Black-and-white portrait photograph of a business professional in a suit

Decision architecture for cybersecurity investments

Decision architecture for cybersecurity investments

Structured verification of the commercial case behind cybersecurity decisions, for owners, boards and investors navigating incentivized risk narratives.

Structured verification of the commercial case behind cybersecurity decisions, for owners, boards and investors navigating incentivized risk narratives.

Our experience:

/

SERVICES

Three perspectives under one roof

Advisory for security organisations. Diligence for the capital behind them. Building where the two meet.

Tech Funds & Enterprise

Decision support for boards: decoding incentivised risk narratives, refining security strategy, monitoring critical investments

Tech Funds & Enterprise

Decision support for boards: decoding incentivised risk narratives, refining security strategy, monitoring critical investments

Founders &
Capital Owners

Fractional leadership, strategic and operational advisory for founders and their capital partners building security ventures

Founders &
Capital Owners

Fractional leadership, strategic and operational advisory for founders and their capital partners building security ventures

B2B Security Companies

Commercial strategy, sales operations, and revenue leadership for security firms competing on value rather than price

B2B Security Companies

Commercial strategy, sales operations, and revenue leadership for security firms competing on value rather than price

/

WHY US

Our position in value chain

Metastrategy is a boutique consultancy providing strategic decision support in the security market — to companies selling security, to organisations buying it, and to capital investing in it.

Our offering is structured to minimise subjective incentives and to provide skin in the game on key engagements. It is designed to support you in cases where competence and a promise alone are not enough to build trust.

Our experience to utilise it

We have hands-on experience in building VC-backed security product and service companies, as well as growing revenue inside large multinational security organisations.

We have designed cybersecurity strategies and risk management systems for leading EMEA banks, investment funds, insurers, telecoms, and multinational production companies. Our frameworks are used by global tech consulting companies.

Credentials

  • Portrait of Grzegorz Żurawski, Business Development Manager at IMET

    Grzegorz Żurawski

    Business Development Manager
    IMET

    What I value most in working with Karol is where he starts: with understanding the company's operating model, its constraints, its goals and how it makes decisions. Only on that basis does he assess which directions are justified and where resources are worth committing. The conversation is therefore not about fashionable tools but about their practical usefulness, their impact on the organisation and the quality of the management board's decisions. At IMET, the starting point was investment in new technologies and applications of machine learning in a mid-sized e-commerce company. It resulted in two decisions: how to commercialise our internal pricing data, and a new purchasing policy built on reconfiguring the product range.

  • Portrait of Lars Northeved, Chief Technology Officer at GEA

    Lars Northeved

    Chief Technology Officer
    GEA

    I worked with Karol during the digital transformation program in GEA, in the ISMS track for "Product Security". Karol was instrumental in the Product Security Strategy development, the security organization as well as the policies and procedures. During the many workshops and meetings Karol managed to explain the different options we had to choose from and what consequence the choice would have. Karol possesses an outstanding overview of the standards, and thanks to a high abstraction level, how standards can benefit companies.

  • Portrait of Damian Banat, Cybersecurity Architect at Cyrima

    Damian Banat

    Cybersecurity Architect
    Cyrima

    I worked with Karol on cybersecurity and regulatory compliance projects (including NIS2, DORA and ISO 2700x) at a provider of SaaS applications and B2B cybersecurity and risk services. Karol designed the strategy and coordinated its implementation, including the work of client-side experts, mine among them. He ran the implementation on a hypothesis-driven basis: we tested assumptions as the work progressed and adjusted course as new variables came to light. He reconciled competing stakeholder priorities, untangled dependencies and drove concrete decisions within project constraints. I recommend him as a trusted partner for overseeing and coordinating complex cybersecurity investments.

  • Portrait of Grzegorz Żurawski, Business Development Manager at IMET

    Grzegorz Żurawski

    Business Development Manager
    IMET

    What I value most in working with Karol is where he starts: with understanding the company's operating model, its constraints, its goals and how it makes decisions. Only on that basis does he assess which directions are justified and where resources are worth committing. The conversation is therefore not about fashionable tools but about their practical usefulness, their impact on the organisation and the quality of the management board's decisions. At IMET, the starting point was investment in new technologies and applications of machine learning in a mid-sized e-commerce company. It resulted in two decisions: how to commercialise our internal pricing data, and a new purchasing policy built on reconfiguring the product range.

