
LLM in Business - Cloud or On-Premises?
Updated:
Cloud vs local LLM: cost, privacy and GRC.
Read more
Risk
Compliance
Industrial Cybersecurity
Andrzej Dudek - Information Security / ISMS, ISO/IEC 27001 and TISAX ®.
I connect governance, risk and compliance with practical engineering.
Governance / GRC → Risk & requirements → Practical engineering & validation.
I work as a Quality & Information Security Systems Analyst with a background in automotive quality and process auditing. I connect responsibilities, risks and requirements with solutions people can use in daily operations.
This is how I apply GRC and risk management in industrial and automotive environments: connecting ISO/IEC 27001, TISAX ®, NIS2 and customer requirements with production, IT and OT. My background in IATF 16949 and VDA 6.3 keeps that work grounded in processes.
More about me
Understand the process. Connect risks and requirements. Improve through practice.
Find what needs to change.
Understand how work happens.
Assess the consequences.
Identify the obligations.
Build and validate in practice.
Measure results. Capture lessons. Improve.
Three recent articles and three recent projects, ordered by their latest content update.

Updated:
Cloud vs local LLM: cost, privacy and GRC.
Read more

Updated:
Risk management starts with the right process.
Read more

Updated:
GRC in practice and why it matters.
Read more

Updated:
Limited local AI PoC: Ollama, Python and JSON output.
Read more

Updated:
GRC, ISO 27001 and PDCA in real operations.
Read more

Updated:
ESP32 OT/IoT monitoring for industrial systems.
Read more
For the experience behind this work, read about my professional background and approach.
I connect experience in quality and information security with an understanding of industrial processes. I turn requirements into actions and build improvements that support everyday work.
I translate quality and information security requirements into practical rules, documentation and actions suited to the organisation.
Structuring self-assessments and supporting evidence to identify gaps and prepare for external assessments.
ISO/IEC 27001 · IATF 16949 · TISAX®
I start by understanding how the process works and where the risks are. Then I look for practical improvements that meet the requirements.
I start with the process, assess the risks and identify applicable requirements. I use GRC to connect responsibilities and controls with practical, informed decisions.
Select an area on the GRC diagram to explore it.
Select a symbol to explore its role.
Selected traffic metrics based on Google Analytics data