{"id":189,"date":"2026-08-17T03:51:48","date_gmt":"2026-08-17T03:51:48","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/?p=189"},"modified":"2026-08-17T03:51:48","modified_gmt":"2026-08-17T03:51:48","slug":"final-paper","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/2026\/08\/17\/final-paper\/","title":{"rendered":"Final Paper"},"content":{"rendered":"\n<p><strong><\/strong><\/p>\n\n\n\n<p>CYSE 368 \/ INTERNSHIP<br>Final Internship Paper<br>ITA International<br>Student: Michael Blanchard<br>Instructor: [ Teresa Duvall &amp; Jade Hines]<br>Internship Class: CYSE 368 \/ Internship<br>Term: Summer 2026<br>Date: August 9, 2026<br>Table of Contents<\/p>\n\n\n\n<ol>\n<li>Introduction \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026. 1<\/li>\n\n\n\n<li>Management Environment \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026 3<\/li>\n\n\n\n<li>Major Work Duties, Assignments, and Projects \u2026\u2026\u2026\u2026\u2026\u2026\u2026.. 4<\/li>\n\n\n\n<li>Use of Cybersecurity Skills and Knowledge \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026.. 6<\/li>\n\n\n\n<li>How the ODU Curriculum Prepared Me \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026 7<\/li>\n\n\n\n<li>Internship Outcomes and Objectives \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026 8<\/li>\n\n\n\n<li>Most Motivating or Exciting Aspects \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026.. 9<\/li>\n\n\n\n<li>Most Discouraging Aspects \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026 9<\/li>\n\n\n\n<li>Most Challenging Aspects \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026. 10<\/li>\n\n\n\n<li>Recommendations for Future Interns \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026.. 10<\/li>\n\n\n\n<li>Conclusion \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026.. 11<br>References \u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026\u2026 12<\/li>\n\n\n\n<li>Introduction<br>My internship at ITA International has been one of the most valuable experiences I<br>have had during my time at Old Dominion University. I decided to pursue this<br>internship because I wanted to experience cybersecurity outside of a classroom and<br>understand what the field actually looks like in a professional environment. I found<br>the ITA International internship on LinkedIn only a few hours after it was posted. I<br>applied because the position looked like an opportunity to combine cybersecurity,<br>quality, compliance, technology, and professional development. Looking back,<br>applying so quickly ended up being one of the best decisions I made during college<br>because the internship gave me the chance to work with experienced professionals and<br>see how cybersecurity connects to many different parts of an organization.<br>I completed my internship with ITA International in Newport News, Virginia,<br>working primarily with Glenn Mallo and Jim Stewart. My role allowed me to work on<br>projects involving CMMC, quality initiatives, databases, documentation, and the<br>company&#8217;s underwater data center work. Although the position was connected to<br>cybersecurity, it was not limited to the technical tasks that I originally associated with<br>cybersecurity. I learned that cybersecurity can involve compliance, quality assurance,<br>risk management, documentation, communication, process improvement, and making<br>sure that an organization can demonstrate that it is meeting required standards. This<br>broader understanding became one of the biggest takeaways from my internship.<br>ITA International is a technology-enabled professional services company<br>headquartered in Newport News, Virginia. The company describes itself as a global<br>service provider that combines subject matter expertise, data analytics, and technology<br>to support mission success. Its capabilities include operations, training, engineering,<br>cyber support, intelligence, data analytics, statistics, machine learning, software<br>engineering, and sustainability-related services. ITA has long-standing relationships<br>with government customers, including organizations within the Department of<br>Defense and Department of Homeland Security. The company also supports<br>customers through technology-enabled professional services rather than relying on a<br>single product or service. This makes the company a good environment for an intern<br>because the work can involve many different disciplines at the same time (ITA<br>International, 2026a).<br>ITA International was founded in the early 2000s and developed from a<br>marine-focused business into a broader provider of integrated professional and<br>technical services. Public company information identifies ITA as a Newport<br>News-based organization with a global presence. The company&#8217;s history also shows a<br>progression toward data analytics and technology-enabled services. For example, ITA<br>has supported federal customers through large data analytics and engineering efforts<br>and has continued expanding its technology and mission-support capabilities. In 2025,<br>ITA International was also recognized for its CMMI Development Maturity Level 3<br>appraisal, which reflects the organization&#8217;s emphasis on established processes and<br>continuous improvement (ITA International, 2025).