top of page

  Springboard Cybersecurity Trainee Project:  
Cloud Architecture & Deployment Strategy

Evaluated public, private, and hybrid cloud architectures to compare their security, scalability, accessibility, and cost-effectiveness for enterprise environments. The project analyzed the advantages, limitations, and ideal use cases for each deployment model while examining cloud provider responsibilities under the shared responsibility model. It also explored how organizations can balance security, regulatory compliance, and operational efficiency when selecting a cloud strategy, demonstrating a foundational understanding of cloud computing concepts aligned with NIST guidance.

  Springboard Cybersecurity Trainee Project:  
Zero Trust Security Strategy

Created a presentation explaining the core principles of the Zero Trust security model and how organizations can strengthen their cybersecurity posture by adopting a “Never Trust, Always Verify” approach. The project explored identity and access management (IAM), multi-factor authentication (MFA), passwordless authentication using FIDO2 and biometrics, role-based access controls, and continuous verification. It also examined how Zero Trust improves breach prevention, monitoring, audit readiness, and regulatory compliance, demonstrating a practical understanding of modern identity-centric security architectures and enterprise access management.  

  Springboard Cybersecurity Trainee Project:  
Network Access Control (NAC) Strategy

Researched and analyzed the role of Network Access Control (NAC) in securing enterprise networks by controlling device access based on identity, security posture, and organizational policies. The project explored core NAC capabilities, including device profiling, compliance validation, restricted network access, and centralized policy management, while examining real-world use cases such as BYOD, IoT security, guest access, and infected device containment. It also highlighted how NAC supports a defense-in-depth security strategy by reducing unauthorized access, limiting lateral movement, and strengthening overall network resilience.

  Springboard Cybersecurity Trainee Project:  
System Hardening & Endpoint Security

Explored fundamental system hardening techniques used to reduce the attack surface of enterprise systems and improve endpoint security. The project examined best practices including operating system patch management, USB port security, protection against malicious removable media, self-encrypting drives (SEDs), and the risks associated with third-party software. It also emphasized the importance of proactive security controls and secure configuration management in preventing unauthorized access, malware infections, and data loss, demonstrating a foundational understanding of defense-in-depth and endpoint protection principles.  

  Springboard Cybersecurity Trainee Project:  
IoT Security Risk Assessment

Analyzed common cybersecurity challenges affecting Internet of Things (IoT) environments, with a focus on device security, network communications, and cloud infrastructure. The project examined real-world threats such as the Stuxnet and Mirai attacks while evaluating security best practices, including strong authentication, firmware management, network segmentation, encryption, and continuous monitoring. It also explored the importance of asset discovery and device visibility in managing IoT ecosystems, demonstrating how proactive security controls can reduce risk and strengthen the resilience of connected devices and critical infrastructure. 

  Springboard Cybersecurity Trainee Project:  
Secure File Transfer Protocols (SFTP vs. FTPS)

Researched and compared SFTP and FTPS as secure alternatives to traditional FTP for protecting data in transit. The project examined each protocol’s architecture, encryption methods, authentication mechanisms, firewall considerations, and enterprise use cases. It also evaluated the advantages and trade-offs of SSH- and TLS-based file transfer solutions, demonstrating an understanding of secure communication protocols, data protection, and best practices for transferring sensitive information across enterprise and cloud environments.

  Springboard Cybersecurity Trainee Project:  
RFID & NFC Security Assessment

Explored the security of RFID and NFC technologies by analyzing common vulnerabilities, attack techniques, and defensive countermeasures used in modern access control systems. The project examined the capabilities of the Proxmark3 RDV4 as a security research tool, identified weaknesses in legacy RFID implementations, compared passive and active RFID tags, and evaluated strategies for mitigating risks through strong encryption, mutual authentication, secure key management, multi-factor authentication (MFA), and regular security assessments. This project demonstrates an understanding of physical access security, wireless communication technologies, and the importance of securing contactless authentication systems.

  Springboard Cybersecurity Trainee Project:  
Data Classification & Information Protection

Applied enterprise data classification principles to categorize information based on sensitivity, business impact, and access requirements. The project evaluated a variety of organizational data—including customer information, encryption keys, employee records, financial data, intellectual property, and public communications—and assigned appropriate classifications such as Public, Internal Use, Confidential, and Restricted. This exercise reinforced the importance of data governance, least-privilege access, regulatory compliance, and information protection strategies used to safeguard sensitive organizational assets.

 

© 2026  Mike DiDomenico. 

 

bottom of page