Skip to main content

Cyber Connect Edition 2 2026

Page 1


Human elements OF CYBER

The part of the Mythos story we are not yet discussing

Rise of the Cyber SITH: cyber-enabled cognitive warfare

Future-proof authentication in a post quantum world

PUBLISHED BY:

Source2Create

ABN: 25 638 094 863 team@source2create.com.au www.source2create.com.au

PUBLISHER

Abigail Swabey aby@source2create.com.au

EDITOR

Craig Ford craig.ford@aisa.org.au

EDITORIAL ASSISTANTS

Jane Saafi and Stuart Corner

ADVERTISING

Megan Spielvogel megan.spielvogel@aisa.org.au

DESIGN

Rachel Lee

© Copyright 2026 Source2Create Pty Ltd. All rights reserved.

No part of this publication may be reproduced, stored, or transmitted in any form or by any means without prior written permission from Source2Create Pty Ltd.

While every care has been taken to ensure the accuracy of content, Source2Create Pty Ltd, its editors, and staff accept no liability for errors, omissions, or consequences arising from reliance on information contained herein. The views expressed by contributors are their own and do not necessarily reflect those of the publisher. Readers should independently verify advertisement details and seek professional advice as needed. Compliance with laws including the Competition and Consumer Act 2010 (Cth) remains the advertiser’s responsibility.

Source2Create Pty Ltd acknowledges the Biripi people, Traditional Custodians of the land on which this magazine is produced, and pays respects to Elders past and present.

Security Insight

34 The cybersecurity leader’s balancing act: mastering multiple mindsets in a complex world

40 Future-proof authentication in a post quantum world

44 Still calling humans the weakest link in cybersecurity? Seriously...

50 Moving beyond the blame game: a human-centric approach to cybersecurity

54 The culture tax: why cyber’s best people keep being “difficult to work with”

Training & Recruitment

58 The hiring paradox: why cyber can’t find people who are already there

WORD Fore

Industry reports state that 75% of business email compromise attacks last

year successfully bypassed multi-factor authentication.

The control the industry spent years persuading boards to fund and the baseline organisations were told would meaningfully reduce their risk, is now being routinely defeated. The technology hasn’t failed; the attackers have learned to work around it, through adversary-in-themiddle techniques, session hijacking, and social engineering that exploits the people on the screens and the phone lines.

There is an impossibility at the heart of Australian cyber security currently. Investment in tools and controls has never been higher. Regulatory expectations are tightening, with ASIC treating cyber negligence with the same seriousness as financial negligence and the Privacy Act’s automated decision-making obligations taking effect later this year. The Australian Government’s 2023–2030 Australian Cyber Security Strategy has moved into Horizon 2 with ambitions to scale maturity across the economy. And yet, we are experiencing more cyber attacks than in the previous years, a rate that exceeds both the United States and the United Kingdom. The Australian Cyber Security Centre received a cybercrime report every six minutes. The average cost per incident climbed to $80,850.

It is not for the lack of better tools, but I believe we have underinvested in workforce capability, security culture, leadership literacy, and the ability to learn from each other across sectors and organisational boundaries, particularly with small businesses who are most vulnerable.

AISA’s position papers, published earlier this year, make this case from several angles. Our paper on building cyber knowledge across the Australian Public

Service argues that security cannot remain the domain of specialist teams; it needs to be understood by the leaders making procurement, design, and service delivery decisions every day. Our position on critical infrastructure and national resilience centres collaboration, information sharing, and workforce uplift as the foundations of resilience — not just technical controls, but the human networks that make detection, response, and recovery possible in practice. And our call for secure-by-design digital delivery recognises that security is not a gate at the end of a project; it is a discipline that requires capable people embedded throughout the lifecycle, from discovery through to operation.

The articles in this edition of Cyber Connect tell the same story from the practitioner’s perspective.

This is where AISA’s role matters most. AISA is a community of more than 14,000 professionals who understands that resilience is ultimately a human capability — built through shared learning, professional development, honest conversation about what is working and what is not, and the willingness to keep showing up for work that is often invisible until something goes wrong.

Technology will keep evolving, AI will change the landscape and the threats will keep adapting. But the difference between an organisation that weathers a breach and one that is broken by it will almost always come down to people..

AI-DRIVEN ATTACKS are outgrowing how SOCs operate

There’s a common assumption that when a Security Operations Centre (SOC) begins to struggle, the cause is capability, with the typical response being to add more tooling, more automation, or more analysts.

What we’re seeing across many security teams suggests something different. The way most SOCs operate no longer reflects how attacks unfold in an environment shaped by AI.

The issue isn’t visibility or talent. It’s the structure of the operating model itself, with most SOCs still relying on an event-based approach that doesn’t match how modern attacks behave.

AI-enabled attacks now move through cloud, identity, SaaS and human workflows in ways that appear legitimate when viewed step by step. The signal only becomes clear when those steps are interpreted as part of a sequence. Traditional SOC workflows assume threats will present as discrete alerts, but increasingly they don’t.

This misalignment is creating real pressure, even in organisations with strong detection and mature monitoring.

AI has changed how attacks progress AI has become integral to offensive operations. It accelerates reconnaissance, identifies misconfiguration chains, and automates decision making across multiple paths at once. It has also lowered the

barrier to entry, enabling a wider range of actors to operate with speed and precision.

What we’re seeing at The Missing Link is that attacks are no longer built around single points of failure. Instead, they progress quietly by combining small gaps.

A weak identity control, a permissive cloud policy or an overlooked SaaS configuration may each appear insignificant on their own, but when combined in the right sequence they form a viable attack path.

This isn’t an edge case anymore. It’s becoming a consistent pattern. In some environments, we’ve seen this play out in ways that are easy to underestimate, such as MFA processes being bypassed through social engineering, or low-risk identity and SaaS misconfigurations combining into high-impact access. In both cases, nothing appears critical in isolation, but the outcome is significant.

Much of this activity blends into normal operations. It uses valid access, follows expected workflows, and rarely appears suspicious when viewed in isolation. The challenge has shifted from identifying obvious anomalies to recognising how routine activity connects over time.

Why the event-based SOC struggles to keep up

Most SOCs are still operating with processes designed for a different threat landscape. Alerts are handled individually, context is gathered manually, and understanding only emerges once enough information has been brought together.

For AI-enabled attacks, that approach is increasingly unreliable and shows up in a few consistent ways:

Manual context building slows investigations:

Analysts often work across SIEMs, identity platforms, cloud consoles and ticketing systems to understand what’s happened. As environments grow, the effort required increases, and that delay gives attackers time to escalate privileges, extract data or maintain access before the full sequence is recognised. This is especially true where detection and response times are already under pressure.

These issues aren’t resolved by adding more tools or increasing headcount. They stem from how the model itself is structured.

Interpretation varies from analyst to analyst:

When information’s fragmented, outcomes depend heavily on individual judgement. Two analysts can review similar signals and reach different conclusions. As attack patterns become more distributed and subtle, that variability becomes a risk.

