Startups

Connecting the dots on diversity in cybersecurity recruitment

Comment

Image of people standing on a gray surface amid yellow dots.
Image Credits: gremlin (opens in a new window) / Getty Images

Mandy Andress

Contributor
Mandy Andress is the chief information security officer at Elastic, an enterprise search company, and has more than 25 years of experience in information risk management and security.

More posts from Mandy Andress

Critical thinking and problem-solving are considered vital attributes for the cybersecurity professional — so it’s time our industry applied those capabilities to connect the dots between the skills shortage and lack of diversity.

There’s no question that recruiting talent in sufficient numbers right now is a growing challenge — but it’s one that I believe a more inclusive talent pipeline would help to alleviate.

In its Cybersecurity Workforce Study 2021, industry body (ISC)2 found that 2.7 million information security jobs remain unfilled worldwide. While this number is down from 3.1 million in 2020, we’re a long way from where we need to be. In the face of increased digitization and a rising tide of attacks, the current cybersecurity workforce of 4.2 million people globally needs to grow 65% to keep up with the demand for its skills.

In other words, we’re going to need to draw from a wider talent pool to plug the gaps. But as researchers from Washington, D.C.-based think tank the Aspen Institute point out in their Diversity, Equity and Inclusion in Cybersecurity report, diversity efforts to date “have not addressed the overwhelming white-ness and male-ness of the cybersecurity field.” Estimates suggest that only 4% of U.S. cybersecurity workers self-identify as Hispanic, 9% as Black and 24% as women, the report noted.

It’s clear that our industry faces serious future risks if it doesn’t find ways to recruit new talent to fill the growing number of vacancies. But more than that, its current lack of diversity poses more immediate risks because company systems aren’t homogeneous, and neither are potential assailants.

The authors of The Business Value of a Diverse Infosec Team from the cybersecurity think tank Institute for Critical Infrastructure Technology make this point forcefully: “Homogeneous experiences and perspectives yield less success compared to problem-solving done by teams with varied backgrounds.”

Proactive cybersecurity strategies, by contrast, aggregate a multitude of perspectives, which brings the benefit of innovation, problem-solving and consensus-building.

Shifting the narrative

As the chief information security officer (CISO) at search-powered solutions company Elastic, I believe that individual information security leaders can do a great deal to shift the narrative, at least within their organizations. What this takes is a hefty dose of fresh thinking when it comes to recruitment.

The cybersecurity team I lead as an LGBTQIA+ female CISO includes people who represent the array of human nature when it comes to neurodiversity, sexual orientation, gender identity, race and age. The picture is just as varied when it comes to background, educational pathway and industry experience.

But let me be clear: Diversifying the cybersecurity talent pipeline is not just a numbers game for me. I’m not just focused on onboarding in sufficient numbers to run a fully staffed team. It’s also about improving the quality of that team and the work we perform.

Put simply, a more diverse cybersecurity team is a better cybersecurity team. In a multidisciplinary field like this, different perspectives are critical. When threats and tactics change around us daily, the diverse viewpoints on my team help counter complacency by bringing new thinking to situations. Our adversaries, after all, are continuously trying new tactics, finding new ways to bypass controls and identify vulnerabilities. My team’s different perspectives bring a more disruptive “hacker mindset” to our work in countering attacks.

Our industry’s overreliance on specialists with the “right” qualifications and educational backgrounds might actually be a weakness — a point of view reinforced for me by David Epstein’s 2019 book, “Range: Why Generalists Triumph in a Specialized World.” Epstein argues that generalists with wide-ranging interests are more creative, more agile and able to make connections that their more specialized peers can’t see, especially in complex and unpredictable fields — a description that is a good fit for cybersecurity.

The value of diverse thinking within my current team is evident in the ongoing data protection certification process that we perform for customers. For this key compliance process, diversity is our strength, because our team can quickly get beyond “the way things have always been done” and find better, more efficient and — critically — safer ways to meet changing compliance objectives.

Another example where I’ve seen a clear-cut advantage of diverse thinking is from my team’s approach to supporting our fully distributed workforce. Being a distributed company by design, with almost 80% of our employees working remotely, demands that my team think differently when it comes to data privacy and protection. Our constant innovation in supporting secure remote working meant we were already prepared in this area when the pandemic hit, while cybersecurity teams at other companies were still struggling to make the leap.

