Notes & Articles

Blog

Notes on how I build and how I break - architecture, research, and the craft of security.

2026-03-22
My Security Stack: The Tools I Trust in Production

After testing hundreds of tools, here is the complete security stack I use every day - with pros, cons, and alternatives.

toolsarchitectureconsulting
2026-03-20
What Running a Homelab Taught Me About Enterprise Security

A Dell R630, Proxmox, 16 services in production. My homelab is the laboratory where I test every idea before bringing it to clients.

architecturecareer
2026-03-16
DevSecOps in Practice: CI/CD Security That Actually Works

Security in CI/CD pipelines should not slow down development. Here is how to integrate security without friction.

devsecopsarchitecture
2026-03-14
Zero Trust Architecture: Beyond the Marketing Buzzword

Zero Trust is everywhere in cybersecurity marketing. But actually implementing it is another story. Here is a practical approach.

architectureconsultingsme
2026-03-12
The Case for Deception in Depth

Defense in depth is a known concept. Deception in depth - layering deception across every level of infrastructure - is the next step.

deceptionarchitecture
2026-03-10
Why Every Company Will Need a Deception Layer by 2027

Deception technology is moving from niche to necessity. Here is why it is the future of low-cost detection.

deceptionarchitecture
2026-03-08
Cyber Threat Intelligence for SMEs: You Don't Need a SOC

CTI is not just for large enterprises. How to democratize threat intelligence for SMEs with limited resources.

ctiarchitecture
2026-03-05
AI in Cybersecurity: Hype vs Reality in 2026

Everyone talks about AI in security. But what actually works and what is just marketing? My perspective after using it in production.

ai-securityarchitecture
2026-03-02
The Italian Cybersecurity Gap: Why SMEs Are the Most Vulnerable

Italy has a specific cybersecurity problem. SMEs are the backbone of the economy but the most exposed. Here are the data and solutions.

smeconsulting
2026-03-01
AI/LLM Penetration Testing: A New Attack Surface

AI systems are not just tools - they are attack surfaces. How to test the security of an LLM.

ai-securitypentesting
2026-02-25
DNS Security: The Most Overlooked Layer in Your Defense

91% of malware uses DNS. Yet most companies do not monitor their DNS traffic. Here is why you should.

architecturetoolssme
2026-02-20
Security by Design: Lessons from Building 6 Platforms

Presidio, Valta, Mirage, Cipher, PhishSim, Tempest - every platform taught me something different about security engineering.

architecturedevsecops
2026-02-18
Building vs Buying Security Infrastructure: The Real Trade-offs

I have built 6 security platforms from scratch. But it is not always the right choice. Here is how to decide.

architectureconsultingtools
2026-02-12
Threat Intelligence Feeds: Which Ones Actually Matter

With hundreds of CTI feeds available, most are noise. Here are the ones I use in production and why.

threat-intelligencetoolsarchitecture
2026-02-08
Cybersecurity for Boards: What Directors Need to Know

Cybersecurity is no longer just an IT problem. Here is how to communicate cyber risk to the board of directors.

consultingsmecompliance
2026-02-05
From Pentester to Platform Builder

My journey from testing systems to building them - and why offensive experience makes every defensive architecture better.

careerpentesting
2026-01-28
Open Source Security Tools: Enterprise-Grade on a Startup Budget

You do not need six-figure budgets for enterprise security. Here is the open source stack I run in production.

toolssmearchitecture
2026-01-22
Building a SOAR Platform: Lessons from 5 Production Playbooks

Security response automation looks simple on paper. Reality is full of edge cases. Here is what I learned.

xdrarchitecturetools
2026-01-15
Phishing Simulation: What 80 Templates Taught Me

From analyzing 80 phishing templates I learned more about human psychology than about technology.

pentestingarchitecture
2026-01-08
Wazuh vs Splunk vs Elastic Security: An Honest Comparison

I have used all three in production. Here is a comparison based on real experience, not vendor spec sheets.

xdrtoolsconsulting
2025-12-20
How to Evaluate Your Company's Cyber Risk in 30 Minutes

You do not need a 50k assessment to understand where you are vulnerable. Here is a quick method for an initial risk evaluation.

consultingsmecompliance
2025-12-08
SOAR Playbooks: Automating Incident Response

Five playbooks, thousands of executions. What actually works in incident response automation with Shuffle SOAR.

xdrarchitecture
2025-11-25
Security Awareness Training That Actually Works

Most security awareness training is a waste of time. Here is how to build a program that actually changes behavior.

phishingconsultingsme
2025-11-12
Building a SOC Portal with Grafana

How I transformed Grafana from a monitoring tool into a complete SOC portal with 95% coverage.

xdrarchitecture
2025-11-05
MITRE ATT&CK in Practice: Mapping Real Incidents

MITRE ATT&CK is more than a poster on the SOC wall. Here is how I use it to improve detection and response on real incidents.

xdrarchitecturetools
2025-10-18
Zero Trust on a Budget: M365 + Conditional Access