Event-based workflows don’t match how attacks unfold:

Attackers link together small actions into a coherent sequence. When each step is assessed in isolation, the broader pattern is easy to miss until the organisations already exposed.

These issues aren’t resolved by adding more tools or increasing headcount. They stem from how the model itself is structured.

A sequence-based approach is emerging Organisations that are responding effectively to AI-enabled threats aren’t simply adding more capability. They’re changing how their SOCs operate so that the work aligns with how attacks behave. The shift is subtle but important:

Context is established earlier:

Signals are interpreted as part of a sequence as they occur, rather than being pieced together later. This allows analysts to begin with a clearer understanding from the outset.

Automation removes low-value effort: Tasks such as enrichment, evidence gathering and initial correlation are standardised. Analysts spend less time assembling information and more time interpreting it.

Workflows reflect how attacks behave: Investigations follow structured approaches aligned to how attacks progress across identity, cloud and application layers, making it easier to recognise meaningful behaviour earlier.

AI supports reasoning:

AI assists with summarisation, correlation and prioritisation, but decisions involving business impact, uncertainty or risk remain with human analysts.

At The Missing Link, this is where we see the most meaningful change. Progress comes not from adding more into the existing model, but from changing how the work itself is structured.

This ultimately comes down to redesigning how the SOC operates, so context is established earlier, decisions are more consistent, and less of the process relies on manual effort.

What needs to change

Most organisations already possess the capability they need. The shift lies in how those capabilities are organised and applied.

That means moving away from alertcentric processes and towards sequencebased analysis, reducing fragmentation so decisions are made with full context, and automating work that doesn’t require human judgement.

It also means using AI to support reasoning rather than replace it and aligning investigation practices with how attackers operate.

This doesn’t require abandoning existing platforms but rethinking how the SOC functions as a system.

What this means for security teams AI-enabled attacks aren’t just increasing in volume. They’re changing how compromise unfolds.

As attackers move through environments in sequences rather than isolated events, the gap between what the SOC can see and what it can understand becomes more significant. That’s where time is lost and risk builds.

The organisations that adapt will be the ones that align how their SOC operates with how attacks progress, particularly in environments where a managed SOC model is used to reduce operational complexity and improve consistency.

If you’re reviewing how your SOC operates, it’s worth understanding where context is still being built manually and where decisions slow down.

That’s typically where the gap becomes most visible and where meaningful change begins. At The Missing Link, we see these patterns across different environments and can provide an external view of where that pressure is building and where to focus first..

The part of the

MYTHOS STORY

WE ARE NOT YET DISCUSSING

There is a long-standing assumption in cyber security that finding a serious vulnerability takes time.

In April this year, Anthropic introduced a new AI model called Claude Mythos. The early accounts have been striking. In a short period of testing, the model surfaced more than 2000 previously unknown software vulnerabilities, including a flaw that had been sitting inside OpenBSD for twenty-seven years. In testing against Firefox, it produced 181 working exploits in a window where earlier models had produced 2. Researchers using Mythos have since helped chain multiple bugs into a working privilege escalation on macOS within days.

Anthropic has been right to keep Mythos out of broad public release. Access has been limited to a small group of trusted partners through Project Glasswing, giving defenders a head start before similar capabilities reach adversaries. The timeline for that broader availability is being discussed in terms of months rather than years.

Most of the commentary on Mythos so far has focused on the volume of vulnerabilities being discovered. The number that we keep returning to in our own work, though, is a different one. In the early wave of disclosures, more than 99% of what has been identified remains unpatched at the point of disclosure. That figure tells us something more fundamental about the remediation function that was never designed to operate at the pace of what is now arriving at its front door.

This is the part of the Mythos conversation we have not yet had openly enough, and it is the part that matters most for how we lead our cyber functions through the next year.

Patching was always the harder half Anyone who has worked in cyber security long enough to actually ship a fix into a complex production environment knows that finding vulnerabilities and fixing them are very different kinds of work. Finding is usually owned by one team, a defined vulnerability scanning capability, or a time boxed penetration test or a scenariosbased red or purple teaming exercise, and a relatively contained set of dependencies. Fixing, by contrast, has always been a coordination problem more than a technical one.

A serious vulnerability in a typical enterprise does not belong to one team. The platform team owns part of the fix. The application team owns another part. A vendor often owns the most critical piece, and on their own timeline. A change advisory board controls when the fix can be deployed. A business risk owner signs off the residual risk while the work is being done. Every party is acting reasonably within their remit, and the overall result is a remediation timeline that is set not by the fastest team in the chain, but by the slowest. Anyone who has sat in those change calls knows how rational decisions accumulate into slow outcomes.

What has held this together for the last couple of decades is not the absence of vulnerabilities, but the cadence at which they were disclosed and could be addressed. Patch cycles, release windows, and change controls were all designed around a flow of findings that could be prioritised and absorbed over time.

Mythos changes that cadence fundamentally. It compresses discovery into a volume and concurrency that those processes were never built to handle. The chain itself becomes the constraint, and adding more findings to the front of it does not make it move any faster.

Mythos changes that cadence fundamentally. It compresses discovery into a volume and concurrency that those processes were never built to handle. The chain itself becomes the constraint, and adding more findings to the front of it does not make it move any faster.

The currency we have refused to spend There is a reason the remediation chain has not been compressed more aggressively over the years, and it is worth naming, because it sits at the centre of what Mythos asks of us.

The only resource available to compress remediation timelines is availability. To patch faster, we have to take systems down more often, hold more frequent change windows, accept more changerelated incidents, and tolerate more disruption to the people using the systems. We have been unwilling to spend that resource, because availability has become, over the last fifteen years or so, the single number our organisations are most reluctant to compromise.

Most large organisations now treat 99.99 percent availability as a floor of acceptable performance for any system that matters. Some are reaching for one or two more nines on top of that. The number appears in SLAs, in vendor contracts, in operational dashboards, and in the unwritten rules about when a system can be touched. It has become the dominant measure of operational excellence in modern enterprises.

This was a workable equilibrium for a long time. The threats we faced were mostly slow enough that confidentiality and integrity could be defended without significant cost to availability. The implicit deal was that the cyber function would provide protection without disrupting operations, and the business would treat cyber security as a serious investment area in return. Both sides honoured the deal, and the deal worked.

What Mythos and the capabilities behind it are doing is breaking that deal. When confidentiality and integrity can be compromised at a much faster pace, the controls that defend them have to operate at a pace that current availability

tolerances do not allow. There is no version of the response to this that does not eventually require spending availability differently than we have been spending it.

The conversation we have not yet had with our Boards is whether the availability targets they are operating to were set in a world that no longer exists. Most of those targets were calibrated when the cost of slower patching was tolerable. If slower patching now means meaningful exposure to AI-discovered, AI-chained compromise of confidentiality and integrity, the maths underneath those targets has changed.

