← All projects

Cybersecurity · GRC

Compliance Audit & Regulatory Analysis

NIS2 and EU AI Act readiness assessment and security-tool evaluation for an international logistics IT division.

October 2025 Completed NIS2EU AI ActAuditZscalerFortiGate

During my internship at DPDgroup IT Solutions Poland (DigitsPL) in Warsaw, I contributed to the security team’s compliance and governance initiatives within an international environment.

Context

The organization needed to assess its readiness against two major regulatory frameworks — the NIS2 Directive and the upcoming EU AI Act — while keeping its security tooling aligned with evolving requirements.

What I did

  • Conducted regulatory analysis of NIS2 and the EU AI Act, mapping obligations to the company’s existing controls and identifying gaps.
  • Evaluated and documented security tools in production: Zscaler, FortiGate, SentinelOne, Azure, and Microsoft Intune.
  • Produced clear, actionable findings for both technical and non-technical stakeholders.

What I learned

Working in English, in an international team, taught me how GRC is as much about communication and clarity as it is about technical depth. A finding nobody understands is a finding nobody fixes.

This experience confirmed my interest in pursuing a career oriented towards GRC and audit.