About us
About us
IS Consulting is a boutique advisory firm specialising in cybersecurity for organisations of critical importance but with limited resources. We work in an advisory capacity and independently of vendors, helping smaller entities achieve genuine security and regulatory compliance, without placing on them burdens designed for large corporations.
How we came to be
IS Consulting was founded in 2020, during the pandemic, when the rapid acceleration of digitalisation and the mass shift to remote work exposed a serious gap. Organisations that had to move their operations online overnight often lacked the competencies or resources to do so securely. At the same time, the number of attacks rose sharply, aimed in particular at digitally immature entities. We founded the company to address that gap: to give smaller and critical organisations access to competencies that previously only large corporations could afford. That conviction is still expressed today in our motto, that everyone deserves security in the digital world.
Founder

"I believe that everyone deserves security in the digital world, regardless of a company's profile or size."
Quote translated from Polish.
The company was founded and is run by Michał Zdunowski, an expert with more than fifteen years of experience in cybersecurity. Before founding IS Consulting, he gained experience at the Ministry of the Interior and Administration (MSWiA), Accenture, DB Schenker, JTI and PerkinElmer. He is the author of the book "NIS2 w Polsce" ("NIS2 in Poland") published by INFOR, as well as industry publications in Menedżer Zdrowia (Termedia), Pentest Magazine and eForensics Magazine. He regularly speaks at industry conferences, including The Hack Summit, Hospital360, Forum Cyberbezpieczeństwa in Karpacz (Cybersecurity Forum), ZDG TOR railway forums, Cybersec EXPO & Forum and PharmaConnect. Beyond running the company, he is president of the Bezpieczniaki association, which teaches young people cybersecurity skills as a competence for the future, not merely basic awareness.
Our team
Although we operate as a boutique, we have a wide range of competencies thanks to a team of experts specialised in key areas.
NIS2 and KSC compliance expert
Specialises in compliance with the NIS2 directive and its Polish implementation (KSC), the national cybersecurity requirements.
Education and awareness building expert
Specialises in training, awareness programmes and raising team competencies.
Transport sector expert
Specialises in the specifics of cybersecurity in transport and logistics.
AI compliance expert
Specialises in compliance with the AI Act and management of artificial intelligence risk.
Infrastructure and application vulnerability expert
Specialises in security testing, vulnerability scanning and application analysis.
How we work
Our approach is based on a few principles that set us apart from typical vendors. We are independent of vendors, meaning we do not tie clients to a particular manufacturer or technology, but advise in their best interest. We act proportionately, matching safeguards to the organisation's real risk and scale, rather than overreaching. We treat security as support for people and their everyday work, not as a barrier. And we focus on genuine feasibility, that is, on solutions that a smaller organisation can actually implement and maintain.
Cooperation and affiliations
We are a member of ECSO (European Cyber Security Organisation), the European organisation bringing together entities working for cybersecurity, and a member of the NCC-PL community, the National Cybersecurity Competence Centre, part of the European network of coordination centres. We also cooperate with healthcare sector organisations, including NIL-IN and Ogólnopolskie Stowarzyszenie Szpitali Prywatnych (OSSP, the Polish Association of Private Hospitals), and, in the railway sector, with TOR Audytor on audits. We also run training for the railway sector in cooperation with ZDG TOR. These relationships help us stay close to the realities of the industries we serve.


