./whoami

Łukasz Sobiecki

Cybersecurity Consultant/ Incident Response/ Penetration Testing/ Secure Software
Co-founder & Board Member @ DC9 Cyber

I help organizations respond to incidents, identify vulnerabilities, and build secure, resilient IT environments.

CyberLegion Member ENISA incident response support Cyber Europe — Cyber Reserve for Poland Locked Shields 2026 Operation Cyber Flag 2026 qualifier winner Speaker ×2 — 8th Cybersecurity Forum UWPL Captain — 3rd place in OCF26 final
cat about.md

About me

Łukasz Sobiecki is a Polish cybersecurity expert, co-founder and board member of DC9 Cyber. He specializes in incident response, penetration testing, application security, and the secure use of AI. He is a member of CyberLegion, the volunteer formation of the Polish Cyberspace Defense Forces, a participant in Locked Shields 2026, Cyber Europe 2026, and Operation Cyber Flag 2026, a speaker at the 8th Cybersecurity Forum, and the author of formd, an open-source form backend.

Over 20 years of IT experience — a path from developer and administrator to cybersecurity expert and board member.

I work at the intersection of applications, infrastructure, DevOps, and security, partnering with private, public, and regulated organizations. I translate technical problems into business decisions.

With my company, we earned the opportunity to support ENISA on incident response for Poland. I also took part in the Cyber Europe exercise as Cyber Reserve for Poland.

I don't just point out vulnerabilities. I understand the code, the infrastructure, the deployment process, and how organizations actually operate.
  • 20+ years of IT experience
  • ENISA incident response support (Poland)
  • Cyber Europe — Cyber Reserve for Poland
  • proud CyberLegion member
  • developer → admin → security → board
  • applications · infrastructure · DevOps · security
  • private, public, and regulated sectors
  • tech translated into business
./achievements --top

Key achievements

20+
years of experience
Software engineering, infrastructure, DevOps, and cybersecurity.
LS26
Locked Shields 2026
Participation in the largest international cyber defense exercise.
1.
place in OCF26 qualifiers
UWPL team victory in the attack-defense format.
3.
place in OCF26 final
UWPL team captain during the Operation Cyber Flag 2026 final.
whoami --affiliation

CyberLegion

★

Proud member of CyberLegion

I am a proud member of CyberLegion — a volunteer formation operating alongside the Polish Cyberspace Defense Forces, bringing together specialists who support the cyber defense of the Republic of Poland.

It is within CyberLegion that I develop operational skills and take part in international cyber defense exercises. In this role I participated in, among others, Locked Shields and Operation Cyber Flag — testing technical skills, procedures, and the ability to operate under pressure in realistic crisis scenarios.

Locked Shields 2026 Operation Cyber Flag 2026 cyber defense of Poland
operations log

Cyber Europe, Locked Shields & Operation Cyber Flag

[ exercise ] Locked Shields 2026

Large-scale cyber defense scenario

I took part in Locked Shields 2026 as a member of a team facing a realistic large-scale cyberattack scenario. The exercise required simultaneously protecting services, analyzing incidents, coordinating actions, and making decisions under time pressure.

service protection incident analysis coordination
[ exercise ] Operation Cyber Flag 2026

UWPL team captain

Together with the UWPL team, I won the OCF26 qualifying phase. During the final, I had the honor of serving as captain of the team that finished in 3rd place.

  • defending our own services
  • rapid detection and patching of vulnerabilities
  • attacking other teams' systems
  • maintaining operational continuity
  • technical decisions under heavy pressure
[ exercise ] Cyber Europe 2026 · ENISA

Participation in Cyber Europe as Cyber Reserve for Poland

Together with DC9, I took part in Cyber Europe 2026 — one of the key European cybersecurity exercises, organized by ENISA. During the exercise I was involved in handling a cybersecurity incident, technical analysis, coordinating communication, and preparing recommendations for further action.

It's a valuable format because it tests not only technical skills, but also procedures, inter-organizational communication, and the ability to operate under time pressure in a crisis scenario — strengthening cyber resilience across Europe.

incident handling technical analysis communication coordination recommendations
./talks --list

Talks

Łukasz Sobiecki speaking at the 8th Cybersecurity Forum in Warsaw
Łukasz Sobiecki speaking on “Can I trust AI?” at the 8th Cybersecurity Forum, Palace of Culture and Science, Warsaw, 2026.
[ speaker ] VIII Forum Cyberbezpieczeństwa · 2 sessions

Can I trust AI? How to use AI (un)safely and what it gives us

At the 8th Cybersecurity Forum I spoke twice on the same topic: on day one I ran a workshop followed by a Q&A session (45 + 10 min), and on day two I gave a presentation. I covered how to use AI tools safely — and unsafely — where the real risks lie, and what benefits AI brings to everyday work.

A full room both times — thank you all very much!

