Last updated 26 August 2026

Security & Compliance

Most vendor security questionnaires ask the same forty questions. This page answers them in advance, and says plainly where the honest answer is "not applicable" rather than dressing it up.

Frameworks we work in

FrameworkWhat we do with it
ISO/IEC 27001:2022 Gap analysis through to certification audit. Karol is a Lead Implementer certified by BSI.
SOC 2 · ISAE 3402 Readiness for Type I and Type II: scoping the trust services criteria, closing gaps, and standing beside you through the auditor's fieldwork.
GDPR Records of processing, technical and organisational measures, DPIAs, breach procedures. Outsourced Data Protection Officer.
Swiss FADP (revised) Data Protection Advisor, held simultaneously with the GDPR role — useful where entities straddle the EU and Switzerland.
Cyber Essentials · Cyber Essentials Plus · IASME Cyber Assurance Implemented end to end for a UK entity, including the assessed Plus tier.

How this website is built

A consultancy that advises on security should be able to describe its own attack surface. Ours is deliberately close to zero:

This is a deliberate change of posture. The previous site ran on WordPress and was compromised in July 2026. The installation was current on the day of the attack, with a stock theme and three plugins — keeping the software up to date, the defence users are told to rely on, did not prevent it. The response was not to harden the same architecture but to remove it. The underlying issue has been reported to the platform's security team; we will describe it here once they have assessed it and any fix is available.

Our own operations

Where the honest answer is "no"

We are a small firm and will not pretend otherwise. WarsawIQ does not hold its own ISO/IEC 27001 certificate, does not operate a 24/7 security operations centre, and does not carry a formal, independently audited control set of its own. What we bring is people who have built and been audited on those things inside larger regulated businesses. If your procurement process requires a certified supplier rather than a certified practitioner, say so early and we will tell you straight away whether we can meet it.

Reporting a security problem

If you find a vulnerability in this site or in anything we have built for you, write to karol.chlasta@warsawiq.com. We will acknowledge within two working days, keep you informed while we fix it, and credit you if you would like to be named. We will not threaten anyone who reports a problem in good faith.

← Back to the home page