<br>The customers served by ITA are different from the customers of a typical<br>commercial technology company. A significant part of ITA&#8217;s work supports<br>government and national-security missions. Its public materials identify relationships<br>with the Department of Defense and Department of Homeland Security, while its<br>recent contract announcements show continued involvement in major federal<br>programs. In January 2026, ITA announced that it had been awarded a position on the<br>Missile Defense Agency&#8217;s SHIELD IDIQ contract, which has a ceiling of $151<br>billion. The announcement described the contract as supporting rapid delivery of<br>innovative capabilities for homeland defense and warfighter missions (ITA<br>International, 2026b). This environment helped me understand that cybersecurity and<br>quality are especially important when an organization works with sensitive<br>information and government requirements.<br>When I first arrived at ITA International, one of my biggest impressions was that<br>the workplace felt much more professional and collaborative than what I was used to<br>in a classroom. I was introduced to the people I would be working with, learned about<br>expectations, and began becoming familiar with the organization&#8217;s work and<br>processes. My initial training included learning how work was organized,<br>understanding the projects I would be supporting, reviewing information related to<br>quality and cybersecurity, and learning how to communicate professionally. I also had<br>to become comfortable with asking questions and taking notes because there were<br>many terms and processes that were new to me.<br>My initial impression was also that there was much more to cybersecurity than I<br>had previously understood. Before the internship, when I heard the word<br>cybersecurity, I mainly thought about protecting computers, networks, accounts, and<br>data from attacks. Those areas are still important, but ITA showed me the business<br>side of cybersecurity. A secure organization needs policies, procedures, evidence,<br>documentation, quality controls, trained employees, risk management, and continuous<br>improvement. Cybersecurity has to be integrated into the way an organization<br>operates rather than treated as a separate task.<br>There were several learning outcomes and objectives that I wanted to achieve<br>during the internship. First, I wanted to develop a better understanding of how<br>cybersecurity knowledge is applied in a real organization, especially through<br>compliance and CMMC-related work. Second, I wanted to improve my professional<br>communication, teamwork, and ability to work with experienced professionals. Third,<br>I wanted to strengthen my ability to apply quality assurance, documentation, database,<br>and process-improvement skills to cybersecurity-related work. These objectives gave<br>me a direction for the internship, but the experience ultimately taught me more than I<br>expected.<br>This paper explains my internship experience from beginning to end. It discusses<br>the management environment, my major duties and projects, my use of cybersecurity<br>skills, connections to the Old Dominion University curriculum, and the extent to<br>which my learning objectives were fulfilled. It also discusses what motivated me,<br>what discouraged me, what challenged me, and what I would recommend to another<br>student preparing for the same type of internship. Most importantly, the paper explains<br>how this experience changed the way I understand cybersecurity and how it has<br>influenced the professional direction I want to take after college.<\/li>\n\n\n\n<li>Management Environment<br>The management environment at ITA International was one of the strongest parts<br>of my internship. I worked closely with Glenn Mallo and Jim Stewart, and their<br>supervision gave me a balance between guidance and independence. I was not<br>expected to know everything when I arrived. Instead, I was given opportunities to<br>learn, ask questions, complete assignments, and gradually take more ownership of my<br>work. This was important because one of my goals was to become more confident in a<br>professional setting.<br>The organization operates across several areas of expertise, so management<br>naturally involves coordination between different groups. ITA&#8217;s public description of<br>its organizational structure and services shows that the company brings together<br>operations, engineering, training, cyber, intelligence, data analytics, and<br>software-related capabilities. The company&#8217;s 2023 organizational changes were<br>specifically intended to improve customer focus, collaboration, and shared success.<br>That structure matched what I experienced because many assignments required<br>communication between people with different responsibilities (ITA International,<br>2023).<br>Glenn and Jim were effective supervisors because they were available when I<br>needed direction while also allowing me to learn through the work itself. When I did<br>not understand a task, I could ask questions and receive clarification rather than being<br>expected to guess. At the same time, I was encouraged to think through problems and<br>become more independent. This approach helped me realize that good supervision is<br>not simply telling an employee what to do. It is also about developing the employee&#8217;s<br>ability to solve problems, communicate, and make decisions.