Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Reporting
Dec 28, 2024 Vid Grosek

Compliance vs Security: Different Goals, Same Budget

A WAF in detection-only mode satisfies an audit checkbox but blocks nothing. Here's how compliance and real security diverge — and how to bridge the gap.

Read More
Reporting
Dec 23, 2024 Vid Grosek

Building the Business Case for Security Investment

Security teams fail to get budget not for lack of merit, but because they can't speak the language of money. I show exactly how to change that.

Read More
Reporting
Dec 18, 2024 Vid Grosek

Incident Response: What Executives Need to Know

Unprepared executives destroy forensic evidence, make uninformed decisions, and miss GDPR deadlines. Here's the incident response playbook for leadership.

Read More
Reporting
Dec 13, 2024 Vid Grosek

Security Metrics That Actually Matter

10,000 patches in a quarter looked impressive — until 95% were on dev machines. Here are the metrics that actually indicate security improvement.

Read More
Reporting
Dec 08, 2024 Vid Grosek

Vulnerability Prioritization: Beyond CVSS Scores

Blindly following CVSS scores leads teams to fix the wrong things first. I share the contextual prioritization matrix I use across real engagements.

Read More
Reporting
Dec 03, 2024 Vid Grosek

Communicating Security Risk to Executives

A 120-page report full of CVSS scores lost the CEO in seconds. Here's how I frame findings as business risk — downtime, revenue loss, reputation.

Read More
Reporting
Nov 28, 2024 Vid Grosek

Writing Effective Penetration Test Reports

A great pentest with a poor report delivers zero value. Learn the exact structure — exec summary, findings, remediation — that drives real change.

Read More
Evasion
Nov 23, 2024 Vid Grosek

Phishing Evasion: Bypassing Email Security

How phishing evades secure email gateways, sandboxing, and DMARC — with practical hardening steps for every layer of your email stack.

Read More
Evasion
Nov 18, 2024 Vid Grosek

Defense Evasion: Hiding from Logs and Monitoring

Log clearing, surgical log modification, and anti-forensics — how attackers erase their tracks and what architecture stops them.

Read More
Evasion
Nov 13, 2024 Vid Grosek

Network Evasion: Hiding in Plain Sight

How attackers blend C2 traffic with DNS queries, HTTPS, and legitimate protocols — and which network anomalies betray them.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch