Security · Risk · Compliance · Management systems

I help organizations safely achieve their business goals.

I combine 20+ years of experience in technology, information security, risk management and management systems. I help put processes in order, reduce risk and build solutions that keep working after the project ends.

  • MBA – Kozminski University
  • 20+ years of experience
  • Information security and risk management
  • Internal audits and management systems
  • Experience in large organizations and a practical, business-oriented approach
  • ISO 27001 • ISO 22301 • ISO 27017 • ISO 27018 • ISO 31000
Janusz Figurski — experienced security and risk manager

Janusz Figurski

Information Security • Risk Management • Compliance
🏅 MBA
🏅 ISO 27001
🏅 ISO 22301
🏅 ISO 31000

About me

A practitioner at the intersection of technology, business and management.

For over 20 years I have worked at the intersection of technology, business and management. I started as an engineer and technical specialist. Later I was responsible for product development, digital transformation, information security and management systems in large organizations.

Today I help organizations build and maintain effective processes for managing risk, compliance and information security. I believe good solutions should above all be practical, understandable and something the organization can sustain on its own once the engagement ends.

Experience gained at Siemens, Deutsche Telekom, Netia and GTS, among others. MBA from Kozminski University.

“Less chaos, less risk, more peace of mind — that's the result of a well-organized company.”

When to reach out

When is it worth getting in touch?

You don't always need another project, a new system or an extra full-time hire. Sometimes all it takes is an experienced person who can help put things in order, set a direction and see the matter through to the end.

I most often support organizations in situations such as:

01

A client requires ISO 27001 or proof of security from us

Information security requirements are increasingly becoming a condition for cooperation. I help prepare the organization to meet client expectations and put security and compliance in order.

02

We are preparing for an audit or certification

An external audit, certification or client review should not be a stressful event. I help assess readiness, organize documentation and prepare the team for the audit.

03

We have documentation, but we're not sure it works in practice

Procedures exist, but nobody uses them. Registers are kept only for audits. I help turn documentation into a tool that supports the daily work of the organization.

04

We keep a risk register, but it doesn't translate into business decisions

A risk register shouldn't just be an Excel sheet. I help implement a practical approach to identifying, assessing and monitoring risks that supports running the organization.

05

We don't have anyone responsible for information security or compliance

Not every organization needs a full-time specialist. I can support the organization as an external manager responsible for selected areas of security, risk or compliance.

06

The board expects better control over risk

I help organize the reporting of risks, actions and non-conformities so that management receives the information they need to make decisions.

07

We want to implement or maintain a system compliant with ISO 27001, ISO 22301 or ISO 31000

I support organizations both at the implementation stage and in later maintenance, helping the system grow alongside the organization.

08

We need support but don't want to create another full-time role

Many organizations need experience and support only a few days a month. I offer a flexible cooperation model tailored to the needs and scale of the business.

09

We want to put risk, compliance and information security in order

I help connect business, regulatory and organizational requirements into a coherent system that supports company goals instead of generating extra bureaucracy.

If you recognize your organization in any of the examples above, it's probably worth a conversation.

Book a call

Experience

Over 20 years of experience in the technology and telecommunications industry.

Experience gained at Siemens, Deutsche Telekom, Netia and GTS — from engineer, through product development and digital transformation, to security and risk.

  1. 01

    Engineer

    Technology and technical solutions

  2. 02

    Presales

    Technical advisory for clients

  3. 03

    Product Manager

    Product and services development

  4. 04

    Product Director

    Strategy and product portfolio

  5. 05

    Digital transformation

    Organizational and process change

  6. 06

    Security & risk

    Management systems, audits, compliance

Engagement models

One-off support or ongoing cooperation — in the role of an external manager.

Every organization is at a different stage of development. That's why I offer both one-off support and long-term cooperation in the areas of risk, compliance and information security.

01One-off

Assessment and action plan

For organizations that want to understand their current maturity level and structure their next steps.

As part of the engagement I analyze:

  • management processes
  • documentation
  • the way risks are identified and assessed
  • fulfillment of client and regulatory requirements
  • operation of management systems
  • readiness for audits and certifications

The outcome is a practical action plan with priorities, recommended improvements and a roadmap of next steps. It's a good starting point for organizations that want to consciously plan further development.

02Ongoing engagement

External Management Systems Manager

For organizations that have or are implementing management systems and need regular support without creating another full-time role.

The scope of cooperation may include:

  • maintenance and development of management systems
  • coordination of activities related to ISO 27001, ISO 22301 or other standards
  • risk and improvement reviews
  • documentation updates
  • audit preparation
  • support for process owners
  • reporting to management

This model keeps the system in good shape all year round, not just before the audit.

03Ongoing engagement

External Risk & Compliance Manager

For organizations that want to put risk, compliance and information security in order without building their own team.

Within an ongoing engagement I support the organization in areas such as:

  • risk management
  • information security
  • regulatory and contractual compliance
  • internal audits
  • policies, procedures and standards
  • risk and action registers
  • training and awareness building
  • preparation of reports for management
  • coordination between business, IT and security

It's a solution for organizations that need an experienced partner supporting the board and process owners in day-to-day risk and compliance management.

Not sure which model is right for you?

Let's start with a short conversation. Together we'll identify the organization's needs and choose a scope of support adequate to the scale of operations and current challenges.

Book a call

FAQ

Frequently asked questions.

Didn't find your answer? Send a message — I'll reply personally.

Contact

Let's talk about your organization's needs.

If you'd like to put risk management, compliance or information security in order — get in touch. I respond within one business day.

Book an online meeting

By submitting the form, you consent to being contacted about your inquiry.