The point is not to abandon availability as a priority, or to lower the bar for its own sake. The work is to examine whether the current targets were set for a world that has now changed, and to make explicit the cyber risk implications of holding those targets constant. The three sides of the CIA triad were always meant to be in balance with one another. We have allowed one corner to dominate the other two for long enough that the system is no longer in equilibrium.

Not every finding is equal, and we have to stop treating them as if they are The other shift Mythos demands of us is in how we decide which vulnerabilities deserve attention first.

For two decades, the dominant approach has been to prioritise vulnerabilities by severity score. A high-severity finding goes to the top of the queue. A medium-severity

finding waits. A low-severity finding may never be looked at. This approach has the advantage of being simple to operate and easy to report on. It has the disadvantage of being wrong in ways we have been aware of for years and have not yet fully acted on.

Most high-severity vulnerabilities are never actually exploited in any given environment. Research from FIRST, the body that maintains the CVSS scoring framework, has shown that only around 2.3 percent of vulnerabilities rated CVSS 7 or higher see actual exploitation attempts. At the same time, around 28 percent of vulnerabilities that are exploited carry only medium scores. We have been spending our scarce remediation capacity on the wrong things, and we have known this for a while.

What Mythos and the capabilities behind it are doing is breaking that deal. When confidentiality and integrity can be compromised at a much faster pace, the controls that defend them have to operate at a pace that current availability tolerances do not allow. There is no version of the response to this that does not eventually require spending availability differently than we have been spending it.

The reason this matters more now is that Mythos does not respect severity-based reasoning. It reasons across systems. It finds ways to combine moderate weaknesses into viable paths from one point in an environment to another. The macOS work showed this clearly. No single bug in that chain was catastrophic on its own. The combination was.

What this asks of us is a shift from thinking about vulnerabilities as a list to thinking about them as positions on a map. A medium-severity vulnerability sitting on an internet-facing system that connects to sensitive data through a few short steps is far more urgent than a high-severity vulnerability sitting on an isolated internal system that an attacker would have no realistic way to reach. The severity score does not tell us which is which. The position of the finding within a viable attack against our specific environment does.

The underlying idea, sometimes called kill chain reasoning or attack path mapping, is not new in offensive security. What is new is that the tooling to apply it at scale on the defensive side is starting to mature. The cyber leaders who get ahead of this shift will be the ones who can show their Boards a clear picture of which findings actually matter and why, rather than a heat map of how many are open.

When we combine these two shifts, availability spent more deliberately, and prioritisation done by attack path rather than by severity, what we end up with is

The work in front of us this year is harder than the work of buying new tooling or running another assessment. It is the work of starting two conversations that we have been avoiding.

a more surgical approach to cyber risk management. We are not patching faster across the board. We are patching the right things faster, and accepting that some other things will sit longer because they do not sit on any viable path to anything that matters. That is a more defensible answer to the volume problem than promising to remediate everything within thirty days, and a more useful one in front of a Board.

What this asks of cyber leaders

The work in front of us this year is harder than the work of buying new tooling or running another assessment. It is the work of starting two conversations that we have been avoiding.

The first conversation is with our Boards about availability. Not abandoning it, not lowering the bar for its own sake, but examining whether the current targets were set for a world that has now changed, and making the trade-offs visible to those accountable for them. This is a conversation that has to be held carefully,

because availability is deeply tied to commercial commitments and customer expectations, and our role is not to disrupt those casually. It is to make sure the tradeoffs are visible to the people who are accountable for them.

The second conversation is with our own teams and our wider organisations about how we prioritise vulnerabilities. The listbased view of vulnerability management has served us well enough to get here. It will not serve us well from here. We need to be building the data foundation, the tooling, and most importantly the language

to talk about cyber risk in terms of paths rather than findings. This work takes time. The organisations that begin it now will be in a meaningfully different position twelve months from now than the ones that delay.

Neither of these conversations is comfortable. Both of them require credibility that takes years to build, and judgement that takes longer. They are the conversations our profession has spent decades preparing for, even if we did not know it at the time. The part most likely to be resisted, in both cases, is worth examining carefully rather than avoiding. The events of this year are the moment we get to have these conversations, and the moment we will be judged on how well we have them.

The fundamentals of our discipline still hold. Hygiene, defence in depth, identity and resilience all matter as much as they ever did. What changes is the pace at which all of these have to operate, and the standard against which they will be judged. The cyber leaders who carry their organisations through this well will be the ones who can describe what has shifted underneath the function, set the right new conversations in motion, and bring their Boards along with calm, considered judgement rather than alarm.

The events of this year have set the work in motion. The cyber leaders who recognise it for what it is will be the ones who carry their organisations through what follows. .

About the author

Jay Hira is a cyber security leader with over two decades of global experience. He has worked with more than 100 organisations on the decisions that shape cyber risk, resilience, and long-term value, particularly where strategy, regulation, and customer trust intersect. His work spans attack, defence, architecture, governance, strategy, transformation, and operating model design and operationalisation. Jay champions continuous improvement, learning from setbacks, and building teams that perform well when conditions are uncertain. linkedin.com/in/jayhira

HUMAN The

capabilities

AI CAN’T REPLACE

Why the future of cybersecurity will depend less on what we know and more on who we become

Asenior incident responder watches as an ensemble of AI agents investigates suspicious lateral movement across a corporate network. One agent maps the network. Another analyses behavioural anomalies. A third cross-references threat intelligence. A fourth drafts containment options.

The recommendation is clear: isolate the affected systems immediately.

The responder hesitates. The recommendation is technically sound, yet it would disrupt critical services relied upon by thousands of customers. The AI agents have calculated technical risk. She must exercise judgement.

This is the new reality.

For decades, cybersecurity has invested heavily in technology. As artificial intelligence becomes increasingly capable, the next challenge may be developing people. The future of cybersecurity may depend less on what we know and more on who we become.

As intelligent systems become embedded in professional practice, access to information and automated support is no longer the differentiator it once was. The more important question is: What human capabilities and dispositions become more valuable when intelligence itself is no longer scarce?

The cybersecurity profession is entering an era where intelligence is abundant, but judgement becomes scarce. Judgement. Critical thinking. Communication. Curiosity. Integrity. Empathy. Trust. These may become the capabilities that matter most.

The new divide in cybersecurity

For years, the challenge was access to knowledge. Today, information and firstdraft intelligence are available to everyone. Historically, specialised knowledge was concentrated in universities and expert communities. AI is disrupting that model. For the first time in history, we are seeing the large-scale democratisation of knowledge and intelligence. Learners, career changers and professionals can access expertise and problem-solving support almost instantly.

This may prove to be one of the most profound shifts in the history of learning.

Yet while access to knowledge expands, judgement remains stubbornly human. It develops through experience, reflection, mentoring and responsibility. The emerging divide is between those who can wisely orchestrate increasingly autonomous AI systems and those who cannot. As intelligence becomes abundant, capabilities such as judgement, critical thinking, systems thinking, collaboration and ethical decision-making grow more valuable.

