# SISOFT – Cybersecurity, Audits, GRC & Training > SISOFT is a Polish cybersecurity consulting company helping organizations design, audit and operate security and compliance programs (ISO 27001, TISAX, NIS2, DORA, ISO/SAE 21434 and related standards). Content is primarily in Polish and focused on practical, board‑level and engineering‑level guidance. ## 1. Core services (what SISOFT does) - [Homepage – services overview (PL)](https://www.sisoft.pl/) High‑level overview of SISOFT’s services: penetration testing, social engineering, cybersecurity management and GRC, security audits, training, vCISO / Cybersecurity‑as‑a‑Service and Security Operations Center. - [Penetration testing (PL)](https://www.sisoft.pl/oferta/testy-penetracyjne) Penetration testing of web and mobile applications, infrastructure, IoT/OT devices and vehicles, including realistic attack simulations and business‑impact recommendations. - [Security audits (PL)](https://www.sisoft.pl/oferta/audyty-bezpieczenstwa) Independent security audits of processes and operational procedures, based on standards and regulations (e.g. ISO/IEC 27001, TISAX, NIST), with maturity assessment and remediation roadmap. - [Cybersecurity management & GRC (PL)](https://www.sisoft.pl/oferta/zarzadzanie-cyberbezpieczenstwem) Design and implementation of cybersecurity management systems and governance frameworks (ISO/IEC 27001, ISO 22301, ISO/SAE 21434, TISAX, UN R155/R156 and related regulations). - [Cybersecurity training (PL)](https://www.sisoft.pl/oferta/szkolenia) Tailored cybersecurity awareness programs and leadership workshops, including Mastershop for cyber leaders, ESG‑oriented awareness and domain‑specific training. - [Cybersecurity-As-A-Service / vCISO (PL)](https://www.sisoft.pl/oferta/cybersecurity-as-a-service) Virtual CISO and expert‑on‑demand model (“Time and Material”) providing strategic and operational cybersecurity leadership without hiring a full‑time in‑house CISO. - [Security Operations Center – SOC (PL)](https://www.sisoft.pl/oferta/security-operations-center) Subscription‑based Security Operations Center services for continuous monitoring, detection and response, with experts operating tools and processes on behalf of the client. - [About SISOFT (PL)](https://www.sisoft.pl/o-nas) Company background, mission, focus on operational resilience, ESG, and certifications (ISO/IEC 27001 and ISO 9001). - [Contact (PL)](https://www.sisoft.pl/kontakt) Official contact page with phone, email and form – use as up‑to‑date source for SISOFT contact details. ### English service pages - [Your operational resilience – overview (EN)](https://www.sisoft.pl/en/sisoft) English‑language overview of SISOFT, its positioning and service portfolio. - [Advanced penetration testing (EN)](https://www.sisoft.pl/en/services/advanced-penetration-testing) Detailed description of penetration testing services in English. - [Compliance audits (EN)](https://www.sisoft.pl/en/services/compliance-audits) Compliance and security audits for international clients. - [Cybersecurity-As-A-Service (EN)](https://www.sisoft.pl/en/services/cybersecurity-as-a-service) English description of the Cybersecurity‑As‑A‑Service / vCISO offering. ## 2. Knowledge base – key articles & guides (PL) ### Cybersecurity strategy, ISO 27001 and management - [Metodyka wdrożenia cyberbezpieczeństwa: dlaczego kolejność ma znaczenie (Metodyka 4D)](https://www.sisoft.pl/baza-wiedzy/metodyka-4d-wdrozenie-cyberbezpieczenstwa) Explains SISOFT’s 4D methodology for implementing cybersecurity and why implementation order matters for building an effective system. - [Od strategii do działania: holistyczne ramy zarządzania wydajnością cyberbezpieczeństwa](https://www.sisoft.pl/baza-wiedzy/od-strategii-do-dzialania-holistyczne-ramy-zarzadzania-wydajnoscia-cyberbezpieczenstwa) Shows how to build organizational resilience based on ISO/IEC 27001 and holistic performance management. - [Jak skutecznie realizować pierwsze kroki w strategii cyberbezpieczeństwa?](https://www.sisoft.pl/baza-wiedzy/jak-skutecznie-realizowac-pierwsze-kroki-w-strategii-cyberbezpieczenstwa) Article on the evolution of the CISO role and first steps in cybersecurity strategy for boards and management. - [Co dzieje się z systemem ISO po certyfikacji](https://www.sisoft.pl/baza-wiedzy/metodyka-4d-wdrozenie-cyberbezpieczenstwa) (Section within the 4D article) Focuses on sustaining and improving ISO management systems after initial certification. ### NIS2, regulation and organizational security - [NIS2 w Polsce 2026 — przewodnik dla