<br>Another important part of the management environment was communication. I saw<br>how meetings, emails, documentation, and informal conversations were all part of<br>keeping projects moving. I learned that a project can be technically correct and still<br>have problems if people are not communicating clearly. In cybersecurity, this is<br>especially important because a security issue may involve technical staff,<br>management, quality personnel, compliance personnel, and other departments.<br>Everyone needs to understand their responsibilities.<br>Overall, I believe the management environment was effective for an internship<br>because it gave me access to experienced professionals without making me feel like I<br>was expected to already be an expert. I was able to learn from the people around me<br>and gradually become more comfortable contributing. This environment also showed<br>me what I should look for in a future workplace: strong communication,<br>accountability, mentorship, teamwork, and managers who are willing to teach.<\/li>\n\n\n\n<li>Major Work Duties, Assignments, and Projects<br>My internship duties covered several different areas. The major categories of work<br>included CMMC projects, quality initiatives, database-related work, documentation,<br>and support for ITA International&#8217;s underwater data center project. Having multiple<br>types of assignments was valuable because it prevented me from thinking of<br>cybersecurity as one specific job function. Each project required a different way of<br>thinking, but they all connected to the larger goal of helping an organization operate<br>securely, consistently, and effectively.<br>One of my main areas of work was supporting CMMC-related projects. CMMC, or<br>the Cybersecurity Maturity Model Certification program, is important to organizations<br>in the defense industrial base because it establishes cybersecurity requirements<br>associated with protecting certain federal information. During the internship, I learned<br>more about the importance of organizing evidence, understanding requirements,<br>documenting processes, and checking whether an organization can demonstrate that<br>its practices meet expectations. This was different from studying cybersecurity<br>standards in class because I was seeing the administrative and operational work<br>required to prepare for compliance.<br>CMMC work is necessary to a company such as ITA because compliance is<br>connected to its ability to support government customers and protect sensitive<br>information. It is not enough for an organization to say that it is secure. It needs<br>repeatable processes and evidence showing how security requirements are addressed.<br>My work helped me see why documentation matters. A missing document, outdated<br>procedure, or incomplete piece of evidence can create additional work and potentially<br>create risk. This made me more careful with details in every other assignment.<br>I also worked on quality initiatives. Before this internship, I did not naturally<br>connect quality assurance with cybersecurity. I now understand that the two areas<br>overlap significantly. Quality management involves making sure processes are<br>defined, followed, measured, documented, and improved. Cybersecurity also depends<br>on reliable processes. If a company has a security procedure but employees do not<br>follow it consistently, the procedure does not provide much protection. Quality<br>therefore supports cybersecurity by helping organizations create repeatable and<br>dependable processes.<br>Database work was another valuable part of my internship. Working with<br>information in databases helped me understand that data management is not simply<br>about storing information. Organizations need accurate information, consistent<br>formats, appropriate access, and processes for maintaining that information. From a<br>cybersecurity perspective, data should also be protected against unauthorized access,<br>alteration, or loss. Even when a database assignment did not look like a traditional<br>cybersecurity task, it still required me to think about accuracy, organization, access,<br>and the importance of information.<br>I also supported work related to ITA International&#8217;s underwater data center project.<br>The project was particularly interesting because it combined technology, engineering,<br>quality, environmental conditions, data, and cybersecurity. An underwater data center<br>has unique challenges because equipment operates in a remote and physically<br>demanding environment. Maintenance, monitoring, reliability, network performance,<br>physical protection, and cybersecurity all have to be considered together. My work on<br>this project helped me understand how cybersecurity can become part of a larger<br>engineering and quality problem rather than existing separately.<br>The underwater data center project also gave me the opportunity to think about<br>predictive maintenance and monitoring. Sensors and data could potentially be used to<br>monitor conditions such as temperature, pressure, power consumption, cooling<br>performance, vibration, water intrusion, and network performance. If unusual activity<br>is detected, personnel could investigate before a larger failure occurs. From a<br>cybersecurity perspective, connected sensors and remote systems also create security<br>considerations. Devices must be protected, communications need to be secure,<br>software updates need to be controlled, and access needs to be managed.