Skip to content
TrackPodcasts
newsMar 3, 202620:15

Does diversity matter in cyber? [CISOP]

CyberWire Daily

About this episode

Show Notes: As cybersecurity matures, one area still lags: diversity. In this thought-provoking episode of CISO Perspectives, host Kim Jones takes the mic solo to address a topic that remains both critical and controversial. Kim explores the current state of diversity in the cybersecurity field, why progress has been slow, and how inclusive teams drive greater innovation and resilience. Tune in for an honest conversation that challenges the status quo and pushes the industry forward. Want more CISO Perspectives?: Check out a companion ⁠⁠blog post⁠⁠ by our very own Ethan Cook, where he breaks down key insights, shares behind-the-scenes context, and highlights research that complements this episode. It’s the perfect follow-up if you’re curious about the cyber talent crunch and how we can reshape the ecosystem for future professionals. Learn more about your ad choices. Visit megaphone.fm/adchoices

Interactive timestamps

Jump to segment

Get every episode summarized

Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

248 searchable segments. Every word is indexed and playable.

Does diversity matter in cyber? [CISOP]

CyberWire Daily

0:00
20:15

Full transcript

CyberWire DailyDoes diversity matter in cyber? [CISOP]. Machine-transcribed; use the interactive transcript above to jump the player to any line.

0:00You're listening to the CyberWire Network, powered by N2K. This exclusive N2K Pro subscriber-only episode of CSO Perspectives has been unlocked for all CyberWire listeners through the generous support of Meter, building full stack zero trust networks from the ground up. Signed by security and network leaders everywhere, Meter delivers fast, secure by design, and scalable connectivity without the frustration, friction, complexity, and cost of managing an endless proliferation of vendors and tools. Meter gives your enterprise a complete networking stack, secure wired, wireless, and cellular, in one integrated solution built for performance, resilience, and scale. Go to Meter.com slash CISOP today to learn more in Book Your Demo, that's M-E-T-E-R dot com slash CISOP.

1:08Welcome to CSO Perspectives. I'm Kim Jones and I'm thrilled that you're here for this season's journey. We're bringing the deep conversations out of the conference, or more realistically the conference bar, and tackling a single complex issue from every conceivable angle across a multi-episode arc. As we continue our inaugural season, we're examining the challenges surrounding the Cyber Talent ecosystem. Today we explore the question, does diversity matter in cyber? Let's get into it. I thought long and hard before I put together today's podcast topic, going back and forth

2:09about whether or not I should discuss this. In this current political climate, I understand that some will believe this to be a political statement. Be assured that it is not. I just can't see how we can talk about the talent ecosystem without addressing the issue of diversity and how crucial it is to our profession. Some of you might enter this discussion with preconceived notions about my views and opinions. My hope is that those who choose to listen to this podcast are, by definition, inquisitive and open-minded. As CISOs passed present and future, we cannot pioneer creative solutions to thorny problems if we assume that we already know the answers before we even start the conversation. Given the potentially controversial nature of this topic, I've decided to do this podcast solo. This way, any slings and arrows regarding the content will be focused exclusively on me.

3:10So here goes. As anyone who has ever worked with me is aware, one of my favorite sayings is, making lemonade out of lemons is easy. The job of a security professional is to make lemonade out of two apples, a grapefruit, and a cup pot, and make it look easy. Problems and situations where asked to address are not ones whose answers can be found on Google. In a career where no might be the first answer, but how must be the last, our ability to put forth creative solutions to thorny problems is one of our most indispensable competencies. When I find that security teams are failing to innovate, my experience has been that it's a result of a failure to think critically about the issues. Critical thinking is the ability to evaluate, analyze, and objectively incorporate information

4:13to develop a unique interpretation and synthesize an appropriate resolution. By our critical thinking, we can conceptualize solutions to truly vexing problems in circumstances. In a world where raw, unsynthesized data is at our fingertips, the need for individuals and teams who can think critically is at a premium. We need to sort through amounts of chaff as we try to define where the relevant gold kernels are. In most cases, the kernels and chaff look almost identical. So where does one gain critical thinking skills? Optimally, these skills are taught in some type of structured academic program focused on problem-based learning. However, the best critically thinking teams are ones made up of folks with exposure to diverse experiences outside of their primary areas of expertise. What is commonly known as thinking outside the box is in actuality, remembering solutions to challenges unrelated to business or technology, and wondering if those experiences can help

5:18solve the current problem. If everyone came from the same background, lived in the same neighborhood, and had the same teachers, dressed the same, thought the same, and played the same games. How on Earth could they be expected to suddenly, spontaneously, have a unique thought? Multi-layered perspectives about things outside of tech disciplines from human behavior, psychology, linguistics and cognition, philosophy, cultural belief systems, and religious contexts. The current events, economics, sociology and political science, and certainly what the past has taught us, history and how individuals and societies as a whole are sculpted, molded, and influenced through cultural context, promotes more creative security solutions. One example of anemic thinking concerns the implementation of email encryption software such as PGP.