Capabilities enable effective performance in complex environments. Dispositions shape how we approach them. Curiosity drives exploration. Integrity shapes decisions. Courage challenges assumptions. Empathy understands consequences. Resilience supports adaptation.

AI may augment knowledge and automate tasks, but it cannot develop these qualities for us.

From Prompting to Conducting

Much of the conversation around AI has focused on prompting, a junior analyst generating a penetration testing script, a career changer drafting a risk assessment, or a student explaining a concept. These uses remain relevant, but the frontier has moved.

We are shifting toward agentic AI with systems that plan, reason and act with growing autonomy, and physical AI embedded in vehicles, industrial systems and smart infrastructure. The professional’s role is evolving from operating technology to orchestrating ecosystems of intelligent digital and physical agents.

Future professionals will act less like individual prompters and more like conductors of complex AI ecosystems. They will design, orchestrate, monitor and intervene in multi-agent systems that autonomously investigate alerts, simulate attack paths and recommend responses.

An AI ensemble might independently detect anomalies, simulate scenarios, generate summaries and propose options. AI may even assist in evaluating organisational and ethical considerations. However, responsibility for decisions and their consequences remains fundamentally human.

Looking credible is not the same as being correct. Being technically optimal is not always the same as being responsible.

That evaluation requires judgement that is earned, not downloaded.

Experience matters more, not less Cybersecurity continues to attract students and career changers from diverse backgrounds which is a positive development that brings fresh perspectives. Yet experience remains one of the profession’s most valuable assets.

Experienced practitioners offer pattern recognition honed over years, contextual awareness, professional judgement, confidence under pressure, and an instinct for when something is not right. They know when to trust the AI ensemble and when to intervene.

AI can accelerate learning, but it cannot replace lived experience. In many ways, advanced AI systems may increase the value of experience. The best conductors will be those who understand both the technology and the human contexts in which it operates.

The dispositions that distinguish trusted professionals

While the profession focuses heavily on technical skills, far less attention is given to dispositions, the qualities that distinguish trusted professionals and leaders.

Curiosity drives continuous learning. Integrity shapes ethical decision-making. Courage enables people to challenge assumptions, including those confidently asserted by AI. Empathy supports clear stakeholder communication. Resilience helps navigate uncertainty and change.

Two professionals may have similar technical knowledge and AI access. What differentiates them is how they think, behave and lead amid complexity and competing priorities. In an AI-enabled future, technical expertise may open the door, but dispositions determine whether others trust them once inside.

If judgement matters more, we need to understand how it develops If judgement is becoming the real differentiator, we must better understand how it develops especially as more people enter the profession through varied pathways.

AI can accelerate knowledge acquisition, but it cannot replace the journey of building professional identity, confidence and trustworthiness. These qualities emerge through authentic experiences, mentoring and reflective practice.

At La Trobe University, our work explores how human capabilities, dispositions and professional identity develop across the cybersecurity pipeline from outreach and education through to early-career practice. The profession has spent decades studying technology. The next challenge may be understanding people.

A shared responsibility

Developing trusted cyber professionals cannot be left to chance. Cyber educational providers such as Universities and TAFE must build judgement, systems thinking and ethical reasoning. Industry must provide mentoring and authentic workplace experience. Professional associations should foster belonging and lifelong learning. Schools, families and communities shape early confidence and aspiration, and especially for people from diverse backgrounds across culturally and linguistically diverse (CALD), underrepresented and nontraditional backgrounds.

The goal is not simply producing more cybersecurity professionals. It is developing trusted professionals and leaders who can thrive in an AI-rich future.

Final reflection

We often speak of a cyber skills shortage. We should also recognise the human capability imperative. The future of cybersecurity will not be determined solely by the intelligence of our machines. It will be shaped by our ability to develop people who can wisely orchestrate them. Because when intelligence becomes abundant, the real differentiator may no longer be what we know. It may be who we become.

Key takeaways

• As AI systems become more capable, human judgement, critical thinking and systems thinking grow more valuable.

• Dispositions such as curiosity, integrity, courage, empathy and resilience underpin trusted practice and leadership.

• Experience, mentoring and professional identity remain critical.

• More research is needed on how human capabilities develop across education and workforce pathways.

• Building the future workforce is a shared responsibility across education, industry, associations and communities. .

About the author

Associate Professor Leanne Ngo is Director of Student Engagement and Employability in the School of Computing, Engineering and Mathematical Sciences at La Trobe University and leads Human Factors in Cybersecurity. Her work focuses on cybersecurity culture, human behaviour, employability, professional identity and the development of futureready cyber and tech professionals and graduates. She is an award-winning educator who works with industry, professional associations and communities to build a more inclusive, resilient and human-centred cybersecurity workforce. Outside work, Leanne enjoys recreational fishing, boating, cooking and mentoring emerging professionals and community leaders. linkedin.com/in/leanne-ngo-86979042

secure system: OF THE THE MYTH

WHY CYBER RESILIENCE IS THE NEW SECURITY

Every major cyberattack of the past decade has delivered the same message: prevention alone is not enough.

From the SolarWinds supply chain attack to the Colonial Pipeline ransomware attack, organisations with mature security programs, advanced tools, and significant investments were still compromised. Not because they ignored security—but because they relied too heavily on the idea that systems can be made secure.

That idea is a myth.

No matter how well designed or defended, systems are complex, interconnected, and constantly evolving. Vulnerabilities exist. Misconfigurations happen. Humans make mistakes. And attackers only need one weakness to succeed.

The real question is no longer: Can we prevent every attack?

It is: What happens when prevention fails?

That’s where cyber resilience begins.

Traditional cybersecurity has focused on stopping attacks before they happen blocking unauthorised access, patching vulnerabilities, and building stronger perimeters. These controls are essential, but they are no longer sufficient.

Cyber resilience takes a different view. It assumes that some attacks will succeed and prepares for that reality.

Instead of asking, “How do we stop everything?”, resilient organisations ask:

• How do we keep operating during an attack?

• How do we limit the damage?

• How quickly can we recover?

This shift is not philosophical it’s operational. And increasingly, it’s what separates organisations that survive incidents from those that don’t.

Modern digital environments have outgrown traditional security models.

Cloud adoption, remote work, and interconnected supply chains have expanded the attack surface far beyond organisational boundaries. Attackers exploit not just technical vulnerabilities, but also human behaviour, trusted relationships, and third-party dependencies.

The result is a simple but uncomfortable truth: prevention is probabilistic, not absolute.

Attackers don’t need to defeat every control. They only need to bypass one.

And when they do, the real damage often begins after the initial breach.

Regular simulations, clear governance, and well-rehearsed response strategies are essential. Because in a crisis, organisations do not rise to the level of their plans, they fall to the level of their preparation.

