Skip to content
View 0xmichail's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report 0xmichail

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xmichail/README.md

Michalis

This profile and the repositories linked from it reflect my personal research, ideas, experiments, and opinions, published in a personal capacity.

I work in cybersecurity risk, GRC, and assurance.

Cyber Risk GRC Assurance Threat-informed Security as Code OSCAL DORA NIS2 Python Markdown

Most of my work sits between methodology, evidence, controls, and practical tooling. I am interested in how risk assessments can become more structured, traceable, and useful without removing human judgment from the process.

Selected work

  • ToBeDecidedLater — early-stage research and engineering workspace for threat-informed, OSCAL-oriented cyber assurance.

Current focus

  • cybersecurity risk assessment methodologies
  • ICT and third-party risk
  • incident response playbooks
  • audit-ready evidence flows
  • threat-informed risk scenarios
  • NIS2, DORA, ISO 27001, and operational resilience
  • AI-assisted, human-owned cyber risk work

Things I am building or exploring

I use GitHub mainly as a working space for small tools, research notes, and experiments around:

  • cyber risk assessment as code
  • incident response workflows
  • assurance and evidence management
  • MITRE ATT&CK / D3FEND mappings
  • OSCAL-based assessment ideas
  • local-first knowledge tools

Some repositories are intentionally exploratory: I use them to make reasoning, assumptions, and trade-offs visible while an idea is still being shaped.

Background

Cybersecurity Risk & Compliance specialist with a diploma in Electrical and Computer Engineering, an M.Sc. in Applied Mathematics, and experience across banking, telecommunications, and technology environments.

My path includes hands-on RF/IP network engineering, network operations leadership, security governance, and previous CISO responsibility. I like both the governance side of security and the practical side: building small tools, understanding how systems fail, and using CTF-style practice to keep technical intuition alive.

I am interested in the leadership layer of security as well: how technical risk, regulatory pressure, business constraints, and evidence come together in decisions that security leaders and CISOs have to own.

I care about work that is:

  • clear enough to be reviewed;
  • structured enough to be repeated;
  • practical enough to be used;
  • honest enough to show uncertainty.

How I work with AI

I use AI as an assistant for implementation, drafting, review, and structuring ideas.

The problem framing, methodology, risk logic, validation, and final decisions remain human-owned.

Pinned Loading

  1. ToBeDecidedLater ToBeDecidedLater Public

    Early-stage research workspace for threat-informed cyber risk scenarios, control mapping, evidence-based assurance, and OSCAL-oriented artifacts.

    Python

  2. 0xmichail 0xmichail Public

    Config files for my GitHub profile.