Portfolio of Lukas Schepens

About Me

Hello, I'm a student at Howest University of Applied Sciences. I'm currently following the TI Cyber Security Professional program.
When I'm not studying, I enjoy playing the music, being a scout leader, spending time with my friends and family, and exploring new technologies.

Curriculum Vitae

Education

Experience

Skills

Languages

Volunteer Experience

Contact

Email: lukas.schepens@howest.be
LinkedIn: https://www.linkedin.com/in/lukas-schepens-a60093336/

Blog

Internship at Evara

Summary: A short description of my internship experience at Evara.

In this blog post, I will share my experiences and insights from my internship at Evara.
During my time there, I had the opportunity to work on 2 projects related to cybersecurity,
The setup of Armis Centrix and making the decision of which tool to use BitSight or Sweepatic.

Armis Centrix

Armis Centrix is a cybersecurity platform that provides comprehensive visibility and security for connected devices.
During my internship, I was responsible for setting up Armis Centrix and configuring it to monitor and protect the organization's network.
Through this experience, I gained valuable insights into the importance of device security and the challenges of managing a large number of connected devices.

BitSight vs Sweepatic

During my internship, I was also involved in the decision-making process of choosing between BitSight and Sweepatic for the organization's cybersecurity needs.
Both tools offer unique features and capabilities, and I had the opportunity to evaluate their strengths and weaknesses.
Through this experience, I learned about the importance of selecting the right cybersecurity tools for an organization and the factors that should be considered in the decision-making process.

Tryhackme

Summary:A small post about how I use Tryhackme.

Alongside my coursework, I regularly work through challenges on TryHackMe to build practical, hands-on cybersecurity skills. The platform offers guided rooms covering a wide range of topics,
from network scanning and enumeration to privilege escalation and web application exploitation, giving me a structured way to apply concepts I'm learning academically in a more realistic setting.
What I like most about TryHackMe is the balance it strikes between guided learning and genuine problem-solving. Some rooms walk you through a concept step by step,
while others present a more open-ended challenge that forces you to think like an attacker and figure things out on your own. This mix keeps the learning active rather than passive.
Doing these challenges consistently has helped reinforce topics from my Cybersecurity specialization at Howest, while also exposing me to tools and techniques I might not encounter directly in class.
It's become a small but valuable part of how I keep developing my technical skills.

My Experience as a Scout Leader

Summary: A short description of my experience as a scout leader.

Being a scout leader has been a rewarding experience for me. It has allowed me to develop leadership skills, build strong relationships with the children and their families, and make a positive impact on the community.
As a scout leader, I have organized various activities and events for the children, such as outdoor adventures, team-building exercises, and community service projects.
Through this experience, I have learned the importance of teamwork, communication, and empathy in leadership.

Exploring New Technologies

Summary: A short description of my interest in exploring new technologies.

I have always been fascinated by new technologies and their potential to transform our lives.
Whether it's the latest advancements in artificial intelligence, cybersecurity, or software development, I enjoy staying up-to-date with the latest trends and innovations in the tech industry.
Exploring new technologies allows me to expand my knowledge and skills, and it also opens up new opportunities for personal and professional growth.

Orange Cyberdefense Live

Summary: A short description of my experience at the Orange Cyberdefense Live event.

Attending the Orange Cyberdefense Live event was an incredible opportunity to learn about the latest trends and innovations in cybersecurity.
The event featured insightful presentations from industry experts that allowed me to gain knowledge with cutting-edge security tools and techniques.
Overall, the event provided valuable networking opportunities and enhanced my understanding of the evolving cybersecurity landscape.
At this event I went to more then 4 seperate talks about a lot of different topics like a talk about SASE,
a talk about making incident response plans, a talk from a CISO about how they handled a security incident that they had and a talk from the CEO of Farys of what security measures they have in place.

