{"id":20,"date":"2024-04-06T20:38:25","date_gmt":"2024-04-06T20:38:25","guid":{"rendered":"https:\/\/wp.odu.edu\/odupresentationtemplate\/?page_id=2"},"modified":"2024-12-02T16:09:32","modified_gmt":"2024-12-02T16:09:32","slug":"aboutme","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/","title":{"rendered":"Final Paper"},"content":{"rendered":"\n<p><strong>Introduction:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>At the beginning of this year, I began searching for an internship in Cybersecurity specifically to help me fulfill the credit requirements for this class, CYSE 368. During this process, I did not have a specific company or role in mind due to my lack of knowledge about Cybersecurity and the industry in general. Aside from my experiences at ODU and TCC before this, I knew little about how exactly cyber professionals functioned on a day-to-day basis. Because of this, I really just wanted to be able to work at a company that was deeply involved in Cybersecurity so that I could learn more about what they do. I understand preventing of hacking and network defense, but it seemed like a job such as this would have a large amount of downtime when you are not being threatened. This was my primary learning goal no matter where I ended up working at, as this is obviously very pertinent to working in the field.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; In general, it was a long and arduous process trying to find an internship for myself. I spent the better part of a year applying and following up to job postings, to no avail. Eventually, as time was about to run out on me taking this class, I began correspondence with Professor Duvall. Though it took some time for us to work things out, she was eventually able to reach out to an acquaintance, Greg Tomchick at Valor Cybersecurity, who offered me a job. I am very grateful that she was able to do this, as this opportunity came just in the nick of time for me. On top of getting a chance to learn more about what cyber professionals actually do, I also wanted to learn more about vulnerabilities\/defense and how they do this at Valor. From an outsiders point of view, knowing about what kinds of attacks someone may be susceptible to and how to defend against them is probably the single most important part of Cybersecurity, which is why I wanted to learn about this as well.<\/p>\n\n\n\n<p>Additionally, going into my time at Valor, I knew that they were more of a company who outsources their work to other companies rather than working on cyber defense internally. Because of this, I wanted to know how exactly companies like this are able to outsource their assistance to other clients, and specifically focus on any of the difficulties involved with protecting their sensitive information. I also wanted to know more about what types of clients that they offer their services to. Initially, I assumed that most of them were going to be relatively small commercial companies that simply wanted to ensure that they were protected from outside attacks. Finally, in my interview with Greg before the internship, we began to talk about some of the things that we would potentially do during my time at Valor. One of them was exploring the impact of AI on the field of Cybersecurity, and we even planned to co-author a paper about our findings as an End-of-Year paper to be published by Valor. To fit into working on this project, I chose my final goal to be learning more about AI and it\u2019s impact of the cyber world. Leading up to my time at Valor, I had not fully considered the impact of AI on the field, and I surmised that this would be a suitable learning goal that could give me a broader point of view on the field. Overall, I was very happy to be starting my time at Valor Cybersecurity this fall, and I was eager to learn more about AI in Cybersecurity, how professionals operate in the field, known vulnerabilities and exploits, and how Valor interacts with its clientele.<\/p>\n\n\n\n<p><strong>About Valor:<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Before starting my employment at Valor Cybersecurity, I did some research to find out as much as I could about the company. From an initial search, it was clear that they primarily market their services towards small and medium sized businesses. This was not particularly surprising, as I also found that they have a very small workforce of only around ten employees. Their clients would generally turn towards Valor because \u201cthey start their journey with confusion (about Cybersecurity), a hunch that they may not be fully covered, or even a false sense of security.\u201d This makes complete sense to me, as a company would probably not reach out to someone for Cybersecurity unless they felt like they were inexperienced or at risk of an attack. However, it extends further than this. They follow this statement with: \u201cthey stay because they get continuous actionable insights to make informed decisions, allocate resources wisely, and build a robust cybersecurity strategy for the company\u2019s continued growth and success.\u201d So, it seems that they receive clients that want to make sure they are up to date and safe in their systems, but they do such a good job that the client continues to keep Valor in their back pocket for future situations, which is a great place to be as a company. Needless to say, I found this to be a very good method of business, and it is a great sign that a lot of companies come to Valor time and time again due to outstanding service. Going through a list of their clients, it seemed that many of them were indeed small companies, but they also frequently exchanged information with the government and military, which explains their need for higher levels of security. In particular, they highlighted their compliance and regulation protections, which I know are very important in order to deal with military and government clients. Some of the other benefits they offer are Risk analysis, reputation protection, competitive business advantages, and proactive defense. Learning more about what they offer to clients made me want to know more about the company itself and how\/why it was made.