6:19In the seminal paper Why Johnny Can't Encrypt, the authors showed that great technology failed to be effective because its creators did not adequately factor in usability issues. Specifically, only 33% of users were able to properly sign an encrypted email in 90 minutes, and 25% of users accidentally sent their secret email in the clear. In a follow-up study done eight years later, these problems persisted despite upgrades to the software. It would be a fallacy to believe that the designers of PGP were inept, rather the problem was their frame of reference regarding usability. The designers made a great tool that made sense to a technologist, but how do you make a tool intuitive enough so that non-technologists whose priorities are not security-based can and want to use the tool? A critically thinking team might have considered different perspectives to help the developers envision a more user-friendly solution.

7:21If innovative solutioning is enhanced by critical thinking and critical thinking is boosted by a variety of perspectives and experiences, it stands to reason by a more diverse team in gender, ethnicity, cultural viewpoint, age, foundational education, physical abilities and sexual and gender orientations will provide more innovative solutions to problems. A 60-year-old black man raised in New England has a different set of outlooks and priorities than a 30-year-old woman raised in Kansas. A first-generation immigrant who attended college part-time while supporting her family has a different perspective from a fourth-generation trust funder with influential parents who went to school on family money. A combat veteran will have a different viewpoint than a conscientious objector. The issue is not whose outlook is correct or better, rather it's that collective experiences and contexts help feed the innovation engine, resulting in more varied and creative solutions.

8:27In theory, cybersecurity should have no issues with diversity. Most of my peers would describe our profession as one of the last great meritocracies in the technology field. As one of my colleagues said, I really couldn't care less about your race, creed, color, religion or sexual orientation. Do you like hard work? Do you like whooping up on the bad guys? Do you like keeping people safe? If you answered yes to those questions, then I've got a job for you. Indeed, I've built all of my CSO teams with this philosophy using those same three questions as my final interview questions for job candidates. While I've never set out to create highly diverse teams, my teams have always been the most diverse in the organizations in which I've worked. This is a bit surprising, given cybersecurity's less than stellar diversity track record. Reliable demographic data for the cyber profession is hard to come by on the best of days.

9:29Today is not the best of days. What statistics can be gathered are quite disheartening. For 65% of our profession is white. This is followed by Asian, African-American and Hispanic or Latino, which cover around 9% for each group. For comparison in the United States, the demographic analysis says that 19.5% of the population identified as Hispanic or Latino and 14.4% identified as African-American. Asian makeup about 26% of all cyber security employees, although they represent 50.5% of the population. And less than 25% of cyber executives self-identified as non-white.

10:41Have you ever imagined how you redesign and secure your network infrastructure if you could start from scratch? What if you could build the hardware, firmware, and software with a vision of frictionless integration resilience and scalability? What if you could turn complexity into simplicity? Forget about constant patching, streamline the number of vendors you use, reduce those ever expanding costs, and instead spend your time focusing on helping your business and customers thrive. Meet Meter, the company building full stack of zero trust networks from the ground up, with security at the core, at the edge, and everywhere in between. Meter designs, deploys, and manages everything in enterprise needs for a fast, reliable and secure connectivity. They eliminate the hidden costs and maintenance burdens, patching risks, and reduce the inefficiencies of traditional infrastructure.

11:44From wired, wireless, and cellular to routing, switching, firewalls, DNS security, and VPN, every layer is integrated, segmented, and continuously protected to a single unified platform. And because Meter provides networking as a service, enterprises avoid heavy capital expenses and unpredictable upgrade cycles. Meter even buys back your old infrastructure to make switching that much easier. Go to Meter.com slash CISOP today to learn more about the future of secure networking and book your demo. That's M-E-T-E-R.com slash CISOP. When I spoke at RSA in 2018 on diversity and cybersecurity, changing the conversation, I opened the talk by mentioning that in 2017, I had spoken, sat on, or moderated panels

12:46participated in or otherwise attended seven diversity sessions or diversity conferences here in the United States, either as individual sessions at large cybersecurity conferences, or smaller venues devoted specifically to diversity. I ended 2017 with the opinion that cybersecurity was not ready to take diversity seriously, and vowed never again to attend a seminar focused solely on diversity. When RSA approached me politely to speak on diversity in 2018, I explained my position and was told that I had an obligation to come and talk about why I felt the industry was not prepared to take diversity seriously. At that time, women made up only 10.5% of cyber professionals, black and brown people made up less than 12%. Since then, we have focused on the issue and the numbers and innovation have improved. When we diversified, we thought more critically and solutions better than ever.

