Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Shortage Of Women Hurting IT Security Industry, Study Finds

(ISC)2 survey indicates that women have the skills and attitudes most needed in infosec

Today's information security teams increasingly need to improve their communications with other groups, align their activities more closely with business objectives, and excel at a variety of diverse tasks, industry experts say. And a new study suggests that these skills and attributes are most common among the industry's smallest minority of professionals: women.

Women represent about 11 percent of the current IT security workforce, according to "Agents of Change: Women in the Information Security Profession" (PDF), a new report written by Frost & Sullivan and published by the (ISC)2 security professionals' association. Yet women's strongest skill sets are the very skill sets that are in short supply across the industry, the report suggests.

"Security is becoming less about technology and more about people -- understanding their behavior and protecting users as they do their work," says Julie Peeler, director of the (ISC)2 Foundation. "The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

"The report data indicates that the perspectives of women offer viewpoints needed to elevate the security industry to the next level," adds Michael Suby, author of the report and vice president of research at Frost & Sullivan.

Survey respondents were divided into two job title categories: Leaders and Doers. The Leaders (3,466 respondents) category included job titles such as executives, managers, and strategic advisers. Doers (2,348 respondents) included respondents with job titles such as security analysts and compliance auditors.

In the Leaders category, more women (34 percent) were in consultant and adviser job titles than men (26 percent), and more than twice as many men as women were network security or software architects. In the Doers category, 38 percent of women cited security analyst as their job titles, versus 27 percent of men. A higher proportion of men held security engineer and network administrator job titles.

"The 2013 Global Information Security Workforce Study identified 'security analyst' as the number one most needed position in the information security industry, leading the way for a strong female presence in the future," the report says.

IT security has traditionally been dominated by males who study computer sciences in school and are strong in technology, Peeler observes. But as security practices increase their focus on communication and training, it's possible that women will play a more important role.

"In the past, companies have taken their IT people, who are strong technically, and tried to teach them how to communicate with staff and management," Peeler notes. "But recently, they've begun to discover that it's easier to teach technology to someone who communicates well than it is to teach communication to someone who's basically a technical person."

But getting women into the security profession may not be easy, Peeler says. The percentage of females in the industry has not changed much in the past several years, and there doesn't appear to be a great influx on the horizon.

"More needs to be done in the schools and in business to make security more attractive to women," Peeler says. "Studies show that many females are bored by the idea of working alone in a room with a machine. But as the industry becomes more about people and less about technology, that could change."

"Combating [current] threats requires a community approach to training, and hiring qualified security professionals from a variety of backgrounds," Suby states. "As our research reveals, women leaders are the strongest proponents of security and risk management education and training in the industry. This type of mentality is crucial to building standards in the industry and echoes the report's findings that women are indeed, 'agents of change' in the future of information security."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jobewan
50%
50%
jobewan,
User Rank: Apprentice
11/7/2013 | 9:37:12 PM
re: Shortage Of Women Hurting IT Security Industry, Study Finds
"The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

The above statement is open ended to the point of being non sequitur. Valuing a concept and being good at same, are also two very separate concerns.

The reason information security has really always been about people, is that people are the greatest threat to information security; a position borne out by significant empirical data.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11937
PUBLISHED: 2020-08-06
In whoopsie, parse_report() from whoopsie.c allows a local attacker to cause a denial of service via a crafted file. The DoS is caused by resource exhaustion due to a memory leak. Fixed in 0.2.52.5ubuntu0.5, 0.2.62ubuntu0.5 and 0.2.69ubuntu0.1.
CVE-2020-15114
PUBLISHED: 2020-08-06
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting i...
CVE-2020-15136
PUBLISHED: 2020-08-06
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints func...
CVE-2020-15701
PUBLISHED: 2020-08-06
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.1...
CVE-2020-15702
PUBLISHED: 2020-08-06
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges....