Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
Entra ID account recovery: review the paths around MFA
A lost phone, an unavailable passkey, or an administrator locked out by a Conditional Access change is not just a helpdesk problem. It is an identity security event. The question is not whether an organization has MFA. The question is whether it can restore the right person’s access without…
Read MoreDORA threat-led penetration testing: how to assess a TLPT provider
Before procuring threat-led penetration testing (TLPT), establish whether your financial entity must perform it under DORA. A need to assess detection and response may justify a voluntary adversary simulation, but that need alone does not create a regulatory TLPT obligation. For entities identified…
Read MoredMSA migration: when to proceed, stop, and recover
Do not sign off a dMSA migration because the application still works during the start phase. Completion disables the old account. Accept the change only after fresh authentication proves the completed configuration works. Microsoft overview A delegated Managed Service Account (dMSA) replaces a…
Read MorePenetration Test Retest: Turn Findings into Verified Remediation
A penetration test report becomes useful when an owner can turn each relevant finding into a change and demonstrate its effect. Closing a ticket does not establish that the tested system changed. A fix may exist in a development branch, cover one access path or depend on a configuration that has…
Read MoreIncident Response Logging: Evidence You Need Before an Incident
During an incident, the first difficult question is often not which tool to use. It is whether the organisation has retained the records needed to explain what happened. A sign-in alert may identify an account and a time, while leaving the subsequent resource access, configuration changes and data…
Read MoreCloud IAM Security Review: Workload Identities and Least Privilege
A cloud permission review is incomplete if it stops at the roles assigned to employees. Applications, build systems, scheduled jobs and support integrations also act through identities. A workload with broad access may become a route to production data when another principal can assume its identity…
Read MoreNIS2 in Slovenia: Evidence for ZInfV-1 Implementation
A security policy describes an intended way of working. Implementation evidence shows what the organisation actually does, where it does it and how it responds when a measure fails. For a Slovenian organisation working on ZInfV-1, the useful next step is often connecting existing documentation to…
Read MoreActive Directory Ransomware Recovery: Test the Forest Recovery Plan
A successful backup job confirms that a copying process completed. It does not show that administrators can recover identity services when their usual accounts, management tools and production network are unavailable. An Active Directory ransomware recovery exercise should establish whether the…
Read MoreExternal Attack-Surface Review: Finding Exposure Before It Becomes an Incident
Map internet-facing assets to their owners, verify exposure and prioritize corrective actions with a practical asset-to-action register.
Read MoreCI/CD and GitHub Actions: Secrets and Supply-Chain Controls
Review GitHub Actions trust boundaries, workflow permissions, deployment identities and runners before a source-code change reaches production.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.