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Knowing about why and how the company was founded was my next goal, as I believed it would paint a better picture of why they do what they do and their motives and missions as a company. I found that the company was founded by none other than Greg Tomchick himself, the man that I would be interning under this semester. He started off as a Minor League Baseball player with an economic firm on the side as his primary source of income. However, tragedy eventually struck Greg\u2019s previous company. After he had retired from the MLB and was focusing on his business, it was devastated by a cyber-attack. His business was not very experienced with cybersecurity or keeping themselves safe, and the results of this attack showed it. In 2016, his company was attacked with devastating repercussions. Many customers lost money and had personal information leaked, large amounts of employees had to be let go, and in total, they lost over seventy-five thousand dollars that day. Within a short matter of time, Greg had no choice but to shut down the business for good. This loss of his business inspired him to bring change to others around him and ensure that they would not fall victim to the same mistakes he did. After a career pivot and a few years of cybersecurity experience under his belt, Greg would go on to found Valor Cybersecurity in Hampton Roads. He saw a gap in the market, where nobody else was offering this kind of outsourced protection in the area. There was not a single company to turn to the in the Hampton Roads area at the time that could have helped prevent this kind of attack. Because of this, he created Valor in an attempt to help others get through the struggles he did and be able to protect themselves against attacks. Personally, I think that this is a very noble cause that I can absolutely get behind. From how they make it sound, he takes it upon himself to help others where they could not help him, which I can deeply respect. Overall, doing this analysis into how Valor was founded and Gregs past only made me more excited to begin my time working at Valor Cybersecurity this upcoming semester.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Because of all I learned about Valor prior to meeting with Greg, I was very optimistic about my potential upcoming time working with him. My communications first started with him at the interview stage, and it was clear pretty early on to it that he was going to be taking me in, which I was overjoyed about. I didn\u2019t have a great idea of what I wanted to do in the industry, or what there even was to do for me at a place like Valor. Throughout the meeting, he bounced some ideas off of me such as researching vulnerabilities for clients, focusing on the impact of AI in the industry, or working hands on with various pieces of technology to understand how they function. He ensured that I could think about it, and we would meet up soon to discuss what I was going to be doing to begin my time at Valor. I felt as if this meeting was the breath of fresh air that I had been waiting for the entire time and was thrilled that I had been offered to come work with him for the semester.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; After a few weeks of back and forth and a few difficulties with scheduling, we were finally able to start focusing on what I would be doing. There was not necessarily an orientation or training for this job, which I did initially find somewhat confusing. I spent most of the first few weeks writing papers for him about where I see myself in the industry and a summary of my past experiences to see how they could best be applied towards his company in the coming months. It was a relatively slow start for the first couple of weeks, to say the least. To be entirely honest, these first few weeks had me apprehensive about how the rest of my time at Valor would go. A lot of our communication was between email, and the responses could sometimes be delayed days if not upwards of a week. I kept wondering when I could start getting into the meat of the internship, and the first few weeks of this did not have me feeling great about the future of my internship.<\/p>\n\n\n\n<p>We would not meet in his office in person for a few months after this, but I still feel as if it is relevant for this section. He works in a place that is a shared office space, where Valor and many other companies have their own sections to themselves and can rent out other space as necessary. I thought the place looked incredibly modern and was not what I was expecting from an office in cybersecurity. I pictured a more traditional looking office and was blown away with how cool the place looked. While I did not spend very much time in the office itself, I enjoyed the little time I did spend there and I find the concept of a shared office space very interesting.<\/p>\n\n\n\n<p><strong>Management Structure \u2013<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; During my time at Valor, I was incredibly isolated from the rest of the company. My communication was entirely through Greg, to the point where I did not even meet a single other person who worked at Valor during my months with them. This led to me not having a great picture of what exactly goes on at the company besides what he would tell me during my time there. The projects that I did complete were almost entirely remote as well, which I generally prefer. I only went out for meetings\/other projects about five times during the internship, which certainly has its pros and cons. For an internship such as this, I do feel as if I could have benefited from it being more in person. I think a remote job is best for things such as work-life balance, but this was not a priority for me during my time at Valor. I wanted to do as much as I possibly could to determine what I might want to do moving forward in the industry, and I feel as if a larger emphasis on in-person events could have fostered this in a better way. However, to his credit, Greg was a very supportive and helpful overseer during the work that I did. Since my communication was only through him, he was very receptive to feedback and questions, and encouraged me to do these things until