Cybersecurity Capstone
A team engagement built around Global Synergy Solutions (GSS), a fictional organization that handled protected health information, responding to a simulated breach. Served as the team's GRC Analyst.
Team Engagement
In Collaboration With
Each teammate covered a different workstream. The rest of this page focuses on my individual role and contributions as GRC Analyst.
Titus Cassimatis
Noel Hackett
Mary Helfer
Fares Joyner
Victor Teinert
Eduardo Sanchez
The Scenario
Global Synergy Solutions (GSS)
GSS, a fictional organization handling protected health information, experienced a simulated breach. The team investigated and responded, with the work culminating in a final published deliverable: the Cybersecurity Resilience Guide.
As GRC Analyst, my focus was on the legal and regulatory side of the response and on the IAM misconfigurations exposed across AWS and Azure during the investigation.
What the Role Looked Like
The GRC Workstream in Practice
Legal & Regulatory Obligations
Assessed the incident against applicable data protection and breach notification laws, including GDPR and CCPA style privacy obligations and HIPAA-relevant duties given GSS handled PHI. Evaluated whether the team's response actions satisfied those obligations or fell short.
Governance & Policy Fixes
Identified compliance gaps between how GSS actually responded and what its legal and regulatory duties required. Proposed policy and governance fixes to close them.
AWS & Azure Misconfigurations
Reviewed IAM policies, AWS credential reports, CloudTrail logs, Azure RBAC assignments, and Azure Activity Logs to identify findings: wildcard permissions, users without MFA, unrotated access keys, overprivileged service principals, and orphaned or persistence role assignments created inside the attack window.
MITRE ATT&CK (Cloud)
Mapped attacker behavior and misconfigurations to cloud ATT&CK techniques: permission discovery, privilege escalation via AssumeRole, persistence through new account and role creation, and data exfiltration from cloud storage. Used the mapping to structure incident analysis and prioritize remediation.
Disciplined Use of AI Tools
Used AI tools during the IAM audit with disciplined cross-verification against official AWS and Azure documentation, given how hallucination-prone cloud IAM analysis can be.
Lessons Learned & Resilience Guide
Contributed to the team's Lessons Learned analysis and Security Recommendations report, translating findings into actionable, framework-aligned recommendations. Contributed to the compliance and governance sections of the team's final published deliverable, the Cybersecurity Resilience Guide.
The Connection
Technical Findings, Regulatory Conclusions
The compliance assessment and the IAM analysis were not separate tracks. Technical findings from the cloud audit fed directly into the legal and regulatory risk conclusions, and those conclusions in turn shaped the policy and governance fixes proposed to close the compliance gaps.
Mapping the same findings to MITRE ATT&CK cloud techniques kept the technical and regulatory work anchored to a common reference, so incident analysis and remediation prioritization stayed aligned across the team's workstreams.
Tools & Techniques
How the Analysis Got Done
Standards & Frameworks
What the Work Was Anchored To
Findings and recommendations were mapped to recognized frameworks.
Skills Developed