Skip to main content

The 10 Most Eminent Women Leaders in Security October 2021

Page 1

VOL 10 I ISSUE 02 I 2021

Secured Future Secure as if there is NO Tomorrow

Digital Wellbeing Maximizing Security with Comprehensive Security Platform


EDITOR’S NOTE The Lurking Threats Behind the Digital Welfare

I

n today’s digitized world, where businesses are booming with innovative ideas and solution-driven strategies, organizations are implementing the latest technologies to gain a competitive edge. These technologies preserve an enormous amount of data, making data one of the most critical aspects for any business and a big target for cybercriminals. Cybercriminals for years have been conducting cyberattacks, but the unexpected spread of the COVID-19 virus came as a massive opening for them. The surge in the cases of a pandemic caused governments to impose worldwide lockdowns, increasing the number of remote working during that period. These lockdowns stroke as the perfect opportunity for cybercriminals as there was a heightened number of vulnerable devices for massive cyberattacks. They hit the iron while it was hot, targeting data of hundreds of individuals and organizations in a planned, coordinated large-scale cyberattack. Sounds scary, right? How, as individuals, are we supposed to prevent private data and information if there is a considerable risk for data breaches and ransomware attacks. How are we supposed to feel safe where these attacks can range from targeting individuals to large organizations? As one of the victims of these cyberattacks, I felt vulnerable and helpless when these cybercriminals overtook almost everything from my e-mail to the intricate details of banking cards initiating unauthorized transactions. However, I was fortunate enough to recover each of my accounts. I was redirected by professionals in the digital security space of the


E H T

Most Eminent

1

Women Leaders in Security, 2021

various organizations to help prevent further attacks on my data. The horror that I went through that day isn’t something that I would like to go through again, but even if I do, these professionals will always assist me to protect my data, ensuring my trust in them. The leaders in the digital security space are consistently coming up with innovative solutions, despite the lack of talent in the industry. However, women from various professional backgrounds are now venturing into the digital security space to fill this gap. They are leading with their sheer expertise to secure our data as their priority. From connecting dots to developing new software, from protecting our essential data to educating the next generation, these women leaders are laying a robust foundation for a better cyber-secure future. The future in digital security is challenging, which is like an adventure, and these cyber leaders are overcoming the difficulties of today to prepare for a better and secure tomorrow. Explore this edition of CIO LOOK’s “The 10 Most Eminent Women Leaders in Security, 2021” to know more about the journey of a few extraordinary cyber leaders. They have helped change the landscape of the digital security space, creating their impact with their profound knowledge, determination to protect, and resilience. While flipping through pages, make sure to scroll through articles written by our in-house editorial team and CxO standpoints of the leading experts to gain insights into the industry. Dive right in!

Aditya Gaikar


CONTENTS ARTICLE

22 36 08 12

Secured Future Secure as if there is NO Tomorrow

Digital Wellbeing Maximizing Security with Comprehensive Security Platform

Chelsey Costello Helping You Find Your Dream Job in Cybersecurity

Debra Baker A Profound Leader Ensuring the Security of Your Critical Resources


18 26 30 38 44

Emily Mossburg Connecting the Dots of Cybersecurity

Gily Netzer A Remarkable Leader in Cybersecurity and Marketing

Lori Sussman A Fearless Veteran Educating Future Cybersecurity Experts

Sivan Tehila Shaping the Cybersecurity Industry by Building New Technologies and Preparing Next Generation of Cyber Leaders

Tanya Janca Helping Anyone and Everyone Create Secure Software


Hitesh Dhamani Editor-in-Chief CONTENT

Senior Editor Alan Swann Executive Editors Aditya Gaikar Alex Spellman

FOLLOW US ON

www.facebook.com/ciolook www.twitter.com/ciolook WE ARE ALSO AVAILABLE ON

DESIGN

Visualizer Dave Bates Art & Design Director Shubham Dali Associate Designer Kartik Balapurkar

CONTACT US ON

Email info@ciolook.com

SALES

Senior Sales Manager Kshitij S. Customer Success Manager Jack Ryan Sales Executives John, Trimukh TECHNICAL

Technical Head Aditya K. Technical Consultant Victor Collins SME-SMO

For Subscription www.ciolook.com Copyright © 2021 CIOLOOK, All rights reserved. The content and images used in this magazine should not be reproduced or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, without prior permission from CIOLOOK. Reprint rights remain solely with CIOLOOK.

Research Analyst Eric Smith SEO Executive Nikita Khaladkar

sales@ciolook.com

October, 2021


Featuring Person

Company Name

Brief

Andrea Knoblauch Principal (Security)

Softchoice softchoice.com

Softchoice is a technology solutions and services provider.

Chelsey Costello Principal Consultant

Talenza talenza.com.au

Talenza is a full-service technology and business operations recruitment agency.

Christina Richmond VP of Security Services

IDC idc.com

IDC is the world's leading tech media, data and marketing services company.

Debra Baker Sr. Technical Program Manager

RedSeal redseal.net

RedSeal helps government agencies and Global 2000 companies measurably reduce their cyber risk.

Dr. Lori Sussman Assistant Professor

University of South Maine System maine.edu

The University of Southern Maine is a public university with campuses in Portland, Gorham and Lewiston in the U.S. state of Maine.

Emily Mossburg Global Cyber Leader

Deloitte deloitte.com

Deloitte is a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax, and related services.

Gily Netzer CMO

Cymulate cymulate.com

Cymulate is trusted by hundreds of companies worldwide, including leading healthcare and financial services.

Karen Gaines Global Head of Cybersecurity Defense

Siemens siemens.com

Siemens is a technology company focused on industry, infrastructure, transport, and healthcare.

Sivan Tehila Founder

Cyber Ladies NYC cyberladiesnyc.com

Cyber Ladies NYC is a place where women can share knowledge, mentor others, and become role models for young women at the beginning of their careers.

Tanya Janca Founder and CEO

We Hack Purple wehackpurple.com

We Hack Purple is dedicated to helping anyone and everyone create secure software.


Chelsey Costello Principal Consultant

Talenza

www.ciolook.com

08

| MM2021 |


Chelsey Costello

Helping You Find Your Dream Job in Cybersecurity

C

ybersecurity is continuously branching its way into every industry, and the recruiting sector isn't new to it; professional recruiters leverage cybersecurity utilizing it to transform business strategies and deliver talent acquisition solutions for organizations. Chelsey Costello, the Principal Consultant at Talenza, is a dynamic leader specializing in recruiting cybersecurity professionals.

