Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
Compliance vs Security: Different Goals, Same Budget
A WAF in detection-only mode satisfies an audit checkbox but blocks nothing. Here's how compliance and real security diverge — and how to bridge the gap.
Read MoreBuilding the Business Case for Security Investment
Security teams fail to get budget not for lack of merit, but because they can't speak the language of money. I show exactly how to change that.
Read MoreIncident Response: What Executives Need to Know
Unprepared executives destroy forensic evidence, make uninformed decisions, and miss GDPR deadlines. Here's the incident response playbook for leadership.
Read MoreSecurity Metrics That Actually Matter
10,000 patches in a quarter looked impressive — until 95% were on dev machines. Here are the metrics that actually indicate security improvement.
Read MoreVulnerability Prioritization: Beyond CVSS Scores
Blindly following CVSS scores leads teams to fix the wrong things first. I share the contextual prioritization matrix I use across real engagements.
Read MoreCommunicating Security Risk to Executives
A 120-page report full of CVSS scores lost the CEO in seconds. Here's how I frame findings as business risk — downtime, revenue loss, reputation.
Read MoreWriting Effective Penetration Test Reports
A great pentest with a poor report delivers zero value. Learn the exact structure — exec summary, findings, remediation — that drives real change.
Read MorePhishing Evasion: Bypassing Email Security
How phishing evades secure email gateways, sandboxing, and DMARC — with practical hardening steps for every layer of your email stack.
Read MoreDefense Evasion: Hiding from Logs and Monitoring
Log clearing, surgical log modification, and anti-forensics — how attackers erase their tracks and what architecture stops them.
Read MoreNetwork Evasion: Hiding in Plain Sight
How attackers blend C2 traffic with DNS queries, HTTPS, and legitimate protocols — and which network anomalies betray them.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.