  • Portrait of Lars Northeved, Chief Technology Officer at GEA

    Lars Northeved

    Chief Technology Officer
    GEA

    I worked with Karol during the digital transformation program in GEA, in the ISMS track for "Product Security". Karol was instrumental in the Product Security Strategy development, the security organization as well as the policies and procedures. During the many workshops and meetings Karol managed to explain the different options we had to choose from and what consequence the choice would have. Karol possesses an outstanding overview of the standards, and thanks to a high abstraction level, how standards can benefit companies.

  • Portrait of Damian Banat, Cybersecurity Architect at Cyrima

    Damian Banat

    Cybersecurity Architect
    Cyrima

    I worked with Karol on cybersecurity and regulatory compliance projects (including NIS2, DORA and ISO 2700x) at a provider of SaaS applications and B2B cybersecurity and risk services. Karol designed the strategy and coordinated its implementation, including the work of client-side experts, mine among them. He ran the implementation on a hypothesis-driven basis: we tested assumptions as the work progressed and adjusted course as new variables came to light. He reconciled competing stakeholder priorities, untangled dependencies and drove concrete decisions within project constraints. I recommend him as a trusted partner for overseeing and coordinating complex cybersecurity investments.

  • Portrait of Grzegorz Żurawski, Business Development Manager at IMET

    Grzegorz Żurawski

    Business Development Manager
    IMET

    What I value most in working with Karol is where he starts: with understanding the company's operating model, its constraints, its goals and how it makes decisions. Only on that basis does he assess which directions are justified and where resources are worth committing. The conversation is therefore not about fashionable tools but about their practical usefulness, their impact on the organisation and the quality of the management board's decisions. At IMET, the starting point was investment in new technologies and applications of machine learning in a mid-sized e-commerce company. It resulted in two decisions: how to commercialise our internal pricing data, and a new purchasing policy built on reconfiguring the product range.

  • Portrait of Lars Northeved, Chief Technology Officer at GEA

    Lars Northeved

    Chief Technology Officer
    GEA

    I worked with Karol during the digital transformation program in GEA, in the ISMS track for "Product Security". Karol was instrumental in the Product Security Strategy development, the security organization as well as the policies and procedures. During the many workshops and meetings Karol managed to explain the different options we had to choose from and what consequence the choice would have. Karol possesses an outstanding overview of the standards, and thanks to a high abstraction level, how standards can benefit companies.

  • Portrait of Damian Banat, Cybersecurity Architect at Cyrima

    Damian Banat

    Cybersecurity Architect
    Cyrima

    I worked with Karol on cybersecurity and regulatory compliance projects (including NIS2, DORA and ISO 2700x) at a provider of SaaS applications and B2B cybersecurity and risk services. Karol designed the strategy and coordinated its implementation, including the work of client-side experts, mine among them. He ran the implementation on a hypothesis-driven basis: we tested assumptions as the work progressed and adjusted course as new variables came to light. He reconciled competing stakeholder priorities, untangled dependencies and drove concrete decisions within project constraints. I recommend him as a trusted partner for overseeing and coordinating complex cybersecurity investments.

/

ARTICLES

Latest thinking

Latest thinking

DECISION ARCHITECTURE

DORA and NIS2 now put personal liability for cyber risk oversight on management bodies. This piece sets out why compliance is not a substitute for a real decision framework, and what such a framework has to contain.

Article cover image

DECISION ARCHITECTURE

Cyber risk decisions rest on information shaped by every actor who passes it along. This piece maps the incentive architecture that produces that distortion, and what it takes to see through it.

Article cover image

DECISION ARCHITECTURE

DORA and NIS2 now put personal liability for cyber risk oversight on management bodies. This piece sets out why compliance is not a substitute for a real decision framework, and what such a framework has to contain.

Article cover image

DECISION ARCHITECTURE

Cyber risk decisions rest on information shaped by every actor who passes it along. This piece maps the incentive architecture that produces that distortion, and what it takes to see through it.

Article cover image

/

NEWSLETTER

Get email notifications about new publications, 

case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.

/

NEWSLETTER

Get email notifications about new publications, case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.

/

NEWSLETTER

Get email notifications about new publications, 

case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.