This, in turn, has driven salaries in the junior and midlevels higher as a result. Talenza has consulted with its clients and further developed its partnerships by giving direct market information on salaries and candidate insights like what would motivate them to move jobs. The Imperativeness of Work Culture

Chelsey leads the Brisbane Cyber Security division and is a very passionate advocate for women in technology. She genuinely enjoys working with candidates to find their dream job and working with clients to fill skill gaps in their team. She consults with clients to truly understand their requirements and dig deep into the interwebs to find the perfect candidate for the role.

Talking about the significance of positive work culture, Chelsey mentions that it doesn't happen overnight, and it's a combination of many things that match up to create a positive outcome. In Chelsey's opinion, it is essential, but she understands that a positive work culture looks different to everyone. She expresses that it's up to a company to create a truly unique work culture that attracts people who are going to perform at their best – this looks different from one person to the next.

The Inspirations For the past four years, Chelsey has been working in Cybersecurity. She expresses that she wishes she had of considered a career in cyber security at a younger age but felt that the options weren’t known or encouraged. Chelsey also notes a lack of female representation overall means that historically, there haven’t been a many female role models within the industry.

The Valuable Contribution Towards Communities When it comes to giving back to the community, Chelsey doesn't believe that there is one pronged approach, and she strives to contribute to the community across as many paths as possible. Firstly, by actively addressing gender biases in recruitment. She makes it a personal mission to only present genderbalanced shortlists, and in the past twelve months, 44% of the placements she has made in security were female.

Chelsey is constantly inspired by the emerging leaders in the field that have come from various background and stumbled their way into the industry. Her work with AWSN lets her see this firsthand each day. Overcoming the Scarcity

Besides, Chelsey speaks at events and aims to truly partner with her clients, candidates, and the industry as a whole. She speaks at events about diversity and inclusion; most recently, this has been as AISA BrisSec.

The domino effect of the pandemic caused disruption globally. Chelsey saw a significant shortage of talent due to a lack of new talent coming into the country.

www.ciolook.com

09

| October2021 |


I am also big on diversity and inclusion, and I am passionate about attracting and empowering existing female talent in cyber security.

www.ciolook.com

10

| October2021 |


She volunteered for the Australian Women in Security Network at the AusCERT conference. She is a longterm partner of AWSN, helping to support and organize events and encourages new members and networking. Chelsey’s achievements are going above and beyond for women, creating more opportunity and visibility than they may have previously had. Alongside that genuine partnership piece with clients, she helps them to enrich their business through not only gender diversity but also diversity of thought.

completely unaware that a career in technology was an option, and it is because of that stereotype, she didn't choose a career path that she perhaps would have loved. This is why she has now dedicated herself to paving the way for representation and equal opportunities for women within her industry. Chelsey says, "There is something for everyone in Cybersecurity, and it is such an inclusive and fun environment. I believe the visibility of this starts at the grassroots. I recently spoke at an event at St Stephens College, addressing young girls on why they should consider a career in IT. It is of paramount importance to me that girls and women know that they can do anything they want to do. You want to be in technology, go for it, astronaut, go you, the most important thing is to stay true to yourself and remember gender stereotypes are just that, stereotypes!”

Envisioning Robust Future The Talenza Cyber Security team is going from strength to strength, with many people taking notice. While it is increasing its headcount on the horizon, for Chelsey, it's more about making a positive contribution to society as a good global citizen first and foremost.

"I encourage anyone who is looking to take the next step in their career in Cyber to just go for it. The industry is crying out for women in the sector. You will never be out of a job, and it is an exciting, evolving, and FUN community to be a part of," concluded Chelsey.

Bequeathing Emerging Entrepreneurs Chelsey's passion for the industry stems from growing up thinking girls had to pick "girl jobs" and boys pick boy jobs. As a self-confessed tech lover, she was

www.ciolook.com

11

| October2021 |


Debra Baker

Sr. Technical Program Manager RedSeal, Inc.

www.ciolook.com

12

| October2021 |


Debra Baker A Profound Leader Ensuring the Security of Your Critical Resources

T

he web of cybersecurity has become widespread globally, but it still has its flaws, making it vulnerable to numerous threats. However, cybersecurity professionals are consistently upping the game and innovating new ways to eliminate these threats while also providing transparency across the services. One such professional we, at CIO Look, came across is Debra Baker, Sr. Technical Program Manager at RedSeal.

infrastructure visibility, awareness, and security of hybrid networks, including on-premises, cloud, and hybrid cloud. She is also the creator and leads a Cyber Protection Team at RedSeal that reviews the latest threats and vulnerabilities and writes threat solution briefs guiding how to use RedSeal to defend from the latest threats.

Playing a Significant Role

One of the biggest challenges Debra faces is getting cross-department collaboration at customer sites, where she has to work with customer teams on integrating RedSeal into the customer's business processes. She states that to truly have a successful Risk Management program, the networking (onpremises and cloud), security, vulnerability management, and compliance teams must work together. One needs to have collaboration between technical teams and leadership to be cyber resilient.

Tackling the Problems

In her role, Debra helps her clients use and adopt RedSeal products and services to improve their cybersecurity posture by providing cyber visibility, compliance, and risk management. In addition, she also manages product-related governance such as FIPS 140 and Common Criteria by coordinating with third-party vendors and engineering. She also is responsible for managing the SOC2 and FedRAMP certifications for RedSeal's Cloud Security Posture Management (CSPM) product Stratus. RedSeal Stratus enables organizations to understand and secure their cloud and hybrid cloud environments.

Impactful Influence Debra says, "Leaders need to be prepared to hear the good and the bad. Having a manager that says you can be yourself, with both the positive ideas you have and the complaints you have, is empowering. Giving this freedom of thought and inclusivity leads to innovation. Now you feel confident in sharing ideas that you may not have in a stifling environment." That said, she mentions that leaders named Ramesh Kaza at RedSeal, Ashit Vora at Cisco, and Kristina Rogers at Entrust have always supported, challenged, and allowed her to express her ideas.

One of Debra's roles is to manage large-scale enterprise-wide RedSeal deployments providing

“

Those who run the world, Run RedSeal.