Once inside, attackers move laterally, escalate privileges, and establish persistence. In many high-profile incidents, the breach itself was minor but the impact escalated due to delayed detection and slow response.

In other words, organisations are often better at building defences than managing failure.

If failure is inevitable, systems must be designed to withstand it.

Cyber resilience is not a single tool or technology, it is a design philosophy built around four key principles:

Critical systems should never depend on a single point of failure. Diverse configurations, backup environments, and alternative communication channels ensure continuity even when components are compromised.

Flat networks amplify damage. Segmentation limits how far attackers can move, preventing local compromises from becoming systemic failures.

Backups alone are not enough. Recovery must be fast, reliable, and tested. The goal is not just to restore data, but to restore operations with minimal disruption.

Resilient systems evolve. They learn from incidents, update configurations, and adapt to emerging threats. Static security is fragile security.

Technology does not respond to crises, people do.

During a cyber incident, decisions must be made quickly and under pressure. Leaders must prioritise actions, coordinate teams, and balance technical and business risks in real time.

Yet many organisations are unprepared for this reality.

Incident response plans often exist only on paper. Roles are unclear. Escalation paths are undefined. And when a real incident occurs, confusion replaces coordination.

Resilience requires more than tools, it requires readiness.

Regular simulations, clear governance, and well-rehearsed response strategies are essential. Because in a crisis, organisations do not rise to the level of their plans, they fall to the level of their preparation.

Traditional security metrics focus on activity:

• Number of alerts

• Vulnerabilities patched

• Threats detected

But these metrics say little about what truly matters: how well an organisation can withstand and recover from an attack.

Resilience shifts the focus to outcomes:

• How quickly can systems be restored?

• How much disruption can be tolerated?

• How effectively can damage be contained?

Metrics like recovery time, operational continuity, and business impact provide a far more meaningful measure of security in practice.

Cyber resilience is not just an IT concern, it is a business priority.

Disruptions affect revenue, operations, reputation, and customer trust. In critical sectors such as healthcare, finance, and infrastructure, the consequences extend far beyond individual organisations.

Regulators are beginning to reflect this reality, placing increasing emphasis on resilience over pure prevention.

For business leaders, the implication is clear: cybersecurity must be integrated into broader risk management strategies. It is no longer enough to protect systems, organisations must ensure they can continue to operate, even under attack.

The gap between prevention and reality will only continue to widen.

As systems become more complex and adversaries more sophisticated, breaches are not a possibility, they are an inevitability.

Organisations that rely solely on prevention will remain vulnerable. Those that embrace resilience designing systems to absorb, adapt, and recover will be far better positioned to navigate uncertainty.

Because the future of cybersecurity will not be defined by the absence of breaches.

It will be defined by how well we handle them.

The idea of a perfectly secure system is comforting, but false.

Security will fail. The only question is when.

Resilience is what determines what happens next. .

About the author

Zubaida Rehman is a PhD candidate in Cybersecurity at RMIT University and a researcher at CloudTech Group. Her work lies at the intersection of cybersecurity, blockchain technologies, and machine learning, with a focus on securing decentralised systems and networks. Her research interests include cryptocurrency security, network traffic analysis, and IoT security, where she aims to design robust, data-driven solutions for emerging cyber threats. linkedin.com/in/zubaida-rehman-00180269

IF A cyber incident cultural harm, CAUSES WOULD

WE KNOW?

Impacts of cyber incidents are often easy to see. Systems go offline. Services are disrupted. Data is exposed.

Organisations have well established ways of assessing technical, operational, financial and reputational impacts when responding to a cyber incident. These frameworks help us understand what has been affected and how significant the consequences may be.

Working in cybersecurity within a healthcare service that supports many Aboriginal communities, I began to wonder whether there were impacts that sat outside these traditional categories.

The more I thought about it, the more I found myself considering whether a cyber incident could create cultural risks or cultural harm and whether existing assessment approaches would help us recognise them.

The more I thought about it, the less certain I became that I could answer that question with confidence.

I kept coming back to the same thought. If a cyber incident causes cultural harm, would we know?

Perhaps this question stayed with me because my path into cybersecurity wasn’t a traditional one. Before moving into cyber, I worked as a clinical dietitian where I saw

how cultural considerations can influence the way people access, experience and engage with healthcare services. That experience led me to wonder whether culture might also influence how specific communities experience the consequences of a cyber incident.

Existing cyber incident response processes and frameworks provide valuable tools for understanding many incident impacts. What I struggled to understand was whether they also helped identify and respond to potential cultural risks.

As I thought more about the issue I found myself revisiting Indigenous Data Sovereignty. It reminded me that Indigenous Data can be connected to culture, community, governance and self determination rather than being viewed solely as an organisational asset.

As cybersecurity professionals, we are trained to think about data in terms of confidentiality, integrity and availability. But what if information forms part of a community’s identity, history, culture or relationship with a service?

Viewing information in that way challenges us to consider whether we are assessing the full impact of a cyber incident or only the parts we know how to measure.

Understanding Cultural Risk

The next challenge was understanding what cultural risk might mean in a cyber context.

By cultural risk, I don’t mean risk to an organisation’s culture or reputation. Rather, I mean the possibility that some communities may experience the impacts of a cyber incident differently because of culture, lived experience and community context.

If that is the case, would we routinely recognise and assess those impacts when incidents occur?

Existing impact assessments may identify reputational damage, psychological impacts, stakeholder concerns, service disruption or loss of confidence. Many organisations already consider trust, stakeholder confidence and broader community impacts when responding to incidents. What I wasn’t sure about was whether cultural considerations were consistently recognised alongside them.

While cultural impacts may overlap with reputational, social or psychological impacts, they are not necessarily the same thing.

Imagine a rural health service experiences a significant data breach affecting sensitive patient information. Systems are

Culture, lived experience and historical context may influence not only how trust is affected but also how it is rebuilt. If impacts like these do occur, would they be recognised early enough to inform appropriate response and recovery activities?

restored, investigations are completed and services resume.

From an organisational perspective, recovery may appear complete.

But what if some Aboriginal community members no longer feel comfortable engaging with that service because trust has been damaged?

Would that impact be recognised?

Has the community really recovered?

Given the importance of trust in healthcare and the historical experiences that have shaped many Aboriginal people’s relationships with healthcare and government institutions, the same incident may be experienced differently by different communities. Culture, lived experience and historical context may influence not only how trust is affected but also how it is rebuilt.

If impacts like these do occur, would they be recognised early enough to inform appropriate response and recovery activities?

From Question to Action

While reflecting on these questions, I realised I had no practical way to consistently identify whether cultural risks might arise when incidents affect Aboriginal communities, their data and the services they rely on.

To further explore these questions, I discussed them with Aboriginal Health stakeholders in our area. Those discussions highlighted the importance of trust, historical experiences, culturally sensitive information, early engagement and culturally appropriate communication when considering how some Aboriginal communities may experience the impacts of a cyber incident. They also reinforced that experiences and perspectives may

differ between communities, emphasising the need to avoid assumptions and take local context into account when considering risks and impacts.

