AI and security from people who publish in the field.
We work where artificial intelligence, data governance and cybersecurity meet.
What we recommend, we have run ourselves — certification programmes, regulatory audits
and security functions inside regulated businesses.
Państwowy Fundusz Rehabilitacji Osób Niepełnosprawnych
Montpellier Business School
What we do
Three services. Each is backed by work done inside regulated businesses, not
advised on from outside.
Security & Compliance
Certification programmes, policy frameworks, and the evidence trail that holds up when
an external auditor pulls on it.
Cyber risk assessment and security posture review, with a prioritised remediation plan
ISO/IEC 27001:2022 — gap analysis through to the certification audit
SOC 2 and ISAE 3402 readiness, Type I and Type II — scoping the trust services
criteria, closing the gaps, and standing beside you through the auditor's fieldwork
Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance
GDPR and Swiss FADP programmes: records of processing, technical and organisational
measures, policy exceptions
Audit preparation for regulators and clients: evidence packs, control narratives,
dry runs
Outsourced DPO under the GDPR, or DPA under the Swiss FADP
Talks & Training
Security awareness people actually remember, and technical training that leaves a
certification behind.
Security awareness for mixed technical and non-technical audiences
AI literacy for leadership teams
Cloud and machine-learning courses with a certification path
Conference keynotes and invited lectures
Applied R&D
Machine learning on difficult signals — speech, gaze, language, network data — built to
be reproduced, not demonstrated once.
Feasibility studies and proofs of concept with an honest verdict
ML pipelines that run on-premise or in a public cloud
Data quality, validation and enrichment
Joint research and grant collaborations with universities
How we work
Small engagements are welcome. So is being told the answer is no.
Remote by default
Workshops, interviews and reviews over video. On-site in Warsaw, or at your offices,
when the work genuinely needs to be in the room — audit walkthroughs and training
usually do.
Scoped or hourly
A fixed-scope piece with a defined deliverable — a gap assessment, a policy set, a
readiness review — or hours drawn down as you need them. Whichever fits the problem.
We will tell you no
If the work needs a larger firm, a different specialism, or nothing at all, we will
say so at the first conversation rather than the third invoice.
The reasoning is public
Five papers, chosen because each maps onto a service rather than because it is
the most cited. The complete list — 18 publications and 29 talks — is kept current on
Karol's academic site.
2026 — The dual-use dilemma of generative artificial intelligence
in cybersecurity. Security and Defence Quarterly, 52(4), 4–22.
DOI
2025 — Enhancing dementia and cognitive decline detection with
large language models and speech representation learning, written with Piotr Struzik.
Frontiers in Neuroinformatics, 19.
DOI
2023 — Neural Simulation Pipeline: enabling container-based
simulations on-premise and in public clouds.
Frontiers in Neuroinformatics, 17.
DOI
2023 — Migrants vs. stayers in the pandemic: a sentiment analysis
of Twitter content. Telematics and Informatics Reports, 10.
DOI
2022 — MyMigrationBot: a cloud-based Facebook social chatbot for
migrant populations, written with Paweł Sochaczewski.
FedCSIS 2022, Annals of Computer Science and Information Systems.
DOI