I was satisfied with my level of knowledge for what we were doing. I found this to be of great benefit to me personally, and Greg did a great job of being very approachable, which is very important as my only point of contact in the entire company. He was also very lenient with deadlines for projects, to the point where I think it might have even been too lenient. I was given multiple weeks to finish some projects that would have only taken about five hours in total. However, I would of course prefer this to the alternative, and I am a college student with other priorities besides the internship after all. This caused the level of supervision to be relatively low, which might not work well for someone who is not disciplined to get the work done on time. This did work well for me though, and I think that the management was sufficiently effective in keeping me up to date on projects before the deadlines. In summary, while I would have preferred things to be slightly different in regard to the methods of interaction and management structure, I think it was orchestrated about as well as can be given the circumstances.<\/p>\n\n\n\n<p><strong>Major Work Duties:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>Like I described previously, most of the beginning of my internship experience was filled with him learning more about me. I wrote a few essays to help him understand more about my experiences and he used this to determine where he thought I would be a good fit in his company. The main point that I carried across in this paper about me is that I did not know much about the field, but I do like the idea of being able to help other people with cybersecurity. Even through just my college experience, it is clear that cybersecurity can be very difficult to understand from a students perspective, much less an outsider who knows nothing of the field. I emphasized that I think assisting people with this kind of thing would be a very fulfilling experience, and if I was searching for a job in the real world, it would probably be something to this degree.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/frst-paper.png\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"658\" src=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/frst-paper.png\" alt=\"\" class=\"wp-image-189\" srcset=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/frst-paper.png 624w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/frst-paper-284x300.png 284w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/frst-paper-600x633.png 600w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/a><\/figure>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; From this point, I began my first real project at Valor that I would be working on for the next few months. Valor has an up-and-coming program at their company that is referred to as \u201cBuild Your Legacy,\u201d which I would be working with closely from then on out. Build Your Legacy is a free program offered by Valor that they think points out the disconnect between employers and job seekers in the industry, and why so many people have such a hard time breaking into cyber in general. Greg and those at Valor believe that there is a fundamental skillset missing from many young people fresh out of college that the curriculum at these schools simply does not cover. They also think that many people may have the desired skills to land a job, but do not have the right idea with crafting their stories to make them appeal to the company. So, the main purposes of Build Your Legacy are to \u201cEquip you with the skills to scale into any cybersecurity area you choose and craft your unique cybersecurity story. So, no matter what happens in the economy, you\u2019ll have a valuable, income-generating skill set.\u201d<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Personally, I thought that this program that they were offering sounds great. I had a lot of trouble even getting my first job\/internship to fulfill the credit for this class, and this very well could be why. There are many unique skills and tips that this program offers that could help people in my situation immensely with finding their first job and breaking into the industry. With the free copy, they get the synopsis that helps you acquire these skills and a small mini course to put these skills to the test. And if the person wants to go further, they can begin paying for a \u201cPro Program\u201d that offers more direct support, such as access to the full course, group calls, newsletters and live shows, individual coaching calls, in person event access, and job placement assistance\/resume building tips. As for my opinion on this, the program was certainly less impressive to me after hearing this, to be honest. The program is advertised as a one size fits all way into the industry, but it essentially just gives you the framework of the program and then you must pay for more access. And it is not cheap in the slightest, coming in at $1000 per month for the above features. While it is certainly an important thing for your future and I am sure that they deliver on the expected level of quality, I was blown away by how much this was. When Greg had me look over the sites and ask questions\/give feedback about the structure, this was one of the first things I noted. Additionally, I was not the biggest fan of how the site was organized. It uses a lot of \u201cbuzzwords\u201d like \u201cUltimate Cybersecurity Playbook \u2013 A Controversial Bestselling Book,\u201d and in general, the site seemed like it existed to get a copy into their hands in unscrupulous ways. I especially was not a fan of the fact that every time you try to click off of the page, they hit you with a \u201cWait! Before you go\u2026 Send me your email and I\u2019ll rush a FREE copy of your playbook to build your legacy in cybersecurity.\u201d While I did not agree with the way the site was put together or the method of profit, I do at least appreciate that Greg specifically wanted to see what I thought about the site, as I would be our target demographic moving forward.