Besides, the book series Primal Leadership by Daniel Goleman has opened Debra's eyes to the extent a manager–whether good or bad–can have on a person's career and even home life. In her opinion, this book is a handbook for what makes a manager good and bad.

“

www.ciolook.com

13

| October2021 |


Primal Leadership makes it clear that "Leaders who spread bad moods are simply bad for business—and those who pass along good moods help drive a business's success.”

Impact of Positive Work Culture Debra is totally in for a positive work environment. In her opinion, everyone has to be authentic but with a positive slant. She is a glass-half-full kind of a person who tries to see the positive in every situation even when she gets bogged down. She ensures that each person has a chance to express themselves without retaliation and in a respectful way.

According to Debra, the book Find Your Why by Simon Sinek brings together work and passions relating to one's job. Her "WHY" is that everyone deserves to have privacy while online. Knowing that she works in cybersecurity and helps companies secure their networks and data through good cyber hygiene, segmentation, and strong encryption keeps Debra passionate about her job.

Debra thinks that employees should be able to openly express their ideas even when they go against the status quo. There should not be a fear of retaliation. It's the "yes" culture that leads to conformity and stops innovation and new ideas. Management has to be open to hearing the good and the bad and not taking it personally, but instead taking that information and learning from it.

Debra says, "It's great to work in a field where I am helping businesses secure their networks. Through the Crypto Done Right non-profit I founded in collaboration with Cisco and Johns Hopkins, I provide cryptographic guidance in easy-tounderstand language of what encryption algorithms and ciphers are recommended for non-cryptographers." She adds, "Never let a bad manager bring you down.

Offering to the Community When Debra was asked to co-found the League of Women in Cybersecurity, she jumped at the chance to train women in Cybersecurity. It was great for her being able to give back and train other women from what she has learned in cybersecurity. One woman who was inspired by Debra, got her Master’s in Cybersecurity and got a job at AWS. It makes Debra happy when someone she helped along the way is so

Learning how not to let detractors negatively affect you is paramount as you navigate your career. There is always something better just around the corner. Take those situations and learn from them and move on."

www.ciolook.com

14

| October2021 |


successful. League of Women also helped women navigate how to move into the cybersecurity field.

compliant, or are a new employee at an evaluation lab, then this learning path is for you.

At RedSeal, the CEO, Bryan Barney, is all about promoting equal rights for all and respecting people of different backgrounds. One of his first initiatives was to set up a Diversity and Inclusion Council to ensure everyone at RedSeal is heard no matter what position, gender, race, or sexual orientation.

She is also writing a book titled a CISO’s Guide to Cyber Resilience. It’s a handbook for a CISO to know what steps to take to secure their company’s network and to recover from an attack.

What Comes Next?

Debra believes that every woman-owned business can apply for government contracts since women are minorities. She says, "There are great women-based networking opportunities at the Grace Hopper Conference, which is the largest women's conference in the world. Every company that you can think of is represented there.”

Bequeathing Aspiring Entrepreneurs

Debra's vision for RedSeal is to push forward the company to become cloud-centric. RedSeal Stratus is a Cloud Security Posture Management SaaS platform launched in August 2021. Many companies are moving their data centers to the cloud. In addition, RedSeal's advanced cybersecurity analysis capabilities and name recognition is known in the commercial space as well as it is in the Federal space. RedSeal is the best-kept secret securing well-known companies, as well as military and federal agencies.

"For women moving into information technology, Cybersecurity, and programming, Grace Hopper is a great place to find a job. Also, the Women in Cybersecurity annual conference is not only a great place to find women to hire, but also network and advance in the cybersecurity field," concludes Debra.

Debra recently created a Common Criteria for Developers Learning Path for Infosec Institute. If you are responsible for an upcoming Common Criteria Evaluation, are a developer having to make software updates to ensure your product is Common Criteria www.ciolook.com

15

| October2021 |


Emily Mossburg Connecting the Dots of Cybersecurity

I

she says. “How could I continue to connect with my team—and build relationships with other members of our organization—without actually meeting with them face-toface?”

n a world where digital transformation is rapidly evolving, the pandemic caused a rapid shift to remote work that has further accelerated transformation initiatives. While managing remote working arrangements has always been a challenge for cyber professionals, today, cyber teams must manage the increased vulnerabilities that have accompanied a surge in home-office set-ups, related to where and how remote workers are accessing corporate environments. Additionally, because countless organizations across the world are entering this uncharted terrain at the same time, today’s increasingly-sophisticated cyber criminals are on high alert—and ready to attack at unprecedented levels.

Ultimately, Deloitte, like a lot of its clients, began to integrate video conferences and webinars into its daily business practices. As a result, it required the company to re-evaluate it own cyber strategies. Navigating Unique Times In the early days of the pandemic, as Deloitte focused on finding ways to mobilize its newly-remote workforce and remain agile in the face of change, Emily and her team were responsible for viewing each business decision through a cyber lens.

Fortunately, cyber leaders like Emily Mossburg are here to help organizations prepare and defend themselves in this tumultuous moment in history. Her keen understanding of the cyber landscape, cultivated over years of developing and delivering leading-edge solutions as the Global Cyber Leader at Deloitte, allows her to help both her firm and her clients meet today’s evolving cyber needs.

Over the years, she’s learned that if there’s one thing cyber criminals love, it’s rapid organizational change—because when people are distracted, vulnerabilities tend to arise in greater numbers, and are typically much easier to exploit. “Understanding this, we made sure that before we executed any business change, there was an accompanying cyber solution or program in place to minimize any additional risk.”

A Challenged-Filled Journey Throughout her 18 years in Deloitte’s cyber practice, Emily has seen a lot, but the last couple years have unquestionably been the most fascinating.

Implementing Cyber Expertise “I’ve helped many clients tackle a wide range of cyber challenges over the years, but the pandemic was completely unique. Never before have we seen a mass shift to remote work—it was amazing to see,” she says.

For Emily, building these types of transformative cyber programs isn’t anything new—after all, she established some of the first cyber strategies 25 years ago working at a security startup. She’s also guided many global teams through implementations, and developed innovative technical solutions to thwart ever-evolving threats.

As Emily helped her clients work through the transition, Deloitte was also maneuvering through the changes in real time for their own operations. Both experiences offered Emily invaluable insights.