These considerations led me to explore the development of a Cultural Impact Assessment Tool designed to sit alongside existing cyber incident response processes. The concept is intended to help responders recognise when an incident may have cultural implications and prompt escalation for further assessment where appropriate. This allows potential cultural risks to be considered through existing organisational risk management processes rather than being overlooked or only recognised later in the incident response and recovery process.

The aim is not to replace existing approaches but to support earlier recognition of potential cultural risks so organisations can take them into account during response and recovery, helping to minimise harm and better support affected communities.

A Broader Question

My reflections began while considering the potential impacts of cyber incidents on Aboriginal communities, their data and the health services they rely on.

The more I explored the issue, the more I realised it extends beyond any single community.

Australia is one of the most culturally diverse countries in the world.

Communities may experience the consequences of cyber incidents in different ways with culture, lived experience, trust and relationships with organisations all shaping how those impacts are experienced.

Understanding those differences may be important when assessing the impact of an incident and planning how to respond.

Cybersecurity has become very good at understanding what happens to systems. We are getting better at understanding the impact on organisations as well. The challenge may be whether existing approaches always help us understand the full range of impacts experienced by the people and communities affected by cyber incidents.

Not every cyber incident will create cultural risk. But would we recognise potential cultural risks when they arise? And if we did, would it be early enough to shape how we respond and recover? .

About the author

Ebony Crameri is an emerging cybersecurity practitioner in the healthcare sector, bringing a unique perspective shaped by her previous career as an allied health professional. Working within a critical infrastructure environment, her experience spans incident response, vulnerability management, governance, risk and compliance(GRC), cybersecurity awareness and security culture. Ebony is particularly interested in how people and organisational culture influence cybersecurity outcomes and in finding innovative ways to engage people in cybersecurity. linkedin.com/in/ebony-c-a35ab190

Rise OF THE CYBER SITH:

What is “Cognitive Warfare” in relation to Cyber?

Cognitive warfare in relation to Cyber involves the use of digital technologies to influence human psychology & decision-making processes, so that the target/ victim is either unaware of, or unable to alter, the course a malicious actor has directed them towards.

This approach employed by malicious actors moves beyond traditional information management, which normally focusses on the “Black-Hat” information management lifecycle of weaponizing data in order to maximize financial gain, strategic leverage, or operational disruption of a company/individual, because they don’t just steal data, they manage it, just like any other company would treat it like a business commodity where they’re sorting, protecting, and deploying it systematically to exploit weaknesses.

Whereas with Cyber-enabled Cognitive Warfare, they’re focusing on how perceptions and emotions are shaped, targeting the victims/targets with specific content, media, information, and even personal and professional communications that they would respond to, all so that the malicious actor can either gain their trust to act upon later, or lure them into a scenario in which the victim/target opens themselves to be attacked, quite often via (but not limited to) blackmail, extortion, and even sextortion.

In short, the objective typically involves impacting / influencing human behaviour &

institutional stability through the strategic use of information (or disinformation).

Common methods and tactics used?

As with any cyber related attack strategy, where malicious actors use standard cyber intrusion techniques to break down trust in systems and data, when it comes to cognitive warfare, the most common tactics (or methods) used are usually things like;

• “Information Sabotage” where they breach secure systems to steal personal, corporate, or even government held information, then strategically leaked it to the general public, rivals, media, and family/ friends. Often when this method occurs, the stolen data is either subtly or substantially altered with fabricated data, then placed back on to the system it was originally stolen from, as to spread panic, distrust, or even to set up a ransom for the untainted data.

• “Synthetic reality” (a.k.a. generative AI manipulation), which includes, but goes beyond, simply creating deepfaked images, audio, video content of an individual, they’re also used to create artificial/fake crises, or manipulating financial markets. Entire AI generated/ created personas (or Bots) are used to mimic actual human behaviour, often with specific people or target groups in mind, but to also as a means of information flooding, by overwhelming their targets with conflicting reports (often during a crisis), so that it forces “cognitive fatigue” on their targets and often find it too hard to distinguish the truth from fiction.

•

“Exploitation of Cognitive/ Confirmation Biases”, this method is more of a scattershot style, because it doesn’t relate to a specific group, or even individuals, but it still works incredibly well by messing with our basic human psychology, firstly, by playing on the confirmation bias of a group/individual feeding them content that validates their deepest fears or grievances, practically ensuring that they will share it without checking the facts, secondly, it uses what’s known as “emotional hijacking”, effectively hooking people with stories or situations designed to make them feel a certain way, such as furious, confused, or even terrified, which means that rather than thinking it through logically, they post (repost/share) with others in their real or online social circles, causing the misinformation in the original post to go viral, and if it doesn’t, then these malicious actors use “social proof manipulation” by rigging the system with fake likes, shares, and bot comments to make a totally bogus post (or opinion) look like it’s commonly accepted & factual information.

Who are the most likely targets of cyber related “cognitive warfare” style attacks, and why?

There is no one group who are targeted by these types of attacks, they can range from vulnerable groups like teens & preteens, jobless, parents, the elderly, the political &/or ideological, to the influential groups, companies (usually boards or strategic decision makers), governments, defence personnel (and their relatives), as well as regular & social media personalities.

We can see how common this method of “cognitive warfare” has become by looking at the rise in sextortion cases involving teens and pre-teens. Data from the NCMEC cyber tipline, verified by the Australian Centre to Counter Child Exploitation (ACCCE), shows a major shift over the last few years. In 2021, there were around 139 reported cases. That number jumped to about 10,731 cases in 2022 and reached roughly 26,718 in 2023. In the following period, 2024-2025, reports grew by another 323%, bringing the total to approximately 82,764 cases.

Sextortion of teens & preteens is a severe form of cognitive warfare because it exploits their developmental window, one where the brain is uniquely vulnerable to emotional manipulation, cognitive overload, as well as religious &/or social panic, the malicious actors essentially hack the specific psychological architecture of their adolescence, one where social and religious peer group, even family acceptance is a survival mechanism, in order to force compliance.

The malicious actors usually try to isolate teenagers by making them panic about the immediate embarrassment or consequences, often convincing the teens that confiding in their parents, teachers, or the police

Defending against these types of attacks, requires a combination of social resilience, mental self-governance, and cyber awareness.

will get them into major trouble, this fear keeps the teens from speaking up or asking for help, leaving them feeling completely cut off and stuck listening only to the malicious actor, who will usually continue to ask for exploitive material or financial gain. This constant pressure can quickly become overwhelming, taking a heavy toll on a teenager’s mental well-being. It can lead to severe anxiety or feelings of helplessness, making it incredibly difficult for them to see a way out, without resorting to self-harm, or in some cases suicide.

