Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Shortage Of Women Hurting IT Security Industry, Study Finds

(ISC)2 survey indicates that women have the skills and attitudes most needed in infosec

Today's information security teams increasingly need to improve their communications with other groups, align their activities more closely with business objectives, and excel at a variety of diverse tasks, industry experts say. And a new study suggests that these skills and attributes are most common among the industry's smallest minority of professionals: women.

Women represent about 11 percent of the current IT security workforce, according to "Agents of Change: Women in the Information Security Profession" (PDF), a new report written by Frost & Sullivan and published by the (ISC)2 security professionals' association. Yet women's strongest skill sets are the very skill sets that are in short supply across the industry, the report suggests.

"Security is becoming less about technology and more about people -- understanding their behavior and protecting users as they do their work," says Julie Peeler, director of the (ISC)2 Foundation. "The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

"The report data indicates that the perspectives of women offer viewpoints needed to elevate the security industry to the next level," adds Michael Suby, author of the report and vice president of research at Frost & Sullivan.

Survey respondents were divided into two job title categories: Leaders and Doers. The Leaders (3,466 respondents) category included job titles such as executives, managers, and strategic advisers. Doers (2,348 respondents) included respondents with job titles such as security analysts and compliance auditors.

In the Leaders category, more women (34 percent) were in consultant and adviser job titles than men (26 percent), and more than twice as many men as women were network security or software architects. In the Doers category, 38 percent of women cited security analyst as their job titles, versus 27 percent of men. A higher proportion of men held security engineer and network administrator job titles.

"The 2013 Global Information Security Workforce Study identified 'security analyst' as the number one most needed position in the information security industry, leading the way for a strong female presence in the future," the report says.

IT security has traditionally been dominated by males who study computer sciences in school and are strong in technology, Peeler observes. But as security practices increase their focus on communication and training, it's possible that women will play a more important role.

"In the past, companies have taken their IT people, who are strong technically, and tried to teach them how to communicate with staff and management," Peeler notes. "But recently, they've begun to discover that it's easier to teach technology to someone who communicates well than it is to teach communication to someone who's basically a technical person."

But getting women into the security profession may not be easy, Peeler says. The percentage of females in the industry has not changed much in the past several years, and there doesn't appear to be a great influx on the horizon.

"More needs to be done in the schools and in business to make security more attractive to women," Peeler says. "Studies show that many females are bored by the idea of working alone in a room with a machine. But as the industry becomes more about people and less about technology, that could change."

"Combating [current] threats requires a community approach to training, and hiring qualified security professionals from a variety of backgrounds," Suby states. "As our research reveals, women leaders are the strongest proponents of security and risk management education and training in the industry. This type of mentality is crucial to building standards in the industry and echoes the report's findings that women are indeed, 'agents of change' in the future of information security."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
jobewan
50%
50%
jobewan,
User Rank: Apprentice
11/7/2013 | 9:37:12 PM
re: Shortage Of Women Hurting IT Security Industry, Study Finds
"The study shows that women tend to value skills such as communication and education -- the skills that are currently in short supply."

The above statement is open ended to the point of being non sequitur. Valuing a concept and being good at same, are also two very separate concerns.

The reason information security has really always been about people, is that people are the greatest threat to information security; a position borne out by significant empirical data.
Commentary
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Tim Sadler, CEO and co-founder of Tessian,  6/17/2021
Edge-DRsplash-10-edge-articles
7 Powerful Cybersecurity Skills the Energy Sector Needs Most
Pam Baker, Contributing Writer,  6/22/2021
News
Microsoft Disrupts Large-Scale BEC Campaign Across Web Services
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32716
PUBLISHED: 2021-06-24
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidden fields when an association has been loaded with a to many reference. Users are recommend to update to version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-U...
CVE-2021-32717
PUBLISHED: 2021-06-24
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the hashed URL is known. Users are recommend to first change their configuration to set the correct visibility according to the documentation. The visibilit...
CVE-2021-32712
PUBLISHED: 2021-06-24
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in error handling. Users are recommend to update to version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.
CVE-2021-32713
PUBLISHED: 2021-06-24
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in administration vulnerability. Users are recommend to update to the version 5.6.10. You can get the update to 5.6.10 regularly via the Auto-Updater or directly via the download overview.
CVE-2021-32710
PUBLISHED: 2021-06-24
Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2. We recommend to update to the current version 6.3.5.2. You can get the update to 6.3.5.2 regularly via the Auto-Updater or directly via the download overview. For older versions o...