Difficult: Attracting Women To Cybersecurity

Cybersecurity is a male-dominated field. Women make up only 10% of the global cybersecurity workforce. The field is missing out on a lot of capable people and women are missing out on an interesting, well-paid career path. There have been numerous initiatives trying to change the situation, but fighting existing stereotypes has proven to be hard.

The underlying problem: society still views technology as a ‘boy thing’. Boys are the inventors, the hackers, the tinkerers. We don’t expect girls to have the same interest in building the cool stuff. They are expected to be better at soft skills like empathy, talking and feelings.

These expectations still drive girls toward people-focused careers and away from science and technology, despite all efforts. Or perhaps, ‘despite’ isn’t the right word here…

Don’t Focus Tech

There are several articles that aim to get girls interested in a career in cybersecurity. But even those articles can’t avoid that tech-avoidant girly girl stereotype from popping up from time to time.

It is very telling that the tech part is often assumed to be the ‘bad’ part. It is the part that needs to be sugarcoated somehow. Yes, it is somewhat reluctantly admitted that the field has its roots in technology. But these roots are to blame for the field’s poor reputation. The articles try to lure attention away from this ‘bad’ part by repeating over and over again that the field is so much more than ‘just tech’.

They keep going on about how the field needs to broaden its definition beyond the technical domain and that it is such a misconception to think that cybersecurity is only about keeping information and computers safe. Girls shouldn’t think that the domain is highly technically focused. They must know that cybersecurity is so much more than ‘hacking and passwords’. It is a multidisciplinary field, and if you don’t like tech, there are plenty of non-technical areas to go into as well! And don’t worry; you don’t really need a technical background or technical skills to get a job in cybersecurity.

Looking for tech skills and technical qualifications in cyber candidates is condemned as a bad practice. It ’puts women off’ and even ‘naturally excludes’ them. Girls and tech don’t mix very well, apparently.

Female Skills Wanted

Next to the assumption that you’ll have to downplay the tech part in a career in order to sell it to women, there is the assumption that women will be naturally attracted by the ‘people part’. This is the part that gets advertised as a strong selling point.

These articles point out how professionals in cybersecurity have to deal with all kinds of different people. They argue how important it is to know a thing or two about business and organisational psychology. They stress the field’s connection with fields like behavioral science and politics. And they discuss the need for people who can serve as translators and bridge-builders. That’s where the girls come in, with their naturally superior soft skills as ‘strong communicators and collaborators’.

This is not to downplay the importance of the ‘people part’ in cybersecurity. It is just as important as the tech part. But it is very typical that in articles aimed at women, it’s this people part that gets emphasized over the tech part. This echoes existing stereotypes of tech-avoidant people-oriented females versus technical, tinkering males.

A lot of the opinions expressed in those articles come from women in cybersecurity themselves. But women can have gender prejudices too. These societal expectations are deeply ingrained in us all. And as this blog post shows, it is hard to fight them, even with the best of intentions.

In The Real World

But what if the writers of those articles have intentionally sugarcoated the tech bits? What if they know that that is the only way to get their message across? What if too much talk about tech really does scare the girls away?

The people interviewed in those articles have years of experience as an expert in the field. If there is anybody who knows what works and what doesn’t, it’s them. And probably, they’re right. Emphasizing all the different and interesting social aspects of the field is more likely to draw girls’ attention than talking about technical challenges.

But this preference is, for a large part, the result of the subtle (and not so subtle) messages society keeps sending to girls: You’re a helper, not a tinkerer. A message this kind of article keeps reinforcing.

As long as this keeps happening, things are not going to get any better. If girls keep seeing themselves as non-tech people persons first, they are less likely to choose a career in cybersecurity. Cybersecurity might be broad and multidisciplinary, but it is still a tech field. You work with tech people and you get to deal with tech-related issues. Why go into a tech field when your natural talents lie in an entirely different domain? Not even cybersecurity’s bright career prospects seem enough to change women’s minds about this.

If the field really wants to get more diverse, playing into existing preferences (and reinforcing them) isn’t enough. It’s those preferences themselves that need to be changed. Of course, that is going to be a hell of a job. But unfortunately, no one said that changing the world was going to be easy…

What do you think? Is it realistic to expect those preferences to change anytime soon? Or should the cybersecurity field accept gender preferences as they are today and play into those preferences in order to attract a more diverse workforce?

Medium:      Women In Cybersecurity:


 

« State Sponsored Hackers: Finding The Country Behind The Attack
Cybersecurity Start-Ups Working With GCHQ »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ClearedJobs.Net

ClearedJobs.Net

ClearedJobs.Net is a career site and job fair company for professionals seeking careers in the defense, intelligence and cyber security communities.

K7 Computing

K7 Computing

K7 provides antivirus and internet security products for business and home users.

StratoKey

StratoKey

StratoKey is an intelligent Cloud Access Security Broker (CASB) that secures your cloud and SaaS applications against data breaches, so you can do secure and compliant business in the cloud.

Visa

Visa

Visa is a global payments technology company that connects consumers, businesses and banks in more than 200 countries and territories worldwide.

Entrust

Entrust

Entrust is a global leader in digital security, identities, payments, and data protection.

Evidence Talks Ltd

Evidence Talks Ltd

A leading forensic computing authority developing unique digital forensic technologies. Tools that detect potential terrorists & criminals & used by the military, enforcement & intelligence commmunity

certSIGN

certSIGN

certSIGN develop innovative software for information security and information systems protection.

Abacode

Abacode

Abacode is a Managed Security Services Provider (MSSP). We help businesses consolidate all of their Regulatory Compliance & Cybersecurity needs, under one roof.

ISA Security Compliance Institute (ISCI)

ISA Security Compliance Institute (ISCI)

ISCI, a not-for-profit automation controls industry consortium, manages the ISASecure™ conformance certification program for industrial automation and control systems.

MicroSec

MicroSec

MicroSec is a company specializing in IoT security. We focus on bringing enterprise grade security to IoT and embedded systems.

C3i Hub

C3i Hub

C3i Hub aims to address the issue of cyber security of cyber physical systems in its entirety, from analysing security vulnerabilities to developing tools and technologies.

MorganFranklin Consulting

MorganFranklin Consulting

MorganFranklin Consulting is a management advisory firm that works with businesses and government to address complex and transformational technology and business objectives including cybersecurity.

Analygence

Analygence

ANALYGENCE is your trusted partner for mission support, cyber solutions, and management services.

Tailscale

Tailscale

Tailscale is a VPN service that makes the devices and applications you own accessible anywhere in the world, securely and effortlessly.

OX Security

OX Security

OX is a DevOps software supply chain security solution. Teams can verify the integrity and security of every artifact using a pipeline bill of materials (PBOM).

NextGen Cyber Talent

NextGen Cyber Talent

NextGen Cyber Talent is a non-profit providing a platform to increase diversity and inclusion in the cybersecurity industry.