice.

  6. Improvement

    Simplify. Measure. Refine.

Learn from the result. Improve the process.

Competency Areas

Connecting quality, information security and technical understanding to improve industrial processes.

Governance, Risk & Compliance
ISO/IEC 27001 & IATF 16949
TISAX ®
OT Security
Automation
Governance, Risk and Compliance as a strategic guide

Governance, Risk & Compliance

Connecting processes, risks and applicable requirements to support informed decisions and practical actions.

Approach

Requirements guide the solution; understanding the process and its risks makes it workable. I look for ways to improve existing processes before adding new procedures.

Illustration of the industrial governance and compliance framework

Governance, Risk & Compliance

I start with the process, assess the risks and identify applicable requirements. I use GRC to connect responsibilities and controls with practical, informed decisions.

Hover over the points on the GRC diagram to explore different aspects.

Latest Articles & Projects

Articles explain the analysis. Projects explore practical experiments and applications.

Website Analytics

Selected traffic metrics based on Google Analytics data