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; After learning a bit about what the program had to offer, it was time for me to get to work. Greg requested that I write another paper for him, this time about how I would go about getting the program into the hands of other students at ODU. This was to be my target demographic during my time with the program, which we both thought was a good fit seeing as I am a student here. Most of the people that he was getting into the Build Your Legacy program were generally older, and looking more for a career pivot into cybersecurity rather than a student who is just about to start looking for their first jobs at\/around graduation time. I did some research into how I could best accomplish this, and my ideas were to use digital marketing on social media through a platform like LinkedIn, which is obviously more business and educationally focused compared to traditional media sites. I thought that this was a good way to help more people see the program, though not necessarily ODU students. In addition to this, I said that it would be a good idea to reach out to student clubs and organizations focused on cybersecurity to see if we could put our flier in their meeting rooms to help spread awareness of our program. I also thought that we could potentially implement a referral program of sorts to help students spread the word once they knew about and could recommend the program to others. Finally, I wanted to cooperate with faculty members to see if they could send out emails about this opportunity we had or even talk about it in one of their lectures.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/seond-paper.png\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"643\" src=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/seond-paper.png\" alt=\"\" class=\"wp-image-188\" srcset=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/seond-paper.png 624w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/seond-paper-291x300.png 291w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/seond-paper-600x618.png 600w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/a><\/figure>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>Following this, I began to ask around about ways that I could get more information about our program into the hands of ODU students, and I was shown a Cyber Hiring Event that was taking place on October 15 at ODU. I talked to Greg about this, and we agreed that we should both attend this event to help spread the word. Come October 15<sup>th<\/sup>, we met up for the first time in person to talk about Build Your Legacy with ODU students. He took the lead at the event, showing me how I should describe our program to the students and showing what parts I should push to interest them. Our program has the most benefit for Juniors and Seniors, so he advised to especially focus on them. We would start by handing out the flier and talking about our program being the missing link to cybersecurity curriculum and how this knowledge can help them easily transition into the cyber industry after college. It seemed to really be resonating with them, and almost all of the students that he talked to said that they would check it out afterwords. We also began accepting applications for an internship opportunity like I had for next semester, which is what many students came to the hiring event for. However, Greg was only able to stay for the first half of the event and informed me that I would have to run the booth by myself for the remainder of it. I was initially intimidated to be talking about a program that I am so new to, but this quickly faded after remembering how easy Greg made it sound to talk about. I began using many of the same talking points that he used to appeal to the students, and it was working for me to. As if I had not missed a beat, they took the same liking to the program under my description as when Greg was talking about it previously. Overall, I thought the event was a great success for spreading the word about our program, and we handed out at least fifty fliers to interested students.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/third-paper.png\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"838\" src=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/third-paper.png\" alt=\"\" class=\"wp-image-187\" srcset=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/third-paper.png 624w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/third-paper-223x300.png 223w, https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-content\/uploads\/sites\/36126\/2024\/12\/third-paper-600x806.png 600w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/a><\/figure>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; As my time at the event was ending, I decided to go one step further to getting our program more exposure. Even after handing out so many fliers to interested students, we still had way more to go. To help spread the word, I asked around about if there was something I could do to ensure these fliers end up someplace that students can see them after I left. I was able to find out that the Cyber Hangout Room seemed to be exactly what I was looking for, and I made sure that the fliers ended up there after the event in the hands of ODU staff. Greg was excited that I found a good place for the fliers to end up and requested that I visit the Cyber Hangout Room myself at the end of the following week to check it out and see if the fliers were garnering any interest. Upon following up, it seemed like a pretty decent setup for students to hangout, and there were already quite a few when I came in. There was a lot of stuff set up there, so it took me a bit of time to find it, but I eventually located our Valor fliers. It was propped up on a wall filled with many things happening in cyber at ODU and other opportunities that students could take interest in as well. Now, I do not have an exact account of how many papers we had before and after leaving them in the Cyber Hangout Room, but it did not seem as if the venue was drawing nearly the amount of traction we expected previously. There were very few, if any, papers missing from when I handed them off the week prior. I attribute this to the fact that there were all ready so many opportunities and other things for the students to take advantage of, that our program simply just fell to the wayside as a result. After this, I also reached out to a few other cyber organizations at ODU to see if they would also put some of our fliers in their meeting locations, but nothing productive ever came of this.