<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>vesely.sk — Peter Vesely</title>
<description>Articles on cybersecurity, governance, risk management, AI oversight, compliance, software engineering and operational resilience by Peter Vesely.</description>
<link>https://www.vesely.sk/</link>
<atom:link href="https://www.vesely.sk/rss.xml" rel="self" type="application/rss+xml" />
<language>en</language>
<lastBuildDate>Fri, 07 Aug 2026 00:00:00 GMT</lastBuildDate>
<ttl>60</ttl>
<item>
<title>AI Security Architecture Is Not Just AI Governance</title>
<link>https://www.vesely.sk/blog/ai-security-architecture-is-not-just-ai-governance/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-security-architecture-is-not-just-ai-governance/</guid>
<pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
<description>AI governance defines policies and responsibilities. AI security architecture turns them into technical controls, trust boundaries, identity models, evidence and tests.</description>
<category>AI Security</category><category>ai-security</category><category>security-architecture</category><category>ai-governance</category><category>ai-act</category><category>llm-security</category><category>rag-security</category><category>prompt-injection</category><category>iam</category><category>zero-trust</category><category>threat-modeling</category><category>audit-evidence</category><category>nist-ai-rmf</category><category>owasp-llm</category>
</item>
<item>
<title>Docker Is Healthy, but Unreachable After a Hyper-V to Proxmox Migration</title>
<link>https://www.vesely.sk/blog/docker-healthy-but-unreachable-after-hyper-v-to-proxmox-migration/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/docker-healthy-but-unreachable-after-hyper-v-to-proxmox-migration/</guid>
<pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
<description>After moving an Ubuntu VM from Hyper-V to Proxmox, the VM network worked and the Docker container was healthy, but the application was unreachable because Docker did not restore runtime networking and port mappings correctly.</description>
<category>Infrastructure</category><category>proxmox</category><category>hyper-v</category><category>docker</category><category>ubuntu</category><category>networking</category><category>migration</category><category>infrastructure</category><category>troubleshooting</category><category>operations</category><category>linux</category><category>virtualization</category>
</item>
<item>
<title>Migrating a Windows VM from Hyper-V to Proxmox with Veeam Community Edition</title>
<link>https://www.vesely.sk/blog/migrating-windows-vm-from-hyper-v-to-proxmox-with-veeam-community-edition/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/migrating-windows-vm-from-hyper-v-to-proxmox-with-veeam-community-edition/</guid>
<pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
<description>A practical migration lesson: Veeam Community Edition can restore a Windows Hyper-V VM to Proxmox, but a VirtIO SCSI boot issue may require a temporary SATA boot and a small helper VirtIO disk.</description>
<category>Infrastructure</category><category>hyper-v</category><category>proxmox</category><category>veeam</category><category>windows-server</category><category>virtio</category><category>scsi</category><category>sata</category><category>virtualization</category><category>migration</category><category>backup</category><category>disaster-recovery</category><category>infrastructure</category><category>troubleshooting</category>
</item>
<item>
<title>Threat Modeling for LLM Applications: Where to Start</title>
<link>https://www.vesely.sk/blog/threat-modeling-for-llm-applications-where-to-start/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/threat-modeling-for-llm-applications-where-to-start/</guid>
<pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
<description>LLM applications need threat models that cover more than prompts: trust boundaries, RAG, agents, tools, identity, data flows, provider boundaries and audit evidence.</description>
<category>AI Security</category><category>ai-security</category><category>threat-modeling</category><category>llm-security</category><category>prompt-injection</category><category>rag-security</category><category>iam</category><category>zero-trust</category><category>appsec</category><category>audit-evidence</category><category>owasp-llm</category><category>mitre-atlas</category><category>nist-ai-rmf</category>
</item>
<item>
<title>When a Virtual Server Is Not Just a Disk File</title>
<link>https://www.vesely.sk/blog/when-a-virtual-server-is-not-just-a-disk-file/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/when-a-virtual-server-is-not-just-a-disk-file/</guid>
<pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
<description>Moving a domain controller from Hyper-V to Proxmox can look like a simple virtual machine migration. In practice, Active Directory carries identity, DNS, time, trust and recovery assumptions.</description>