In essence, the cyber challenges resulting from the pandemic weren’t much different. To respond quickly and effectively to shifting cyber threats, she relied

“Not being able to meet with my colleagues in person really forced me to explore the act of inter-office communication,” www.ciolook.com

18

| October2021 |


Emily Mossburg

Global Cyber Leader Deloitte

www.ciolook.com

19

| October2021 |


Empowering your people with understanding, connection and trust for a cyber-powered future.

heavily on the diversity of thought and varied experiences from her workplace and leadership teams. “We always encourage our clients to embed cyber into their organizations and establish a clear vision and mission around their cyber efforts,” she explains. “You need buy-in from all areas of the workforce if you hope to connect the dots across the broader ecosystem and marketplace.”

“Cyber is more than just a technology issue, which means all segments of the organization, including legal, HR, and even third-party vendors, need to be involved and comfortable in sharing their cyber ideas and concerns.” Shaping the Future Moving forward, Emily plans to continue leading Deloitte's global cyber practice well into the future—helping clients adapt to a rapidly-changing cyber landscape, embed cybersecurity early and transform their cyber operations accordingly.

Promoting A Diverse Work Culture In many ways, Emily believes the pandemic underlined the need for a diverse, inclusive culture when building a strong cyber posture.

She also will push for more diversity and inclusive practices in cyber, and play a key role in encouraging more women leaders to indulge their curiosity, ask questions and, ideally, join the space.

“When you need to respond to a pressing cyber issue quickly, you need to make sure the members of your team feel comfortable speaking up and sharing their thoughts,” she says. “To be effective, they need to be able to tap into their best selves. And I think a diverse and inclusive workforce facilitates that.”

“Don’t wait for the perfect opportunity to find you—or for you to find the perfect opportunity. Seize an opportunity that interests you, jump in, and make that opportunity yours. Shape that opportunity for yourself. But don't wait, it’s an amazing and fulfilling space to be part of," concludes Emily.

In part, that is why Emily has been one of the founders of Deloitte’s ‘Women in Cyber’ initiative, which focuses on increasing the number of women in the cyber field. At the same time, however, she believes a diverse and inclusive cyber approach shouldn’t be limited to the cyber team.

www.ciolook.com

20

| October2021 |


CHOOSE OUR SUBSCRIPTION

1 Year 12 Issues $250

6 Months 6 Issues $130

Stay in the known.

Subscribe to CIOLOOK Get CIOLOOK Magazine in print, and digital on www.ciolook.com

3 Months 3 Issues $70

1 Month 1 Issue $25


Secured Future

Secure as if there is H

NO TOMORROW

ave you ever considered making your career in Cybersecurity? If you have a knack for the digital security space, you might feel butterflies in the stomach. If you seek a sector to fill your entrepreneurial drive, venturing into Cybersecurity can be an excellent career option. However, the cyber security industry demands a lot of knowledge. Before beginning your journey, there are a few things to know firsthand, like the myths and truths of the security industry to work for today’s entrepreneurs to make a career in the security industry? Let us reveal some critical points of Cybersecurity as a career opportunity and the important things to consider.

solutions. Business leaders need to be prepared for the worst situations at every point in the security industry. The security environment demands ideas for complex problems. To make things easier, leaders need to promote diversity and inclusivity in the organization. Promoting equal opportunities makes people believe in achieving the common goal of the organization. Everyone comes from a different background; coming from diverse backgrounds helps to deal with challenges with experience through his/her knowledge. Passion – Whatever you do in life, business, or any other thing, if you lack the passion for doing anything – you will always be far from your goal. Finding the right person at the right job helps to get things on track quickly. Working in the cybersecurity field, you need people with commitment and passion.

Positive Work Culture – Business leaders can deliver their best by cultivating a work environment where everyone performs best. Having a positive work culture enhances and streamlines the workflow motivating the team to give their absolute best. Cybersecurity can be an enriching industry when surrounded by a team that has a positive mindset.

Giving back - Cybersecurity is the industry where companies are indirectly involved in giving back to the community. Business Leaders can continuously contribute to the world by providing their services and securing the business world.

Drastic Changes – This pandemic has changed the business world scenario. More people have come online, and the traditional approach is no longer in place. The same goes for the business leaders; they have to focus more on the security process for the employees and the organization. As more attacks are prone on IT, securing the businesses becomes crucial. This is the time we have seen more and more digitalization along with the increase in attacks. This is something it comes along with, so leaders have to adapt to these changes.

The Future Ready In the challenge filled cybersecurity space, leaders aren’t afraid to take risks; and knowledge is the key differentiator here. Learning as much as you can, staying up-to-date with the industry trends, and spending time with the industry experts to gain insights, will always boost the morale to face these hurdles.

Investment – Investing in Cybersecurity is an excellent way to keep up with the security trends; it can help to have a better future and keep up with the competition. In many ways, it is the best decision to make as the world is transforming towards digitalization.

Overall, the security industry is very much an opportunity than a challenge. However, the training methods and the awareness needs to be increased that is why the increase in the number of entrepreneurs can help the cyber industry to seek talented individuals for a secure tomorrow.

Challenges – One of the biggest challenges for business leaders is to come up with continuous innovative www.ciolook.com

22

| October2021 |


www.ciolook.com

23

| October2021 |


Gily Netzer CMO Cymulate

www.ciolook.com

26

| October2021 |


Gily Netzer A Remarkable Leader in Cybersecurity and Marketing

W

omen have been at the forefront of many industries with their exemplary leadership skills and diligence, and cyber security is no exception. Leading by example, women have not only changed the landscape of the industry, but also have inspired other women to pursue a career in the cyber security. Amongst those women, one is Gily Netzer.

consistent growth year-over-year and is passionate about Business to Human (B2H) style marketing. Educating Market About Game-changing Technology Gily mentions that Cymulate’s journey since inception has been fast paced, challenging and exciting. Success has come through the execution of its short-term and long-term vision, constantly fine tuning its positioning, messaging, and platform to better meet its customers’ needs. It has also come by educating the market and creating awareness that its game-changing approach and technology can solve critical enterprise and service provider security posture validation needs. Gily has built a multi-faceted marketing team which includes product marketing, brand, and corporate communication, digital, field, channel marketing teams which has put Cymulate into the top leadership position within security posture category and led to better brand awareness, demand generation, pipeline acceleration, retention of hundreds of customers and more.

