About us

About us

IS Consulting is a boutique advisory firm specialising in cybersecurity for organisations of critical importance but with limited resources. We work in an advisory capacity and independently of vendors, helping smaller entities achieve genuine security and regulatory compliance, without placing on them burdens designed for large corporations.

How we came to be

IS Consulting was founded in 2020, during the pandemic, when the rapid acceleration of digitalisation and the mass shift to remote work exposed a serious gap. Organisations that had to move their operations online overnight often lacked the competencies or resources to do so securely. At the same time, the number of attacks rose sharply, aimed in particular at digitally immature entities. We founded the company to address that gap: to give smaller and critical organisations access to competencies that previously only large corporations could afford. That conviction is still expressed today in our motto, that everyone deserves security in the digital world.

Founder

Michał Zdunowski, founder of IS Consulting

"I believe that everyone deserves security in the digital world, regardless of a company's profile or size."

Quote translated from Polish.

The company was founded and is run by Michał Zdunowski, an expert with more than fifteen years of experience in cybersecurity. Before founding IS Consulting, he gained experience at the Ministry of the Interior and Administration (MSWiA), Accenture, DB Schenker, JTI and PerkinElmer. He is the author of the book "NIS2 w Polsce" ("NIS2 in Poland") published by INFOR, as well as industry publications in Menedżer Zdrowia (Termedia), Pentest Magazine and eForensics Magazine. He regularly speaks at industry conferences, including The Hack Summit, Hospital360, Forum Cyberbezpieczeństwa in Karpacz (Cybersecurity Forum), ZDG TOR railway forums, Cybersec EXPO & Forum and PharmaConnect. Beyond running the company, he is president of the Bezpieczniaki association, which teaches young people cybersecurity skills as a competence for the future, not merely basic awareness.

Our team

Although we operate as a boutique, we have a wide range of competencies thanks to a team of experts specialised in key areas.

  • NIS2 and KSC compliance expert

    Specialises in compliance with the NIS2 directive and its Polish implementation (KSC), the national cybersecurity requirements.

  • Education and awareness building expert

    Specialises in training, awareness programmes and raising team competencies.

  • Transport sector expert

    Specialises in the specifics of cybersecurity in transport and logistics.

  • AI compliance expert

    Specialises in compliance with the AI Act and management of artificial intelligence risk.

  • Infrastructure and application vulnerability expert

    Specialises in security testing, vulnerability scanning and application analysis.

How we work

Our approach is based on a few principles that set us apart from typical vendors. We are independent of vendors, meaning we do not tie clients to a particular manufacturer or technology, but advise in their best interest. We act proportionately, matching safeguards to the organisation's real risk and scale, rather than overreaching. We treat security as support for people and their everyday work, not as a barrier. And we focus on genuine feasibility, that is, on solutions that a smaller organisation can actually implement and maintain.

Cooperation and affiliations

We are a member of ECSO (European Cyber Security Organisation), the European organisation bringing together entities working for cybersecurity, and a member of the NCC-PL community, the National Cybersecurity Competence Centre, part of the European network of coordination centres. We also cooperate with healthcare sector organisations, including NIL-IN and Ogólnopolskie Stowarzyszenie Szpitali Prywatnych (OSSP, the Polish Association of Private Hospitals), and, in the railway sector, with TOR Audytor on audits. We also run training for the railway sector in cooperation with ZDG TOR. These relationships help us stay close to the realities of the industries we serve.

ECSO: European Cyber Security OrganisationNCC-PL: National Cybersecurity Competence Centre

Let's talk

Want to find out how we can help your organisation? Let's talk.