1,000+ audits. 60 countries. One team.

Security without pain. Compliance without stress.

One of the few firms worldwide holding the full set of PCI SSC accreditations. 1,000+ projects in 60 countries.
19 out of 20 clients come back.

Banks & financial institutions | Fintech & payment processors | eCommerce & payment platforms

Poznań
Warsaw
Manchester
Birmingham
Edinburgh
Founder & CEO

Kris Olejniczak

Patronusec was built to answer a question most compliance and cybersecurity firms never ask themselves: what does security look like when the person across the table actually understands your business?

With 15+ years in cybersecurity and 12 in PCI DSS, seven PCI SSC qualifications - including QSA (#203-393) - he has delivered audits and advisory projects for banks, fintechs and global organisations in 60+ countries. As CEO, he owns the company's strategy and the quality of every service Patronusec delivers.

Outside work, he tests himself in the mountains.

Christopher Ince

Principal Security Consultant · 12 years

If your organisation is going through a PCI DSS audit or working on a P2PE solution - Chris is the person who will guide you through the process smoothly and without any surprises.

As a PCI DSS QSA (#205-825) and PCI P2PE Assessor (#400-205) with over 15 years of experience in InfoSec, PCI compliance and ISO 27001, he sets the standards for all PCI projects at Patronusec and mentors the QSA team.

Outside work, he experiments with 3D printing and AI solutions, and makes a point of discovering local craft beer wherever in the world his work takes him.

PCI QSA PCI P2PE CISA ISO 27001 LA

Paweł Olejniczak

Head of Professional Services · 12 years

If your organisation needs mature security management but isn't ready to build its own team - Paweł and his team will take on that responsibility and act as your in-house security department.

As Head of the vCISO team at Patronusec, he oversees the day-to-day work of consultants, ensures service quality and develops the people who manage security in our clients' environments. He built his experience at Deloitte and PwC, then went on to lead risk management at Nordea Bank and Standard Chartered Bank in Poland - meaning he knows the realities of regulated financial environments from the inside. He holds the PCI Professional certification (PCIP #1007-690).

Privately, a car enthusiast with a talent for turning weekends into unforgettable travel adventures.

CISSP CISM CRISC CISA

Agnieszka Leszczyńska

Head of Quality Assurance · 10 years

Before any report reaches a Patronusec client, it passes through Agnieszka's hands - someone who catches even the smallest errors and inconsistencies. That's why 80% of our reports are accepted by the AQM with no comments at all.

As PCI DSS QSA (#205-906) and PCI Professional (PCIP #1007-774), she is responsible for the independent review of every report, leads certification audits and advisory projects for Patronusec clients. She has worked with PCI and ISO standards for 8+ years - and it shows in every document that leaves our team.

Outside work, a fiction reader, true crime podcast devotee and language enthusiast - speaks Russian and currently taming Spanish. She is also conducting ongoing research into how many pairs of shoes and handbags can reasonably be classified as "essential." Results remain inconclusive.

PCI QSA ISO 27001 LA ISO 27001 LI

Mat Clarke

Principal Security Consultant · 10 years

Mat has a thorough understanding of both technology and security standards - before becoming a PCI assessor, he worked in penetration testing and digital forensics for the British police. That background means his audits go well beyond ticking boxes. Mat identifies real technical risks, not just formal non-conformities.

As a PCI DSS QSA (#204-935), PCI QPA (#1300-179) and PCI P2PE Assessor (#400-182) with over 10 years in cybersecurity, he has delivered projects for clients in banking, fintech and eCommerce across four continents.

Outside work, he's a devoted Manchester United supporter and loves to attend live music concerts whenever he gets the chance.

PCI QSA PCI P2PE QSA PCI QPA ISO 27001 LA ISO 27001 LI

Bartłomiej Konopka

Information Security Consultant · 4 years

If you're struggling to convince your board to invest in security, or you're not sure how to sell compliance internally - Bartek will find a way. Always calm, always smiling, always with a solution.

He built his experience as a Risk Analyst at Standard Chartered Bank, where he handled compliance reporting and risk management in a heavily regulated environment. At Patronusec he works within the vCISO team, helping clients maintain PCI DSS compliance and build InfoSec maturity.

Outside work, he explores cities the way few people do - on rollerblades. When he's not rolling through a new street, he's trading his consultant's badge for a firefighter's helmet.

vCISO

Monika Ostrowska

Information Security Consultant · 4 years

If your ASV scans are returning errors you don't understand, or ISO 27001 requirements feel overwhelming - Monika will walk you through every step, calmly and precisely, until everything is clear.

