Why this site, why now
After twenty years of doing security work quietly, a few words on why I'm finally writing in public — and what I intend to put here.
I’ve owned this domain since 2005. For two decades it did exactly one job:
it gave me an email address that wasn’t on someone else’s platform. That was
the whole ambition. vassilis@mandrakis.com — nothing behind it.
That seems like a waste now, so I’m fixing it.
The short version
I’ve spent twenty-five years in and around IT and security: a web developer in the late ’90s, then a long stretch teaching Computer Science and running school IT infrastructure, and since 2021 the CISO of a public university. The work has always been real, but it has always been invisible. Security done well looks like nothing happening. There is no portfolio in “nothing happened.”
I’m now deliberately moving toward red team work, and that transition surfaced a problem I’d been able to ignore for years: a career spent on the defensive side leaves very little that’s legible to anyone outside the organisations you worked for. The disclosures, the architecture decisions, the incidents quietly handled — none of it is written down anywhere a stranger can read it.
So this site is the correction. It’s where I make the work legible.
What I intend to put here
Three kinds of things, roughly:
Detection engineering, from the inside. I designed and built my employer’s SOC rather than buying a managed one. That means I know what the blue side actually sees — which alerts fire, which don’t, where the gaps are, and why. That knowledge has a second life as offensive insight, and I want to write from that seam.
Tradecraft and infrastructure notes. The unglamorous half of red teaming — how you stand things up, how you stay quiet, what earns trust from a defender’s tooling and what trips it. There’s far more written about exploitation than about infrastructure, and I find the infrastructure more interesting.
Field notes from the certification path. I’m working through CRTO, with OSEP planned next. Not as marketing — as a record. The parts that were hard, the parts that clicked, the things I’d tell myself at the start.
A note on pace
I have a full-time CISO role, a master’s in progress, and three children. I’m not going to pretend this will be a high-frequency publication. I’d rather post something worth reading once a quarter than something forgettable every week.
If that suits you, the RSS feed is the honest way to follow along. If you’re here because you’re hiring for red team work — the about page has the full story, and the door is open.