Co-founder & CTO
Petru Kovaci
Petru is the co-founder and CTO of Intrudify, named to Forbes 30 Under 30 and to the Global 30 Under 30 in Cybersecurity 2026, with 10+ years in offensive security and red teaming.
OSCE3-certified, and a doctoral researcher on the convergence of cybersecurity and AI. Previously a threat analyst at CrowdStrike and a senior security engineer at Airbus Defence and Space, after Secureworks and IBM. He founded Blackbox Information Security, a Romanian penetration testing and NIS2 practice.
6 articles by Petru
- How to Prepare and Answer a Customer Security Questionnaire A questionnaire pulls in engineering, HR and legal at once, and the first one always costs the most. What makes the second one cheaper is a library of answers someone has already checked.
- How to Prepare for a Security Audit Audit preparation fails in the same two places every time, and neither is the audit itself. Here is the order of work, and the evidence list to build against.
- SOC 2 vs ISO 27001: Which One Do You Actually Need? They are not competing versions of the same thing. One is an audit report about your controls; the other is a certificate saying you run a management system. That difference decides which your buyer will accept.
- Compliance vs Security: Why Passing an Audit Is Not Being Safe Every breached company with a clean audit report is the same story. Compliance measures whether you can demonstrate conformance; security measures whether an attacker gets in. Those come apart more often than anyone likes.
- Risk Assessment for Compliance: How to Do One Auditors Accept Most first risk assessments are a spreadsheet of generic threats with invented numbers. Auditors can tell. Here is the method that survives being asked "why this rating".
- The NIST Cybersecurity Framework Explained The CSF gets confused with every other NIST document, and with certification schemes it has nothing to do with. It is a voluntary structure for organising a security programme, and that is genuinely useful once you stop expecting a checklist.