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Around this time, I began submitting my 50-hour reflections for this class, and we concluded that neither me nor the professor were thrilled about the content of the internship. Personal opinions about the content of the program aside, I did not necessarily want to be focusing on marketing a product for the entirety of my internship experience. The professor agreed after reading my reflection, and through some discussion, we decided that I would be moving towards a more \u201ctechnical product\u201d in the coming weeks. During the downtime is when I did the few remaining things for the marketing strategy like checking up on the fliers and reaching out to more people about them. However, none of my strategies were ever really implemented nor did I see any sort of outcome of my work towards this, which was somewhat disappointing. Looking back on it now, I am not even positive that he saw the message about my work during this time, as I followed up on it over a week after no response and we simply moved into the next topic. It does seem like this Build Your Legacy program is a decent chunk of their business, as they supposedly have thousands of reviews based on their site, but I never really got the full scope of how important it was without seeing any numbers or results. Overall, I did not have the greatest time working with marketing and Build Your Legacy and was eager to move on to another project that I might resonate more with.<\/p>\n\n\n\n<p><strong>NOTE:<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; For the future projects I was asked to sign an NDA about the work I was doing and was told \u201cPlease keep in mind that&nbsp;you signed an NDA not to disclose to outside parties. Feel free to include your questions and you can feel free to describe that you are &#8220;helping Valor with balancing client decision making of the infrastructure to utilize in order to gain compliance with government regulations.&#8221;&nbsp;<\/p>\n\n\n\n<p>I can attest for you if Duvall has any specific questions but please do not include the specific slides or details of what we have come up with, as it is confidential.\u201d Because of this, I am not able to send specific pictures of what I have worked on and will have to keep the descriptions of my workings and results slightly more obscure. Please let me know if there is a problem with any of the content in the rest of this section and we can discuss it between myself and Greg potentially as well.<\/p>\n\n\n\n<p><strong>END NOTE<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Going into a potential new technical product, I was very excited about what I was going to be doing. I was finally moving out of the world of marketing, which I had decided I did not enjoy doing, and moving towards something hopefully more integrated into cybersecurity itself. He began with having me look at a spreadsheet that contained all sorts of compliance information, and evaluated a company based on how thoroughly they fulfilled the requirements. My work, however, was more focused on the mathematical side of things. Since I had a fair bit of knowledge with Excel, he wanted me to set up formulas to make navigation and number keeping easier for the company. So, I was tasked with making it so that the numbers for levels of compliance satisfaction were displayed in an easy-to-read table for the client, and if any of the criteria were changed in the technical table, it would instantly update for the client section as well. As this was more of a transitionary assignment, I did not expect much of it, and it was relatively simple and quick with my already established skillset. As for the value it brought to the company, I am sure that it is a useful addition to their sheet that they will use going forward, but I also think that this was a relatively simple fix that anyone at the company could have done given some time.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Though the previous project may have been short and simple, it led into what I would end up focusing on for the remainder of my time at Valor: Compliance. Essentially, there was a change in regulation in the government some time mid-October that required people to be much more serious about compliance when dealing with the government or military. The same sorts of regulations were still in effect, but they were enforced to a higher degree now, which meant that clients could not slack off when it comes to compliance. Because of this, Valor needed someone to reevaluate their options for compliance based on what the client needed and determine what would be the best way for them to follow compliance laws without disrupting their business ecosystem. To do this, I researched many of the different levels of compliance of things such as DoD, CMMC, ITARS, and DFS and determined how to pick and choose what the client needed to be compliant with based on what they were doing. And there were many systems offered to these clients, such as Microsoft\u2019s GCC High, Amazons AWS GovCloud, and quite a few others that all had differing levels of compliance with various things. I created charts and tables to help display this to both Valor and the customer on what the best platform to use would be for various clients depending on what ecosystems they were integrated in and what levels of compliance that they needed. Again, while I cannot share the specific findings of my work, I got the impression that my weeks of research would be invaluable to Valor going forward and would create a baseline for that they offer most clients going forward. Overall, though there were many ups and downs throughout my time at Valor Cybersecurity, I believe that I ended on a high note and finally got a taste of real cybersecurity work.