An avid marketer and a results-driven leader, Gily is a marketing strategist and veteran leader with 20 years of international B2B Cybersecurity experience. She currently serves as Chief Marketing Officer at Cymulate, a SaaS-based Continuous Security Validation platform that makes it simple to know and optimize security posture of companies all the time and empowers companies to control and safeguard their business-critical assets. Gily's experience includes marketing leadership roles in startups such as Cymulate, Illusive Networks (of Team8) and large brands, including Symantec. She speaks at events (e.g., GRC World Forums - PrivSec, Ladies in Cyber, Wonder Women in Tech) and is a contributor to publications such as Forbes, Help Net Security, CyberSecurity Ventures, IT Toolbox, etc. She is also one of the few CMOs that can claim to have served in an F-15 squadron.

Transitioning from a Well-Known Company to Startup As a Chief Marketing Officer for her current and last cybersecurity startup, transitioning from a well-known, large company, Symantec, was a big change. Where both startups focused on innovative, new cybersecurity technologies, Symantec focused on well-established customer base with commodity solutions which were easier to sell. At Symantec, Gily worked on a large marketing team where she could focus mostly on field and channel-driven demand generation. Coming into the startup atmosphere with limited resources and team, she learned to be very agile, resourceful, and

Gily is also an Advisory Board member and volunteers as a mentor to students at the Hebrew University, educating the next generation. She is building teams across regions, establishing new technological categories, forming a marketing machine, market leadership, relationships to drive business and

www.ciolook.com

27

| October2021 |


knowledgeable. The change was necessary for her to take both startups from an unknown brand to the market leader position, each in their respective categories.

“

Educating and Offering Value to Security Professionals Second challenge Gily witnessed was COVID-19. Cymulate crossed out its existing 2020-2021 plan and devised an entirely new strategy to fit the challenges COVID brought along with it. People were concerned about their health, job security, providing for their families, working from home, and had no physical events to interact and build relationships with, and more. It is at that point that the company moved over from a pure B2B strategy to a Business to Human (B2H) strategy, thinking of the prospects/customers and partners’ hearts and minds and doing things different. It began doing more for the community, reaching people from a different angle, thinking repeatedly what the value it can create for them and seeing the ROI (Return on Investment) as a longer term KPI.

Cymulate challenges, assesses and optimizes security posture against threat evolutions, simply and most comprehensively.

“

Talking about the impact of the pandemic, Gily shares that the Business to Human (B2H) strategy Cymulate incorporated at the start of the pandemic is here to stay. Cymulate will continue to give back to the community and to be mindful of the impact the pandemic might have had on its prospects and fine tune its marketing accordingly. The company created a free,

www.ciolook.com

28

| October2021 |


Cymulate is the premier continuous security validation vendor. It has created a superior way to assess its customers’ security posture effectively against realworld threats and differentiated itself from the competition by effectively automating everything with software as a service, updated 365/24/7, is simple for enterprises to deploy and manage. The platform is customizable to all maturity levels and enterprise sizes. It is by far the most comprehensive covering the full attack kill-chain, attack vectors as well as purple teaming and red teaming techniques. Building Skill Sets of Cyber Practitioners Moreover, Cymulate just launched a free Cymulate Academy with ISC2 Cybersecurity CPE credits associated with the courses which help build cyber practitioners’ skill sets. It has several opensource projects underway that look at automating continuous automated red teaming, DevOps integration with continuous security validation assessments and even automating the incorporation of new attacker tactics, techniques, and procedures (TTPs) into cybersecurity control checks. It would like to bring in changes to security controls in making things easier to manage and run, more automated and controls which have a better grasp on how to measure and convey actual risk in a better fashion.

online, cyber education program to educate and offer value to security professionals. It extended an offer to use its Continuous Security Validation Platform for 2 free months as COVID broke, and people started working from home with less security controls, just to enable enterprises and security professionals to be safer. The goal is long term and trust-based relationships. The team at Cymulate also thinks about the environment and as a thank you to new customers, they plant trees on their behalf. They have increased community benefit by offering referral to existing customers who bring them new customers by making contributions on their behalf to their favorite charities.

Optimizing Cyber Posture of Companies Continuously Cymulate enables companies to challenge, assess and optimize their cyber posture, simply and continuously. It has been chosen as the best product for 2021 by F&S and as the leader in Innovation by Frost Radar. Its 5year vision is to be the largest and leading validation company without analysts.

Having Optimized Cybersecurity Controls and Incident Response Plans According to Gily, advancements and improvements come when one combines technical development with innovation. Enterprises with modern DevOps change minute by minute and with attackers and threats evolving daily, it is essential for enterprise IT security assessments to maximize coverage, customizability and come with a constantly updating series of tests to ensure that their cybersecurity controls, incident response plans and personnel are optimized. The real innovation is realized by being able to do that in an automated and easily understood fashion and to offer it as software as a service which makes it an easy addition with little to no overhead to incorporate and run.

www.ciolook.com

A Note to Emerging Women Leaders Gily encourages women to step into the industry by saying that there are tremendous opportunities in cyber security industry. If one is a passionate about cyber security and technology, Gily encourages one to study it! She advises, “Also keep in mind that beyond technical roles, there are a vast number of other roles in other cybersecurity domains such as risk management, marketing, and sales as well. I think the biggest advice I can give is to just jump in.”

29

| October2021 |


Lori Sussman

Assistant Professor University of Southern Maine

www.ciolook.com

30

| October2021 |


Lori Sussman

A Fearless Veteran Educating Future Cybersecurity Experts

C

ybersecurity is one of the most critical issues that several organizations deal with today on a global scale. With the ever-growing expansion of digitalization of data, it becomes challenging to protect essential information. Numerous instances of data breaches, ransomware attacks are becoming dangerous threats and heading further into the future, and it will become more critical to build secure cyberspace. However, leaders in Cybersecurity are consistently improving existing technologies, and it is necessary to educate the upcoming generation to utilize their unique take on Cybersecurity.

proudly graduated as a second lieutenant in the Signal Corps, the Information Technology branch within the US Army. Lori served over 24 years of US Army service with distinction and retired at the rank of Colonel. It was her honor and good fortune to assume various leadership positions culminating in brigade command. She benefitted greatly from the mentorship and the sponsorship of enlightened senior officers and officials. During her service, Lori pursued and completed four master's degrees, which proved to be an essential factor as she moved from the public to the private sector after her retirement. She explored large corporations, small businesses and also ventured into entrepreneurship. As a result, she got to work for elite high technology companies such as Cisco, Hewlett Packard, and a local South Carolina Fortune 5000 company. Lori managed highly complex, diverse, and active organizations engaged in developing, acquiring, integrating, deploying, and sustaining state-of-the-art business, technology, and security systems for clients in these roles.

