Independent post-incident analyses of public security breaches, read through a GRC and Human Risk lens. Frameworks referenced: NIST CSF 2.0, ISO/IEC 27001:2022.
These are learning exercises based on public reporting, not internal investigations. Where I interpret rather than report fact, I say so.
| Case Study | Focus | Status |
|---|---|---|
| Uber 2022 Breach | MFA fatigue, social engineering, hardcoded credentials | Complete |
| Self-Audit: web-vuln-control-mapping (ES) | Four real findings from auditing my own tool: API input handling, security headers, dependencies, and an unpopulated control mapping | Complete |
Contact: garaysebastiang@gmail.com | Portfolio | LinkedIn