  • — workshop + Q&A (45 + 10 min)
  • — presentation
  • Palace of Culture and Science, Warsaw · organized by the Polish Ministry of Digital Affairs
full room ×2 AI security speaker
git log --author=sobiecki

Open source projects

[ open source ] Go · SQLite · github.com/dc9-dev/formd ↗

formd — website forms without handing your visitors' data to third parties

Static sites are fast, cheap, and hard to attack — until they need a contact form. Then you usually have to send your visitors' messages to an external service and bolt on a captcha that tracks them. I wrote formd to avoid exactly that: form data goes to your server and nowhere else.

It's a single Go binary installed next to the site. It receives and validates submissions, stores them in SQLite, notifies the owner, and sends the sender a confirmation via SMTP or Amazon SES. Forms and submissions are managed in a simple admin panel.

I built it the way I audit applications — assuming someone will try to break it. Spam is stopped by proof-of-work instead of a captcha: a human won't even notice it, while a bot pays in compute for every submission.

  • zero external services — data never leaves your server
  • proof-of-work anti-spam, rate limits, and silent bot rejection
  • admin panel never exposed to the internet (SSH tunnel only), argon2id passwords
  • resistant to header and CSV injection, strict CSP, hardened systemd unit
  • retrying mail queue — an SMTP outage never loses a message
  • automatic deletion of old submissions to support GDPR
Go SQLite proof-of-work anti-spam security by design GDPR
ls -la /specialization

Areas of specialization

01 Incident Response

  • incident analysis and handling
  • triage and containment
  • log and event analysis
  • forensics support
  • attack vector identification
  • remediation recommendations
  • technical and management reports

02 Penetration Testing

  • web application testing
  • API testing
  • infrastructure testing
  • black-box, grey-box, and white-box
  • authorization and business logic testing
  • adversarial simulation
  • configuration reviews

03 Secure Software & DevSecOps

  • secure coding
  • code review
  • CI/CD security
  • threat modeling
  • dependency security
  • application hardening
  • secure architecture design

04 Infrastructure Security

  • Linux and Windows
  • Docker and container environments
  • cloud and on-premise services
  • reverse proxy, TLS, and security headers
  • segmentation and attack surface reduction
  • monitoring and log analysis

05 Security Advisory

  • risk assessment
  • support for boards and technical teams
  • incident response planning
  • workshops for management
  • compliance and digital resilience recommendations
git log --career

Professional experience

DC9 Cyber
Co-founder & Board Member / Senior Security Consultant
Building cybersecurity services, incident response, penetration testing, application and infrastructure security, workshops, and advisory. Working with regulated clients and the public sector.
CERT.ngo
Senior Security Engineer
Security for civil-society organizations, technical support and response, building security capabilities. Previously a board member role.
University of Warsaw
Technical track
Frontend Developer → Head of IT → System Administrator → Senior Frontend Developer → Lead Developer
DeepCodeNine
Owner
Technology, application, infrastructure, and advisory projects.
cat stack.cfg

Technologies

Security

Burp SuiteOWASP ZAPNessusNucleiNmapOpenSearch

Development

PythonPHPLaravelDjangoJavaScriptNode.js

Infrastructure

LinuxWindowsDockerNginxCaddyApache

Cloud & Platforms

AzureMicrosoft 365Google CloudFirebaseAWS

Databases

PostgreSQLMSSQLMariaDBSQLite

Security Engineering

OWASPthreat modelingsecure codingCI/CD securityhardening
man sobiecki

Frequently asked questions

Who is Łukasz Sobiecki?

Łukasz Sobiecki is a Polish cybersecurity expert with over 20 years of IT experience, and a co-founder and board member of DC9 Cyber. He works on incident response, penetration testing, and application security. He is a member of CyberLegion, the volunteer formation of the Polish Cyberspace Defense Forces.

How can Łukasz Sobiecki help an organization?

With cybersecurity incident response, penetration testing, application and infrastructure security audits, secure software and DevOps design, and adopting AI safely. Contact: [email protected].

What did Łukasz Sobiecki talk about at the 8th Cybersecurity Forum?

At the 8th Cybersecurity Forum (30 September – 1 October 2026, Palace of Culture and Science, Warsaw) he spoke twice on “Can I trust AI? How to use AI (un)safely and what it gives us”: a workshop with Q&A on day one and a presentation on day two, both to a full room.

Which cyber defense exercises has he taken part in?

Locked Shields 2026, Cyber Europe 2026 (as Cyber Reserve for Poland, with DC9 and ENISA), and Operation Cyber Flag 2026, where his UWPL team won the qualifiers and, with him as captain, took 3rd place in the final.

What is formd?

formd is an open-source, self-hosted form backend for static sites written by Łukasz Sobiecki: a single Go binary with SQLite, SMTP or Amazon SES delivery, an admin panel, and proof-of-work anti-spam with no third-party captcha. Code: github.com/dc9-dev/formd.

./contact --init

Let's talk about security

I support organizations with incident response, security testing, application and infrastructure audits, and designing resilient IT environments.