Governance SIM Portfolio // Cybersecurity // AI Risk

Digital Ruins

A premium cybersecurity portfolio built for the messy place where governance, risk, identity, AI hygiene, and human behavior collide. Brutal vibe. Controlled execution.

04 Governance SIMs

Scenario-based artifacts with executive briefs, lessons learned, timelines, and control logic.

AI Risk Lab

Practical AI hygiene and governance patterns without turning people into policy-shaped furniture.

MFA Identity Focus

Conditional Access, rollout strategy, adoption risk, and business-readable security controls.

GRC Audit Ready

Built for clarity: what happened, why it mattered, what control failed, and what changes next.

Incident stories with receipts.

These SIMs translate messy cybersecurity incidents into governance decisions, risk language, and audit-ready artifacts. Less theater. More defensible execution.

Governance that people can actually hear.

Talks and workshops focused on cybersecurity governance, AI hygiene, identity risk, and making security frameworks useful outside of a dusty PDF dungeon.

Featured talk

RAFA Academy Presentation

Cybersecurity governance, AI hygiene, and security frameworks translated into practical language for people who need to make decisions, not collect buzzwords.

Talk tracks

What I Cover

AI hygiene, governance and risk, incident response lessons, MFA rollout friction, and the human side of technical control failure.

AI, but with adult supervision.

The AI Lab explores where generative systems fit into governance workflows, what needs guardrails, and where human judgment still needs to stay in the chair.

Prototype

Governance Assistant

A custom assistant concept for policy drafting, control mapping, risk language, and security workflow support.

Focus

AI Hygiene

Practical boundaries for AI use: data handling, review checkpoints, accountability, and the blessed art of not pasting secrets into random boxes.

Output

Risk Language

Plain-language risk translation for leaders, analysts, students, and stakeholders who need the real answer without the fog machine.

Receipts, not vibes.

A cybersecurity academic path grounded in governance, risk, identity, and documentation that can survive scrutiny.

  • Completed Cybersecurity degree with highest honors — academic foundation across security operations, risk, and technical analysis.
  • Current Master's studies in cybersecurity — continued focus on governance, information systems, security controls, and real-world risk decisions.
  • Leadership Community and security leadership — building spaces for cybersecurity learning, mentorship, and practical growth.

Field notes from the ruins.

Writing on privacy, social engineering, authentication failures, governance gaps, and practical security moves that do not require a magic wand or a seven-figure tooling budget.

Privacy

Post-2024 Privacy

State laws snapshot, accountability gaps, and a practical action list for people trying to protect data in the real world.

Read Post

Human Risk

Social Engineering

Baiting, impersonation, SPIT, vishing, and a short verification playbook for when the vibes are off.

Read Post

Web Security

BAC & Auth Failures

Deny-by-default, ABAC/ReBAC, passkeys, MFA, lockouts, and session hygiene for web app security.

Read Post

Send the signal.

Collaboration, speaking, governance projects, AI hygiene discussions, and cybersecurity work that needs clarity instead of theater.

Primary channel

Email is the cleanest path for inquiries, collaboration, speaking requests, and project conversations.

marjean@thedigitalruins.com

Repository trail

Review the work, the structure, and the artifacts. The receipts are part of the point.

github.com/marjeanm