Services

CyberSecurity Solutions

Web Application Penetration Testing

I simulate real attacks on your web app — finding vulnerabilities (SQLi, XSS, logic flaws, unauthorized data access) before criminals do.

More

Web application penetration testing is a specialized security assessment aimed at identifying and eliminating potential weaknesses in web systems and applications. By simulating real attacks, the application is tested against a range of threats — SQL injection, cross-site scripting (XSS), unauthorized access to user data — to ensure maximum protection against possible attacks.

testy bezpieczeństwa AI i LLM
AI & LLM Security Testing

I test the resilience of chatbots and LLM integrations against prompt injection, data leakage and guardrail bypass — following the OWASP Top 10 for LLM.

More

Applications based on artificial intelligence and large language models (LLMs) create an entirely new attack surface. In AI security testing I verify the resilience of chatbots, AI agents and LLM integrations against prompt injection (including indirect, via untrusted data sources), data leakage through model responses, guardrail bypass (jailbreaks) and business-logic abuse. I base the tests on the OWASP Top 10 for LLM, combining manual techniques with custom tooling.

Infrastructure Security Audit

I analyze server and environment configuration, finding misconfigurations and gaps before they become an attacker’s way in.

More

A server infrastructure security audit is a detailed analysis of a server environment’s defenses aimed at uncovering weaknesses and threats. It covers operating systems, applications, network configuration and access policies to identify potential security gaps. The goal is to recommend appropriate remediation, increase protection against attacks and ensure the continuity of critical resources.

Cybersecurity Consulting

I advise on how to genuinely raise your organization’s security level — from strategy to concrete, practical recommendations.

More

Cybersecurity consulting is an advisory service that helps organizations identify, assess and minimize risk related to cyber threats. It provides expertise and recommendations on best practices, technologies and strategies for protecting data and IT systems. By analyzing the current security posture, I help plan and implement effective security measures tailored to the specific needs of the business, increasing its resilience to potential cyberattacks.

Phishing & Social Engineering Tests

A controlled campaign checks how your team reacts to real fraud attempts — and where training is needed.

More

Phishing and social-engineering tests assess how susceptible employees are to social-engineering attacks, including fake emails imitating known sources (phishing). The goal is to identify how easily staff can be manipulated into revealing sensitive information or taking actions that endanger the organization. By simulating social-engineering attacks, companies better understand their weaknesses and raise security awareness among staff — key to protecting against real cyber threats.

Mobile Application Penetration Testing

I test Android and iOS apps — from on-device data security to communication with the server and APIs.

More

Mobile application penetration testing analyzes the security of apps for mobile devices such as smartphones and tablets to detect potential weaknesses and security gaps. Using various methods and tools to simulate attacks, I identify threats such as unauthorized data access, weak authentication mechanisms and man-in-the-middle vulnerabilities. The goal is to protect the app against attacks, improve user-data protection and ensure compliance with security standards.

Desktop Application Penetration Testing

I analyze desktop apps for vulnerabilities, insecure communication and flaws that allow taking control.

More

Desktop application penetration testing is a specialized security assessment of software for desktops and laptops. It simulates attacks to detect potential weaknesses such as software flaws, misconfigurations or susceptibility to various exploits. These tests identify threats that could be used for unauthorized access, data manipulation or other undesired actions. The goal is to strengthen desktop application security, protect stored information and guard against potential cyberattacks.

OSINT & Digital Forensics

I gather and analyze publicly available information about your organization — showing what an attacker could exploit.

More

OSINT (Open Source Intelligence) in digital forensics is the process of gathering and analyzing information from publicly available sources to support investigations and security analysis. It uses data available on the internet, in media, public registries and open databases to collect relevant information that helps identify, locate and monitor the activity of suspicious individuals or groups. OSINT techniques are key for cybersecurity and forensics experts, enabling evidence gathering, threat analysis and tracking criminals’ digital footprints — increasing the effectiveness of investigations and prevention in the digital space.

Network Penetration Testing

I assess your corporate network security — finding weak points and gaps that could be used to reach your systems.

More

Network penetration testing assesses the security of an organization’s network infrastructure to identify weaknesses and gaps that could be exploited by attackers. I simulate external and internal attacks to find vulnerabilities such as unprotected access points, weak system configurations, flaws in communication protocols and other threats that could lead to unauthorized access, data loss or network disruption. The goal is not only to detect weaknesses but also to recommend remediation and strengthen the overall security level of the network infrastructure against cyberattacks.

How I work

Practical, experience-based expertise

Continuous learning keeps me up to date with the latest attack scenarios.

Education

IT Technician, B.Eng. in Information Processing & Protection, M.Sc. in Data Security in Computer Systems

Certifications

Key certifications: CISSP, OSWE, OSCP, Burp Suite Certified Practitioner, eWPTX, eWPT, AWS Certified Cloud Practitioner.

Conferences

I actively take part in many industry conferences, both as a speaker and an attendee.

Training

I keep upskilling constantly — I have completed 70+ industry trainings and courses, and run some myself. Cybersecurity changes every day, so staying current is essential.

Let's Work Together

Send Me a Message