The list of who they’re not targeting and how might be depressively shorter than that of who they do target and the methods used, but to put things in perspective, not everyone falls into these groups or categories, nor are they guaranteed to be targeted even if they are, but by simply being aware of what cognitive warfare is, the methods used, and who might be a target, it becomes that much easier to defend against such attacks, or at least be able to recognise the signs that someone is falling into that trap.

Steps/methods to help defend against “cognitive warfare” style attacks. Defending against these types of attacks, requires a combination of social resilience, mental self-governance, and cyber awareness.

It’s more than just fact checking content (which is still important), think of it like giving your mind a built-in filter, for starters we need to better educate people in basic cyber awareness, helping to spot dis-information before it spreads, we also need to consider mental self-governance, which is all about keeping ourselves in check, catching our own potential biases and thinking things through when a post or article makes upset, BEFORE we share it.

We can lower our target profile by tightening up privacy settings, turning off tracking ads that profile our habits & vulnerabilities, flagging bot accounts, because threat actors rely on us being passive about security, so through mental self-governance, questioning emotional headlines, and practicing cyber awareness, we can be better prepared for these types of digital attacks. .

About the author

Kyle is a local and international public speaker, self-described polymath, and cybersecurity professional with 20 years of technical and support experience. He has held key roles, including Cyber Security Analyst at Bega Group and Senior Security Engineer at ReeceTech, email security & cyber awareness at Mimecast, Security Operations at Tabcorp, and holds diverse certifications across cybersecurity (Cert IV), ITIL, networking, training, and audio-visual arts. Driven by a passion for education, career development, and youth mentoring through organizations like the Raise Foundation, Kyle works as a consultant and educator dedicated to cyber awareness training for students and industry professionals alike. Outside of work, he is an avid tinkersmith & blacksmith who enjoys electronics, 3D printing, and cultivating his encyclopaedic knowledge of the Halo and Star Wars universes. linkedin.com/in/kyle-waters-688b00159

VS Compliance capability:

A professor I deeply respect, Prof. Atif Ahmad at the University of Melbourne, once told me something that stuck.
Compliance checks if you have the right pieces on the chess board. Compliance doesn’t consider how well you play chess.

That line has shaped how I think about cybersecurity compliance ever since. Not because it dismisses compliance. It doesn’t. But because it draws a line between two things the industry has been confusing for years: having a certification and having the capability to protect yourself.

The market has been chasing the wrong axis

The compliance industry started with good intentions. Organisations under pressure to demonstrate good security practices created demand for certifications. That demand created pressure to certify quickly. And that pressure built an entire ecosystem competing on one thing: speed.

Platforms, auditors, enterprises, organisations going through the process. Everyone played a part. It wasn’t one bad actor. It’s structural.

The result is an entire market that has been optimising for one axis: get certified. Get the badge. Get the pieces on the board.

But having the pieces was never what protected you.

Knowing how to play was.

Regulation works. That’s not the debate. Before going further, let me be clear. Regulation and compliance frameworks have a critical role. Research consistently backs this up. One study found that highly regulated industries perform nearly 200% better on cybersecurity than their low-regulated counterparts (Malaivongs et al., 2022). Other research shows that even indirect regulatory influence drives meaningful security adoption, with entire industries adopting encryption not because it was mandated, but because regulatory design incentivised it (Thaw, 2013).

Regulators play an essential role in setting expectations, raising the floor, and holding organisations accountable. The question isn’t whether compliance matters. It does.

The question is whether the process of achieving compliance is building real capability or just generating paperwork.

Compliance can build capability. But only if you let it. Here’s what gets lost in the speed race. A well-designed compliance process is genuinely powerful. The framework gives you structure. The standard shows you what good looks like. The audit should force honest self-examination. Gap assessments surface blind spots. Remediation builds muscle.

All of that develops real cybersecurity maturity, if you engage with it properly.

Maturity, in this context, means the depth of an organisation’s cybersecurity capability: how well you understand your risks, how effectively your controls operate, how your people respond under pressure, and how continuously you improve. It’s the difference between having a policy and living it.

When compliance is done right, the process itself builds that maturity. Your capability and your certification move together. They’re coupled.

When compliance is done wrong, they decouple. You move up on paper without moving forward in practice. You get the badge, but the security underneath it hasn’t changed.

A simple way to think about it I find it helpful to map this on two axes.

The vertical axis is compliance and certification achievement.

The horizontal axis is cybersecurity capability and maturity.

Four positions emerge:

The bottom-left is the starting point. No certification, limited capability. Most organisations begin here, and there’s no shame in that.

The bottom-right is where organisations with real capability sit before they’ve formalised it. They know how to play, they just haven’t entered the tournament. The certification would be straightforward because the substance is already there.

The top-left is checkbox compliance. Certified, but the underlying capability hasn’t kept pace. The process was shallow, the templates were filled, the badge was issued. The pieces are all on the board, but the organisation can’t play. This is where the race to speed pushes you.

The top-right is where compliance and capability meet. The certification reflects genuine maturity. The process was substantive. It challenged the organisation, surfaced gaps, and built real muscle. This is compliance as recognition, not as destination.

The healthy path is diagonal: compliance done right moves you across both axes simultaneously because the process itself is building your capability as you go.

The broken path is vertical: compliance done wrong lifts you up on the certification axis without any corresponding growth in capability. And when the market rewards speed above all else, the distance between the badge on the wall and the security underneath it only grows.

Where does risk fit?

Some practitioners argue that a risk-based approach solves this. Understand your risks first, then invest capability where it matters most.

There’s merit in that. Risk helps you calibrate where to focus. But risk-based approaches carry the same vulnerability as compliance-based ones: they can be gamed. “We assessed our risk and determined it’s low” becomes the new checkbox. The risk register becomes the new set of pieces.

More fundamentally, risk assessment itself requires capability. You need mature people, mature processes, and a mature understanding of your environment to assess risk properly. An immature organisation doing a risk assessment is like a beginner evaluating their own chess game. They don’t know what they don’t know.

Risk doesn’t come before capability. It depends on it.

So what should you take from this? Compliance and capability are not competing priorities. They’re the same journey. The industry just forgot that.

If your compliance process didn’t challenge you, didn’t stretch you, didn’t make you uncomfortable at any point, question whether you’re really where you think you are.

Have the right pieces. But learn to play. .

MASTERING MULTIPLE MINDSETS IN A COMPLEX WORLD

In the modern cyber landscape, the role of a security leader is no longer defined by a single skillset or a fixed leadership style.

Instead, it is a constant act of mental agility — the ability to shift seamlessly between different mindsets depending on the situation at hand. One day, you might be designing security controls for Generative AI deployments. The next, you could be in the middle of a high-pressure incident response call with regulators, executives, and technical teams all looking to you for direction.

The challenge? These mindsets often pull in different directions. The mark of a great leader is not just being able to operate in each mode, but to transition between them effortlessly, ensuring that every decision — no matter the mindset — aligns with business objectives, executive expectations, and the long-term vision of the organisation.