<br>Another area of work involved documentation and written communication. I<br>contributed to materials that required information to be organized clearly for other<br>people to understand and use. This taught me that professional writing is different<br>from writing an assignment for a class. A workplace document needs to be accurate,<br>concise, useful, and understandable to its intended audience. It may become part of a<br>process, training material, evidence package, or communication between departments.<br>Because of that, I learned to pay more attention to wording and details.<br>Each of these duties was necessary to the organization for a different reason.<br>CMMC work supported compliance and cybersecurity requirements. Quality<br>initiatives supported reliable processes and continuous improvement. Database work<br>supported information management. Documentation supported communication and<br>organizational knowledge. The underwater data center work supported research and<br>development of innovative technology. Even though the assignments were different,<br>they all showed me that a successful organization depends on many connected pieces<br>working correctly.<br>One of the biggest lessons from these assignments was that cybersecurity is a team<br>effort. I saw people with different areas of expertise working toward the same goal.<br>Someone might understand a technical issue better, while someone else understands<br>quality, compliance, operations, or a customer&#8217;s requirements. The best outcome<br>comes from combining those perspectives. This experience changed the way I think<br>about cybersecurity careers because I no longer see the field as only technical work<br>performed by someone sitting at a computer.<\/li>\n\n\n\n<li>Specific Use of Cybersecurity Skills and Knowledge<br>I entered the internship with a foundation in cybersecurity from my coursework at<br>Old Dominion University. I already understood basic concepts such as confidentiality,<br>integrity, availability, access control, risk, network security, security policies,<br>vulnerabilities, and the purpose of cybersecurity frameworks. I also had experience<br>researching cybersecurity topics, writing technical assignments, working with<br>computers, and learning how security controls are designed to reduce risk. These<br>skills gave me a starting point, but the internship showed me how different it can be to<br>apply those concepts in a real organization.<br>The most direct cybersecurity connection was my work with CMMC-related<br>projects. I had learned about cybersecurity frameworks and compliance in school, but<br>the internship showed me the amount of work required to translate requirements into<br>real organizational practices. I learned that cybersecurity compliance involves more<br>than knowing what a requirement says. People have to understand the requirement,<br>identify the organization&#8217;s current practices, create or maintain documentation, collect<br>evidence, identify gaps, communicate findings, and make improvements. That process<br>helped turn an abstract concept from class into something I could understand<br>practically.<br>I also used skills involving risk awareness and attention to detail. When reviewing<br>information or working with documentation, I learned to think about what could go<br>wrong if information was incomplete or inaccurate. I became more aware of the<br>importance of version control, consistency, and making sure that information could be<br>understood by someone else. These habits are important in cybersecurity because<br>security decisions often depend on accurate information.<br>The internship also required skills that I had not fully developed before starting.<br>One of those skills was professional communication. I had communicated with<br>classmates and professors, but communicating with coworkers in a professional<br>environment is different. I had to listen carefully, take useful notes, ask appropriate<br>questions, write professional messages, and understand when I needed clarification. I<br>also had to become comfortable speaking about work even when I was still learning<br>the subject.<br>Another skill I developed was the ability to research unfamiliar concepts<br>independently. There were many terms and processes that I had not encountered<br>before. Instead of expecting someone else to explain everything, I learned to take<br>notes, search for reliable information, review documentation, and then return with<br>specific questions. This helped me become more independent. I realized that a<br>cybersecurity professional will never know everything because the technology and<br>threats continue to change.<br>My understanding of cybersecurity changed significantly because of the internship.<br>Before ITA, I viewed cybersecurity primarily as technical protection. Now I see<br>cybersecurity as a combination of people, processes, technology, compliance, risk<br>management, and continuous improvement. A firewall or security tool can be useful,<br>but it cannot replace good procedures, trained employees, accurate documentation,<br>and responsible management. The internship made cybersecurity feel more like an<br>organizational discipline instead of only a technical discipline.