MY SERVICES

Cyber Security Solutions

security consulting
cyber security solutions
testy penetracyjne
skanowanie sieci
Why

24/7 Cybercriminals Are Attacking

Cyberattacks focus mainly on the financial, government, military and infrastructure sectors — with finance leading at around 1,100 attacks per week. Ransom demands have also risen sharply in recent years, reaching between 4 and 14 million USD.
Don't become their next victim! I'll identify and help you fix vulnerabilities in your software, such as:

  • Cross-Site Scripting (XSS)
  • SQL Injection
  • Authentication flaws
  • Vulnerable components
  • Broken authorization
  • Misconfigurations
  • Insecure deserialization
  • Data leaks
Experience

I've Helped Improve Security for These Companies

Case studies

Selected analyses and findings

security testing
Audyt aplikacji
Testy penetracyjne aplikacji mobilnych
How I work

Practical, experience-based expertise

Continuous learning keeps me up to date with the latest attack scenarios.

Test penetracyjny aplikacji webowej
Education

IT Technician, B.Eng. in Information Processing & Protection, M.Sc. in Data Security in Computer Systems

Skanowanie aplikacji
Certifications

Key certifications: CISSP, OSWE, OSCP, Burp Suite Certified Practitioner, eWPTX, eWPT, AWS Certified Cloud Practitioner. See all →

Digital Forensics
Conferences

I take part in many industry conferences as both speaker and attendee — including as a speaker at The Hack Summit (2021 and 2023).

OSINT
Training

I keep upskilling constantly — I have completed 70+ industry trainings and courses, and run some myself. Cybersecurity changes every day, so staying current is essential.

Working together

How we work together

1
Contact & free consultation

We talk about your needs, goals and scope — no obligation.

2
Scope & quote

I define the exact scope, timeline and a quote matched to the risk.

3
Penetration testing

I run the tests, combining manual techniques with custom tooling.

4
Report with recommendations

A clear report: vulnerabilities, real risk and concrete remediation steps.

5
Retest after fixes

After fixes are applied I verify the vulnerabilities are effectively closed.

Regulatory compliance

Penetration testing for NIS2, DORA, PCI DSS & ISO 27001

Compliance is today the most common reason companies order security testing. I run penetration tests that meet the requirements of key regulations and standards — with an audit-ready report.

NIS2
EU directive

Testing and assessment of security effectiveness required from essential and important entities.

DORA
Financial sector

Digital operational resilience testing required from financial entities (since 2025).

PCI DSS
Card payments

Regular penetration testing required when handling payment card data.

ISO 27001
ISMS

Testing that supports certification and maintenance of your information security system.

I offer

Flexible pricing models

Fixed price
Penetration testing fixed price

Quote / Individual

  • Cost Transparency
  • Time Efficiency
Hourly rate
Penetration testing hourly rate

Rate / Hourly

  • Work Transparency
  • Scalability
Budget-based
Penetration testing budget-based

Tailored / To Budget

  • Goal-Focused
  • Innovative Approach
Pay for results
Pay for found vulnerabilities

You pay / For Results

  • Priced By Severity (CVSS Scale)
  • I Risk My Time, Not Your Budget

I price every project individually — I don't publish rates because I match them to scope and risk.

Phishing tests
About me

Penetration Tester · Security Expert · CyberSec

I started my security career in the Data Center of one of the largest banks in Poland, where I soon became a penetration tester. Later I delivered audits for, among others, one of the world's largest investment funds, software houses, and the automotive and hospitality industries. Today I lead an offensive security team at a global technology company — running penetration tests, Red Team exercises and cloud security assessments. I discovered the public vulnerabilities CVE-2018-8763 and CVE-2018-8764, and I speak at industry conferences.

In 2018 I founded CYBERSEC, under which I help organizations improve their cybersecurity. That same year I started my blog my127001.pl to share knowledge. For the past few years I have also been developing a specialization in the security of solutions based on artificial intelligence and large language models (AI/LLM).

400+

Penetration Tests Performed

1300+

Vulnerabilities Found

12+

Years of Experience

Tester Penetracyjny
Michał Kędzior

ETHICAL HACKER

Cybersecurity Consulting
Let's Work Together

Send Me a Message