Difficult: Attracting Women To Cybersecurity

Cybersecurity is a male-dominated field. Women make up only 10% of the global cybersecurity workforce. The field is missing out on a lot of capable people and women are missing out on an interesting, well-paid career path. There have been numerous initiatives trying to change the situation, but fighting existing stereotypes has proven to be hard.

The underlying problem: society still views technology as a ‘boy thing’. Boys are the inventors, the hackers, the tinkerers. We don’t expect girls to have the same interest in building the cool stuff. They are expected to be better at soft skills like empathy, talking and feelings.

These expectations still drive girls toward people-focused careers and away from science and technology, despite all efforts. Or perhaps, ‘despite’ isn’t the right word here…

Don’t Focus Tech

There are several articles that aim to get girls interested in a career in cybersecurity. But even those articles can’t avoid that tech-avoidant girly girl stereotype from popping up from time to time.

It is very telling that the tech part is often assumed to be the ‘bad’ part. It is the part that needs to be sugarcoated somehow. Yes, it is somewhat reluctantly admitted that the field has its roots in technology. But these roots are to blame for the field’s poor reputation. The articles try to lure attention away from this ‘bad’ part by repeating over and over again that the field is so much more than ‘just tech’.

They keep going on about how the field needs to broaden its definition beyond the technical domain and that it is such a misconception to think that cybersecurity is only about keeping information and computers safe. Girls shouldn’t think that the domain is highly technically focused. They must know that cybersecurity is so much more than ‘hacking and passwords’. It is a multidisciplinary field, and if you don’t like tech, there are plenty of non-technical areas to go into as well! And don’t worry; you don’t really need a technical background or technical skills to get a job in cybersecurity.

Looking for tech skills and technical qualifications in cyber candidates is condemned as a bad practice. It ’puts women off’ and even ‘naturally excludes’ them. Girls and tech don’t mix very well, apparently.

Female Skills Wanted

Next to the assumption that you’ll have to downplay the tech part in a career in order to sell it to women, there is the assumption that women will be naturally attracted by the ‘people part’. This is the part that gets advertised as a strong selling point.

These articles point out how professionals in cybersecurity have to deal with all kinds of different people. They argue how important it is to know a thing or two about business and organisational psychology. They stress the field’s connection with fields like behavioral science and politics. And they discuss the need for people who can serve as translators and bridge-builders. That’s where the girls come in, with their naturally superior soft skills as ‘strong communicators and collaborators’.

This is not to downplay the importance of the ‘people part’ in cybersecurity. It is just as important as the tech part. But it is very typical that in articles aimed at women, it’s this people part that gets emphasized over the tech part. This echoes existing stereotypes of tech-avoidant people-oriented females versus technical, tinkering males.

A lot of the opinions expressed in those articles come from women in cybersecurity themselves. But women can have gender prejudices too. These societal expectations are deeply ingrained in us all. And as this blog post shows, it is hard to fight them, even with the best of intentions.

In The Real World

But what if the writers of those articles have intentionally sugarcoated the tech bits? What if they know that that is the only way to get their message across? What if too much talk about tech really does scare the girls away?

The people interviewed in those articles have years of experience as an expert in the field. If there is anybody who knows what works and what doesn’t, it’s them. And probably, they’re right. Emphasizing all the different and interesting social aspects of the field is more likely to draw girls’ attention than talking about technical challenges.

But this preference is, for a large part, the result of the subtle (and not so subtle) messages society keeps sending to girls: You’re a helper, not a tinkerer. A message this kind of article keeps reinforcing.

As long as this keeps happening, things are not going to get any better. If girls keep seeing themselves as non-tech people persons first, they are less likely to choose a career in cybersecurity. Cybersecurity might be broad and multidisciplinary, but it is still a tech field. You work with tech people and you get to deal with tech-related issues. Why go into a tech field when your natural talents lie in an entirely different domain? Not even cybersecurity’s bright career prospects seem enough to change women’s minds about this.

If the field really wants to get more diverse, playing into existing preferences (and reinforcing them) isn’t enough. It’s those preferences themselves that need to be changed. Of course, that is going to be a hell of a job. But unfortunately, no one said that changing the world was going to be easy…

What do you think? Is it realistic to expect those preferences to change anytime soon? Or should the cybersecurity field accept gender preferences as they are today and play into those preferences in order to attract a more diverse workforce?

Medium:      Women In Cybersecurity:


 

« State Sponsored Hackers: Finding The Country Behind The Attack
Cybersecurity Start-Ups Working With GCHQ »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

LogmeOnce

LogmeOnce

LogmeOnce provides users with solution to multiple Password problems, Single Sign-On (SSO), and Identity Management.

NTNU Center for Cyber & Information Security (NTNU CCIS)

NTNU Center for Cyber & Information Security (NTNU CCIS)

NTNU CCIS is a national centre for research, education, testing, training and competence development within the area of cyber and information security.

Cyberia Group

Cyberia Group

Cyberia is a leading Internet and Security services provider with operations in Saudi Arabia, Lebanon and Jordan.

Seric Systems

Seric Systems

Seric is a technology business specialising in security, infrastructure and data management.

Blake, Cassels & Graydon (Blakes)

Blake, Cassels & Graydon (Blakes)

Blakes is one of Canada’s top business law firms serving national and international clients in specialist areas including cyber security.

HCL Technologies

HCL Technologies

HCL offer an integrated portfolio of products, solutions and services built around Digital, IoT, Cloud, Automation, Cybersecurity, Analytics, Infrastructure Management and Engineering Services.

Ziroh Labs

Ziroh Labs

Ziroh Labs leverages advanced cryptography to keep your highly sensitive, private data safe throughout the lifecycle of data.

Cybersecurity Professionals

Cybersecurity Professionals

Search vacancies from top cyber security jobs worldwide on CyberSecurity Professionals. View IT security jobs or upload your CV to be seen by recruiters from industry leading firms.

Orpheus Cyber

Orpheus Cyber

Orpheus Cyber provides predictive and actionable intelligence to our clients - enabling them to anticipate, prepare for and respond to the cyber threats they face.

Binalyze

Binalyze

Binalyze is the world's fastest and most comprehensive enterprise forensics solution. Our software helps you to collaborate and complete incident response investigations quickly.

ProArch

ProArch

ProArch is a global team of multidisciplinary experts in cloud, infrastructure, data analytics, cybersecurity, compliance, and software development.

PatchAdvisor

PatchAdvisor

PatchAdvisor core services include Vulnerability Assessments/Penetration Testing, Application Vulnerability Assessments, and Incident Response.

Metallic.io

Metallic.io

Metallic (formerly TrapX) is a SaaS portfolio for enterprise-grade backup and recovery, designed to protect your data from corruption, deletion, ransomware, and other threats.

Inveo Group

Inveo Group

Inveo group is the Italian leader for the management of privacy and data protection issues.

EK3 Technologies

EK3 Technologies

EK3 Technologies mission is to provide comprehensive cybersecurity and IT solutions that allow our clients to focus on sustaining their business.

RedSense

RedSense

RedSense provides industry-leading threat intelligence services, adversary space interaction & monitoring, net flow monitoring and interpretation for our clients.