About Andrzej Dudek
Quality & Information Security Systems Analyst - connecting governance, risk and practical engineering.
Systems support people - people create value
I work with information security management systems in an industrial and automotive context. My background in quality, process auditing and management systems helps me connect ISO/IEC 27001 and TISAX ® requirements with the way people, production and technology work together.
The problems I focus on include translating requirements into responsibilities and controls, preparing useful evidence, understanding IT/OT dependencies and checking whether improvements work. SecureHaveNET brings that experience together with technical experiments, analysis and lessons learned.
All content on this website reflects my personal perspective and does not represent the views of any organization I am connected with.
More about me
My work developed from quality and process auditing into management systems, information security and GRC. The common thread is understanding how work happens and making improvements that last.
Professional journey
Building on process knowledge to manage risk in industrial environments
My story
I started in quality, close to production and the everyday questions behind it: what went wrong, why it happened and how to keep it from happening again. That work led me into management systems and process audits, where I began looking beyond individual problems to how the whole process works.
Two books helped shape my thinking along the way: The Toyota Way by Jeffrey K. Liker and Doktryna jakości. Rzecz o turkusowej samoorganizacji by Professor Andrzej Jacek Blikle. They helped me put into words what I value in my work: understanding problems at their source, improving processes and trusting the people who work with them every day.
They also connect with the thought behind my motto: systems support people, and people create value.
From there, my work grew into information security through ISO/IEC 27001 and TISAX ®, and then into the connections between IT, OT and production. The questions are still familiar: what needs protecting, what can go wrong, and how can we make the process work better? This is the experience I bring to GRC today.
Approach
The key is understanding the process first, not the requirement. I start with the problem and how work is really done, assess the risk, then identify applicable requirements. Often, the solution is to simplify or improve an existing process.
Compliance is non-negotiable, but the form of implementation is flexible. Working with quality, IT and production, I look for proportionate, usable solutions and then check what can be simplified, automated or measured. I validate the result against the original problem and requirements, record limitations and lessons learned, and use them to improve the next iteration. Clear communication helps people understand and use the result.
Technical environment
From requirement to technical reality. My lab helps me understand the technical side of risk, security controls and IT/OT dependencies. I use virtualization, networking, monitoring, backup, SIEM, automation and OT/IoT to examine how controls work in practice.
Experiments with local LLMs are part of this environment: a way to explore useful applications and their risks. Technical understanding supports my core work in GRC and ISMS by making requirements, limitations and trade-offs more concrete. These projects document experiments and PoCs in my own environment; their scope and results should be read in that context.
Practical evidence: local LLM tests and limitations, OT/IoT station, Wazuh / SIEM and Zabbix + Grafana monitoring.
Education
An engineering foundation in materials, manufacturing processes and technical analysis.
Master of Science in Engineering (M.Sc. Eng.)
2001-2006Silesian University of Technology (Politechnika Śląska)
- Field of study
- Technical and Computer Science Education
- Faculty
- Mechanical and Technological Engineering
- Specialization
- Engineering Materials
Pedagogical preparation
Completed as part of the degree programme, including pedagogical coursework and teaching practice.
Selected Qualifications & Training
Six selected milestones connecting process auditing, information security and technical practice.
Q&A: Experience, Approach & Practice
How do you turn complex requirements into something that actually works in daily operations?
The key is understanding the process first, not the requirement. I start from how work is really done, then map requirements onto it. In many cases, it’s not about adding new procedures, but structuring what already exists. This reduces resistance and increases adoption.
What is the most common mistake made when implementing standards like ISO 27001 or TISAX ®?
Treating requirements as documentation tasks instead of operational improvements. When the focus is only on “having it written,” systems become disconnected from reality. The real value comes when requirements are embedded into processes and decision-making.
How do you approach audits to make them effective instead of stressful?
I treat audits as structured conversations about processes, not inspections. The goal is to understand how things work and identify gaps early. When people see audits as support rather than control, the quality of information and cooperation improves significantly.
How do you balance strict compliance with operational efficiency?
Compliance is non-negotiable, but the form of implementation is flexible. The decision is whether to integrate a requirement into existing processes or create something new. The best solutions meet requirements while remaining simple and usable.
What role does communication play in GRC and industrial cybersecurity?
A critical one. Even the best-designed system will fail if people don’t understand it. Clear communication translates requirements into everyday language and builds cooperation across departments like production, quality, and IT.
How does your technical lab support your work in management systems?
It allows me to test and understand how systems behave in practice-virtualization, monitoring, backups, and automation. This helps bridge the gap between formal requirements and real infrastructure, making decisions more practical and grounded.
How do you typically approach solving complex problems?
I focus on data and simplicity. Methods like 5Why, supported by facts, are often enough to identify root causes. More advanced tools are useful, but clarity and structured thinking usually bring the fastest results.
What motivates you to keep developing in this field?
The combination of structure and change. Standards provide a framework, but every environment is different. There is always something to improve, optimize, or better understand.
