Team · Expert profile · 4crypto

Adam Czubak, PhD - cybersecurity expert

Adam Czubak, PhD is an expert in cybersecurity, information security and computer networks. He founded 4crypto Sp. z o.o. and serves as its CEO and CTO; since 2004 he has also been an academic at the University of Opole.

Holding both roles has a practical consequence for clients: the person accountable for commercial commitments is the same person who owns the technical direction. Architectural decisions are not separated from responsibility for the outcome, and a conversation about the scope of an audit or a deployment starts straight away with someone who knows the technical detail. As CTO he oversees the development of 4crypto's own tooling, including a SOAR platform that runs without moving data outside the EEA, and the architecture of the SOC 24/7 service.

He combines three roles that rarely come together in this industry: a practitioner who runs audits and penetration tests, a researcher who led a nationally funded R&D project, and a certified instructor who has been training security engineers in Poland and abroad for well over a decade.

Professional profile

His work spans two areas that always overlap in practice: the technical layer - designing and deploying controls, testing, hardening, protocol analysis - and the process and regulatory layer, meaning building information security management systems and bringing organisations into compliance with specific legislation.

Through 4crypto he delivers IT security audits, penetration tests, vulnerability scanning, system hardening and ISMS implementations to ISO/IEC 27001. Clients include local government, healthcare providers, public institutions and private companies.

The compliance work covers the Polish Cybersecurity Act (KSC), NIS2, the Polish National Interoperability Framework (KRI), GDPR, DORA, eIDAS and the AI Act. These instruments differ in scope - some are Polish national law, others EU-wide - and they bind different categories of entity, so the first step in any compliance engagement is establishing which of them actually apply to the organisation in question.

Certifications

Cybersecurity

  • CISSP - Certified Information Systems Security Professional (ISC2)
  • CEH - Certified Ethical Hacker (EC-Council)
  • CNSS 4011 / 4013 - US national training standards for information assurance
  • US DoD 8570.01-M - US Department of Defense qualification requirements for information assurance positions

Cisco and network security

  • CCNP Security, CCNP Enterprise
  • CCNA CyberOps, CCNA
  • CCSI no. 35146 - Cisco Certified Systems Instructor, authorised to deliver official Cisco training
  • Cisco Certified Specialist: Firepower, VPN Implementation, ISE, Web Content Security

Other vendors

  • Check Point CCSA
  • Juniper JNCIS-ER
  • Microsoft MCSA, MCITP, MTA
  • Linux LPIC-1, Novell CLA and DCTS (SUSE Linux)

The full set of team certification badges is shown in the "Team certifications" section on the home page.

Technical competence and research areas

A multi-vendor track record translates into practical work in heterogeneous environments - places where equipment from several vendors sits side by side and the security boundary has to hold despite differences in configuration and logging models.

  • Network security architecture - firewalls, VPN, IDS/IPS, network access control (NAC/ISE), segmentation
  • Offensive security - threat modelling, penetration testing, vulnerability analysis
  • Hardening of Linux and Windows systems
  • Applied cryptography and protocol security - IPsec, IKE/IKEv2, TLS 1.3, ChaCha20 and multi-key channels
  • Post-quantum cryptography - PQC, ML-KEM, sntrup761 key exchange in SSH
  • Algorithmic vulnerabilities - complexity-based attacks, resilience of stateful systems
  • IoT and IoE device security

Academic and training activity

Adam Czubak has been with the University of Opole since 2004, where he carries out research and teaching in computer science and cybersecurity. He holds a doctorate in computer science and is the author or co-author of more than 30 scientific publications on computer networks and IT security.

Between 2006 and 2017 he taught within the Cisco Networking Academy programme at the University of Opole. Since 2013 he has held Cisco Certified Systems Instructor (CCSI) status, the credential required to deliver official Cisco certification training. His instructional work was recognised with the Cisco CCSI Security Instructor Excellence Award and a distinction for ten years of active instructor service.

Training portfolio

  • CCNP Security and CCNP Routing & Switching
  • CCNA, CCNA Security, CCNA CyberOps
  • Cisco technologies: ISE, VPN, Firepower, ASA
  • Enterprise network and infrastructure security
  • Security awareness - organisational awareness training

Training is delivered in Poland and on foreign markets, including the United Kingdom and the Nordic countries. On certified and bespoke courses he works with training organisations including Altkom Akademia, Insoft Services and Comarch.

Research and R&D projects

CyberEva - an NCBR project

From 2021 to 2024 Adam Czubak was project manager of CyberEva, a nationwide research and development project funded by Poland's National Centre for Research and Development (NCBR) under the CyberSecIdent programme.

The project set out to build a system for assessing and monitoring the security posture of IoT/IoE devices, aimed at the end user - the citizen. It was national in scope and addressed an area where protection has historically been weakest while device counts grow fastest.

  • Role: project manager
  • Scale: 28 people across 9 research teams
  • Areas: IoT security, vulnerability analysis, threat monitoring
  • Technology stack: Kubernetes, Docker, PostgreSQL, NGINX, GitLab, Redis

Research directions

The research concentrates on problems that bear directly on running systems rather than on theoretical models alone:

  • stream ciphers and multi-key channels (ChaCha20),
  • security of the IKE, IKEv2, IPsec and TLS 1.3 protocols,
  • post-quantum cryptography: PQC, ML-KEM, sntrup761 in SSH,
  • algorithmic complexity attacks and their effect on stateful devices,
  • resilience of firewalls and connection-tracking infrastructure,
  • security of IoT and IoE devices.

Implementation and consulting projects

Alongside his academic work, Adam Czubak runs commercial projects as CEO and CTO of 4crypto Sp. z o.o. The scope covers audits and risk analysis, threat modelling and penetration testing, network security architecture, system hardening, ISMS implementation and regulatory compliance.

Since 2013 he has also delivered consulting and training projects outside Poland - in the United Kingdom and the Nordic countries. These covered Cisco Security solutions, enterprise network architecture, VPN, network access control and corporate environment security.

The project approach rests on three principles: connecting research results with engineering practice, treating security as the sum of technology, process and regulation, and transferring knowledge to the client's own team so that the organisation can maintain what has been deployed once the engagement ends.

Outreach

Adam Czubak is a co-organiser of the CACS conference (Conference on Applied CyberSecurity) in Opole and runs initiatives that spread cybersecurity knowledge among students, IT professionals and public institutions.

Research and training activity based in Opole strengthens the region's competence base and makes it possible to bring standards developed on international projects into the local academic and business environment.

Contact

A free consultation lasts 30 to 60 minutes and serves to establish scope, scale and a high-level timeline. It carries no obligation.

4crypto.eu