<br>The quality work especially changed my understanding. I learned that a quality<br>program can support cybersecurity by creating consistency. When processes are<br>documented and employees follow them, an organization has a better chance of<br>knowing what is happening and identifying problems. Continuous improvement also<br>applies to cybersecurity because controls cannot simply be created once and forgotten.<br>Organizations have to review their processes, respond to changes, and improve over<br>time.<br>The underwater data center project also expanded my view of cybersecurity into<br>operational technology and emerging technology. A system that combines computers,<br>sensors, networking, engineering equipment, and remote monitoring has both physical<br>and digital risks. Cybersecurity has to account for the entire environment. This made<br>me more interested in areas where cybersecurity overlaps with engineering, critical<br>infrastructure, data analytics, and emerging technologies.<\/li>\n\n\n\n<li>How the ODU Curriculum Prepared Me<br>The Old Dominion University cybersecurity curriculum prepared me for the<br>internship by giving me a foundation in security concepts and by requiring me to think<br>about problems from different perspectives. My classes taught me vocabulary and<br>concepts that became easier to recognize once I encountered them at ITA<br>International. Topics involving cybersecurity principles, risk, ethics, networks,<br>security controls, and information systems gave me a framework for understanding<br>the work I was seeing.<br>One of the strongest connections was between coursework involving cybersecurity<br>frameworks and the CMMC work I supported. In school, frameworks can sometimes<br>feel like lists of requirements that need to be memorized. At ITA, I saw why<br>frameworks exist and how they influence an organization&#8217;s processes. The internship<br>helped me understand that frameworks are useful because they give organizations a<br>structured way to identify and manage security risks.<br>My coursework also prepared me to research and learn independently. College<br>assignments often require finding sources, comparing information, and explaining a<br>topic in writing. Those same skills were useful at ITA when I encountered unfamiliar<br>subjects. I was able to take a question, research it, organize what I found, and<br>communicate the information in a useful way. This was especially important because I<br>was exposed to topics that were outside my normal classroom experience.<br>At the same time, the internship revealed areas that classroom learning cannot fully<br>reproduce. School assignments generally have clear instructions, deadlines, and<br>expected outcomes. A workplace project may change as new information becomes<br>available. A manager may ask for something different from what you originally<br>expected. A document may need to be revised several times. You also have to work<br>with other people whose priorities and schedules may be different from yours. These<br>realities taught me skills that are difficult to learn only through coursework.<br>The internship reinforced the importance of communication and teamwork. In<br>school, group projects provide some experience with teamwork, but the professional<br>environment has different expectations. At ITA, communication was directly<br>connected to getting work completed and supporting organizational goals. I learned<br>that being technically capable is not enough if I cannot explain what I am doing, ask<br>for help, or work with people from other areas.<br>The internship also introduced me to concepts that I had not fully encountered in<br>school, particularly the connection between quality management, cybersecurity<br>compliance, and emerging technologies. I had learned about security controls and<br>frameworks, but I had not previously thought deeply about how quality systems<br>support security. I also had limited exposure to underwater data center technology.<br>Seeing those areas together helped me understand that a cybersecurity career can<br>involve much more than the topics that are normally associated with entry-level<br>security jobs.<br>Overall, ODU gave me the foundation I needed, but ITA gave me the context.<br>School helped me understand the language and basic concepts of cybersecurity. The<br>internship helped me understand how those concepts affect real people, projects,<br>organizations, and customers. I believe both experiences are necessary. Without<br>school, I would have had less background knowledge. Without the internship, I would<br>have had a much weaker understanding of how cybersecurity operates in the<br>workplace.<\/li>\n\n\n\n<li>Internship Outcomes and Objectives<br>The first objective I identified at the beginning of the internship was to develop a<br>stronger understanding of how cybersecurity is applied in a real organization. I believe<br>this objective was fully achieved. My work with CMMC, documentation, quality<br>initiatives, databases, and the underwater data center project showed me that<br>cybersecurity is integrated into many business processes. I learned that security is not<br>only about responding to attacks. It is also about preventing problems, managing risk,<br>meeting requirements, protecting information, and creating reliable processes.