The SecureBlock blog
Field notes on offensive security, compliance, and the pentest craft.
Written by the testers, engineers, and operators who run SecureBlock engagements. Long-form, occasional, no marketing filler.
methodologyphilosophy
Featured
Why we do manual pentesting
Scanners find signatures. Attackers chain business logic. Here's why every SecureBlock engagement is human-led, and why that changes the finding mix.
Marta Kovač June 18, 2026 5 min read
Read post All posts
3 entriespricingproduct
How we scope in under two minutes
A discovery call, a scoping spreadsheet, three follow-up emails, and a quote three weeks later. We rebuilt the whole thing as a four-question form. Here's the rubric behind it.
Luka Šikić·May 27, 2026·6 min read
compliancesoc2
A field guide to SOC 2 evidence packs
The awkward gap between a great pentest report and the evidence your SOC 2 auditor actually wants to see. What we put in the pack, and why.
Mirna Novak·April 11, 2026·7 min read

