Security engineering · Kraków, Poland

Security engineering for systems that cannot fail.

SoftQ is an independent security practice — and, before that, a software development house. We work with high-tech scale-ups and the engineering teams inside larger companies, and we start where the risk actually lives: in the code and the pipeline, the cloud, the network from edge to firewall, the endpoints and the identities behind them.

Twenty years building and defending production systems. I'm comfortable in multidisciplinary R&D teams and with IT and security specialists — and experienced at starting a security function from scratch.

Michał, owner

PracticeIndependent, vendor-neutral
BaseKraków · working across the EU
Good fit forScale-ups & platform teams

01 Capabilities

What we work on.

  • Application & product security

    Reading what you build the way an attacker would: design decisions, login and permission logic, inherited third-party code, and the checks that belong in every build — described in OWASP and CWE terms your developers already use.

  • Network & perimeter

    From the cloud edge to the server room: Zero Trust access, secure web gateways, WAF in front of what you expose, and on-premises firewall estates that stay segmented and in shape.

  • Endpoints & identity

    Hardened, monitored machines and login that resists phishing, with least privilege that survives contact with reality.

  • Cloud & platform oversight

    Direction and oversight rather than a hand on your console: which baselines apply, what a finding really means, and what your platform team should fix first.

  • Detection & incident response

    Monitoring that surfaces real problems, and a steady hand when one arrives — containment, evidence, root cause and the difficult conversations, framed with MITRE ATT&CK.

  • Awareness that fits the audience

    Security guidance written separately for business teams, R&D, and dev, IT and DevOps — because the same message rarely changes behaviour in all three.

  • Assurance & certification readiness

    Turning engineering work into what buyers, investors and auditors accept: ISO 27001 readiness run on compliance-automation tooling, control evidence that collects itself, supplier oversight, and defensible answers to security questionnaires.

  • Tooling choices without a vendor agenda

    Fifteen years on the cybersecurity distribution side of this industry means we know what the platforms really do once the demo ends, which ones fit a team your size, and when the honest answer is that you don't need to buy anything.

Also part of the job

  • Vulnerability & exposure management — scanning, prioritisation by what is genuinely reachable, and estate-wide checks when a serious flaw goes public.
  • Third-party & supplier security — vendor reviews, an inventory that stays current, and a clear picture of which data leaves the company.
  • Continuity & recovery — backups that get restored rather than assumed, and the power and hardware they quietly depend on.
Attacks land on people, configuration and code — not on intentions or documents.

02 Domains

Where the stakes are already high.

I've worked where a security decision carries physical or financial weight: industrial control systems on a factory floor, blockchain infrastructure holding real value, and business-critical applications carrying sales, delivery and after-sales processes. Different worlds, same discipline — work out what must never fail, then protect that first.

  • Industrial & OT
  • Blockchain & digital assets
  • Business-critical applications
  • SaaS platforms

03 Standards

Published frameworks, honest claims.

We work to published frameworks rather than a private maturity model, and we say plainly where we prepare and advise rather than certify — including where NIS2 or DORA changes what your customers start asking for.

  • OWASP standards
  • Secure SDLC
  • CWE
  • MITRE ATT&CK
  • CSA — CCM & Zero Trust
  • NIST CSF 2.0
  • CIS Benchmarks
  • ISO/IEC 27001 — readiness

04 How we work

Look first, fix in order, leave it running.

We look before we recommend, fix in the order that actually reduces exposure, and leave behind named owners, short runbooks and evidence that keeps collecting itself. That works as a single scoped review, as a project delivered with your engineers, or as standing availability for design decisions and escalations.

05 Licensing & rollout

SentinelOne, licensed and set up properly.

We supply SentinelOne licences through CLICO, the value-added distributor for the platform in Poland and Central Europe, and we help you get them into production: agent rollout, exclusions and policy baselines, fitting it around the systems you already run, and a walkthrough of the console with the people who will use it. Your team keeps its own dedicated web console — alert triage and containment stay in your hands, and we hand over working policies and a short runbook rather than a monitoring contract.

  • Licences via CLICO
  • Deployment assistance
  • Initial policy configuration
  • Console handover

06 Contact

Start with the part you're least comfortable with.

Tell us what you run and what's being asked of you — a customer's security review, investor due diligence, a release nobody wants to sign off. You'll get a candid answer, including a clear no if someone else is the better fit.