Lori Sussman, Assistant Professor in the Department of Technology at Cybersecurity at the University of Southern Maine, is one such leader who uses her years of expertise to educate and train future cybersecurity experts. Lori is a veteran who dedicated over two decades of life to the US Army. She now helps organizations build the leadership, technology, and security capability needed for this increasingly global and connected future. In 2015, Lori was named one of the CRN 2015 Women of the Channel Power 50 Solution Provider by The Channel Company's CRN Magazine for her exemplary record of success accelerating her clients' needs through technology solutions. A Unique Journey

Lori felt her calling when she read about the need to move from success to significance in the book "Half Time." So she enrolled in the University of New England (UNE) doctoral program in transformative educational leadership.

In a non-traditional path to academia, Lori's career started at West Point as part of the fourth class to allow women into its ranks. Even when dealing with some animosity about women being part of the Corps of Cadets, she learned to "cooperate and graduate." She

In 2018, the University of Southern Maine hired Lori as part-time faculty, and she became full-time faculty in 2019. In three short years, she helped create a new program for a Master's in Cybersecurity, started a community service Cybersecurity Ambassador

www.ciolook.com

31

| October2021 |


“

Preparing students today for the world of tomorrow.

“

program, and started USM's Cyber Defense team called the Husky Hackers. Lori states that it has been an exceptional experience watching students thrive and grow.

and community involvement, thus providing resources for the state, the nation, and the world.

The Mission and Vision of USM

Consistent with the USM mission to be a center for discovery, scholarship, and creativity, Lori emphasizes projects, writing, problem-solving, active student learning, application of theory to practice, and measurable outcome-based learning when teaching technology or cybersecurity courses. She evaluates students using critical thinking papers, written case studies, class presentations, small group work, and applied projects in the university and community.

Leveraging Technology to Teach

The University of Southern Maine (USM) is a unique institution with a mission to provide students with a high-quality, accessible, affordable education. It has comprehensive undergraduate, graduate, and professional programs designed to educate future leaders in the liberal arts and sciences, engineering and technology, health and social services, education, business, law, and public service.

Lori utilizes engaged learning techniques to ensure that all of her students can bring theory to practice by applying their knowledge, skills, and abilities in contexts beyond the traditional classroom and providing application opportunities in the community, the laboratory, and other venues. This engaged learning challenges students because it requires sustained and

The faculty is committed to fostering a spirit of critical inquiry and civic participation. Both students and faculty enjoy a culture of academic freedom in an environment that advocates diversity in all aspects of campus life and academic work. USM supports sustainable development, environmental stewardship, www.ciolook.com

32

| October2021 |


focused application, reflection, and collaboration. In addition, she uses real-world examples to focus on technology and cybersecurity activities to understand the issues better. Putting her students first, Lori creates programs that graduate students with skills, knowledge, and capabilities for the workforce. She strives to immerse students in the technology but with enough creative space to evolve, learn, and grow. When meeting with a student, Lori examines their values, personality, culture, likes/dislikes, strengths/challenges, skills, attitudes, and beliefs. These attributes inform how one can collaboratively navigate their academic career to land that technology job for which they aspire. She spends a great deal of time making sure that her students achieve the objectives of their college experience. They should have a purpose for their present and lifelong learning. Finally, Lori wants to help her students to appreciate the larger view of themselves, their university, and their community. Students must see a connection between their experiences at USM and the real world. Heading Into the Future

The university is starting to shape programs that include opportunities related to experiential learning, internships, scholarships, curriculum and workshop development, outreach programs, and applied research. It has a collective goal of increasing the cyber talent and workforce capacity to meet Maine's and private industry cyber needs.

Lori focuses on creating programs that increase diversity in the technology and cybersecurity workforce. She recently founded the USM Cybersecurity Awareness, Research, and Education Support (CARES) Center, intending to take advantage of being in the state's fastest-growing region.

A Note to Younger Ones USM is a multi-campus university with nearly 20,000 students, making it one of the largest institutions in the University System of Maine. The CARES Center's goals are to create various educational pathways that provide access to underrepresented populations.

www.ciolook.com

In her advice to emerging women leaders in the security space, Lori says, "Be fearless. Believe in your intuition, and don't take no for an answer."

33

| October2021 |


Digital Wellbeing

N

themselves ready with a contingency plan to combat online threats.

o business can thrive in the long term without better security systems. Ensuring the security of business-critical data is the most fundamental need of all organizations. Having a strong and most comprehensive platform for ensuring the safety of the most valuable data is essential for the success of businesses. The pandemic has contributed to the shift of more and more businesses into digitalization. However, threats to cyber security are also rising, with cybercriminals finding different ways to hack the information of businesses. Remote work presents a greater number of security concerns for organizations. Combating the challenge presented by cybercriminals requires cyber security experts to provide capable solutions that strengthen the security of the businesses and minimize the threats created by criminals.

The adoption of the Internet of Things (IoT) and Cloud Computing has dominated the cyber security industry. Many cyber security experts are focusing on developing information security solutions using cloud computing. The cloud computing products and services developed on analytics as a service platform help users recognize and mitigate information security threats quickly. These technologies play a critical role in securing the assets of businesses from cyber threats. They provide the most comprehensive platform for maximizing the information security of businesses. Cyber security experts tap the latest technological potential for creating a strong platform for enhancing information security systems. The growing adoption of the latest technologies will be more crucial for ensuring the protection of the valuable information and assets of the businesses. To ensure better business continuity, cyber security experts need to continuously evolve in their solutions for eliminating all the threats to security systems.

Higher dependence on traditional authentication methods is irrelevant as cybercriminals are more aware of breaking the security of such systems. With the increasing number of online threats to security, the requirement for evolved security solutions is currently the need of the cyber security industry. New time demands more evolved solutions. Old ways need to be given for better adoption of new ways for strengthening the security of organizations. Those who don't adopt new ways expose themselves to cyber criminals' attacks on their valuable business details. The outdated security solutions are no longer viable, efficient enough for protecting organizations from increasing and new threats caused by cybercriminals.

