📅 Day 131 — Project Retrospective: Turning a Real Website Build Into Portfolio Evidence
🔄 Topic
Converting the Farina website project into honest cybersecurity-adjacent portfolio material.
🎯 Goal
Summarize what the website build proves and how to present it without pretending it was pure cybersecurity work.
🛠 What I Did
I reviewed the Farina website project as portfolio evidence. This was not a pure cybersecurity lab, and I should not pretend it was. But it still proves useful skills: repository work, GitHub operations, frontend architecture, deployment workflow, DNS thinking, privacy awareness, performance optimization, validation, and public-system responsibility. The honest framing is that I built and maintained a real production website, then analyzed its operational and security implications.
Main areas covered:
- real production project
- React/Vite frontend
- GitHub Pages deployment
- custom domain
- SEO and image automation
- form validation
- privacy-aware analytics
- security review
🔗 Key Cybersecurity Connections
This matters because employability is based on proof of useful work. A real website shows practical ability: building, documenting, troubleshooting, deploying, and thinking about risk.
🔍 Investigation Questions
- What does this project prove?
- Which parts are cybersecurity-relevant?
- Which parts are general engineering?
- How can I describe the work honestly?
- What evidence can I show in GitHub or the blog?
🚨 Detection Opportunities
Potential monitoring ideas:
- repository change history
- deployment workflow history
- public route inventory
- validation commands
- security checklist
- privacy/analytics review
Example:
project=farina-farm-website
change_type=public_website_update
risk_area=repository_deployment_or_public_input
triage=review_change_intent_and_validate_build
🧭 MITRE ATT&CK Techniques
Possible mappings depending on confirmed behavior:
- T1195 — Supply Chain Compromise
- T1552 — Unsecured Credentials
- T1078 — Valid Accounts
🗺 Visual Investigation Diagram
Real project
↓ Engineering work
↓ Operational lessons
↓ Security connections
↓ Portfolio evidence
⚠ Challenges
The challenge was avoiding fake intensity. Personal life interrupted study, so the honest story is not ‘I studied hard every day.’ It is ‘I kept building something real and extracted security lessons from it.’
📚 What I Learned
I learned that portfolio work does not need to be perfect. It needs to be honest, useful, and clearly explained.
➡ Next Steps
- Publish selected gap posts
- Add a short project summary to portfolio material
- Continue with structured cybersecurity study when ready
🧠 Reflection
This was useful because it turned a real project into security-aware learning without pretending that every task was a pure cybersecurity lab.
🧩 Lessons Learned
What worked
Keeping the story honest.
What broke
Feeling that non-cybersecurity work does not count.
Why it broke
Operational web work still teaches relevant security-adjacent skills.
Fix / takeaway
Frame the project honestly: real website build plus security-aware reflection.
📈 Skill Progression Context
This supports my cybersecurity progression because modern defenders need to understand how real systems are built, deployed, changed, and broken.
😄 TL;DR
Not pure cybersecurity, still real operational proof.
