Operations

1/29/2018
10:30 AM
Laura Lee
Laura Lee
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

An Action Plan to Fill the Information Security Workforce Gap

Nothing says #whorunstheworld like an all-female blue team taking down a male-dominated red team in a battle to protect sensitive customer data, and other ideas to entice women into a cyber career.

It has become a familiar, fear-invoking industry statistic: the 2017 Global Information Security Workforce Study from Frost & Sullivan estimates that a jaw-dropping 1.8 million positions will need to be filled globally by 2022. The same report revealed a mere 11% of information security professionals globally are women. This number has remained unchanged for the last few years, even though the number of women in postsecondary education is steadily increasing. Women today feel empowered to attain degrees and establish meaningful careers, but consistently they are not choosing careers in cybersecurity.

If we are going to make a true impact on the cybersecurity workforce shortage, we will need to tap into the largely untapped resource of educated women. But where do we start? We must enable women to envision themselves in a cyber career. Young girls practice for careers in fashion by dressing Barbie dolls and sketching clothing designs. They dress up as doctors, nurses, and teachers and practice these roles with siblings and friends. We must reach women — both young and seasoned — by making cybersecurity a more tangible, appealing career opportunity.

You've heard it before. In order to cultivate interest in cybersecurity as a career field, we must introduce it early to girls and young women. The United States is surprisingly delayed in its introductions to the technical skills that make up cybersecurity, such as computer science. In other countries, including Singapore, Hong Kong, and Israel, elementary schools cover these topics as early as kindergarten.

New Initiatives Launching in 2018
There are groups launching initiatives to fill this gap. During 2018, the Girl Scouts of America, in partnership with Palo Alto Networks, will roll out a program awarding a series of 18 cybersecurity badges to scouts grades K-12. Other groups, such as Girls Who Code, support clubs and summer enrichment programs for female students. At the college level, one- and two-day hackathons are becoming popular as well. This early and continued exposure is an amazing first step, but we cannot stop here.

As technology advances, we must leverage it to engage youth — especially young women — and make cybersecurity a tangible career path. Programs designed for youth, including SoCal Cyber Cup and CyberPatriot, utilize virtual environments, artificial intelligence, and machine learning to put students into real-world situations and actively defend like true practitioners. These programs transform the abstract into actual practice, allowing students to envision a career in cybersecurity and better train as future cyber warriors.

In addition, these programs pair student teams with coaches and mentors, which gives young girls a chance to interact with cyber professionals. Having real-world role models to guide them drives excitement and encourages commitment to the field. These programs often need more practitioners to volunteer their time, so in 2018, consider taking on a role as a mentor to do your part in encouraging young women to join the world of cyber professionals. Coach an all-female cyber team yourself. Nothing says #whorunstheworld like an all-female blue team taking down a male-dominated red team in a battle to protect sensitive customer data.

Proactive Hiring, Cross Training, and Wage Inequities
Exposing girls to a career in cybersecurity is crucial, but it will take time for those efforts to become fruitful. How an organization recruits, compensates, and trains staff can and will directly affect the number of women who join the field in the coming years.

When recruiting women to join their cybersecurity teams, hiring managers must carefully craft job descriptions to ensure they are inclusive of both genders. Although women are entering the cyber profession with higher education levels — 51% have a master's degree or higher, as compared to 45% of men — studies have shown that most women will discourage themselves from applying for technical positions for which they do not meet every qualification listed, whereas men will still put their name in the hat when meeting only a portion of the requirements. Women also are less likely to apply when job descriptions use common male-associated language, such as analytical, assertive, or tactical, even if they fully possess the right characteristics. We must be sure that our hiring practices are not discouraging women.

There are other changes to make beyond recruiting. The largely untapped market of educated women applies to more than just college graduates. Cross-training women from other fields with transferrable skill sets is the fastest way to address the skills gap. To do this, we must make the field more appealing by addressing equal compensation and offering continuous professional development opportunities and mentorship. According to another Frost & Sullivan report, females in nonmanagerial roles earn 6% less than their male counterparts. This wage gap must be addressed if organizations expect to attract and retain skilled women. The same report revealed that women who are encouraged by mentors and have opportunities to hone and build their skills are more satisfied and successful. Women are looking for this level of training and engagement to grow, and these efforts build a more skilled workforce in general.

The cybersecurity workforce shortage will soon reach a critical level, and it is imperative we tap into the market of educated women if we expect to have an impact. By working together — as professionals and organizations — we can ensure more individuals enter the field to fill those million-plus job openings and that the pool of talented, highly skilled cyber professionals continues to grow.

Related Content:

Laura Lee is executive vice president of cyber training and assessments at Circadence. She leads development around the company's AI-powered, multi-player cyber training platform, Project Ares. Lee brings an exceptional record of leadership in the field of cyber exercises and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8980
PUBLISHED: 2019-02-21
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-8979
PUBLISHED: 2019-02-21
Koseven through 3.3.9, and Kohana through 3.3.6, has SQL Injection when the order_by() parameter can be controlled.
CVE-2013-7469
PUBLISHED: 2019-02-21
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
CVE-2018-20146
PUBLISHED: 2019-02-21
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
CVE-2019-5727
PUBLISHED: 2019-02-21
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.