In the future, online radicalization will certainly lead to more challenges in the security industry. Industry leaders need to be prepared enough to develop better solutions, and they also need to come up with contingency plans and strategies. Cyber security infrastructure should be strengthened to enhance security solutions. It is important to protect the privacy and liberty of individuals and businesses, and cyber security experts should take steps to enhance the privacy of businesses. Digital space should not be a ground for cybercriminals by strengthening the security of businesses in all aspects. Internet should be a safe place for everyone. Business leaders and security experts have to combine their business and technical skills to strengthen security in the online environment, which will be the most revolutionary thing from everyone's perspective.

As the threats to cyber security are increasing, there is a dire need for expert security professionals. They should come up with ways to prevent harm to the security of the organizations. Key cyber security experts are implementing the latest technologies such as Artificial Intelligence, Big Data Analytics, Internet of Things, Machine learning, etc., in the business units to enhance the security of the businesses. These adoptions of the latest technologies help cyber security experts identify and detect the risks and threats, which helps them prepare well to avoid and minimize the threats. Cyber security experts are also keeping www.ciolook.com

36

| October2021 |


Maximizing SECURITY with COMPREHENSIVE SECURITY Platform

www.ciolook.com

37

| October2021 |


Sivan Tehila Shaping the Cybersecurity Industry by Building New Technologies and Preparing Next Generation of Cyber Leaders

W

protect against potential cyberattacks on the train, which is considered a national critical infrastructure.

e are living in a highly complex time where, on the one hand, cybersecurity attacks have become more sophisticated, and at the same time, there are too many security tools but not enough talent in the industry.

The Journey Continues When Sivan moved to New York in 2019, she joined Perimeter 81, a leading cloud security company, as Director of solution architecture. During her career in Israel, she often felt like she was the 'only woman in the room'. After moving to the US, she noticed that it's the same here. That's when she decided to start a community to empower women who work in the cybersecurity industry and encourage other women to create and develop a career in cybersecurity. That's how Cyber Ladies NYC began.

Many experts in cyber security are walking an extra mile to address these issues. One such expert, we at CIO Look, came across is Sivan Tehila. A cybersecurity expert and an entrepreneur with over 15 years of experience, Sivan is dynamically contributing to solving the problems in this industry. She is the Founder of Cyber Ladies NYC, and a Program Director & Professor at Yeshiva University. Besides, she also co-founded Onyxia, a brand-new cybersecurity startup (stealth mode) with the vision to support small-medium businesses to protect themselves in the evolving cybersecurity era. Sivan is a cybersecurity strategist, solution architect, and trailblazer for women in cyber.

Creating Next Generation Leaders Recently Sivan has been nominated as the Program Director for the online and in-person cybersecurity programs at Yeshiva University. She has been teaching at Yeshiva University for two years before starting her current position as Program Director, and that's how she realized that she is enjoying teaching and developing new content. Sivan feels that educating and preparing the next generation of cybersecurity leaders is a critical mission, and she is very excited and grateful for this opportunity.

Being Involved in Complicated Defense Operations at Young Age Sivan started her career in the Israeli Defense forces, where she served for ten years as an Information Security Officer. She served as the Head of the Information Security Unit in the Intelligence forces and the CISO of the Research and Analysis Division in her latest positions. During her military service, she got her primary training, and at a relatively young age, she was responsible for building strategies and plans for complicated defense operations and managed dozens of soldiers under her command. Later she joined Rafael, an Israeli Defense industry, and then Israel Railways, where she designed and built a unique and innovative Security Operation Center (SOC) to monitor and www.ciolook.com

Sivan also developed a cybersecurity program for Manhattan High School for Girls, and there's nothing more rewarding than witnessing the program's impact on them. Last year, one of her student's parents called to tell her that thanks to her program, their daughter decided to learn computer science in college and planned to continue to the Masters program Sivan is managing at YU. "I can't even describe the feeling I had at that moment," expresses Sivan.

38

| October2021 |


Sivan Tehila

Program Director & Professor at YU, Co-Founder & CEO at Onyxia , Founder at Cyber Ladies NYC

www.ciolook.com

39

| October2021 |


These are very fulfilling moments that drive Sivan to continue her mission to support the next generation of cybersecurity leaders and hopefully get more women to join them! Sivan's vision at the Cybersecurity Masters program at YU is to prepare the next generation of cybersecurity leaders, readying them for great jobs and impactful careers. At YU, they provide the next generation of cybersecurity leaders with the tools, mindset, and values to deal with the evolving cybersecurity threats and protections. Also, since women make up only 20% of the cybersecurity workforce, promoting diversity and gender equality in the cybersecurity industry is another vision of Sivan and her Cyber Ladies NYC Community. Helping Women Find Jobs in Cybersecurity Industry As part of this year's YU and Cyber Ladies NYC activities, they launched a mentorship program to help women find their first job in the cybersecurity industry. It was a challenging but extremely rewarding opportunity with three successful and unique programs and over 50 mentees participating. Upon completing the program, an astounding 60%+ of the participants were able to start a new job in the field during the pandemic. “While this is just the beginning for these programs, the potential for positive impact is tremendous. There will be an influx of women seeking to join the cyber workforce, and I am very proud of the impact we have created," asserts Sivan. Creating and Building Something Meaningful Everywhere Sivan always keeps moving and sees herself

Photo Courtesy Ina Ricardo Lax www.ciolook.com

40

| October2021 |


“Our vision is to prepare the next genera on of cybersecurity leaders with the tools, mindset, and values required to deal with evolving cybersecurity threats and protec ons.” everywhere she can create and build something meaningful and helpful. She loves working with students, and her long-term mission is to train and prepare the next generation of cybersecurity leaders with 50% women.

to build their career paths with the help of leaders in the industry. She adds,"Get yourself a mentor you appreciate, and trust is another way to learn from someone else's journey and support your career/ business decisions.”

She is also extremely excited and passionate about technology and building new products to support these leaders. She believes the technology she is currently working on with her brand-new company will make CISO's and IT managers' lives much easier and support and make their work more efficient, meaningfully improving their company's security posture.