<category>Infrastructure</category><category>hyper-v</category><category>proxmox</category><category>active-directory</category><category>windows-server</category><category>domain-controller</category><category>virtualization</category><category>backup</category><category>disaster-recovery</category><category>incident-response</category><category>infrastructure</category><category>cybersecurity</category>
</item>
<item>
<title>AI-generated content will need more than a label</title>
<link>https://www.vesely.sk/blog/ai-generated-content-will-need-more-than-a-label/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-generated-content-will-need-more-than-a-label/</guid>
<pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
<description>AI transparency will not be solved by a small icon under an image. Organisations will need provenance metadata, signatures, watermarking, verification tools, human review and audit evidence.</description>
<category>AI</category><category>ai</category><category>ai-governance</category><category>compliance</category><category>cybersecurity</category><category>audit-evidence</category><category>verification</category><category>privacy</category><category>software-security</category>
</item>
<item>
<title>Vibe Coding Can Build Your Application. But Who Builds Its Security?</title>
<link>https://www.vesely.sk/blog/vibe-coding-builds-applications-who-builds-security/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/vibe-coding-builds-applications-who-builds-security/</guid>
<pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
<description>AI can generate working applications quickly, but functionality is not the same as security. The next challenge is proving that AI-generated systems are hardened, compliant and trustworthy enough for production.</description>
<category>AI Security</category><category>ai-security</category><category>cybersecurity</category><category>vibe-coding</category><category>ai</category><category>appsec</category><category>devsecops</category><category>software-security</category><category>secure-by-design</category><category>docker</category><category>zero-trust</category><category>compliance</category><category>audit-evidence</category><category>verification</category><category>ai-engineering</category>
</item>
<item>
<title>AI Needs Better Engineering, Not More Tokens</title>
<link>https://www.vesely.sk/blog/ai-needs-better-engineering-not-more-tokens/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-needs-better-engineering-not-more-tokens/</guid>
<pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
<description>The future of AI will not be decided only by larger models or longer context windows. It will be decided by the engineering process around them: workflow, memory, rules, verification, review and evidence.</description>
<category>AI</category><category>ai</category><category>ai-engineering</category><category>software-engineering</category><category>vibe-coding</category><category>ai-agents</category><category>developer-productivity</category><category>governance</category><category>cybersecurity</category><category>devsecops</category><category>code-review</category><category>audit-evidence</category><category>verification</category>
</item>
<item>
<title>Every Software Has a Bug</title>
<link>https://www.vesely.sk/blog/every-software-has-a-bug/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/every-software-has-a-bug/</guid>
<pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
<description>Every piece of software contains weaknesses. The real question is not whether a bug exists, but whether we find it first or an attacker does.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>software-security</category><category>appsec</category><category>secure-by-design</category><category>vulnerability-management</category><category>devsecops</category><category>code-review</category><category>testing</category><category>risk-management</category><category>incident-response</category><category>security-maturity</category>
</item>
<item>
<title>Vibe Coding Needs Memory, Skills, and Review</title>
<link>https://www.vesely.sk/blog/vibe-coding-needs-memory-skills-and-review/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/vibe-coding-needs-memory-skills-and-review/</guid>
<pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
<description>Vibe coding is fast, but without durable memory, reusable skills, deterministic verification and independent review, AI-assisted development can quickly become chaos.</description>
<category>AI Security</category><category>ai-security</category><category>vibe-coding</category><category>ai</category><category>ai-agents</category><category>software-engineering</category><category>devsecops</category><category>software-architecture</category><category>developer-productivity</category><category>governance</category><category>cybersecurity</category><category>automation</category><category>code-review</category>
</item>
<item>
<title>AI-Assisted Development Needs Security From Day One</title>
