How I Test

Vid Grosek, lead penetration tester at Telprom d.o.o. in Ljubljana, follows an attacker-minded methodology focused on real attack paths rather than checklists. As Slovenia's first OSCE3- and OSCP+-certified penetration tester with 18+ years of experience, he runs engagements across Slovenia and the EU.

Every penetration test is unique. But I follow certain principles that ensure consistent, high-quality results.

Think Like an Attacker, Not an Auditor

Checkbox pentests find checkbox vulnerabilities. Real attackers don't follow checklists. They start with one entry point and follow chains of opportunity until they reach their goal.

Depth Over Breadth

I'd rather find one critical path to compromise than ten medium-severity findings that go nowhere. These attack paths keep my focus on what actually matters to your business risk.

Documentation as I Go

Every step is documented in real-time. This means you can reproduce my findings, and the report contains actual attack paths, not just lists of tools.

Communication During Engagement

If I find a critical vulnerability, I don't wait until the end. I notify you immediately so you can take action.

Reports That Serve a Purpose

Technical reports for your IT team. Executive summaries for management. Each audience gets the information they need to act.

Frequently Asked Questions

How do you approach a penetration test?

I think like an attacker, not an auditor. I start with one entry point and follow chains of opportunity until I reach the goal, focusing on real attack paths rather than checklists.

Do you follow a checklist?

No. Checkbox pentests find checkbox vulnerabilities. Real attackers don't follow checklists, so I prioritize depth over breadth and one critical path to compromise.

When do you report critical vulnerabilities?

If I find a critical vulnerability, I don't wait until the end of the engagement. I notify you immediately so you can take action right away.

What kind of report can I expect?

You get a technical report for your IT team and an executive summary for management. Each audience receives the information it needs to act, including the actual attack path, not just a list of tools.

Next step: learn more about Vid Grosek or talk to me about your penetration test.