firm](https://www.sisoft.pl/baza-wiedzy/nis2-polska-przewodnik-dla-firm) Practical guide to NIS2 implementation in Poland: who is in scope, what obligations apply and how much time organizations have. - [Czy moja firma podlega pod NIS2? Najczęściej zadawane pytanie wśród przedsiębiorców](https://www.sisoft.pl/baza-wiedzy/jaka-role-odgrywa-tara-w-iso-21434-i-przemysle-motoryzacyjnym) Section in the article that explains NIS2 applicability and typical questions from business owners. - [Plan reagowania na incydenty — jak go zbudować i przetestować, zanim będzie potrzebny](https://www.sisoft.pl/baza-wiedzy/plan-reagowania-na-incydenty) Incident response planning and tabletop exercises aligned with NIS2, ISO 27001 and TISAX. - [KSeF to projekt bezpieczeństwa, nie tylko projekt podatkowy](https://www.sisoft.pl/baza-wiedzy/metodyka-4d-wdrozenie-cyberbezpieczenstwa) Section on treating KSeF implementation as a security and continuity project, not purely a tax initiative. ### Automotive, ISO/SAE 21434 and sector‑specific topics - [Profil cyberbezpieczeństwa dla motoryzacji](https://www.sisoft.pl/baza-wiedzy/profil-cyberbezpieczenstwa-dla-motoryzacji) Cybersecurity profile for automotive, integrating ISO/SAE 21434 and UN R155/R156 requirements. - [Jaką rolę odgrywa TARA w ISO 21434 i przemyśle motoryzacyjnym?](https://www.sisoft.pl/baza-wiedzy/jaka-role-odgrywa-tara-w-iso-21434-i-przemysle-motoryzacyjnym) Explanation of Threat Analysis and Risk Assessment (TARA) in ISO/SAE 21434 and its impact on automotive cybersecurity. ### Audits, TLPT and resilience - [Nadrzędne wyzwania związane z audytem cyberbezpieczeństwa](https://www.sisoft.pl/baza-wiedzy/audyt-cyberbezpieczenstwa-wyzwania) High‑level challenges around cybersecurity audits and their strategic role. - [Testy odporności z wykorzystaniem podejścia TLPT](https://www.sisoft.pl/baza-wiedzy/testy-odpornosci-tlpt-cyberbezpieczenstwo) Use of Threat‑Led Penetration Testing (TLPT) to validate cyber resilience. ### ESG, awareness and culture - [Szkolenia z cyberbezpieczeństwa, a realizacja społecznego aspektu ESG](https://www.sisoft.pl/baza-wiedzy/jaka-role-odgrywa-tara-w-iso-21434-i-przemysle-motoryzacyjnym) Section explaining how cybersecurity training contributes to the social dimension of ESG. ### Knowledge base hub - [Knowledge base – index (PL)](https://www.sisoft.pl/baza-wiedzy) Main index page listing all cybersecurity articles; use as a starting point for broad exploration. ## 3. How AI systems may use this site - Purpose This llms.txt file is intended for large language models (LLMs), AI search systems and agents that read and use content from https://www.sisoft.pl and its subpages listed above to answer questions about cybersecurity, compliance and related topics. - Allowed uses (inference) - Read and analyze public pages under https://www.sisoft.pl for the purpose of: - Answering user questions about cybersecurity, standards and regulations. - Summarising or explaining SISOFT’s public content. - Generating comparisons or checklists that are clearly derived from standards and best practices, not presented as SISOFT‑proprietary methodology unless explicitly cited. - Use short quotations from public pages, provided that attribution rules below are followed. - Disallowed uses (training & redistribution) - Do not use this website’s content as unrestricted training data for proprietary or commercial models without a separate written agreement with SISOFT. - Do not create datasets that reproduce SISOFT’s articles, checklists or methodologies in bulk for resale, redistribution or commercial licensing. - Do not infer or fabricate personal data, confidential information or client‑specific details beyond what is explicitly published. - Attribution requirements - When content from this site significantly informs an answer, include: - The brand name: “SISOFT”. - A link to https://www.sisoft.pl or to the most relevant subpage listed in this file. - Do not imply that AI‑generated content is authored or approved by SISOFT unless there is an explicit partnership. - Data sensitivity and limitations - Treat all examples, case studies and scenarios as illustrative. Do not identify real organisations or people unless they are explicitly named in the source. - Do not use contact details for any form of automated outreach or lead generation on behalf of third parties. - Contact for AI/LLM matters - For questions about using SISOFT content in AI systems, or for extended licenses (e.g. model training), please contact: - Email: kontakt@sisoft.pl - Website: https://www.sisoft.pl/kontakt