<link>https://www.vesely.sk/blog/ai-assisted-development-needs-security-from-day-one/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-assisted-development-needs-security-from-day-one/</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<description>AI makes it easier than ever to build and deploy software. That also means basic web security, AppSec and DevSecOps checks must happen before publishing, not after deployment.</description>
<category>AI Security</category><category>ai-security</category><category>cybersecurity</category><category>appsec</category><category>devsecops</category><category>ai</category><category>web-security</category><category>vibe-coding</category><category>secure-by-design</category><category>astro</category><category>vercel</category><category>cloudflare</category><category>security-headers</category><category>csp</category><category>caa</category>
</item>
<item>
<title>AI Just Changed the Threat Model</title>
<link>https://www.vesely.sk/blog/ai-just-changed-the-threat-model/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-just-changed-the-threat-model/</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<description>Autonomous AI agents change enterprise security assumptions. The next generation of cybersecurity will be about continuously proving that infrastructure is still trustworthy.</description>
<category>AI Security</category><category>ai-security</category><category>threat-modeling</category><category>cybersecurity</category><category>ai</category><category>zero-trust</category><category>nis2</category><category>cyber-resilience</category><category>compliance</category><category>open-source</category><category>filipos</category><category>integrity-monitoring</category><category>audit-evidence</category><category>governance</category>
</item>
<item>
<title>Risk Management Needs Evidence Infrastructure</title>
<link>https://www.vesely.sk/blog/risk-management-needs-evidence-infrastructure/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/risk-management-needs-evidence-infrastructure/</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<description>NIS2, AI and modern infrastructure change risk management from a static register into a continuous evidence problem. Existing open-source tools solve parts of it, but the missing layer is proof of trust.</description>
<category>Risk Management</category><category>risk-management</category><category>nis2</category><category>ai</category><category>cybersecurity</category><category>governance</category><category>compliance</category><category>audit-evidence</category><category>integrity-monitoring</category><category>zero-trust</category><category>cyber-resilience</category><category>open-source</category>
</item>
<item>
<title>FILIP:OS, Part 3: What an Integrity Violation Really Means</title>
<link>https://www.vesely.sk/blog/filipos-part-3-what-an-integrity-violation-really-means/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/filipos-part-3-what-an-integrity-violation-really-means/</guid>
<pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
<description>A practical explanation of how FILIP:OS creates an integrity baseline, detects filesystem drift, classifies changes and preserves evidence without treating every difference as an attack.</description>
<category>Projects</category><category>filipos</category><category>integrity-monitoring</category><category>cybersecurity</category><category>file-integrity</category><category>sha256</category><category>drift-detection</category><category>linux-security</category><category>nis2</category><category>siem</category><category>audit-evidence</category>
</item>
<item>
<title>Compliance Is Not a Folder Full of PDFs</title>
<link>https://www.vesely.sk/blog/compliance-is-not-a-folder-full-of-pdfs/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/compliance-is-not-a-folder-full-of-pdfs/</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
<description>Real compliance is not about collecting policies and audit screenshots. It is about proving that important controls work when the business actually needs them.</description>
<category>Compliance</category><category>compliance</category><category>governance</category><category>audit</category><category>risk-management</category><category>cybersecurity</category><category>evidence</category><category>resilience</category>
</item>
<item>
<title>FILIP:OS Integrity: Is This Still the Machine We Installed?</title>
<link>https://www.vesely.sk/blog/filipos-integrity-is-this-still-the-machine-we-installed/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/filipos-integrity-is-this-still-the-machine-we-installed/</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
<description>Small Linux appliances do not become risky only when they fail. They become risky when nobody knows what changed.</description>
<category>Projects</category><category>FILIP:OS</category><category>linux</category><category>integrity</category><category>operations</category><category>open-source</category><category>automation</category><category>infrastructure</category>
</item>
<item>
<title>AI Governance Will Define the Next Decade</title>
