The VITI Security Blog
Practical writing on managed IT + cybersecurity.
By the engineers doing the work - not a marketing team summarizing it. We write when we have something to say, not when the calendar says we should.

Active Directory Hardening: Critical Case
A password-spray attack from 80+ source IPs compromised three service accounts. We rebuilt the AD trust model, deployed Defender for Identity, and implemented conditional access. Twelve months on: zero successful sprays.

API Security Testing: Healthtech Case Study
A healthtech startup's APIs had grown faster than their auth model. We pen-tested, refactored OAuth, added rate limiting and schema validation. 18 high/critical findings closed; p99 latency improved.

DPDP Compliance for Vicidial: 7-Week Case
A licensed debt collections agency needed to align its Vicidial deployment with India's DPDP Act — call recording handling, agent access, retention, and consent. Audit cleared, customer complaints down 60% YoY.

Cyber Insurance Readiness: 60-Day Case
A 200-person manufacturer received a renewal denial unless seven specific controls were in place within 60 days. We delivered all seven, ran a tabletop, and the underwriter approved at 18% lower premium.

Bug Bounty Program Launch: SaaS Case Study
A B2B SaaS founding team wanted external security feedback but feared scope creep, payout sustainability, and triage overhead. We designed and launched their HackerOne private program — 14 valid findings in the first 90 days, budget held.

WordPress Incident Response: 90-Min Case
A direct-to-consumer brand discovered an attacker exfiltrating order data through a compromised admin account. We contained the incident in 90 minutes from notification and walked away with a hardening brief the client actually adopted.

Toll-Fraud Prevention: 92% Reduction Case
A wholesale voice carrier was losing roughly $25k a month to toll fraud and routing abuse. We rebuilt the SBC tier on OpenSIPS HA, added behavioural rate-limits, and got fraud down 92%.

Bug Bounty Challenges: 10 Critical Realities
The honest list of problems bug hunters deal with — duplicates, slow triage, severity disputes, scope creep, payout inconsistency, burnout, and the legal gray zones — with practical mitigations.

Bug Bounty Hunting 2026: Beginner Roadmap
A focused 90-day roadmap for new bug bounty hunters in 2026 — what skills to build, which platforms to start on, the tools you actually need, and how to write a report that gets paid.