Taking action

What matters most, of course, is transforming words into action. For me, it helps that I work for an organization that prioritizes inclusivity and acceptance for all employees in its Source Code.

This gives managers and employees alike a clear set of cues as to who we are as an organization and who we aspire to be, telling employees: “Just come as you are.” By creating an environment that is inclusive for all employees, through a commitment to equal pay, emphasis on internal hiring and prioritizing skills over location, we can hire and retain the best talent wherever they reside.

This year, our company’s aspirational DEI goals include a 40% hiring rate target for women or non-binary individuals, with a 30% hiring rate target for technical roles — globally. And for underrepresented groups, our hiring rate target in the U.S. is 35%, with 27% for technical roles.

With that backing, I’ve personally taken positive steps to ensure that Elastic increases diversity in its cybersecurity talent pipeline. So here are my pointers for other information security leaders:

  • Broaden the scope of qualifications. Look beyond traditional schooling and minimum career experience to see skills, qualifications, experiences and capabilities gained from shorter programs, online certificates, other jobs and participation in cybersecurity communities that support core foundational understanding of systems and their vulnerabilities.
    Some of the most successful teams that I’ve built over the years have not only come from a variety of IT backgrounds, such as systems architecture, business analysis and project management but from outside of the IT discipline entirely. For example, I hired a former emergency medical technician who moved into healthcare fraud analysis before joining my team. Former lawyers have brought attention to detail. People with a marketing background have proved adept at tackling customer data privacy challenges with empathy, while those from the financial sector bring new thinking to compliance issues.
    But what they all have in common, and what has made them strong additions to my infosec teams, is their curiosity, a willingness to question, and excitement to learn and try new things. These transferable experiences are just as important, if not more important, than specific skills.
  • Encourage underrepresented groups. Add language that explicitly states your interest in groups often left out of hiring pools, such as women, people of color and members of the LGBTQIA+ community. Job descriptions should make explicit that the company fosters a welcoming environment for everyone and encourages personal and professional development of its cybersecurity talent.
    For example, I have recruited for an intern program recently immigrated individuals who do not have the standard security qualifications. Most of these recruits quickly moved into full-time roles and outperformed cybersecurity veterans. I have also taken steps to work more closely with local community colleges on sourcing graduates and with recruitment specialists who focus on supplying more diverse candidates for cybersecurity roles, such as CyberSN.
  • Make your hiring process accessible. Many would-be applicants are discouraged if the hiring process isn’t adapted for those with accessibility needs. We’ve worked to ensure that everything from our recruiting site to our internal digital properties and tools follows international guidelines and translates to a positive environment for all candidates and employees.
    Anonymized hiring is an important part of this process. I regularly review resumes with the identifying information stripped to ensure that unconscious bias plays no part when we’re making judgments on job candidates.

Cybersecurity teams need people with diverse life experiences, education and skills, so our recruitment efforts need to reach a far wider audience. If they don’t, we risk overlooking talent and excluding viewpoints that could be instrumental in delivering on our mission as an industry. If we allow that to happen and continue instead to compete for the increasingly sparse talent that fits nicely with age-old biases, we’ll only have ourselves to blame.

More TechCrunch

Boeing’s Starliner spacecraft has successfully delivered two astronauts to the International Space Station, a key milestone in the aerospace giant’s quest to certify the capsule for regular crewed missions.  Starliner…

Boeing’s Starliner overcomes leaks and engine trouble to dock with ‘the big city in the sky’

Rivian needs to sell its new revamped vehicles at a profit in order to sustain itself long enough to get to the cheaper mass market R2 SUV on the road.

Rivian’s path to survival is now remarkably clear

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

1 hour ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

In a research note, HSBC estimates that the Indian edtech giant Byju’s, once valued at $22 billion, is now worth nothing.

HSBC believes that $22 billion Byju’s is now worth zero

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Apple’s annual list of what it considers the best and most innovative software available on its platform is turning its attention to the little guy.

Apple’s Design Awards winners highlight indies and startups

Meta launched its Meta Verified program today along with other features, such as the ability to call large businesses and custom messages.

Meta rolls out Meta Verified for WhatsApp Business users in Brazil, India, Indonesia and Colombia

Last year, during the Q3 2023 earnings call, Mark Zuckerberg talked about leveraging AI to have business accounts respond to customers for purchase and support queries. Today, Meta announced AI-powered…

Meta adds AI-powered features to WhatsApp Business app

TikTok is testing streaks that are similar to Snapchat’s in order to boost engagement, including how long people stay on the app.

