Governance that survives contact with reality
Security decisions.Made defensible.
Cybersecurity governance, risk, identity, audit, and AI work translated into evidence leaders can understand—and decisions teams can defend.
Professional work across risk management, audit readiness, access governance, and compliance.
Practical AI hygiene and governance patterns without turning people into policy-shaped furniture.
Conditional Access, rollout strategy, adoption risk, and business-readable security controls.
Built for clarity: what happened, why it mattered, what control failed, and what changes next.
Risk work with a decision attached.
Start with the flagship Enterprise Risk Register, then explore audit, identity, compliance, governance, AI, and technical-security capabilities.
Enterprise Risk Register
Probability-impact scoring, response planning, vendor and fourth-party exposure, AI/SaaS governance, and audit-ready documentation in one recruiter-friendly case study.
View Case StudyGRC & Cybersecurity Portfolio
Browse featured work by professional capability and see clearly labeled Available, In Development, and Planned artifacts.
Open PortfolioIncident stories with receipts.
These SIMs translate messy cybersecurity incidents into governance decisions, risk language, and audit-ready artifacts. Less theater. More defensible execution.
MFA Ghost
Entra ID rollout planning, Conditional Access, risk tiering, adoption friction, and the quiet danger of controls nobody actually understands.
02Shiny Trust Breach
Vendor trust, breach timelines, executive response, AI risk language, and contractor onboarding controls that should have existed yesterday.
03Trust Betrayal
SOC escalation, internal trust breakdowns, corrective action, lessons learned, and the accountability gap between policy and reality.
04Human Failure Vector
People-layer risk without the lazy blaming. Behavioral design, training debt, process gaps, and controls built for actual humans.
Governance that people can actually hear.
Talks and workshops focused on cybersecurity governance, AI hygiene, identity risk, and making security frameworks useful outside of a dusty PDF dungeon.
RAFA Academy Presentation
Cybersecurity governance, AI hygiene, and security frameworks translated into practical language for people who need to make decisions, not collect buzzwords.
What I Cover
AI hygiene, governance and risk, incident response lessons, MFA rollout friction, and the human side of technical control failure.
AI, but with adult supervision.
The AI Lab explores where generative systems fit into governance workflows, what needs guardrails, and where human judgment still needs to stay in the chair.
Governance Assistant
A custom assistant concept for policy drafting, control mapping, risk language, and security workflow support.
AI Hygiene
Practical boundaries for AI use: data handling, review checkpoints, accountability, and the blessed art of not pasting secrets into random boxes.
Risk Language
Plain-language risk translation for leaders, analysts, students, and stakeholders who need the real answer without the fog machine.
Receipts, not vibes.
A cybersecurity academic path grounded in governance, risk, identity, and documentation that can survive scrutiny.
- Completed Cybersecurity degree with highest honors — academic foundation across security operations, risk, and technical analysis.
- Current Master's studies in cybersecurity — continued focus on governance, information systems, security controls, and real-world risk decisions.
- Leadership Community and security leadership — building spaces for cybersecurity learning, mentorship, and practical growth.
Field notes from the ruins.
Writing on privacy, social engineering, authentication failures, governance gaps, and practical security moves that do not require a magic wand or a seven-figure tooling budget.
Post-2024 Privacy
State laws snapshot, accountability gaps, and a practical action list for people trying to protect data in the real world.
Read PostSocial Engineering
Baiting, impersonation, SPIT, vishing, and a short verification playbook for when the vibes are off.
Read PostBAC & Auth Failures
Deny-by-default, ABAC/ReBAC, passkeys, MFA, lockouts, and session hygiene for web app security.
Read PostSend the signal.
Collaboration, speaking, governance projects, AI hygiene discussions, and cybersecurity work that needs clarity instead of theater.
Primary channel
Email is the cleanest path for inquiries, collaboration, speaking requests, and project conversations.
marjean@thedigitalruins.comRepository trail
Review the work, the structure, and the artifacts. The receipts are part of the point.
github.com/marjeanm