<br>The second objective was to improve my professional communication, teamwork,<br>and confidence. This objective was also fulfilled. When I first started, I was<br>sometimes nervous about asking questions or speaking up because I did not want to<br>seem like I did not know enough. As the internship continued, I realized that asking<br>questions is part of learning. I became more comfortable communicating with<br>coworkers and supervisors. I also became better at taking notes, following up on<br>assignments, and explaining what I understood.<br>The third objective was to strengthen my ability to apply quality, documentation,<br>database, and process-improvement skills to cybersecurity-related work. This<br>objective was fulfilled and went beyond what I expected. The quality side of the<br>internship showed me how process improvement can support security. Database work<br>taught me the importance of accurate and organized information. Documentation<br>taught me the importance of creating clear evidence and instructions. CMMC work<br>connected these skills directly to cybersecurity and compliance.<br>A fourth outcome that developed naturally during the internship was increased<br>professional independence. I learned to look for answers before immediately asking<br>someone else, while still recognizing when a question needed to be escalated. I<br>became better at researching unfamiliar topics and organizing my work. This was<br>important because cybersecurity professionals have to be able to learn continuously.<br>Technology changes too quickly for someone to depend only on what they learned in<br>college.<br>The internship also fulfilled an outcome that I did not fully anticipate: learning<br>more about the different career paths within cybersecurity. Before ITA, I knew I<br>wanted a cybersecurity career, but I was less certain about what type of work I wanted<br>to pursue. After seeing compliance, quality, data, emerging technology, and technical<br>work together, I have a better understanding of the options available to me. I am now<br>more interested in roles that allow me to combine cybersecurity knowledge with<br>analysis, compliance, technology, and problem solving.<\/li>\n\n\n\n<li>Most Motivating or Exciting Aspects<br>The most motivating part of the internship was being trusted to contribute to real<br>work. There is a major difference between completing an assignment for a grade and<br>knowing that the information you are working on is connected to an actual<br>organization and its projects. That responsibility motivated me to take my work<br>seriously and pay closer attention to details.<br>I was also excited by the variety of projects. Working on CMMC, quality<br>initiatives, databases, documentation, and underwater data center research meant that I<br>was constantly learning something new. The underwater data center project was<br>especially interesting because it connected cybersecurity with technology,<br>engineering, data, and environmental challenges. It made me realize that cybersecurity<br>can be involved in innovative projects that I would not have expected when I first<br>chose the major.<br>Another motivating aspect was seeing experienced professionals work. Glenn and<br>Jim helped me understand how professionals approach problems, communicate, and<br>make decisions. Watching them gave me a better idea of the type of professional I<br>want to become. It also made me appreciate the value of mentorship. I learned that<br>sometimes the best way to understand a subject is to watch someone who has been<br>working with it for years and then ask questions about why they do things a certain<br>way.<br>Finally, seeing my own growth was motivating. At the beginning, I was more<br>hesitant and unsure. By the end, I was more comfortable asking questions, completing<br>tasks, and discussing what I had learned. Knowing that I had developed during the<br>internship gave me more confidence in my ability to succeed after graduation.<\/li>\n\n\n\n<li>Most Discouraging Aspects<br>The most discouraging part of the internship was realizing how much I still did not<br>know. There were times when I was exposed to a new term, process, or project and<br>initially felt behind. It can be difficult to compare yourself with experienced<br>professionals who have years of knowledge when you are still a college student. I<br>sometimes questioned whether I was learning fast enough.<br>Another discouraging aspect was that some work was less exciting than the<br>projects I was most interested in. Documentation, reviewing information, organizing<br>data, and repetitive quality tasks are not always as exciting as working directly with<br>technology. However, I eventually realized that these tasks are necessary.<br>Cybersecurity involves a lot of careful work that may not look exciting but has a<br>major effect on the organization&#8217;s security and reliability.<br>I also found it difficult when I could not immediately see the final result of a<br>project. Some professional projects take time, involve multiple people, or continue<br>after an intern&#8217;s assignment is finished. In school, you usually submit an assignment<br>and receive a grade. At work, a project may continue through several stages. Learning<br>to be patient and understand my role within a larger process was part of my<br>professional growth.<br>Even though these experiences were discouraging at times, they ultimately helped<br>me develop a healthier attitude toward learning. I stopped viewing not knowing<br>something as a failure. Instead, I started viewing it as a reason to ask questions,<br>research the topic, and improve.