<\/p>\n\n\n\n<p><strong>Application of Knowledge:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>If I had to narrow down a few of my skills that were relevant to my time at Valor Cybersecurity, I would say they were my general good work ethic and mannerisms, my knowledge of decent marketing strategies, and my familiarity with both Microsoft Office programs and proper research techniques. Starting with my work-related skills, I have always thought of myself as a sort of \u201cmodel student\/employee.\u201d Though I may not get everything right on my first try, I put in as much effort as I can to understand what I am doing and complete it to the best of my ability and punctually. I feel as if this was a necessary skill while working at Valor due to the freer form nature of the Internship. There was not much monitoring of myself during my various projects except a check in once every week or so. For a less motivated individual, this could result in them blowing off the work and potentially not completing it on time. I like to believe that I showed the upmost punctuality during my time at Valor, to the point where I might have been completing tasks faster than Greg could assign them to me. I have always believed that it is better to get things in too quickly and have nothing to do than be stressing about them over the whole period, and potentially procrastinating. We had absolutely no problems with any of my work-related skills to my knowledge, and I did every assignment to the best of my ability and in a punctual manner. I think another aspect of Valor\u2019s management that fostered this well was the fact that Greg was so open to, and even supported frequent questions to make sure I understood what I needed to do. This was especially helpful due to the fact that I had not had much other experience with departments such as marketing and compliance previously. To me, this was the single most valuable skill that I brought with me to Valor that could have easily spelled trouble for a less motivated individual.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Additionally, I think my general knowledge of good marketing techniques was also a great boon towards my creativity in the ideas department for Build Your Legacy. As I spend a large amount of time during my internship focusing on this aspect, it was important to for me to at least have a good framework for what I should be doing. The paper that I was instructed to write helped with this immensely, as it was a good place to start, running through each of the options that I could think of to get the word out. However, most of my ideas did not end up getting used, which is fine. After all, I was by no means a marketing guru and the ideas could have just been outside of Valor\u2019s scope. While we did not end up doing anything like creating social media platforms or offering referral program rewards, we did end up doing a fair bit with ODU organizations. Reaching out to professors and organizations within ODU were probably the two most impactful ideas that I came up with during the marketing section of my work, and we got a lot of positive results on both fronts. Coordinating with professors at ODU highlighted some events that we could use to spread the word, like the Cyber Hiring event that me and Greg both attended. We also were allowed to cooperate with the Cyber Hangout room to offer our flier in the common area for any students to see. And while I was not let into the specifics of how successful our endeavors were in this department; I like to believe that it was my ideas on that paper that led to our positive marketing experiences at ODU.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Finally, my experiences with Microsoft Office products and good research techniques were instrumental towards my success in the latter part of my internship. Thankfully, my strong understanding of Microsoft Excel fundamentals was key in my short math\/table rerouting assignment that I was given. My knowledge of how the functions worked within Excel was pivotal to creating what was needed for Valor in this project. I was able to set up the tables as Valor needed with ease, and this could have been much more difficult if I was not already proficient with the tools. My experience with PowerPoint was also relevant for my compliance slides that I made for Valor, to a lesser extent. A general understanding of how PowerPoint operates ensured that I had no technical difficulties when arranging my slides, allowing me to put my effort into making the content as reliable and accurate as possible. However, what was more important for my success with this final project was my knowledge of effective research procedures. To keep it brief, this was likely one of the more difficult pieces of research that I have ever done, for school or otherwise, due to the sensitive nature of the information at hand. It was relatively difficult to see anyone other than the company itself talk about the strength of the product, which makes it hard to get an unbiased opinion on the matter. It was also nearly impossible to find a price point for the compliance systems due to how intricate the matter can be with a wide range of factors effecting the price point. However, due to my previous experience with proper researching techniques, I was able to navigate all of the information I needed to present it to Valor and their future clients in a timely and effective manner. Overall, while my skills were not strictly related to cybersecurity experience, my good research techniques, program familiarity, marketing understanding, and good employee mannerisms contributed greatly to my smooth experience at Valor Cybersecurity this semester.