Talk about SASE:


At the Orange Cyberdefense Live I attended a talk about SASE, or Secure Access Service Edge, a concept that has been gaining a lot of traction in the cybersecurity and networking world.
The session started with an explanation of why traditional network security models are becoming outdated, especially now that more organizations rely on cloud services,
remote work, and distributed teams. The speaker explained how the old perimeter-based approach, where a company protects a clearly defined internal network, no longer makes sense when employees,
applications, and data are scattered across multiple locations and cloud environments.
What stood out to me most was how SASE combines networking and security into a single, cloud-delivered service. Instead of routing traffic through a central data center for inspection,
SASE pushes security functions like firewalling, secure web gateways, and zero trust network access closer to the user, wherever they are.
This was explained using the analogy of moving security checkpoints from one central building out to many smaller checkpoints spread across a city, so people don't have to travel far to get checked and traffic flows more efficiently.
The talk also covered how SASE integrates SD-WAN capabilities with security services like CASB and DLP, all managed from a single, unified platform rather than a patchwork of separate tools.
I found this especially relevant given my background from my internship at Evara, where I worked with Armis Centrix for exposure management as part of NIS2 compliance efforts. A lot of the challenges discussed in the SASE talk,
like visibility across a growing number of devices and endpoints, and the difficulty of enforcing consistent policies across a hybrid environment, felt familiar from that experience.
It made me think about how exposure management platforms and SASE architectures could complement each other: one focused on identifying and prioritizing risk across assets,
and the other focused on enforcing secure, policy-based access no matter where a user or device connects from.
The talk also touched on zero trust principles, emphasizing that no device or user should be automatically trusted, even if they are inside what used to be considered the "trusted" network.
This reinforced a lot of what I have been learning academically about identity-based security and least-privilege access.
Overall, the talk gave me a much clearer picture of how modern enterprise networks are evolving, and it sparked some ideas about how these concepts might apply to future projects.

Talk from CISO about security incident:


I attended a talk given by a CISO who shared a candid, behind-the-scenes account of a real cybersecurity incident their organization had faced a few years earlier.
Rather than presenting the polished, after-the-fact version most companies show publicly, the speaker walked us through the messy reality of how the incident actually unfolded,
which made the talk feel much more valuable than a typical case study. The incident started small: a phishing email that tricked an employee in the finance department into entering their credentials on a spoofed login page.
Because multi-factor authentication wasn't yet enforced company-wide, the attacker was able to access the employee's account and begin quietly exploring internal systems.
It took almost a week before anomalous login patterns were flagged, by which point the attacker had already moved laterally into a few adjacent systems.
The CISO was honest about how the initial detection came almost by chance, through a sharp-eyed sysadmin who noticed unusual VPN activity, rather than through any automated alerting system.
What struck me most was how much of the talk focused on organizational and communication failures rather than purely technical ones.
The CISO described the chaos of the first 24 hours: unclear escalation paths, confusion over who had the authority to disconnect systems, and a lack of pre-written incident communication templates,
which caused delays in informing both leadership and, eventually, customers. They admitted that the technical remediation was actually the easier part,
coordinating people, decisions, and messaging under pressure was where things nearly fell apart.
The lessons they shared afterward centered heavily on preparation. They emphasized the importance of enforcing MFA everywhere,
not just on "critical" systems, and of running regular tabletop exercises so that incident response isn't being improvised for the first time during a real crisis.
They also stressed the value of having pre-approved communication templates ready for executives, legal, and customers, so that valuable time isn't lost drafting messages during an active incident.

Talk about making incident response plans:


At the orange Cyberdefense Live I also went to a talk focused specifically on how to build an effective incident response plan, which felt like a natural follow-up to some of the other security talks I've attended this semester.
The speaker, who worked as a security consultant helping organizations design and test their response strategies, started by pointing out a common mistake: many companies either have no formal incident response plan at all,
or they have one that was written once, filed away, and never touched again.
The talk broke the process down into clear phases, starting with preparation. This included defining roles and responsibilities in advance, so that during an actual incident nobody wastes critical time figuring out who is in charge of what.
The speaker stressed that a good plan names specific people, not just job titles, and includes backup contacts in case someone is unavailable when an incident happens.
They also talked about the importance of maintaining an up-to-date asset inventory and network diagram, since responders can't contain or investigate what they don't know exists.
Detection and analysis was covered next, with an emphasis on having clear criteria for what actually counts as an incident versus a false alarm, since not every anomaly needs to trigger a full response.
The speaker walked through how to build a severity classification system, so that a minor issue like a single infected laptop is handled differently from something like ransomware spreading across multiple servers.
Containment, eradication, and recovery were discussed as a single connected phase, with a strong focus on having pre-approved decisions ready ahead of time. For example, deciding in advance whether it's acceptable to take a critical system offline during business hours,
so that decision doesn't need to be debated in the middle of a crisis.
One of the most memorable parts of the talk was the emphasis on the post-incident review. The speaker argued that this step is often skipped once systems are back online, but it's actually one of the most valuable phases,
since it turns a stressful incident into concrete improvements for the future. They recommended running tabletop exercises regularly to test the plan against realistic scenarios, rather than waiting for a real incident to reveal its weaknesses.
Overall, the talk reinforced how much incident response planning is really about reducing decision-making under pressure. By making key decisions and assigning responsibilities ahead of time, organizations can respond faster and with far less confusion when something actually goes wrong.

