Cybersecurity Portfolio

Cybersecurity case studies: incident response, security metrics, and secure engineering.

Nine projects by Sean Richard that apply recognized security frameworks to a concrete organization, incident, or operational problem. They cover incident reporting, a CIS Controls v8 attack-chain analysis, security KPIs such as MTTD and MTTR, secure development with NIST SSDF and BSIMM, and compliance work across CMMC, PCI DSS, and HIPAA. Each page summarizes the project and links to the full report.

Frameworks and standards applied

Each framework below links to the project where it was used.

Security frameworks and standards, and the case studies that apply each one
Framework or standardApplied in
Incident response reportingCybersecurity Incident Response Report
FERPACybersecurity Incident Response Report, BSIMM Software Security Maturity Assessment
CIS Controls v8CIS Controls v8 Gap Analysis — Luigi's Case Study
CIS Implementation Groups (IG1, IG2)CIS Controls v8 Gap Analysis — Luigi's Case Study
Security operations metricsSecurity KPI & Metrics Analysis
CIS Controls Assessment SpecificationSecurity KPI & Metrics Analysis
NIST SSDFSnowBe Online Secure Software Development Life Cycle Plan
Microsoft SDLSnowBe Online Secure Software Development Life Cycle Plan
DevSecOpsSnowBe Online Secure Software Development Life Cycle Plan
Agile ScrumSnowBe Online Secure Software Development Life Cycle Plan
BSIMMBSIMM Software Security Maturity Assessment
STRIDE threat modelingBSIMM Software Security Maturity Assessment
GLBABSIMM Software Security Maturity Assessment
CMMCSnowBe Online Security Maturity Assessment
Simple Maturity ModelSnowBe Online Security Maturity Assessment
Secure SDLCSnowBe Online Security Policy & Threat Modeling Portfolio
Patch managementSnowBe Online Security Policy & Threat Modeling Portfolio
Threat modelingSnowBe Online Security Policy & Threat Modeling Portfolio
PCI DSSSnowBe Online Security Policy & Threat Modeling Portfolio, SnowBe Online PCI DSS Audit
SAQ DSnowBe Online PCI DSS Audit
ASV scanningSnowBe Online PCI DSS Audit
HIPAA Security RuleElectronic Health Records Security Controls Assessment
HIPAA Privacy RuleElectronic Health Records Security Controls Assessment
HITECH ActElectronic Health Records Security Controls Assessment
NIST CSF 2.0Electronic Health Records Security Controls Assessment
NIST SP 800-53 Rev. 5Electronic Health Records Security Controls Assessment
NIST SP 800-66 Rev. 2Electronic Health Records Security Controls Assessment

Background

Sean Richard is a United States Army veteran completing a B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University, graduating November 2026, after an A.S. in Information Technology. His hands-on background covers Windows and Linux administration, networking, DNS, server infrastructure, and application-layer security.

He also builds and runs production software: a multi-tenant CRM platform, an AI agent fleet, and contractor SaaS. That is the angle this portfolio brings to security work. The secure development, logging, access control, and incident questions in these case studies are the same ones that come up when operating live systems with real customer data.

See the full portfolio for shipped products and work history, or the about page for background.

Questions about this work

Which security frameworks has Sean Richard applied?
Across these nine projects: CIS Controls v8 with Implementation Groups 1 and 2, the NIST Secure Software Development Framework (SSDF), NIST SP 800-53 Rev. 5, NIST CSF 2.0, NIST SP 800-66 Rev. 2, CMMC, BSIMM, PCI DSS including SAQ selection, and the HIPAA Security and Privacy Rules with HITECH.
Is this professional client work or academic work?
Academic. These are portfolio editions of coursework from the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University, graduating November 2026. The organizations are course case studies or fictional scenarios. Each page summarizes the full document, which is linked as a PDF.
What kind of cybersecurity role is this work aimed at?
Security analyst, SOC, and incident response roles, and engineering or technical leadership roles where security judgment matters. The incident response report, the CIS Controls attack-chain analysis, and the security KPI project are the closest match to analyst work.
What does Sean Richard do outside of this coursework?
He founded and operates Autom8ion Lab, Sitehues Media, and BuilderLync, and ships production software including a multi-tenant CRM platform and contractor SaaS. His hands-on background covers Windows and Linux administration, networking, DNS, server infrastructure, and application-layer security.
Can I read the full reports?
Yes. Every case study links to the full document as a PDF: a written report, a slide deck, or both.
Ready to build the system behind your growth?

Tell me what you're operating.