<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Michal Ormos — Writing</title>
    <link>https://www.michalormos.eu/blog.html</link>
    <description>Long-form writing on DevSecOps, cloud security, automation and the boring-but-important parts of running production.</description>
    <language>en-gb</language>
    <atom:link href="https://www.michalormos.eu/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Wed, 20 May 2026 09:00:00 +0000</lastBuildDate>

    <item>
      <title>Hardening an AWS Organization in 30 days: a practical checklist</title>
      <link>https://www.michalormos.eu/blog/aws-organization-hardening.html</link>
      <guid isPermaLink="true">https://www.michalormos.eu/blog/aws-organization-hardening.html</guid>
      <pubDate>Wed, 20 May 2026 09:00:00 +0000</pubDate>
      <description>If you've inherited a single-account AWS environment with IAM users, shared root credentials and no guardrails, here's the playbook to turn it into something an auditor — and a future you — can live with.</description>
    </item>

    <item>
      <title>CI/CD security gates that don't slow the team down</title>
      <link>https://www.michalormos.eu/blog/ci-cd-security-gates.html</link>
      <guid isPermaLink="true">https://www.michalormos.eu/blog/ci-cd-security-gates.html</guid>
      <pubDate>Sun, 12 Apr 2026 09:00:00 +0000</pubDate>
      <description>Most security gates in CI/CD pipelines fail one of two tests: they're so noisy nobody reads them, or they're so slow developers route around them. Here's the version I actually keep in production.</description>
    </item>

    <item>
      <title>Vulnerability management at scale: what actually matters</title>
      <link>https://www.michalormos.eu/blog/vulnerability-management-at-scale.html</link>
      <guid isPermaLink="true">https://www.michalormos.eu/blog/vulnerability-management-at-scale.html</guid>
      <pubDate>Tue, 03 Mar 2026 09:00:00 +0000</pubDate>
      <description>Once you're past a few hundred assets, the scanner is no longer the bottleneck — triage is. Here's what I've learned operating vulnerability management programmes that didn't end in burned-out security teams.</description>
    </item>

  </channel>
</rss>
