“The greatest environmental impact of a consulting firm is not its office — it''s the hundreds of organizations it guides toward sustainable practices.”
— Łukasz Grabowski, CEO of FIB.CODE
ISO certifications (9001 + 27001)
remote / hybrid work
data breach incidents
regulatory compliance areas
As an advisory firm with low industrial impact, our direct environmental footprint is limited. However, this does not exempt us from responsibility.
We operate a fully remote and hybrid work model. Documentation, internal audits, and client communications are based on digital tools.
We commit to calculating and monitoring the company''s carbon footprint in Scopes 1, 2, and relevant Scope 3 categories per the GHG Protocol.
We choose cloud service providers that declare climate neutrality. We monitor the energy efficiency of our IT solutions.
IT equipment is used until end-of-life, then transferred to certified recycling facilities.
As a firm conducting energy audits, we actively help clients identify energy savings.
Client travel is monitored and offset through support for certified CO₂ reduction projects.
Digital security is, above all, about protecting people. Our social responsibility extends beyond our team.
Every team member has an individual competency development plan. Minimum 40 training hours per person annually.
We hold ISO/IEC 27001:2022 certification, with an implemented ISMS, incident response procedures and a zero-breach policy.
We deliver cybersecurity training for local government units as part of the ''Cybersecure Municipality'' program.
Hybrid work model, flexible hours, mental health support. A culture built on trust and autonomy.
We conduct technical and business training. We publish educational materials on cybersecurity.
We apply objective competency-based recruitment criteria. We ensure equal pay for equal work.
As an audit firm, we must be a model of corporate governance. Our management systems are the foundation of trust.
ISO 9001:2015 and ISO/IEC 27001:2022 certified by DNV. Surveillance audits every 12 months.
An implemented Code of Ethics governing conduct, conflicts of interest, anti-corruption policy and whistleblowing.
Zero tolerance for corruption. Due diligence procedures for partners and subcontractors.
Active monitoring and implementation of requirements: GDPR, NIS-2, DORA, Cybersecurity Act, AML.
We are preparing for ESRS/CSRD-compliant reporting from the moment we fall within regulatory scope.
An implemented Business Continuity Plan (BCP) compliant with ISO 22301. Regular contingency plan testing.
We transparently report on the degree of implementation of our ESG commitments.
Full GHG emissions inventory in Scopes 1, 2, and relevant Scope 3 categories.
Formal adoption of an emission reduction target covering travel, IT, and office energy.
Implementation of ESG criteria in the supplier and subcontractor selection process.
Publication of the first ESG report with a double materiality analysis.
Implementation of an environmental management system as a complement to the integrated system.
Achieving neutrality in Scopes 1 and 2 through reduction, green energy, and offsetting.
Becoming the reference company combining cybersecurity, compliance, and sustainable development.
We identify and support those UN Sustainable Development Goals that are most relevant to our operations.
Quality Education
Affordable Clean Energy
Decent Work & Growth
Industry & Innovation
Responsible Consumption
Climate Action
Peace & Justice
Partnerships
European sustainability reporting standard
International standard for greenhouse gas emissions calculation
Framework for reporting impact on economy, environment, and society
17 United Nations Sustainable Development Goals
Certified information security and quality management systems
Energy management systems and energy audit
EU directives on cybersecurity and digital operational resilience
Classification of environmentally sustainable activities
Please direct any questions regarding our ESG policy to:
This ESG Policy was adopted by the Board of FIB.CODE Sp. z o.o. The policy is subject to annual review and update.
FIB.CODE Sp. z o.o. · NIP: 637-220-84-21 · KRS: 0000804872
Last updated: February 2026 · Version 1.0