Towards Secured Future Sivan is a strong force for highlighting the need for greater support for women wishing to enter the bustling cybersecurity space, which men typically dominate. Both professionally and through her Cyber Ladies NYC organization, Sivan is constantly working to spread awareness about challenges and opportunities for women in cyber and the general industry. Currently, Sivan is also working on building a technology that will focus on supporting and improving the security of companies.

Giving Valuable Instructions to Future Entrepreneurs Sivan advises emerging women entrepreneurs in the cybersecurity industry that having a strategy is the key. She states, "Like everything in life, planning in advance can help you deal better with opportunities and failures. Same thing when it comes to our Career. Building a career strategy that includes the education and experience you need to achieve your goals." In fact, this is what she and her partners include in their Mentorship program at YU and Cyber Ladies NYC. They are helping their students

www.ciolook.com

41

| October2021 |


Tanya Janca Founder and CEO

We Hack Purple www.ciolook.com

44

| October2021 |


Tanya Janca Helping Anyone and Everyone Create Secure Software

T

I am the founder of We Hack Purple. When I started this organization, I knew that I wanted to share knowledge with as many people as possible to move our industry towards a more secure future. We started as a subscription model, where I would produce regular amounts of content for our subscribers. Eventually, we realized that if I spent more time creating in-depth courses, rather than creating small amounts of content on a more regular basis, it would create more value for our customers and industry, so we stopped the subscription model. Throughout this time, I moved from being only a content creator to performing sales, learning about marketing, and especially about leadership, blossoming into the CEO I am today.

he cyber security industry has made progress with gender diversity in the past few years, but there is still a long way to go. But there have been few women leaders who are leading by example and encouraging other women to be a part of this fascinating industry. Keeping the spotlight intact on such inspiring leaders from the cyber security industry, we at CIO Look set out on an endeavor to find the Most Eminent Women Leaders in Security. On that journey, we crossed paths with Tanya Janca, the author of ‘Alice and Bob Learn Application Security’ and the Founder and CEO of We Hack Purple.

As a business leader, what is your thought on the changes in the Information Technology & Services and Coaching industry after the pandemic?

Tanya brings her 20 years of experience of coding and IT to the table. She has won countless awards and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). Alongside, she is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. With leaders like Tanya, the future of cyber security for women looks promising. Let’s find out more about Tanya and how she is contributing to the cyber security industry through We Hack Purple.

Information technology services and their uses have changed drastically during the pandemic. I believe that more people, than ever before, are now online and expecting the services they depend on to follow them there. Unfortunately, cybercriminals have also followed this trend, stepping up their game and taking advantage of people who are scared about the pandemic and playing on their emotions to make phishing attacks even more devastating. I feel that companies are taking security more seriously than before, but not seriously enough for me! We need to make products that are safe and secure for our users, and I believe it is our duty to protect our customers and their data.

Below are the highlights of the interview: Give us a brief overview of your position at We Hack Purple Academy, and your journey since inception.

www.ciolook.com

45

| October2021 |


What is your thought on the necessity of a positive work culture? In what ways do you implement it at your organization? I believe that people work for money, but they excel for their boss and/or leadership team. I have had amazing managers, mediocre ones, and awful bosses whom I wish that I had never met. At We Hack Purple, we have a list of values that we always follow, and this has really helped all of us create a more positive work culture. We also have 360 reviews with all managers and employees, to ensure we hear everyone’s side of things. I try to ensure that everyone has their needs heard, and if possible, met. I also ask employees to tell me when there are problems because sometimes it just doesn't come up in any of these other situations, and I believe that my team is my most important resource. At WHP, our people are more valuable than any physical or digital asset, so we treat them that way. What is your opinion on the advancements of Higher Education to improve the offerings with newer technological developments, especially when it comes to building secured companies? I have a lot of negative feelings about universities and colleges and their slow change in regard to technology, especially cyber security. I have had many of them reach out and ask me to work for (approximately) minimum wage in order to make them thousands and thousands of dollars. They want cyber security professionals to create curriculum and teach it, for ‘adjunct professor’ rates, which is very, very low pay. Think “Walmart greeter” pay. Because I'm not a PhD, and I'm not part of their academic pyramid scheme, I'm not considered a ‘real’ professor (despite the fact that I have extensive industry experience, have written a book, and have founded my own Academy). The result of this academic system is that all of us with relevant and up-to-date skills can make significantly more (exponentially more) by working within our field, rather than academia. I believe that current academic systems that I have seen within North America are currently failing their students.

We are a safe and professional space for information security professionals to meet, network, discuss, and learn!

If a trades college were graduating students that did not know how to do their jobs safely and securely, and buildings were burning down, or bridges were falling

www.ciolook.com

46

| October2021 |


down around the world, that would not be acceptable. But right now, universities and colleges worldwide are releasing software developers that are creating incredibly insecure applications, because they don't want to pay people to teach their courses unless they are part of their academic system. I believe the system is completely broken. Which is the best way to meet today’s and tomorrow's challenges with your company’s exceptional application and services for urgent needs coming our way? Investing in your staff, and upgrading your technologist skills, is an excellent investment for today and tomorrow. If you have a team of software developers that you are not keeping up-to-date on security trends and teaching them how to ensure the software they are creating is secure, you will be behind your competition. In what ways do you or your company contributed to the community? If given a chance, what change would you bring in creating a "Community of Secured online learning? We Hack Purple contributes to the community in many ways. Not only have we created a free online community (community.wehackpurple.com), we also provide free content to the public, a diversity scholarship, and I am the founder of #cyberMentoringMonday (an informal mentor/mentee matching community effort that runs every Monday). How do you envision sustaining your company’s competency in a cutthroat and volatile world of Security? Where do you see yourself and the company in the next five years? We Hack Purple is planning to ensure we concentrate on teaching skills that are practical. Many security training companies focus on the glamorous, or obscure, or more “interesting”. We focus on making you completely awesome at your job, or the job you hope to have someday. We want to focus on real life examples, how to set direction, how to solve problems. We want to create students who you can hire directly into a job and know they will excel. Job-ready grads is not something that we believe will ever go out of style.

www.ciolook.com

47

| October2021 |


Turn static files into dynamic content formats.

Create a flipbook
The 10 Most Eminent Women Leaders in Security October 2021 by ciolookmagazine - Issuu