Working with Slovenian IT Teams: A Pentester Perspective
From bilingual NIS2 reports for URSIV to in-person Ljubljana debriefs — what I've learned about effective collaboration with Slovenian IT teams during pentests.
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
How pentesting fulfils GDPR Articles 32, 25, 33, and 35 — and why Slovenian organizations under ZVOP-2 should treat it as a compliance tool, not just a technical exercise.
Read MoreReal patterns from pentesting Slovenian organizations: Active Directory misconfigurations, Kerberoastable accounts, NTLM relay, and recurring web application flaws.
Read MoreFrom SOC analyst roles to CTF achievements and HackerOne findings — practical steps to launch a cybersecurity career in Slovenia's growing market.
Read MoreFrom OSCP and OSCE3 credentials to sample reports and pricing red flags — a practical guide to picking a trustworthy pentest provider in Slovenia.
Read MorePractical breakdown of NIS2 scope, risk management obligations, and supply-chain requirements for Slovenian essential and important entities.
Read MoreFrom NIS2-driven demand to a growing talent gap, here's how Slovenia's cybersecurity market is evolving — and where it's heading.
Read MoreA WAF in detection-only mode satisfies an audit checkbox but blocks nothing. Here's how compliance and real security diverge — and how to bridge the gap.
Read MoreSecurity teams fail to get budget not for lack of merit, but because they can't speak the language of money. I show exactly how to change that.
Read MoreUnprepared executives destroy forensic evidence, make uninformed decisions, and miss GDPR deadlines. Here's the incident response playbook for leadership.
Read MoreRead my expertise pages, research, or prepare for a pentest.