TikTok is testing Snapchat-like streaks

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Your usual…

Inside Fisker’s collapse and robotaxis come to more US cities

New York-based Revel has made a lot of pivots since initially launching in 2018 as a dockless e-moped sharing service. The BlackRock-backed startup briefly stepped into the e-bike subscription business.…

Revel to lay off 1,000 staff ride-hail drivers, saying they’d rather be contractors anyway

Google says apps offering AI features will have to prevent the generation of restricted content.

Google Play cracks down on AI apps after circulation of apps for making deepfake nudes

The British retailers association also takes aim at Amazon’s “Buy Box,” claiming that Amazon manipulated which retailers were selected for the coveted placement.

UK retailers file a £1.1B collective action against Amazon over claims of data misuse

Featured Article

Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Rivian has changed 600 parts on its R1S SUV and R1T pickup truck in a bid to drive down manufacturing costs, while improving performance of its flagship vehicles.  The end goal, which will play out over the coming year, is an existential one. Rivian lost about $38,784 on every vehicle…

5 hours ago
Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Twitch has come up with a solution for the ongoing copyright issues that DJs encounter on the platform. The company announced Thursday a new program that enables DJs to stream…

Twitch DJs will now have to pay music labels to play songs in livestreams

Google said today it is partnering with RapidSOS, a platform for emergency first responders, to enable users to contact 911 through RCS (Rich Messaging Service).

Google partners with RapidSOS to enable 911 contact through RCS

Long before product-led growth became a buzzword, Atlassian offered free tiers for virtually all of its productivity and developer tools. Today, that mostly means free access for up to 10…

Atlassian now gives startups a year of free access

Featured Article

A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Artists have finally had enough with Meta’s predatory AI policies, but Meta’s loss is Cara’s gain. An artist-run, anti-AI social platform, Cara has grown from 40,000 to 650,000 users within the last week, catapulting it to the top of the App Store charts. Instagram is a necessity for many artists,…

5 hours ago
A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Google has developed a new AI tool to help marine biologists better understand coral reef ecosystems and their health, which can aid in conversation efforts. The tool, SurfPerch, created with…

Google looks to AI to help save the coral reefs

Only a few years ago, one of the hottest topics in enterprise software was ‘robotic process automation’ (RPA). It doesn’t feel like those services, which tried to automate a lot…

Tektonic AI raises $10M to build GenAI agents for automating business operations

SpaceX achieved a key milestone in its Starship flight test campaign: returning the booster and the upper stage back to Earth.

SpaceX launches mammoth Starship rocket and brings it back for the first time

There’s a lot of buzz about generative AI and what impact it might have on businesses. But look beyond the hype and high-profile deals like the one between OpenAI and…

Sirion, now valued around $1B, acquires Eigen as consolidation comes to enterprise AI tooling

Carlo Kobe and Scott Smith believed so strongly in the need for a debit card product designed specifically for Gen Zers that they dropped out of Harvard and Cornell at…

Kleiner Perkins leads $14.4M seed round into Fizz, a credit-building debit card aimed at Gen Z college students

A new app called MyGlimpact is intended not only to help people understand their environmental footprint, but why they shouldn’t feel guilty about it.

How many Earths does your lifestyle require?

Prolific Machines believes it has a way of transitioning away from molecules to something better: light.

Prolific Machines, with a $55M Series B, shines ‘light’ on a better way to grow lab proteins for food and medicine

It’s been 20 years since Shira Yevin, the lead singer of punk band Shiragirl drove a pink RV into the Vans Warped Tour grounds, the now-defunct punk rock festival notorious…

Punk singer Shira Yevin pushes for fair pay with InPink, a women-focused job marketplace

While the transport industry does use legacy software, many of these platforms are from an earlier era. Qargo hopes its newer technologies can help it leapfrog the competition.

Qargo raises $14M to digitize and decarbonize the trucking industry

When you look at how generative AI is being implemented across developer tools, the focus for the most part has been on generating code, as with Github Copilot. Greptile, an…

Greptile raises $4M to build an AI-fueled code base expert

The models tended to answer questions inconsistently, which reflects biases embedded in the data used to train the models.

Study finds that AI models hold opposing views on controversial topics

A growing number of businesses are embracing data models — abstract models that organize elements of data and standardize how they relate to one another. But as the data analytics…

Cube is building a ‘semantic layer’ for company data