Overview
Curios is a team of senior security consultants offering enterprise-grade cybersecurity services including penetration testing, cloud security assessments, compliance certification, vCISO services, and security awareness programs. The firm operates with 8+ years of enterprise protection experience, 48 advanced certifications across its team, and 130+ combined years of experience, serving clients across manufacturing, finance, and automotive sectors.
Key people
In the news
- TIBER is a method the ECB wrote for banks in 2018. Its best ideas cost nothing to borrow. Banks get it imposed under DORA. Other suppliers will never be asked. That is fine. The method was never the expensive part. The supervision was. Five things a TIBER test does that a standard pentest usually skips. All five fit a NIS2 budget. - It starts with a threat picture. Named actors, their tooling, the route they would take into your organisation. The scope follows from that, not from an asset list. - It runs on production, with a small
- Ondertussen acht jaar werkt het Curios team van senior security consultants aan de veiligheid van verschillende industrieleiders. En 2027 wordt het jaar waarin we een versnelling hoger schakelen. Dus bouwen we het team uit met drie profielen, in vaste dienst: Sales. Iemand die security begrijpt, het gesprek met een CISO durft aan te gaan en samen met mij de volgende klanten binnenhaalt. Security engineers. Mensen die infrastructuur en identity niet alleen kunnen uitleggen, maar ook beveiligen bij de klant. Offensieve specialisten.
- Before you sign the next penetration test, check who the scope was written for. If it was written to satisfy an audit, it will pass an audit. Whether someone can get in is a separate question. The scope document is where that gets decided. Worth reading what the rules ask. NIS2 Article 21 asks you to assess whether your controls work, not to produce a certificate. DORA has been live since 17 January 2025, and significant entities run threat-led testing under TIBER-EU every three years. Three years. Your estate does not stand
- One of this week's 394 Microsoft fixes mentions us. CVE-2026-70324, elevation of privilege in SharePoint. The acknowledgement reads "Mateusz Gierblinski with Curios". One bug out of 394. We will not pretend it changes the world. But it is the kind we spend our days on. Not how attackers get in: how a small foothold becomes the whole tenant. A scan tells you which patch is missing. We test what someone could do. Penetration test, assessment, retest. https://lnkd.in/ejx3VdhY If you run SharePoint Server: patch it and if you
- Microsoft patched CVE-2026-70324 yesterday. Mateusz Gierblinski found it. A SharePoint elevation of privilege bug, rated Important. One of 394 fixes in this month's Patch Tuesday. The acknowledgement reads: Mateusz Gierblinski, with Curios. At Curios, Mateusz is our senior information security engineer. Inside the team he is the one who reviews the hard findings and quietly raises the bar for everyone else. Me included. I cannot do what he does. My job is making sure he can keep doing it, and finding him colleagues who match.
- Are we secure?" Someone asks it near the end. Item seven, after the budget, ten minutes left. We used to answer it. A slide, three green indicators, a number moving the right way. Everyone nodded. Nobody asks a second question. Not because they're satisfied. Because asking "what does that actually mean" in front of eleven people feels like admitting you don't follow it. So comfort gets recorded as governance. Four questions that work better: → What are the three things most likely to put us on the front page? → If we were breached
- GDPR. NIS2. DORA. CRA.The AI Act. Five years ago your security program answered to one regulator. Soon it answers to five. The frameworks keep coming — and each new acronym raises the same uncomfortable question: who is going to do the work? Not the tooling. The work: → Reading a regulation and knowing which of your controls already satisfy it — and which gaps are real → Sitting across from an auditor and defending the evidence → Translating legal text into engineering backlog, and engineering reality into board language That's a
- Every vulnerability you've ever patched had a name before you met it. Someone gave it that name. This week, that someone was one of ours. Mateusz Gierblinski — Senior Information Security Engineer at Curios, 12 CVEs, OSCP — received a bug bounty from Microsoft's Security Response Center. Most people meet CVEs as lines in a patch report. Few think about where they come from: → A researcher finds a flaw and reports it — before criminals find it → The flaw gets a name, a severity, a fix — one shared language for every scanner, SOC and
Something wrong or missing? Send an update. Fixed within 24 hours.