Talk from the CEO of Farys:


Last week I attended a talk given by the CEO of Farys, who spoke about the general approach their organization takes toward cybersecurity. Since Farys operates critical infrastructure related to water services, the talk emphasized how seriously they take the protection of their systems,
even though the CEO kept the discussion at a fairly high level rather than diving into specific technical details.
The talk touched on some of the fundamental measures most organizations rely on, such as keeping systems and software regularly updated, using firewalls and network segmentation to limit how far an attacker could move if they got in,
and enforcing strong password policies alongside multi-factor authentication for employee accounts. The CEO also mentioned the importance of regular data backups, stressing that having reliable, tested backups is one of the simplest but most effective ways to recover quickly from incidents like ransomware.
Employee awareness was another recurring theme. The CEO explained that technology alone isn't enough, and that ongoing training helps staff recognize phishing attempts and other social engineering tactics, since employees are often the first line of defense. There was also a mention of having clear internal policies around access control,
ensuring that people only have access to the systems and data they actually need for their role.
The talk also briefly covered monitoring, with the CEO noting that they keep an eye on their systems to detect unusual activity early, though the specifics of how this is done weren't discussed in detail. Similarly, there was a general mention of having some form of incident response process in place,
so that if something does go wrong, the organization can react quickly rather than being caught off guard.
Overall, the talk didn't go into deep technical specifics, but it gave a good sense of how a company managing essential infrastructure thinks about cybersecurity at a foundational level.
It reinforced the idea that even basic, well-implemented security practices, like updates, backups, access control, and employee training, form the backbone of a solid security posture, especially for organizations where downtime or breaches could have a real impact on the public.

Making a podcast episode

Summary: A short description of my experience making a podcast episode.

Creating a podcast episode has been an exciting endeavor for me. It has allowed me to explore my communication skills, share my knowledge with others, and connect with a wider audience.
Through this experience, I have learned about the technical aspects of podcasting, including audio editing, recording techniques, and content planning.
Overall, making a podcast episode has been a rewarding experience that has helped me grow my communication skills.
In this podcast episode I talk with a teacher about how they use a Linux environment in a school environment, and how to students learn in the process about Linux.

You can listen to the episode here: https://open.spotify.com/episode/1FZQRUFmzTvniL7JwOvbWU?si=c2a6aafd78964ad3

Making my LinkedIn profile

Summary:A short post about making my LinkedIn Profile.

As part of this module, I spent time properly building out my LinkedIn profile instead of leaving it as a half-finished placeholder. I added a professional profile photo, wrote a clear bio summarizing my background in Applied Computer Science with a Cybersecurity specialization,
and listed relevant skills like network security, pentesting, and Linux administration. I also added my education and my internship experience at Evara, where I worked on Armis Centrix as part of NIS2 compliance efforts.
Beyond just filling in information, I actively expanded my network by connecting with lecturers, fellow students, and professionals I met at events like Orange Cyberdefense Live and Hack The Future.
Reaching out to people I've actually interacted with, rather than just adding random connections, made the process feel a lot more genuine and useful.
Overall, this exercise made me realize how much a well-maintained LinkedIn profile matters for building a professional network and staying visible to people in the field, especially now that I'm getting closer to graduating and job hunting for real.

Hack The Future

Summary: A short description of the Hack The Future hackaton

Hack the Future is a hackathon I took part in, where I worked intensively over a short, high-pressure timeframe to build a working project from scratch.
It was a great chance to apply cybersecurity and coding skills in a real, fast-paced team setting.
Working alongside teammates under time pressure also pushed me to communicate clearly and divide tasks efficiently to get everything done in time.

Making this website

Summary: A short description of how this website came to be.

For a course on professional networking, I built a simple HTML website that works as a personal blog to showcase my growth throughout the year.
I kept the design clean and minimal, focusing on clear navigation and readable typography rather than flashy effects,
since the goal was to communicate professionally rather than impress with visuals.
The site includes a home page, an about me, and a blog section.
I wrote all the HTML and CSS by hand to practice front-end basics while keeping the structure straightforward and easy to maintain.
Then I hosted this website using Combell which was a pretty easy process.
So after all the process of this portfolio website was quite straight forward.