About Andrzej Dudek

Quality & Information Security Systems Analyst - connecting governance, risk and practical engineering.

Systems support people - people create value

I work with information security management systems in an industrial and automotive context. My background in quality, process auditing and management systems helps me connect ISO/IEC 27001 and TISAX ® requirements with the way people, production and technology work together.

The problems I focus on include translating requirements into responsibilities and controls, preparing useful evidence, understanding IT/OT dependencies and checking whether improvements work. SecureHaveNET brings that experience together with technical experiments, analysis and lessons learned.

All content on this website reflects my personal perspective and does not represent the views of any organization I am connected with.

SecureHaveNET brand mark

More about me

My work developed from quality and process auditing into management systems, information security and GRC. The common thread is understanding how work happens and making improvements that last.

Professional journey

Building on process knowledge to manage risk in industrial environments

QualityUnderstanding production, consistency and the causes of problems.
Process AuditingExamining how work is done: ISO 9001 internal auditing, VDA 6.3 certified auditing and CQI-9, CQI-15, CQI-27 assessments.
Management SystemsConnecting responsibilities, documentation and daily operations through IATF 16949.
Information SecurityExtending the systems approach to ISO/IEC 27001 implementation and maintenance, and TISAX ® preparation.
GRC & RiskBringing processes, risks and applicable requirements together to support practical decisions.
Industrial CybersecurityApplying that perspective to IT/OT dependencies, NIST SP 800-82 implementation and awareness training support.
Audit and documentation

My story

I started in quality, close to production and the everyday questions behind it: what went wrong, why it happened and how to keep it from happening again. That work led me into management systems and process audits, where I began looking beyond individual problems to how the whole process works.

Two books helped shape my thinking along the way: The Toyota Way by Jeffrey K. Liker and Doktryna jakości. Rzecz o turkusowej samoorganizacji by Professor Andrzej Jacek Blikle. They helped me put into words what I value in my work: understanding problems at their source, improving processes and trusting the people who work with them every day.

They also connect with the thought behind my motto: systems support people, and people create value.

From there, my work grew into information security through ISO/IEC 27001 and TISAX ®, and then into the connections between IT, OT and production. The questions are still familiar: what needs protecting, what can go wrong, and how can we make the process work better? This is the experience I bring to GRC today.

Approach

The key is understanding the process first, not the requirement. I start with the problem and how work is really done, assess the risk, then identify applicable requirements. Often, the solution is to simplify or improve an existing process.

Compliance is non-negotiable, but the form of implementation is flexible. Working with quality, IT and production, I look for proportionate, usable solutions and then check what can be simplified, automated or measured. I validate the result against the original problem and requirements, record limitations and lessons learned, and use them to improve the next iteration. Clear communication helps people understand and use the result.

Teamwork and collaboration
Information security technical lab

Technical environment

From requirement to technical reality. My lab helps me understand the technical side of risk, security controls and IT/OT dependencies. I use virtualization, networking, monitoring, backup, SIEM, automation and OT/IoT to examine how controls work in practice.

Experiments with local LLMs are part of this environment: a way to explore useful applications and their risks. Technical understanding supports my core work in GRC and ISMS by making requirements, limitations and trade-offs more concrete. These projects document experiments and PoCs in my own environment; their scope and results should be read in that context.

Practical evidence: local LLM tests and limitations, OT/IoT station, Wazuh / SIEM and Zabbix + Grafana monitoring.

Education

An engineering foundation in materials, manufacturing processes and technical analysis.

Master of Science in Engineering (M.Sc. Eng.)

2001-2006

Silesian University of Technology (Politechnika Śląska)

Field of study
Technical and Computer Science Education
Faculty
Mechanical and Technological Engineering
Specialization
Engineering Materials

Pedagogical preparation

Completed as part of the degree programme, including pedagogical coursework and teaching practice.

Selected Qualifications & Training

Six selected milestones connecting process auditing, information security and technical practice.

×
Certificate enlarged

Q&A: Experience, Approach & Practice

How do you turn complex requirements into something that actually works in daily operations?

The key is understanding the process first, not the requirement. I start from how work is really done, then map requirements onto it. In many cases, it’s not about adding new procedures, but structuring what already exists. This reduces resistance and increases adoption.

What is the most common mistake made when implementing standards like ISO 27001 or TISAX ®?

Treating requirements as documentation tasks instead of operational improvements. When the focus is only on “having it written,” systems become disconnected from reality. The real value comes when requirements are embedded into processes and decision-making.

How do you approach audits to make them effective instead of stressful?

I treat audits as structured conversations about processes, not inspections. The goal is to understand how things work and identify gaps early. When people see audits as support rather than control, the quality of information and cooperation improves significantly.

How do you balance strict compliance with operational efficiency?

Compliance is non-negotiable, but the form of implementation is flexible. The decision is whether to integrate a requirement into existing processes or create something new. The best solutions meet requirements while remaining simple and usable.

What role does communication play in GRC and industrial cybersecurity?

A critical one. Even the best-designed system will fail if people don’t understand it. Clear communication translates requirements into everyday language and builds cooperation across departments like production, quality, and IT.

How does your technical lab support your work in management systems?

It allows me to test and understand how systems behave in practice-virtualization, monitoring, backups, and automation. This helps bridge the gap between formal requirements and real infrastructure, making decisions more practical and grounded.

How do you typically approach solving complex problems?

I focus on data and simplicity. Methods like 5Why, supported by facts, are often enough to identify root causes. More advanced tools are useful, but clarity and structured thinking usually bring the fastest results.

What motivates you to keep developing in this field?

The combination of structure and change. Standards provide a framework, but every environment is different. There is always something to improve, optimize, or better understand.