<\/p>\n\n\n\n<p><strong>Relevance of ODU Curriculum:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>While I did not do a great amount of work that would have taken benefit from ODU\u2019s cybersecurity program skillset, there were quite a few pieces of my ODU\/TCC Curriculum that benefited me in my internship. For the marketing project that I was working on at the beginning of my time with Valor, my experiences in my public speaking class were very helpful for keeping a level head and communicating effectively. I had to talk to quite a few people to get the word out, whether it was by email, phone call, or face to face connection, and my previous experiences with public speaking helped me power through the nerves and focus on what I needed to say. In particular, this experience really came to light when we were running our booth at the Cyber Hiring Event. Despite my nerves affecting me greatly leading up to the event and before I was left to manage the booth alone, I was able to focus on exactly what I needed to do and how to show the students the strengths of our programs, due in no small part to my previous public speaking experience. While it is not a typical cybersecurity skill you may think of when it comes to what helped me, there is not doubt that I would have been much less confident in my speaking if I had not taken this course previously.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; In addition to public speaking, the reason that I was so familiar with Microsoft Office programs was due to the multiple classes that I had to take educating me about them. I had to take one of these classes at both TCC and ODU that ensured I understood how each of them operated. In particular the knowledge about Excel was by far the most useful. Many of the commands and programs that are used in Excel are not exactly beginner friendly, but the previous coursework I did on the subject greatly increased my familiarity with it, to the point where the functions that I had to create were no trouble at all.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If I had to pick a cybersecurity class specifically, I would probably look at the one that I am taking this semester: Cyber Policy and Strategy. During this class, we had to pick a policy that we found interest in and dissect all the moving pieces of it and give our opinions about it. This is where a lot of my recent research experience came from, as I spent a long time trying to research the U.S. Cybersecurity Strategy, with particular focus on the ethical, moral, and political implications of the policy. This is also tangentially related to my experience with compliance, as many of the degrees of compliance were touched on in the U.S.\u2019s program. Overall, while the work at my internship was not deeply integrated with cybersecurity, my previous class experiences were a great help in making almost all of my work at Valor easier to understand.<\/p>\n\n\n\n<p><strong>Learning Goal Reflection:<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; For the most part, I have found that I learned a lot of valuable information during my time at Valor, and most of my learning goals were fulfilled to a sufficient degree. The one that I was the most curious about was Learning more about how cybersecurity professionals function and understanding what they do at Valor, which I absolutely learned a ton about. Most of what Valor does is focused on helping clients and reinforcing compliance especially after the recent governmental changes. They also have the Build Your Legacy program as a side project, which I am even more familiar with after months of exposure. Personally, I would say I passed this learning objective with flying colors.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Next was learning about known vulnerabilities and exploits to keep Valor\u2019s clients safe, which I am much less confident about after my time there. The closest I can say I got to this was my work on compliance, which is only tangentially related to vulnerabilities and exploits. This was much more focused on how to get people compliant to communicate with the government and military, though of course protection came hand in hand with this. While I did learn about how to keep the clients safe, I did not learn much about what vulnerabilities and exploits to watch out for nor did I learn about them to a very convincing degree.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Thirdly, I planned to learn more about AI and its impact on the cyber works, and potentially collaborate on an end of year paper about it, which I did not do in the slightest. This was one of the ideas that Greg tossed around at the beginning of the interview process, and while I found it interesting, we did not end up working on anything related to AI. We also discussed co-authoring a different paper about our findings during the compliance research, but this never came to fruition either. Overall, this was easily the least explored learning objective, and I did not learn about AI in the slightest or co-author any paper at all.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Finally, my learning objective about understanding Valor\u2019s clientele and how they protect them ended up going hand in hand with the first objective. Most of what they do is interacting with clients and trying to protect them and get them compliant, which I spent multiple weeks dealing with. However, I do think I could have learned more about how they protect their clients and from what, as I was only focused on the compliance side of things. Overall, though my learning objectives did not end up being exactly what I spent my time on, I still think that I learned a lot of valuable information during my internship.<\/p>\n\n\n\n<p><strong>Exciting Parts of Internship:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>During my internship, by far the most exciting things I experienced were towards the end of my time, generally with the compliance project. This was my first taste of genuine cybersecurity work, and I had a great time with it. Even more exciting than this was a conversation I had with Greg recently about my future career prospects and how to get myself into the industry. He emphasized to me that many people find difficulty breaking into cyber because they are too broad in their goals and knowledge, which companies typically do not want. Companies want someone who knows what they want to do, and who specialize their knowledge to what they want to do for the company. For example, someone who knows they want to be a penetration tester and shifts their learning towards that is much more valuable than someone who is just aimlessly looking for a job in the field. To this end, I began thinking about where I wanted to start in cybersecurity. After reflecting on my past experiences, I realized that I would rather not be in the technical side of things, with coding and hacking at the forefront. I thought that this would be a staggering place to start out and could end up leaving me more confused than anything. In the end, I decided that I am going to try focusing on Governance, Risk-Analysis, and Compliance moving forward, based on my experience with Valor. I had a great time learning more about compliance with my project, and I think my knowledge and experiences will suit me well to breaking into the industry with ease. With Greg\u2019s help, I have tailored my resume and experiences to why I am a valuable candidate in this specific field, and I have hope that I will be able to seek higher employment opportunities soon after college. While it may not be the work that was the most exciting part for me, I found myself very excited about my future career prospects thanks to my knowledge that I accrued during my time at Valor.