Recent data indicates the cybersecurity industry continues to grapple with talent and skills gaps and the lack of diversity across its workforce. In fact, a recent survey from Boston Consulting Group revealed that 75% of cybersecurity workers are men, and in a recent survey from Heidrick & Struggles, only 14% of U.S. cyber leaders identified as women and/or people of color. Beyond this, for women, people of color, and entry-level or remote workers—imposter syndrome or feeling an inherent sense of otherness is not uncommon.  

As we amplify this year’s Cybersecurity Awareness Month theme “See Yourself in Cyber”, focusing on the people that make up the cybersecurity industry— it’s important to recognize what the industry can do to empower more people to see themselves in a cyber career. Here are a few steps we can take collectively to combat the issues surrounding imposture syndrome and diversity, and further progress as an industry. 

Overcoming Imposter Syndrome 

In order to “see yourself” you also must believe that you belong in cyber. When I first started my career in cybersecurity, I experienced a feeling that many of my other female peers have also experienced – that I needed to change to be “one of the guys.” 

Over time, I learned that my opinions and insights are just as valuable as those of my male peers. As such, I always make it a point to create safe spaces for employees to be themselves and feel empowered to advocate for themselves. Overcoming imposter syndrome requires reshaping your view of yourself and what makes you unique in a more positive light. Here are some techniques I’ve practiced to help me become more confident:  

  • Remember time is your biggest helper. As your confidence and knowledge grows in your position, things will get better. Remembering this can be helpful in and of itself. 
  • Take a step back. When you catch yourself playing the comparison game and losing, ask yourself, “am I really comparing apples to apples here?” Most of the time your answer will be “no.” Once you’ve gotten that more realistic perspective, it’s a lot easier to pull yourself out of a negative spiral and prevent the seeds of imposter syndrome from taking root. 
  • Know your own strengths and weaknesses. Having a more accurate self-image can help combat moments of imposter syndrome and can make it easier to set yourself up for success. If you have an over-inflated sense of some of your skills, you can be setting yourself up for failure. In the other direction, if you’re undervaluing your skills, that could cause you to pass on opportunities where you would’ve shined.  

Cultivating a Safe and Inclusive Culture 

Creating a culture where employees feel safe and empowered to do their best work is also essential in our industry. As an employer, it can help to ask the following questions:  

  • Do we encourage open feedback? 
    • Employees must feel empowered to let their teams/organization know what is and is not working for them. This will have a positive impact on work culture and overall productivity.  
  • Is self-care and mental health built into our culture? 
    • While employees must ultimately ensure they are creating a work-life balance for themselves, it’s difficult to do so without the support of a workplace that builds the concept of prioritizing mental health and self-care into their culture.  
  • Does our company culture inspire collectiveness? 
    • Creating spaces for human interaction can help everyone feel more connected, especially in a hybrid environment. At NetSPI, we have Slack channels dedicated to nearly every hobby and interest under the sun, and a “Kudos” channel for employees to call out their coworkers for a job well done. It’s a positive place for the entire organization to find community and celebrate together. This also reiterates that everything we do is a part of an ecosystem. 
  • Are we striving towards more diversity? 
    • Companies should have specific goals/initiatives to seek out diverse new hires. Consider implementing a Diversity, Equity, and Inclusion (DE&I) committee to both retain current diverse employees and reach out into the community. 
    • Every company should revisit their job descriptions and requirements, especially in the technical fields, to ensure they are inclusive of people that come from varying backgrounds. Focusing on hiring based on skillset allows us to open opportunities to those that will excel in the position that may have been prevented in the more traditional experienced-focused mindset. Ultimately, we must ask ourselves, “How do we make cybersecurity jobs more accessible to more people?” 

Championing More Diversity in Cybersecurity 

In order to achieve better growth and diversity in the cybersecurity workforce, more emphasis needs to be placed on the concept of variety in race, ethnicity, gender identity, and diversity of thought. This means developing a deeper understanding of the differences and experiences that shape people’s perspectives, and intentionally incorporating them into creative problem solving.  

When diversity is championed, it drives better culture, productivity, retention rates, and overall business success. Additionally, we can effectively reduce the “boys club” stigma commonly associated with the industry. Ultimately, this encourages more people to pursue cybersecurity-related education, leading to more diversity in the workforce.  

Furthermore, organizations must work together to provide more equitable learning, coaching and mentoring opportunities for talent new to the industry. At NetSPI, we are addressing this issue through NetSPI University, an extensive entry-level training program where candidates gain a baseline skill set to execute web application penetration testing and external network penetration testing, led by NetSPI’s expert pentesters.  

We have also started to partner with organizations such as WiCyS (Women in Cybersecurity) and Girls Hack Village whose purpose is to create a safe space for attendees to learn about cybersecurity and the challenges that women in the industry face.  

Most importantly, organizations must hold themselves accountable to take tangible steps towards more diversity. Beyond basic “check the box” hiring exercises, the question is: “How can cybersecurity leaders hold space and give credibility to varied voices and ideas?” As we take this month to reflect on ways in which we can move the cybersecurity industry forward, it’s imperative to remember that change starts with nurturing our people.