People

The team

Senior practitioners; no offshore second-tier delivery. The people you meet at the start of an engagement are the people who do the work.

Anna Kowalska

Managing Partner & Founder

Anna has 17 years' experience in information security audit and risk management, with a background in ISO 27001 lead-auditor work for major Central European banks. She founded Ellipse Project in 2016 after eight years in two of the larger consultancies. ISO 27001 Lead Auditor, CISA, CRISC.

Focus: ISO 27001, Banking sector, Audit, Risk management

Pavel Novák

Partner, Energy and Critical Infrastructure

Pavel leads our energy and critical-infrastructure practice. Twelve years' experience including in-house roles at a Central European transmission system operator and a major utility group. CISSP, ISA/IEC 62443 Cybersecurity Expert.

Focus: Critical infrastructure, NIS2, IT/OT boundary, Utility sector

Dr Magdalena Wójcik

Head of Advisory, Healthcare

Magdalena leads our healthcare practice. Doctorate in health informatics from a Polish university; nine years' combined experience across clinical IT roles and consulting. Particularly focused on the GDPR Article 9 / NIS2 intersection.

Focus: Healthcare, Clinical IT, GDPR Article 9, Awareness programmes

Tomasz Lewandowski

Senior Consultant, DORA and Financial Services

Tomasz leads DORA engagements for our banking and capital-markets clients. Background includes seven years as a compliance officer at two Polish retail banks and four years in advisory. CISM, FIA Diploma in Investment Compliance.

Focus: DORA, EBA Guidelines, Banking compliance, ICT supplier risk

Kristina Berga

Senior Consultant, Baltic Region

Kristina is our Baltic-region lead, based in Vilnius. Twelve years' experience in information security across the public and private sector, including a period at the Lithuanian national CSIRT. ISO 27001 Lead Implementer.

Focus: Baltic markets, Public sector, CSIRT operations, ISO 27001

Working with us

We grow slowly. Hiring is partner-led; new joiners are paired with a partner for their first six months before being given engagement responsibility. The bar for joining is high, and our retention is correspondingly good.

For roles see our careers page. We are always glad to hear from senior practitioners even when we are not actively recruiting.