🔄 Topic

Converting the Farina website project into honest cybersecurity-adjacent portfolio material.


🎯 Goal

Summarize what the website build proves and how to present it without pretending it was pure cybersecurity work.


🛠 What I Did

I reviewed the Farina website project as portfolio evidence. This was not a pure cybersecurity lab, and I should not pretend it was. But it still proves useful skills: repository work, GitHub operations, frontend architecture, deployment workflow, DNS thinking, privacy awareness, performance optimization, validation, and public-system responsibility. The honest framing is that I built and maintained a real production website, then analyzed its operational and security implications.

Main areas covered:

  • real production project
  • React/Vite frontend
  • GitHub Pages deployment
  • custom domain
  • SEO and image automation
  • form validation
  • privacy-aware analytics
  • security review

🔗 Key Cybersecurity Connections

This matters because employability is based on proof of useful work. A real website shows practical ability: building, documenting, troubleshooting, deploying, and thinking about risk.


🔍 Investigation Questions

  • What does this project prove?
  • Which parts are cybersecurity-relevant?
  • Which parts are general engineering?
  • How can I describe the work honestly?
  • What evidence can I show in GitHub or the blog?

🚨 Detection Opportunities

Potential monitoring ideas:

  • repository change history
  • deployment workflow history
  • public route inventory
  • validation commands
  • security checklist
  • privacy/analytics review

Example:

project=farina-farm-website
change_type=public_website_update
risk_area=repository_deployment_or_public_input
triage=review_change_intent_and_validate_build

🧭 MITRE ATT&CK Techniques

Possible mappings depending on confirmed behavior:

  • T1195 — Supply Chain Compromise
  • T1552 — Unsecured Credentials
  • T1078 — Valid Accounts

🗺 Visual Investigation Diagram

Real project
    ↓ Engineering work
    ↓ Operational lessons
    ↓ Security connections
    ↓ Portfolio evidence

⚠ Challenges

The challenge was avoiding fake intensity. Personal life interrupted study, so the honest story is not ‘I studied hard every day.’ It is ‘I kept building something real and extracted security lessons from it.’


📚 What I Learned

I learned that portfolio work does not need to be perfect. It needs to be honest, useful, and clearly explained.


➡ Next Steps

  • Publish selected gap posts
  • Add a short project summary to portfolio material
  • Continue with structured cybersecurity study when ready

🧠 Reflection

This was useful because it turned a real project into security-aware learning without pretending that every task was a pure cybersecurity lab.


🧩 Lessons Learned

What worked

Keeping the story honest.

What broke

Feeling that non-cybersecurity work does not count.

Why it broke

Operational web work still teaches relevant security-adjacent skills.

Fix / takeaway

Frame the project honestly: real website build plus security-aware reflection.


📈 Skill Progression Context

This supports my cybersecurity progression because modern defenders need to understand how real systems are built, deployed, changed, and broken.


😄 TL;DR

Not pure cybersecurity, still real operational proof.