<\/li>\n\n\n\n<li>Most Challenging Aspects<br>The biggest challenge was keeping up with the amount of information I<br>encountered. Cybersecurity has a large vocabulary, and CMMC, quality management,<br>databases, and emerging technology each have their own terminology. I had to learn<br>how to separate what I needed to understand immediately from information that I<br>could research later. Taking notes became one of my most useful habits.<br>Another challenge was learning to manage my time and priorities. Multiple<br>assignments can require attention at the same time, and not every task has the same<br>urgency. I had to become better at organizing what needed to be completed first and<br>making sure that I did not lose track of smaller responsibilities. This is a skill I know<br>will continue to matter throughout my career.<br>The professional standard for accuracy was also challenging. In school, a small<br>mistake on an assignment may result in losing a few points. In a professional<br>environment, a mistake in documentation or information can create additional work or<br>affect a larger process. I learned to slow down, review my work, and make sure that I<br>understood what I was submitting before considering the task finished.<br>The final challenge was becoming comfortable with uncertainty. Not every<br>problem has an immediate answer. Sometimes the right response is to research, ask<br>someone, test an idea, or wait for more information. I learned that being a professional<br>does not mean always having the answer. It means knowing how to find the answer<br>and knowing when to ask for help.<\/li>\n\n\n\n<li>Recommendations for Future Interns<br>My first recommendation for future interns is to come prepared to learn rather than<br>expecting to already know everything. An internship is designed to provide<br>experience, so students should not be embarrassed by the fact that they have<br>questions. At the same time, interns should make an effort to research topics<br>independently before asking for help when appropriate. This shows initiative and<br>helps the student learn faster.<br>Second, future interns should take notes. There is too much information in a<br>professional environment to remember everything after one meeting or conversation.<br>Writing down terms, instructions, questions, and follow-up items makes it easier to<br>stay organized. I would recommend keeping a running list of unfamiliar concepts and<br>researching them after work or when there is time.<br>Third, students should strengthen their professional communication before<br>beginning. This includes learning how to write professional emails, communicate<br>respectfully, ask clear questions, participate in meetings, and explain what they are<br>working on. Technical knowledge is important, but communication determines how<br>effectively that knowledge can be used with a team.<br>Fourth, future interns should review cybersecurity frameworks and basic<br>compliance concepts before starting. Students do not need to be experts, but<br>understanding concepts such as risk management, access control, policies, procedures,<br>evidence, and security controls will make CMMC-related work easier to understand.<br>Reviewing the NIST Cybersecurity Framework and learning the basic purpose of<br>CMMC would also provide useful background.<br>Fifth, future interns should become comfortable with Microsoft Office and general<br>data organization. Excel, Word, PowerPoint, databases, spreadsheets, and<br>documentation are common parts of professional work. An intern who can organize<br>information clearly and produce professional documents will be more useful to a<br>team.<br>Sixth, future interns should be dependable. Showing up on time, meeting deadlines,<br>responding to communication, and following through on assignments may seem basic,<br>but these behaviors build trust. Once supervisors know they can depend on an intern,<br>they are more likely to give that intern additional responsibilities and opportunities to<br>learn.<br>Finally, I would recommend that future interns take advantage of the people around<br>them. Experienced coworkers are one of the most valuable resources available during<br>an internship. Ask questions, listen to their experiences, and learn how they approach<br>problems. An intern should leave with more than completed assignments; they should<br>leave with a better understanding of how professionals think and work.<\/li>\n\n\n\n<li>Conclusion<br>My internship at ITA International has been one of the most important experiences<br>of my college career. I entered the internship wanting to learn what cybersecurity<br>looked like in a real workplace, and I left with a much broader understanding of the<br>field. I learned that cybersecurity is not only about networks, computers, and attacks.<br>It also includes compliance, quality assurance, documentation, risk management, data,<br>communication, teamwork, and continuous improvement.<br>Working with Glenn Mallo and Jim Stewart gave me the opportunity to learn from<br>professionals while developing confidence in my own abilities. I became more<br>comfortable asking questions, researching unfamiliar topics, communicating with<br>coworkers, and taking responsibility for my assignments. I also learned that being a<br>professional does not mean knowing everything. It means being willing to learn, being<br>dependable, and taking the initiative to find answers.