You do not need millions to implement Zero Trust. With M365 Business Premium and Conditional Access you can start tomorrow.

architecturecompliance
2025-10-02
The Real Cost of a Data Breach for Italian SMEs

The average cost of a data breach in Italy is 3.7M euros. But for SMEs the numbers tell a different - and more personal - story.

smeconsultingincident-response
2025-09-22
NIS2 Is Coming: What Italian SMEs Need to Know

The NIS2 directive changes the rules for cybersecurity in Europe. What it concretely means for Italian SMEs.

compliancearchitecture
2025-09-15
Supply Chain Attacks: How I Found Vulnerabilities in npm and Go Packages

Supply chain is the attack vector of the decade. Here is what I discovered analyzing popular open source packages.

devsecopspentestingtools
2025-09-08
GDPR and Cybersecurity: What Your DPO Is Not Telling You

GDPR requires "appropriate technical measures" but does not say which ones. Here is what it really means from a technical standpoint.

complianceconsultingsme
2025-08-28
Incident Response Plan: The Template Most Companies Get Wrong

Having an incident response plan is not enough. The problem is most plans do not work when they are actually needed.

incident-responseconsultingcompliance
2025-08-14
ISO 27001 for Startups: A Practical Guide

Compliance does not have to be bureaucracy. How to implement ISO 27001 pragmatically without stifling innovation.

compliancearchitecture
2025-08-02
Cloud Security Posture Management: AWS Edition

Cloud security is not just the provider's responsibility. Here is how to manage your security posture on AWS.

cloud-securitytoolsconsulting
2025-07-25
Red Team vs Blue Team vs Purple Team: Which Does Your Organization Need

The difference between red, blue, and purple team is not just about colors. Here is when and why to choose each approach.

pentestingconsultingsme
2025-07-18
The Death of Traditional Antivirus: What Comes Next

Signature-based antivirus is no longer enough. Here is why EDR and XDR are the new standard and how to make the transition.

xdrsmetools
2025-07-10
The Credential Leak Pattern Nobody Talks About

When an HTTP library follows a redirect, what happens to authentication headers? The answer will surprise you.

vulnerability-researchpentesting
2025-06-30
Active Directory Hardening: 15 Quick Wins

Active Directory is attackers' number one target. Here are 15 quick interventions that drastically reduce the attack surface.

pentestingtoolssme
2025-06-20
How Much Does a Penetration Test Cost? A Realistic Breakdown

Pentest prices vary enormously. Here is how to understand what you are paying for and why the lowest price is never the best choice.

pentestingconsultingsme
2025-06-05
30+ Vulnerability Disclosures: What I Learned

From Anthropic to AWS SageMaker, from Echo to aiohttp - my vulnerability research campaign on high-impact open source projects.

vulnerability-researchpentesting
2025-05-22
NIS2 Compliance Checklist: A Step-by-Step Guide for Italian Companies

The NIS2 directive is in effect and many Italian companies are not ready. Here is a practical checklist to get started.

complianceconsultingsme
2025-05-08
Responsible Disclosure: My Experience Reporting to Anthropic

How I found and reported a vulnerability in Claude Code - and what the responsible disclosure process taught me.

vulnerability-researchai-security
2025-05-05
API Security Testing: The Methodology I Use on Every Engagement

APIs are the fastest growing attack surface. Here is my systematic approach to API security testing.

pentestingtools
2025-04-25
Vulnerability Assessment vs Penetration Test: What Your Company Actually Needs

Two different services, often confused. Here is how to know which one you need - and when you need both.

pentestingconsultingsme
2025-04-12
Deception Networks: Why Honeypots Are Your Best Early Warning

60,000+ events captured, 92 attackers profiled. What I learned building Mirage, an AI-powered deception platform.

deceptionarchitecture
2025-04-02
Container Security in Production: Docker Hardening That Works

I run over 50 Docker containers in production. Here are the hardening rules I apply on every deployment.

devsecopsarchitecturetools
2025-03-28
How to Choose an XDR Platform for Your SME

XDR is everywhere, but most platforms are not built for SMEs. Here is how to evaluate your options without getting blinded by marketing.

xdrconsultingsme
2025-03-18
AI-Powered Threat Intelligence: How Valta Scores Relevance

With 19k+ threats tracked from 9 sources, noise is the real enemy. How Valta's AI scoring turns chaos into actionable intelligence.

ctiai-security
2025-03-05
The Future of XDR: Why Detection Without Response Is Dead

The XDR market is evolving rapidly. Here is where it is heading and why platforms that do not automate response are destined to disappear.

xdrarchitecture
2025-02-20
Anatomy of an XDR Platform: Lessons from Building Presidio

Six integrated systems, five SOAR playbooks, a SOC portal at 95%. What I learned building a complete XDR stack from scratch.

xdrarchitecture
2025-01-15
Why I Build My Own Security Platforms

The difference between configuring and building is not just technical - it is a mindset. Here is why I chose to engineer from scratch.

architecturecareer