<\/p>\n\n\n\n<p><strong>Discouraging Parts of Internship:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>After some though and reflection, I have to say that the most discouraging and frustrating part of my experiences at Valor were with the communication aspect. As I have touched on briefly, Greg was not the best at responding to me in a timely manner. There were multiple cases where he did not respond to my communications for over a week, and when I sent a follow-up, he seemed to have not read all of my statements in the prior email. This ended up being very difficult for me, as a lot of the work that I was putting in almost seemed like it was not even being addressed. I understand that he is a busy man, but this did not make it any easier on me. Other than this, I did not really have any discouraging experiences at Valor, and it was overall a worthwhile experience.<\/p>\n\n\n\n<p><strong>Challenging Parts of Internship:<\/strong><\/p>\n\n\n\n<p><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <\/strong>While most of my experience was relatively straightforward, the most challenging part was definitely my work in the compliance section. Like I have stated previously, the sensitive nature of the topic made it much more difficult to find good information about compliance options compared to most research topics, especially when it came to the price point. However, my previous skills and experiences tied in nicely with this, and I was eventually able to present copious amounts of information that will be very valuable in Valor\u2019s future proceedings.<\/p>\n\n\n\n<p><strong>Recommendations for Future Interns:<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If I had to recommend one thing to a future intern, it would be to make sure that you are on top of things. The lack of surveillance over your position could easily lead to negligence, and it is important to stay on top of your work in order to not fall behind. Conversely, I would also recommend that you be a little more forceful about trying new things than I was. I think pushing to have more in person assignments and in the field work to do would be very valuable and teach you even more than I learned. This would also minimize the frustration of the poor communication experience if you were in person. I would also try more to focus on how and who the company operates with, as I never got to meet any of the clients or employees other than Greg and I do feel as if I may have missed out a little. In summary, as long as you stay on top of things and are okay to push out of your comfort zone, I am sure that and internship at Valor Cybersecurity would be very valuable to anyone in a similar position as me.<\/p>\n\n\n\n<p><strong>Conclusion:<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Overall, I think my experiences at Valor were incredibly useful for many of my future proceedings, and I am very thankful that I had the opportunity to work there. I am especially thankful once again to Professor Duvall who helped me secure this wonderful opportunity. I learned that while their may be frustrations and complications that you have to overcome in a workplace environment, the experiences and the knowledge you gain are well worth pushing past them. Breaking out of your comfort zone and trying new things is the best way to grow as a person, both personally and professionally. While I do not have much time left at ODU to be influenced by my internship, I would have mainly focused future class\/elective choices around a specific part of the field that I was interested in. For example, after learning that I was interested in GRC, I would have found what classes taught me more about these proceedings and used them to help further prepare for work after college. Again, one of the most valuable pieces of knowledge I learned was about structuring my future professional path, and I believe it was the piece of information I needed to get into cybersecurity proper. Specializing and tailoring your experiences to show employers why you are valuable in a specific industry seems to be one of the most important skills to have, and I will take it with me gladly. Overall, while there were some ups and downs during my semester at Valor Cybersecurity, the knowledge and skills I gained will help me for many years to come, and I wouldn\u2019t trade it for the world.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; At the beginning of this year, I began searching for an internship in Cybersecurity specifically to help me fulfill the credit requirements for this class, CYSE 368. During this process, I did not have a specific company or&#8230; <a class=\"more-link\" href=\"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":28911,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/pages\/20"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/users\/28911"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/comments?post=20"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/pages\/20\/revisions"}],"predecessor-version":[{"id":190,"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/pages\/20\/revisions\/190"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/zackmitchelleportfolio\/wp-json\/wp\/v2\/media?parent=20"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}