← gociux.com

Insights

Practical writing from the work — vulnerability management, compliance engineering, and incident response in regulated EU environments.

Vulnerability management

Which CVEs actually matter? KEV and EPSS, explained for busy teams

Around 3,000 CVEs are published every month and only a small fraction are ever exploited. How CISA KEV and EPSS turn an impossible patching backlog into a short, defensible priority list.

read →
Compliance engineering

NIS2 just made you a regulated company. Now what?

Who is in scope, the 24-hour and 72-hour incident reporting cascade, the ten baseline security measures, management liability, and where to start.

read →
Identity security

Hardening Entra ID: the ten controls that stop real tenant compromises

Killing legacy authentication, Conditional Access done right, phishing-resistant MFA for admins, break-glass accounts, app consent, and privileged role hygiene.

read →
Compliance engineering

PCI DSS logging requirements without the panic: what Requirement 10 actually asks

What to log, how long to keep it, daily review, time sync, and log integrity — and how to generate the evidence continuously instead of before the audit.

read →
Detection engineering

SIEM for a mid-sized regulated company: build, buy, or managed?

The honest economics of SIEM: why licensing is the smaller cost, where in-house deployments stall, and the questions that cut through vendor noise.

read →
Incident response

A phishing campaign just hit your Microsoft 365 tenant. The first hour.

Scoping with message trace, purging delivered mail, blocking the wave, finding who clicked, and containing compromised accounts.

read →
Pipeline security

Secrets in your repos: how credentials leak through CI/CD and how to stop it

Why API keys end up in git history, the three layers of secrets scanning that work, the first hour after a leak, and how short-lived credentials shrink the problem.

read →