UC Cybersecurity Student Tackles Ransomware Threats at Kroger and U.S. Bank

0
2

Key Takeaways

  • Bernhardt’s interest in digital forensics began in a high‑school criminal justice and forensics academy, sparked by a chance encounter with a ransomware negotiator.
  • Professionals in this niche blend technical IT expertise with investigative insight to limit ransomware damage, lower payment demands, recover data, and prevent leak of stolen information.
  • As a fourth‑year cybersecurity student at the University of Cincinnati, Bernhardt emphasizes the growing importance of securing private information for individuals and organizations.
  • UC’s extensive co‑op program—more than 9,600 participants—provides students like Bernhardt with real‑world experience while they progress toward their degrees.
  • At Kroger Co., Bernhardt served as an information systems auditor intern, automating permission and log collection, correcting security flaws, and verifying firewall effectiveness for financial, SOX, and HIPAA‑compliant databases.
  • His subsequent co‑op at U.S. Bank allowed him to apply and expand those skills in a banking environment, focusing on threat monitoring, access control, and compliance reporting.
  • These hands‑on experiences have sharpened Bernhardt’s digital detecting abilities, reinforced his career motivation, and positioned him to contribute to the fight against evolving cyber threats.

Introduction and Early Inspiration
Bernhardt’s journey into cybersecurity traces back to his time at Colerain High School in Cincinnati, where he enrolled in a criminal justice and forensics academy. The program introduced him to the fundamentals of investigative science, evidence handling, and legal procedures, but it was a casual conversation with a practicing ransomware negotiator that redirected his focus toward the digital realm. That encounter illuminated how technical skill sets could be married with strategic negotiation to combat cybercrime, planting the seed for his later academic and professional pursuits in digital forensics and cybersecurity.

The Role of Ransomware Negotiators and Digital Forensics Professionals
Ransomware negotiators operate at the intersection of technology, law enforcement, and crisis management. Their primary mission is to engage with threat actors who have encrypted an organization’s data, aiming to reduce the ransom amount, secure decryption keys, and ensure that any recovered information is safe to restore. Beyond the negotiation table, these professionals employ digital forensics techniques to trace the attack’s origin, identify compromised systems, and gather evidence that can be used in legal proceedings or to strengthen defenses. By minimizing downtime, preventing data leakage, and preserving the integrity of critical assets, they play a vital role in an organization’s overall cyber resilience strategy.

Bernhardt’s Perspective on Cybersecurity Importance
Now a fourth‑year cybersecurity student in the School of Information Technology at the University of Cincinnati, Bernhardt reflects on his early fascination with the field. He notes, “I learned more about the cybersecurity side of forensics, which I think is very cool and very important,” and adds, “It sounds cheesy to say, ‘I want to better the world and make people feel more secure,’ but there are a lot of bad actors out there and it is only gonna get exponentially worse.” This candid acknowledgment underscores his awareness of the escalating threat landscape and his personal drive to contribute meaningfully to safeguarding private information for both individuals and enterprises.

University of Cincinnati Co‑op Program Overview
The University of Cincinnati boasts one of the nation’s largest cooperative education (co‑op) programs, with over 9,600 students gaining paid, real‑world work experience each cycle. Participants alternate academic semesters with full‑time positions at industry partners, government agencies, nonprofit organizations, or campus research labs. This model allows students to apply classroom theory to practical challenges, earn professional credentials, and build networks that enhance employability upon graduation. For Bernhardt, the co‑op framework has been instrumental in translating his academic interests into tangible skill development within the cybersecurity arena.

First Co‑op Experience at Kroger: Information Systems Auditing
During three consecutive co‑op rotations at Kroger Co., Bernhardt held the title of information systems auditor intern. In this capacity, he supported the retailer’s internal audit function by gathering and analyzing data essential for financial audits, particularly those governed by the Sarbanes‑Oxley Act (SOX) and the Health Insurance Portability and Accountability Act (HIPAA). His responsibilities included verifying that access controls were appropriately configured, ensuring that sensitive files were protected from unauthorized viewing, and confirming that network firewalls operated according to established security policies. By aligning his work with regulatory requirements, Bernhardt helped Kroger maintain compliance while fortifying its defensive posture against potential breaches.

Technical Tasks and Tools Used at Kroger
A significant portion of Bernhardt’s audit work involved scripting and automation. He developed automated code to query user permission directories, extract relevant attributes, and format the outputs into standardized reports for auditors. Similarly, he created scripts to collect and parse system logs from servers and workstations, enabling efficient documentation of access events and anomalous activity. These artifacts were then stored in a centralized repository, facilitating traceability and supporting ongoing compliance monitoring. Additionally, Bernhardt documented how various applications and automated scripts interacted with Kroger’s financial, SOX‑aligned, and HIPAA‑compliant databases, offering recommendations to tighten access restrictions and reduce the attack surface.

Second Co‑op Experience at U.S. Bank: Expanding Skill Set
Following his tenure at Kroger, Bernhardt secured a co‑op position at U.S. Bank, where he broadened his exposure to cybersecurity operations within a financial services context. While specific project details were less publicly disclosed, his role involved assisting the bank’s security operations center (SOC) with threat monitoring, vulnerability assessments, and incident response workflows. He contributed to the tuning of intrusion detection systems, participated in tabletop exercises that simulated ransomware scenarios, and helped draft remediation plans aligned with federal banking regulations. This experience deepened his understanding of how large financial institutions balance stringent regulatory demands with the need for agile, proactive cyber defenses.

Impact of Co‑op Experiences on Career Development
The combination of auditing work at Kroger and operational security tasks at U.S. Bank has provided Bernhardt with a well‑rounded foundation in both preventive and reactive cybersecurity measures. He has cultivated proficiency in scripting languages such as Python and PowerShell, gained familiarity with security information and event management (SIEM) platforms, and sharpened his ability to communicate technical findings to non‑technical stakeholders—skills that are indispensable for modern cybersecurity professionals. Moreover, these co‑op cycles have reinforced his conviction that securing private information is not merely a technical challenge but a societal imperative, motivating him to pursue a career where he can continuously adapt to emerging threats while helping organizations build trust with their customers and partners.

Conclusion: Future Outlook for Bernhardt and Cybersecurity Field
As the cyber threat landscape grows more sophisticated—marked by the rise of ransomware-as-a-service, supply‑chain attacks, and increasingly targeted social engineering—professionals like Bernhardt will be essential in bridging the gap between technical detection and strategic response. His early exposure to digital forensics, complemented by hands‑on co‑op experiences in both retail and banking environments, equips him with a unique perspective that blends compliance awareness, investigative rigor, and practical defense tactics. Moving forward, Bernhardt aims to leverage his academic training and industry exposure to contribute to resilient security architectures, help organizations negotiate and recover from cyber incidents, and ultimately foster a safer digital ecosystem for all.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here