<link>https://www.vesely.sk/blog/ai-governance-will-define-the-next-decade/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-governance-will-define-the-next-decade/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>The future of AI will not be defined only by what systems can do, but by who can govern their risks, security, accountability and auditability.</description>
<category>AI</category><category>ai-governance</category><category>cyber-risk</category><category>cybersecurity</category><category>risk-management</category><category>compliance</category><category>audit</category><category>ai</category><category>responsible-ai</category><category>information-security</category><category>dba</category><category>governance</category><category>digital-transformation</category>
</item>
<item>
<title>AI in HR Is a Governance Risk, Not Just an HR Tool</title>
<link>https://www.vesely.sk/blog/ai-in-hr-is-a-governance-risk/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/ai-in-hr-is-a-governance-risk/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>When HR uses AI to screen, score or evaluate people, the question is not only whether it is useful, but whether it is legal, safe, fair and governed.</description>
<category>AI</category><category>ai</category><category>hrtech</category><category>gdpr</category><category>ai-act</category><category>nis2</category><category>cybersecurity</category><category>governance</category><category>risk-management</category>
</item>
<item>
<title>At 3:00 AM, Preparedness Becomes Cybersecurity</title>
<link>https://www.vesely.sk/blog/at-3am-preparedness-becomes-cybersecurity/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/at-3am-preparedness-becomes-cybersecurity/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>A server outage at 3:00 AM reveals whether cybersecurity exists as a real operating capability, not only as documentation.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>preparedness</category><category>incident-response</category><category>operations</category><category>resilience</category><category>leadership</category>
</item>
<item>
<title>Companies Are Building an Illusion of Security</title>
<link>https://www.vesely.sk/blog/companies-are-building-an-illusion-of-security/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/companies-are-building-an-illusion-of-security/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>Many companies spend thousands on cybersecurity tools, audits and certificates, but still lack ownership, decision-making and a managed security system.</description>
<category>Governance</category><category>cybersecurity</category><category>governance</category><category>compliance</category><category>risk-management</category><category>incident-response</category><category>leadership</category><category>information-security</category>
</item>
<item>
<title>FILIP:OS: Simple for the Operator, Strict on the Inside</title>
<link>https://www.vesely.sk/blog/filipos-safer-operational-layer/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/filipos-safer-operational-layer/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>FILIP:OS started from a simple frustration: Linux is powerful, but real operations too often become scattered scripts, manual fixes and unsafe commands.</description>
<category>Projects</category><category>filipos</category><category>linux</category><category>operations</category><category>alpine</category><category>security</category><category>automation</category>
</item>
<item>
<title>From Polymorphic Viruses to Polymorphic Attacks</title>
<link>https://www.vesely.sk/blog/from-polymorphic-viruses-to-polymorphic-attacks/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/from-polymorphic-viruses-to-polymorphic-attacks/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>In 1994, the problem was a polymorphic virus. Today, the problem is polymorphic attacks. The technology changed, but the principle stayed familiar.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>malware</category><category>polymorphic-virus</category><category>incident-response</category><category>threat-analysis</category><category>onehalf</category><category>security-thinking</category>
</item>
<item>
<title>Having a Firewall Is Not the Same as Having Security</title>
<link>https://www.vesely.sk/blog/having-a-firewall-is-not-security/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/having-a-firewall-is-not-security/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>A firewall, antivirus, backups and logs are not enough. The real question is whether information security is owned, controlled, evidenced and repeatable.</description>
<category>Governance</category><category>cybersecurity</category><category>nis2</category><category>gdpr</category><category>information-security</category><category>risk-management</category><category>governance</category><category>security-maturity</category>
</item>
<item>
<title>How Much Does One Hour of Downtime Cost?</title>