She built her experience as a Data Protection Officer and internal ISO 27001 auditor, which means she understands compliance from both a legal and operational perspective. In Patronusec's vCISO team, she helps clients maintain and develop information security management systems in line with ISO 27001.

In her free time, she enjoys photography as a hobby and loves to travel. She values the opportunity to explore new places and cultures and to find inspiration outside her everyday professional environment.

Personal Data Procetion ISO 27001 IA

Alistair Larmont

Information Security Consultant · 5 years

If you're facing a PCI DSS or ISO 27001 implementation and don't know where to start - Alistair is the person who will turn complex requirements into simple, practical processes that your team can actually maintain.

He built his expertise from the ground up at British Telecom, where as a member of the internal Compliance and InfoSec team he managed compliance in one of the most complex corporate environments in the world. He knows what it means to implement standards not on paper, but in real, large organisations. As a PCI DSS QSA (#207-146) and PCI Professional (PCIP #1007-970), he brings over 3 years of PCI DSS practice and 2 years of ISO 27001 experience.

Away from work, he enjoys exploring new places through caravanning, long walks with his dog, and staying closely connected to community life through his work with the parish council.

PCI QSA ISO 27001 LA ISO 27001 LI

Wojciech Chamski

Security Engineer · 3 years

If you know what you want to achieve in terms of security but don't know how to make it happen technically - Wojtek will quietly analyse the problem, find a solution and simply get it done. No technology is unfamiliar to him - he picks up new tools and systems in no time.

As a Security Engineer in Patronusec's vCISO team, he works with clients who don't need strategy and direction, but someone who rolls up their sleeves and gets the job done - implementing, testing, configuring. Where others see a technical problem with no solution, Wojtek sees a task to be completed.

In his spare time, an avid foodie, who loves exploring new cuisines and cooking. To avoid consequences of his culinary passion, he spends proportional amount of time on a road bike and running.

Security Engineer

Bartosz Wencierski

Information Security Consultant · 5 years

If you want to test whether your employees will click on a phishing link, or build a genuine security culture within your organisation - Bartek is the person to start that conversation with.

In Patronusec's Professional Services team, he is responsible for the delivery and maintenance of Cybersecurity projects for clients. Over the past 3 years he gained experience as an Associate QSA - meaning he understands compliance from both sides: as an auditor verifying requirements and as a practitioner helping to maintain them day to day.

In his spare time, he enjoys collecting new places on the map, experiencing the thrill of sports, and celebrating small gardening victories. He likes staying on the move - traveling, meeting new people, and encountering situations that break routine and bring new lessons along the way.

PCI aQSA

Sylwia Olejniczak

Head of Finance and Administration

Sylwia doesn't crack passwords or review PCI standards - but without her, no project would have a signed contract or a paid invoice. If you have a query about an invoice or need clarification on the terms of your engagement - Sylwia will analyse it and explain everything clearly.

As Head of Administration and Finance, she ensures that the outstanding technical work of our team is matched by equally flawless financial documentation. She oversees contracts, monitors expenses in line with internal regulations and works with clients' finance teams to make sure every invoice is straightforward, clear and in line with what was agreed.

In her spare time she is mastering puzzles.

Track Record

Our Experience

Years of commitment to payment security and compliance, measured in real outcomes.

1000+ Projects delivered across 60+ countries
5 QSAs available to meet your needs
15+ Years with the standard since version 1.2
400+ PCI certification audits completed
Accreditations

Our accreditations

One of the few firms worldwide holding the full set of PCI Security Standards Council accreditations.

PCI SSC

ISACA / (ISC)² / Cloud

patronus-certyfikaty-cissp
patronus-certyfikaty-cism
patronus-certyfikaty-cisa
patronus-certyfikaty-crisc
patronus-certyfikaty-lead-auditor
patronus-certyfikaty-aws-security
Industry impact

Our presence and industry impact

We speak at industry conferences, including PCI Community Meetings
We are members of Business Center Club and FinTech Poland
We present at BCC chapters in Warsaw and Poznań
Accredited and qualified to conduct TLPT tests under DORA
Our values

How we work

Excellence

Our audit doesn't just check compliance — it genuinely raises the security level of your organisation.

Flexibility

We adapt to your organisation. We adjust our approach to the audit - often without changing the scope of the engagement.

Partnership

We are available to our clients before, during and after the engagement. 19 out of 20 of them come back.

There's always a way

We have delivered 1,000+ projects. We will find a solution to your problems and challenges.

For Customers

Want to work with our team?

Book a free consultation - we'll get back to you within 24 hours.

Book a free consultation →
For candidates

Want to join Patronusec?

We're looking for people who want to help and make a difference.

See open roles →