13:51You still with me out there? Haven't run away yet? Well then, let's talk about how we create diverse, critically thinking teams. Here are some starting points. 1. BKSAE-based. As I've stated in the past on this podcast, our profession tends to complain about what is lacking in candidates rather than be specific and concrete about what they want. Getting specific around your knowledge, skill, ability, and experience requirements provides objectivity around your searches for qualified candidates. Remember, a lack of objectivity creates false justifications for exclusion. 2. Diversify your interview panels. I'm going to single out my white male friends for a moment and ask you to visualize the scenario with candor. How would you feel about an organization you were vetting if everyone you interviewed

14:53with was a woman of color? Or if you at nearly 50, face the panel of all 22-year-olds. Even if you were thrilled about the potential opportunity, how would you feel about the company and your prospects for employment and advancement? The phrase DEI initiatives has become code for the return to discriminatory philosophies that would impair our profession and stifle creative solution in critical thinking. Mewly being a person of color does not automatically make me a DEI higher. A lack of a DEI program or policy should not become a cover to return to the days of biased hiring practices. For those not old enough to remember, these policies first came into being because their absence led to systemic inequities. 3. Interview for what you specifically want. Organizations using outdated interview tropes and formats are just as myopic and out of

15:53touch as those who insist that technical interviews are all that should matter. To the latter, having great technical prowess and an inability to communicate or function as part of a team, make you less than optimal for a majority of the non-entry level positions out there. Consider testing critical thinking skills by presenting the candidate with a Kobayashi Maruli problem to solve. The answer is less important than understanding the candidate's thought processes and their ability to unpack their thinking to the interviewer. Note that the next step in such an interview would be to vary the parameters of the problem and see what the candidates do and how they react. 4. Candidates show up. When I talk to young or aspiring cyber professionals, I often hear that they are reluctant to apply for a position in a company because there's no one already they are like them. Every time someone says this to me, my answer is the same.

16:56How the hell is it going to get any better if you don't show up? Folks being the first at anything is hard. I actually kind of sucks in most cases. But if no one steps up to be the first person nothing ever changes, worse, you provide individuals in that company the excuse to keep their hiring practices unchanged since they can't find underserved candidates to apply. The world doesn't change through complaining. It changes through direct action. That old story about everybody blaming someone when nobody did what anybody could have done is still true. Be the courageous hero. If there's no role model, become one, show up. Sadly the topic of diversity, equity and inclusion is currently a contentious hotbed, which is, in my opinion, sending some companies careening have hazardly in the wrong direction.

18:00I submit that teams are stronger, think better, and devise more creative solutions to today's thorniest problems because of the diversity of thinking, not despite it. We need a broad range of perspectives to figure out how to make lemonade out of two apples a grapefruit in a cum quad. Our ability to trailblaze visionary solutions to tricky problems is the unique secret sauce that makes the cyber profession extraordinary. Let's make sure we don't lose that. And that's a wrap for today's episode. Thanks so much for tuning in and for your support as N2K for subscribers. Your continued support enables us to keep making shows like this one. If you enjoyed today's conversation and are interested in learning more, please visit

19:02the CISO Perspectives page to read our accompanying blog post, which provides you with additional resources and analysis on today's topic. There's a link in the show notes. Tune in next week for more expert insights and meaningful discussions from CISO Perspectives. This episode was edited by Ethan Cook, with content strategy provided by myonplot, produced by Liz Stokes, executive produced by Jennifer Eibin, and mixing sound design and original music by Elliot Pelsman. I'm Kim Jones and thank you for listening. Securing and managing enterprise networks shouldn't mean juggling vendors, patching hardware,

20:04or managing endless complexity. Meter builds full stack zero trust networks from the ground up, secured by design and automatically kept up to date. Every layer from wired and wireless to firewalls, DNS security and VPN is integrated, segmented, and continuously protected through one unified platform. With meter security is built in, not bolted on. Learn more and book your demo at meter.com slash CISOP. That's M-E-T-E-R dot com slash CISOP. And we thank meter for their support in unlocking this N2K Pro episode for all cyberwire listeners. M-E-T-E-R dot com slash CISOP

More episodes

More from CyberWire Daily

View all episodes →