Skip to content
DORA

DORA has applied to financial entities and crypto-asset service providers since 17 January 2025 — ICT third-party register, incident reporting, resilience testing. Not sure where you stand? Book a free 30-min call

Jakub Wolak · Rzeszów, PL

Compliance infrastructure for financial entities — from gap analysis to a running SIEM.

I help financial entities, crypto-asset service providers and NIS2 entities meet DORA and NIS2 requirements: gap analysis, ICT risk and third-party registers, monitoring and incident reporting, audit-ready AWS.

A practitioner, not a slide-deck consultant — I run infrastructure at a licensed fintech day to day.

Services

  • 01

    NIS2 readiness audit

    Entity classification (essential or important), a gap analysis of the obligations that actually apply to you, support with the supervisory registration, and a 12-month implementation roadmap.

    Deliverable: report with prioritised actions · fixed price

    classificationgap analysisregistrationroadmap
  • 02

    Managed SIEM & incident response

    SIEM (Wazuh) rollout and operation, detection and alerting, and incident reporting workflows that hit the 24h/72h regulatory windows. Detection rules mapped to NIS2 and ISO 27001 controls.

    Model: implementation + monthly retainer

    Wazuhdetection24h/72h reportingISO 27001
  • 03

    DORA for financial entities & CASPs

    ICT third-party register, ICT risk management, incident reporting to the supervisory authority, and audit-ready AWS: CloudTrail with Object Lock, GuardDuty, access control you can evidence.

    Hands-on experience from licensed entities (MiCA / NBS / KNF)

    ICT registerICT riskCloudTrailGuardDuty

Why me

  • Practitioner from a licensed fintech

    Day to day I run infrastructure at a supervised financial institution — audits, regulator questions and real incidents, not training material.

  • Full stack, one person

    From AWS organisation and access control through SIEM and detection to incident reporting procedures. Engineering and paperwork come from the same place.

  • Concrete deliverables

    A gap-analysis report, a roadmap, working monitoring and detection rules — not a deck someone else still has to implement.

How we work together

  1. 01

    Free consultation

    30 minutes to establish which regime applies to you — DORA, NIS2 or both — and what it means for the setup you already run.

  2. 02

    Readiness audit

    Fixed price, fixed scope: gap analysis against the applicable requirements, the registers and evidence you are missing, and a 12-month roadmap.

  3. 03

    Implementation & operations

    SIEM, incident workflows, audit preparation — delivered as a project or kept running on a monthly retainer.

DORA already applies, and the Polish NIS2 registration deadline falls on 3 October 2026, with the obligations themselves due by 3 April 2027. Supervisory penalties are real, but the binding constraint is calendar time — implementation queues get longer every quarter.

Recent work

  • Multi-account AWS organisation + SIEM for a payments platform — centralised logging, CloudTrail with Object Lock, detection and alerting.

  • ICT third-party register and DORA gap analysis for a licensed crypto-asset service provider.

Tech stack

  • Wazuh / SIEM
  • incident response
  • ISO 27001
  • AWS
  • CloudTrail
  • GuardDuty
  • Terraform
  • Kubernetes
  • Docker
  • GitHub Actions
  • Grafana
  • TypeScript
  • NestJS
  • Node.js
  • PostgreSQL
  • Python

About

I run trapcode.dev out of Rzeszów, Poland. By day I lead infrastructure at a licensed fintech; the rest of the time I take on a small number of engagements around security and compliance — DORA, NIS2, monitoring and incident response. Embedded systems came first (ESP32, PCB design) — that is where the habit of digging down to the layer the problem actually sits in comes from.

Let’s check what applies to you.

A free 30 minutes — no forms, no sales deck.