— Jakub Wolak · Rzeszów, PL —
Compliance infrastructure for financial entities — from gap analysis to a running SIEM.
I help financial entities, crypto-asset service providers and NIS2 entities meet DORA and NIS2 requirements: gap analysis, ICT risk and third-party registers, monitoring and incident reporting, audit-ready AWS.
A practitioner, not a slide-deck consultant — I run infrastructure at a licensed fintech day to day.
Services
- 01
NIS2 readiness audit
Entity classification (essential or important), a gap analysis of the obligations that actually apply to you, support with the supervisory registration, and a 12-month implementation roadmap.
Deliverable: report with prioritised actions · fixed price
classificationgap analysisregistrationroadmap - 02
Managed SIEM & incident response
SIEM (Wazuh) rollout and operation, detection and alerting, and incident reporting workflows that hit the 24h/72h regulatory windows. Detection rules mapped to NIS2 and ISO 27001 controls.
Model: implementation + monthly retainer
Wazuhdetection24h/72h reportingISO 27001 - 03
DORA for financial entities & CASPs
ICT third-party register, ICT risk management, incident reporting to the supervisory authority, and audit-ready AWS: CloudTrail with Object Lock, GuardDuty, access control you can evidence.
Hands-on experience from licensed entities (MiCA / NBS / KNF)
ICT registerICT riskCloudTrailGuardDuty
Why me
-
Practitioner from a licensed fintech
Day to day I run infrastructure at a supervised financial institution — audits, regulator questions and real incidents, not training material.
-
Full stack, one person
From AWS organisation and access control through SIEM and detection to incident reporting procedures. Engineering and paperwork come from the same place.
-
Concrete deliverables
A gap-analysis report, a roadmap, working monitoring and detection rules — not a deck someone else still has to implement.
How we work together
- 01
Free consultation
30 minutes to establish which regime applies to you — DORA, NIS2 or both — and what it means for the setup you already run.
- 02
Readiness audit
Fixed price, fixed scope: gap analysis against the applicable requirements, the registers and evidence you are missing, and a 12-month roadmap.
- 03
Implementation & operations
SIEM, incident workflows, audit preparation — delivered as a project or kept running on a monthly retainer.
DORA already applies, and the Polish NIS2 registration deadline falls on 3 October 2026, with the obligations themselves due by 3 April 2027. Supervisory penalties are real, but the binding constraint is calendar time — implementation queues get longer every quarter.
Recent work
-
Multi-account AWS organisation + SIEM for a payments platform — centralised logging, CloudTrail with Object Lock, detection and alerting.
-
ICT third-party register and DORA gap analysis for a licensed crypto-asset service provider.
Tech stack
- Wazuh / SIEM
- incident response
- ISO 27001
- AWS
- CloudTrail
- GuardDuty
- Terraform
- Kubernetes
- Docker
- GitHub Actions
- Grafana
- TypeScript
- NestJS
- Node.js
- PostgreSQL
- Python
About
I run trapcode.dev out of Rzeszów, Poland. By day I lead infrastructure at a licensed fintech; the rest of the time I take on a small number of engagements around security and compliance — DORA, NIS2, monitoring and incident response. Embedded systems came first (ESP32, PCB design) — that is where the habit of digging down to the layer the problem actually sits in comes from.
Let’s check what applies to you.
A free 30 minutes — no forms, no sales deck.