Governance that survives contact with reality

Security decisions.Made defensible.

Cybersecurity governance, risk, identity, audit, and AI work translated into evidence leaders can understand—and decisions teams can defend.

04 Featured Case Studies

Professional work across risk management, audit readiness, access governance, and compliance.

AI Risk Lab

Practical AI hygiene and governance patterns without turning people into policy-shaped furniture.

MFA Identity Focus

Conditional Access, rollout strategy, adoption risk, and business-readable security controls.

GRC Audit Ready

Built for clarity: what happened, why it mattered, what control failed, and what changes next.

Risk work with a decision attached.

Start with the flagship Enterprise Risk Register, then explore audit, identity, compliance, governance, AI, and technical-security capabilities.

Available

Flagship // Enterprise Risk

Enterprise Risk Register

Probability-impact scoring, response planning, vendor and fourth-party exposure, AI/SaaS governance, and audit-ready documentation in one recruiter-friendly case study.

View Case Study

Explore the full set

GRC & Cybersecurity Portfolio

Browse featured work by professional capability and see clearly labeled Available, In Development, and Planned artifacts.

Open Portfolio

Incident stories with receipts.

These SIMs translate messy cybersecurity incidents into governance decisions, risk language, and audit-ready artifacts. Less theater. More defensible execution.

Governance that people can actually hear.

Talks and workshops focused on cybersecurity governance, AI hygiene, identity risk, and making security frameworks useful outside of a dusty PDF dungeon.

Featured talk

RAFA Academy Presentation

Cybersecurity governance, AI hygiene, and security frameworks translated into practical language for people who need to make decisions, not collect buzzwords.

Talk tracks

What I Cover

AI hygiene, governance and risk, incident response lessons, MFA rollout friction, and the human side of technical control failure.

AI, but with adult supervision.

The AI Lab explores where generative systems fit into governance workflows, what needs guardrails, and where human judgment still needs to stay in the chair.

Prototype

Governance Assistant

A custom assistant concept for policy drafting, control mapping, risk language, and security workflow support.

Focus

AI Hygiene

Practical boundaries for AI use: data handling, review checkpoints, accountability, and the blessed art of not pasting secrets into random boxes.

Output

Risk Language

Plain-language risk translation for leaders, analysts, students, and stakeholders who need the real answer without the fog machine.

Receipts, not vibes.

A cybersecurity academic path grounded in governance, risk, identity, and documentation that can survive scrutiny.

  • Completed Cybersecurity degree with highest honors — academic foundation across security operations, risk, and technical analysis.
  • Current Master's studies in cybersecurity — continued focus on governance, information systems, security controls, and real-world risk decisions.
  • Leadership Community and security leadership — building spaces for cybersecurity learning, mentorship, and practical growth.

Field notes from the ruins.

Writing on privacy, social engineering, authentication failures, governance gaps, and practical security moves that do not require a magic wand or a seven-figure tooling budget.

Privacy

Post-2024 Privacy

State laws snapshot, accountability gaps, and a practical action list for people trying to protect data in the real world.

Read Post

Human Risk

Social Engineering

Baiting, impersonation, SPIT, vishing, and a short verification playbook for when the vibes are off.

Read Post

Web Security

BAC & Auth Failures

Deny-by-default, ABAC/ReBAC, passkeys, MFA, lockouts, and session hygiene for web app security.

Read Post

Send the signal.

Collaboration, speaking, governance projects, AI hygiene discussions, and cybersecurity work that needs clarity instead of theater.

Primary channel

Email is the cleanest path for inquiries, collaboration, speaking requests, and project conversations.

marjean@thedigitalruins.com

Repository trail

Review the work, the structure, and the artifacts. The receipts are part of the point.

github.com/marjeanm