<link>https://www.vesely.sk/blog/how-much-does-one-hour-of-downtime-cost/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/how-much-does-one-hour-of-downtime-cost/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>Before investing in firewalls, monitoring, backups or audits, companies should understand the real business cost of one hour of downtime.</description>
<category>Risk Management</category><category>it</category><category>monitoring</category><category>cybersecurity</category><category>nis2</category><category>business-continuity</category><category>risk-management</category><category>netxms</category><category>infrastructure</category><category>management</category><category>leadership</category>
</item>
<item>
<title>IT Is the Nervous System of Corporate Responsibility</title>
<link>https://www.vesely.sk/blog/it-is-the-nervous-system-of-corporate-responsibility/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/it-is-the-nervous-system-of-corporate-responsibility/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>Modern IT is no longer a printer-support function. It connects legal, operational, manufacturing and cybersecurity responsibility into one risk space.</description>
<category>Governance</category><category>cybersecurity</category><category>nis2</category><category>gdpr</category><category>ai-act</category><category>machinery-regulation</category><category>ot-security</category><category>governance</category><category>risk-management</category>
</item>
<item>
<title>KYC Is Not Know Everything Forever</title>
<link>https://www.vesely.sk/blog/kyc-is-not-know-everything-forever/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/kyc-is-not-know-everything-forever/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>AML and KYC require customer due diligence, but they are not a blank cheque for uncontrolled data collection, AI scoring and permanent profiling.</description>
<category>Compliance</category><category>aml</category><category>kyc</category><category>gdpr</category><category>ai</category><category>compliance</category><category>risk-management</category><category>governance</category><category>privacy</category>
</item>
<item>
<title>OneHalf Was Not Theory. It Was Reality.</title>
<link>https://www.vesely.sk/blog/onehalf-real-cybersecurity-not-presentation/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/onehalf-real-cybersecurity-not-presentation/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>In 1994, dealing with the OneHalf polymorphic virus was not about frameworks or best practices. It was about understanding the mechanism and keeping systems working.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>onehalf</category><category>malware</category><category>polymorphic-virus</category><category>heuristic-analysis</category><category>incident-response</category><category>security-reality</category>
</item>
<item>
<title>Security Starts by Admitting You Do Not Have It</title>
<link>https://www.vesely.sk/blog/security-starts-by-admitting-you-do-not-have-it/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/security-starts-by-admitting-you-do-not-have-it/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>If a company believes compliance, tools and a passed audit mean cybersecurity is under control, it may only have an illusion of security.</description>
<category>Governance</category><category>cybersecurity</category><category>compliance</category><category>governance</category><category>risk-management</category><category>incident-response</category><category>iso</category><category>leadership</category><category>information-security</category>
</item>
<item>
<title>Six Things I Would Start With in a Company Without Cybersecurity</title>
<link>https://www.vesely.sk/blog/six-things-to-start-cybersecurity-right/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/six-things-to-start-cybersecurity-right/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>If I came into a company with no real cybersecurity, I would not start by buying tools or running an audit. I would start with ownership, decisions and control.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>governance</category><category>incident-response</category><category>preparedness</category><category>risk-management</category><category>leadership</category><category>information-security</category>
</item>
<item>
<title>The Biggest Incident Response Failure Is Hesitation</title>
<link>https://www.vesely.sk/blog/the-biggest-incident-response-failure-is-hesitation/</link>
<guid isPermaLink="true">https://www.vesely.sk/blog/the-biggest-incident-response-failure-is-hesitation/</guid>
<pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
<description>The worst failure I have seen during a security incident was not technology. It was hesitation, unclear authority and loss of control.</description>
<category>Cybersecurity</category><category>cybersecurity</category><category>incident-response</category><category>ransomware</category><category>crisis-management</category><category>leadership</category><category>risk-management</category><category>preparedness</category>
</item>
</channel>
</rss>