<br>The CMMC projects were especially important because they changed how I<br>understand cybersecurity compliance. I learned that meeting cybersecurity<br>requirements involves much more than knowing what the requirements say.<br>Organizations have to build processes, maintain documentation, collect evidence,<br>identify weaknesses, and continuously improve. The quality work reinforced this<br>lesson because it showed me how consistency and process improvement support<br>security.<br>The underwater data center project also had a major impact on me. It showed me<br>that cybersecurity can be part of emerging technology and engineering projects. When<br>systems combine sensors, networks, data, physical equipment, and remote operations,<br>security has to be considered from multiple angles. This experience made me more<br>interested in cybersecurity roles that connect technology with analysis, compliance,<br>engineering, and problem solving.<br>The internship will influence the remainder of my time at Old Dominion University<br>because I now have a clearer reason for learning the material in my classes. Topics<br>that once seemed like requirements for a degree now have real examples behind them.<br>When I study cybersecurity frameworks, risk, networks, databases, or security<br>controls, I can connect those subjects to things I have actually seen in a professional<br>environment. This will help me approach the rest of my college work with more<br>purpose.<br>The experience will also influence my professional path after graduation. Before<br>the internship, I knew I wanted a career in cybersecurity, but I was less certain about<br>the direction. Now I understand that there are many opportunities beyond traditional<br>technical security positions. Compliance, governance, risk management, quality, data<br>analytics, security assessment, and technology-focused roles are all areas that interest<br>me more because of what I experienced at ITA.<br>Most importantly, this internship gave me confidence. I started the experience<br>wondering whether I knew enough to contribute. By the end, I understood that I have<br>a strong foundation and the ability to continue learning. I still have a lot to learn, but I<br>no longer see that as a weakness. Cybersecurity is a field where learning never really<br>stops. My goal is to continue building my technical skills while also developing the<br>communication, professional judgment, and problem-solving abilities that I gained at<br>ITA International.<br>I am genuinely thankful to ITA International for giving me this opportunity. I<br>appreciate Glenn Mallo and Jim Stewart for their guidance and for allowing me to<br>experience professional work instead of only learning about it in a classroom. I am<br>also thankful to everyone at ITA who made the internship a welcoming learning<br>environment. This experience has helped me become more professional, more<br>confident, and more aware of what I want from my future career. I will carry the<br>lessons from this internship with me through the rest of my time at ODU and into my<br>professional life.<br>References<br>ITA International. (2023, September 12). ITA International announces new<br>organizational changes to enhance customer focus. ITA International.<br>https:\/\/ita-intl.com\/ita-international-announces-customer-focus-org-changes\/<br>ITA International. (2025, July 28). ITA International appraised at CMMI<br>Development Maturity Level 3 for the second time. ITA International.<br>https:\/\/ita-intl.com\/<br>ITA International. (2026a). ITA International: Operationalizing data to improve the<br>world. https:\/\/ita-intl.com\/<br>ITA International. (2026b, January 20). ITA International awarded position on<br>Missile Defense Agency SHIELD IDIQ contract. ITA International.<br>https:\/\/ita-intl.com\/ita-international-awarded-position-on-missile-defense-agenc<br>y-shield-idiq-contract\/<br>ITA International. (2026c). ITA Careers. https:\/\/ita-intl.com\/ita-careers\/<br>Virginia Business. (2020, August 25). Newport News-based ITA awarded $50M<br>contract.<br>https:\/\/virginiabusiness.com\/newport-news-based-ita-awarded-50m-contract\/<br>Virginia Business. (2025, March 26). Virginia Chamber\u2019s DuVal to lead new ITA<br>venture.<br>https:\/\/virginiabusiness.com\/virginia-chambers-duval-to-lead-new-ita-venture\/<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>CYSE 368 \/ INTERNSHIPFinal Internship PaperITA InternationalStudent: Michael BlanchardInstructor: [ Teresa Duvall &amp; Jade Hines]Internship Class: CYSE 368 \/ InternshipTerm: Summer 2026Date: August 9, 2026Table of Contents<\/p>\n","protected":false},"author":27275,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/posts\/189"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/users\/27275"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/comments?post=189"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/posts\/189\/revisions"}],"predecessor-version":[{"id":190,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/posts\/189\/revisions\/190"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/media?parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/categories?post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/cyse368-mblan013\/wp-json\/wp\/v2\/tags?post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}