Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

AD Attacks
Jul 16, 2024 Vid Grosek

Why I Get Domain Admin in Every Penetration Test

EDR and firewalls don't fix misconfigurations. I walk through my standard 4-hour path from network plug-in to Domain Admin — and what blocks it.

Read More
AD Attacks
Jul 11, 2024 Vid Grosek

The Active Directory Security Mistakes I See in Every Slovenian Company

After 50+ penetration tests in Slovenia, these recurring AD misconfigurations hand me Domain Admin access — almost every single time.

Read More
Authority
Jul 06, 2024 Vid Grosek

Building a Security Culture That Actually Works

Technical controls fail when employees hide phishing clicks out of fear. Here is how to build security awareness that people actually follow.

Read More
Authority
Jul 01, 2024 Vid Grosek

Why Hackers Choose Their Targets (It Might Be You)

"We are not a target" is the most dangerous assumption in cybersecurity. I explain how opportunistic and targeted attackers actually select their victims.

Read More
Authority
Jun 26, 2024 Vid Grosek

Assessing Your Security Maturity: Where Do You Stand?

Investing in red teams before deploying endpoint detection wastes budget. This practical maturity model tells you what each level needs and what to tackle next.

Read More
Authority
Jun 21, 2024 Vid Grosek

Vulnerability vs Risk: What Decision Makers Need to Know

Thousands of scanner findings do not equal thousands of risks. Learn the Risk = Likelihood x Impact framework that turns CVE lists into actionable priorities.

Read More
Authority
Jun 16, 2024 Vid Grosek

How to Buy Security Testing: A Guide for Decision Makers

Not all pentests deliver equal value. I show decision-makers exactly how to vet vendors, read sample reports, and avoid paying for glorified automated scans.

Read More
Authority
Jun 11, 2024 Vid Grosek

How Attackers Think: The Mindset Behind Breaches

APT groups spend weeks in quiet reconnaissance before striking. Understanding attacker patience and creativity is the first step toward stronger defense.

Read More
Authority
Jun 06, 2024 Vid Grosek

Red Team vs Penetration Test: Which Do You Need?

A penetration test maximizes vulnerability coverage; a red team simulates a real adversary. Here is how to choose the right one for your organization.

Read More
Authority
Jun 01, 2024 Vid Grosek

What Penetration Testers Actually Do (And Why It Matters)

From scoping and OSINT to Active Directory exploitation and remediation — a methodical look at what a real pentest actually involves.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch