Professional profile
His work spans two areas that always overlap in practice: the technical layer - designing and deploying controls, testing, hardening, protocol analysis - and the process and regulatory layer, meaning building information security management systems and bringing organisations into compliance with specific legislation.
Through 4crypto he delivers IT security audits, penetration tests, vulnerability scanning, system hardening and ISMS implementations to ISO/IEC 27001. Clients include local government, healthcare providers, public institutions and private companies.
The compliance work covers the Polish Cybersecurity Act (KSC), NIS2, the Polish National Interoperability Framework (KRI), GDPR, DORA, eIDAS and the AI Act. These instruments differ in scope - some are Polish national law, others EU-wide - and they bind different categories of entity, so the first step in any compliance engagement is establishing which of them actually apply to the organisation in question.
Certifications
Cybersecurity
- CISSP - Certified Information Systems Security Professional (ISC2)
- CEH - Certified Ethical Hacker (EC-Council)
- CNSS 4011 / 4013 - US national training standards for information assurance
- US DoD 8570.01-M - US Department of Defense qualification requirements for information assurance positions
Cisco and network security
- CCNP Security, CCNP Enterprise
- CCNA CyberOps, CCNA
- CCSI no. 35146 - Cisco Certified Systems Instructor, authorised to deliver official Cisco training
- Cisco Certified Specialist: Firepower, VPN Implementation, ISE, Web Content Security
Other vendors
- Check Point CCSA
- Juniper JNCIS-ER
- Microsoft MCSA, MCITP, MTA
- Linux LPIC-1, Novell CLA and DCTS (SUSE Linux)
The full set of team certification badges is shown in the "Team certifications" section on the home page.
Technical competence and research areas
A multi-vendor track record translates into practical work in heterogeneous environments - places where equipment from several vendors sits side by side and the security boundary has to hold despite differences in configuration and logging models.
- Network security architecture - firewalls, VPN, IDS/IPS, network access control (NAC/ISE), segmentation
- Offensive security - threat modelling, penetration testing, vulnerability analysis
- Hardening of Linux and Windows systems
- Applied cryptography and protocol security - IPsec, IKE/IKEv2, TLS 1.3, ChaCha20 and multi-key channels
- Post-quantum cryptography - PQC, ML-KEM, sntrup761 key exchange in SSH
- Algorithmic vulnerabilities - complexity-based attacks, resilience of stateful systems
- IoT and IoE device security
Academic and training activity
Adam Czubak has been with the University of Opole since 2004, where he carries out research and teaching in computer science and cybersecurity. He holds a doctorate in computer science and is the author or co-author of more than 30 scientific publications on computer networks and IT security.
Between 2006 and 2017 he taught within the Cisco Networking Academy programme at the University of Opole. Since 2013 he has held Cisco Certified Systems Instructor (CCSI) status, the credential required to deliver official Cisco certification training. His instructional work was recognised with the Cisco CCSI Security Instructor Excellence Award and a distinction for ten years of active instructor service.
Training portfolio
- CCNP Security and CCNP Routing & Switching
- CCNA, CCNA Security, CCNA CyberOps
- Cisco technologies: ISE, VPN, Firepower, ASA
- Enterprise network and infrastructure security
- Security awareness - organisational awareness training
Training is delivered in Poland and on foreign markets, including the United Kingdom and the Nordic countries. On certified and bespoke courses he works with training organisations including Altkom Akademia, Insoft Services and Comarch.
Research and R&D projects
CyberEva - an NCBR project
From 2021 to 2024 Adam Czubak was project manager of CyberEva, a nationwide research and development project funded by Poland's National Centre for Research and Development (NCBR) under the CyberSecIdent programme.
The project set out to build a system for assessing and monitoring the security posture of IoT/IoE devices, aimed at the end user - the citizen. It was national in scope and addressed an area where protection has historically been weakest while device counts grow fastest.
- Role: project manager
- Scale: 28 people across 9 research teams
- Areas: IoT security, vulnerability analysis, threat monitoring
- Technology stack: Kubernetes, Docker, PostgreSQL, NGINX, GitLab, Redis
Research directions
The research concentrates on problems that bear directly on running systems rather than on theoretical models alone:
- stream ciphers and multi-key channels (ChaCha20),
- security of the IKE, IKEv2, IPsec and TLS 1.3 protocols,
- post-quantum cryptography: PQC, ML-KEM, sntrup761 in SSH,
- algorithmic complexity attacks and their effect on stateful devices,
- resilience of firewalls and connection-tracking infrastructure,
- security of IoT and IoE devices.
Implementation and consulting projects
Alongside his academic work, Adam Czubak runs commercial projects as CEO and CTO of 4crypto Sp. z o.o. The scope covers audits and risk analysis, threat modelling and penetration testing, network security architecture, system hardening, ISMS implementation and regulatory compliance.
Since 2013 he has also delivered consulting and training projects outside Poland - in the United Kingdom and the Nordic countries. These covered Cisco Security solutions, enterprise network architecture, VPN, network access control and corporate environment security.
The project approach rests on three principles: connecting research results with engineering practice, treating security as the sum of technology, process and regulation, and transferring knowledge to the client's own team so that the organisation can maintain what has been deployed once the engagement ends.
Outreach
Adam Czubak is a co-organiser of the CACS conference (Conference on Applied CyberSecurity) in Opole and runs initiatives that spread cybersecurity knowledge among students, IT professionals and public institutions.
Research and training activity based in Opole strengthens the region's competence base and makes it possible to bring standards developed on international projects into the local academic and business environment.
Contact
A free consultation lasts 30 to 60 minutes and serves to establish scope, scale and a high-level timeline. It carries no obligation.
- E-mail: office@4crypto.eu
- Phone: +48 691-122-312
- LinkedIn: linkedin.com/in/adamczubak
- PGP key: keys.openpgp.org
Related content
Services delivered personally
- IT security audit
- Penetration testing
- Vulnerability scanning
- Device and system hardening
- ISMS to ISO/IEC 27001
- Security awareness
Compliance and regulation
- KSC - the Polish Cybersecurity Act
- NIS2 - Directive (EU) 2022/2555
- KRI - the Polish National Interoperability Framework
- GDPR - Regulation (EU) 2016/679
- ISO/IEC 27001