1. The Architect Mindset –Designing for the Future

When an organisation decides to integrate Generative AI into its customer service platform, the security leader must think like an architect:

• Anticipating risks such as prompt injection attacks, data leakage, or model poisoning.

• Designing controls like input validation layers, AI usage policies, and continuous model monitoring.

• Ensuring compliance with privacy regulations and ethical AI guidelines.

Example: A large financial services firm rolls out an AI-powered chatbot.

The security leader works with developers to embed real-time anomaly detection into the chatbot’s responses, preventing it from inadvertently revealing sensitive customer data. This proactive design prevents reputational damage before it can occur.

2. The Commander Mindset –Responding to the Now When a ransomware attack hits a manufacturing plant, the leader must pivot instantly into a commander’s role:

• Making rapid decisions with incomplete information.

• Coordinating IT, OT, legal, and communications teams.

• Managing the flow of information to executives, regulators, and the media.

Example: During a late-night incident, a leader directs the isolation of compromised systems while simultaneously briefing the CEO on operational impact. Within hours, they have a recovery plan in motion, ensuring production resumes with minimal downtime.

3. The Diplomat Mindset –Aligning with the Business Even in technical crises, the leader must ensure decisions align with business priorities and risk appetite. This means:

• Translating technical risk into business impact.

• Negotiating with executives on acceptable trade-offs between speed, cost, and security.

Example: A retail chain wants to fasttrack a new e-commerce feature before the holiday season. The security leader negotiates a phased rollout — enabling the business to capture seasonal revenue while ensuring critical security testing is completed in parallel.

4. The Cohesive Force Mindset –Keeping the Organisation Together

In times of uncertainty, the leader becomes the steady hand others rely on:

• Sharing the burden with fellow executives.

• Maintaining unity across teams with different priorities.

• Commanding a room full of strong personalities while remaining empathetic to those under pressure.

Example: After a breach, tensions rise between the marketing team (concerned about brand image) and the IT team (focused on technical containment). The leader facilitates a joint strategy session, ensuring both sides feel heard and aligned on a unified response.

5. The Enabler Mindset –Promoting Growth Around You

True leaders don’t hoard the spotlight — they create it for others:

• Mentoring emerging leaders.

• Delegating high-visibility projects to team members to build their confidence and profile.

Example: A CISO assigns a promising security analyst to lead a tabletop exercise for the executive team, providing guidance behind the scenes. The analyst gains valuable exposure, and the organisation benefits from fresh perspectives.

6. The Visionary Mindset –Carrying the Light Forward

The visionary leader keeps the long-term interests of the organisation in focus:

• Inspiring teams during difficult times.

• Championing investments in resilience even when short-term ROI is hard to prove.

Example: A utilities provider faces budget cuts. The leader successfully advocates for continued investment in OT network segmentation, framing it as essential to national critical infrastructure protection — a decision that pays off when a future attack is contained.

When Mindsets Collide

• The Architect wants to slow down and perfect the design.

• The Commander needs to act immediately.

• The Diplomat must balance both with business realities.

• The Cohesive Force must maintain unity when tensions rise.

• The Enabler must step back to let others shine.

• The Visionary must keep the long game in sight.

The art lies in knowing when to switch gears — and doing so without losing alignment with the organisation’s mission and values.

The Leadership Imperative in Critical Infrastructure

In critical infrastructure sectors — energy, healthcare, finance, transport — the stakes are even higher. Leaders must:

• Protect public safety and national security.

• Maintain profitability and operational continuity.

• Demonstrate measurable returns on security investments.

Example: A hospital’s CISO must ensure patient safety while meeting budget constraints. They implement a tiered security monitoring approach — prioritising life-critical systems for real-time monitoring while scheduling less critical systems for periodic review.

Three Guiding Principles for Cybersecurity Leaders

1. Anchor Every Mindset in Business Alignment

Whether designing, responding, or recovering, decisions must serve the organisation’s strategic objectives and risk appetite.

2. Be the Steady Hand in the Storm

In moments of crisis, your composure and clarity will define how the organisation remembers the event — and you.

3. Lead for Legacy, Not Limelight

Build systems, teams, and cultures that thrive without you in the room. Your greatest achievement will be the leaders you leave behind.

The Leader the World Needs Now

The cybersecurity leader of today is a strategist, tactician, diplomat, mentor, and visionary — often all in the same day. They are the person others choose to depend on, the one who can command a room and lift a team, the one who can design for the future and act in the moment.

In a world of accelerating threats and transformative technologies, such leaders are not just valuable — they are essential.

The Cybersecurity Leadership Mindset Matrix Quick Reference for AISA Readers

In the fast-moving world of cyber, leaders must switch between mindsets with precision. Here’s a snapshot of the six core mindsets — and how they play out in practice.

Mindset Purpose

The Architect Design and build secure, scalable systems for the future.

The Commander Lead decisive, coordinated responses under pressure.

The Diplomat Align security actions with business priorities and risk appetite.

The Cohesive Force Maintain unity, trust, and morale across teams.

The Enabler Empower and grow future leaders.

When It’s Needed

Rolling out new tech like Generative AI, cloud migrations, or IoT deployments.

During a breach, ransomware attack, or critical incident.

Balancing speed-tomarket with security assurance.

When tensions rise between departments during high-stress events.

In day-to-day operations and strategic projects.

The Visionary Keep long-term organisational resilience in focus. During budget planning, strategic reviews, or postcrisis recovery.

How to Use the Matrix

Illustrative Example

Embedding AI usage policies and anomaly detection into a new AI chatbot before launch to prevent data leakage.

Directing isolation of compromised OT systems in a manufacturing plant while briefing the CEO on operational impact.

Negotiating a phased rollout of a retail e-commerce feature to capture seasonal revenue while completing security testing.

Mediating between marketing and IT after a breach to align on a unified public and technical response.

Assigning a promising analyst to lead an executive tabletop exercise, providing mentorship behind the scenes.

Advocating for continued OT network segmentation in a utilities provider despite budget cuts, preventing future large-scale compromise.

• Self-check: Which mindset do you default to? Which do you need to strengthen?

• Team alignment: Share with your leadership team to build awareness of when and how to shift gears.

• Crisis drills: Use scenarios to practice moving between mindsets under simulated pressure. .

About the author

Dr Sriram Raghavan is a seasoned leader with demonstrated expertise in spearheading teams to bridge Technology, Cybersecurity and Business and drive organisational success through innovation. He specialises in delivering scalable and secure engineering frameworks. My technical expertise expands to leveraging AI, Generative AI, Big Data & Analytics, and Secure Cloud-enabled architectures to empower data-driven decision-making and enable transformational change. With almost 20 years at the forefront of Cybersecurity in both industry and academia, he excels at strategically solving complex business challenges and fostering a shared vision of robust security and sustainable growth through adaptable leadership. Dr Raghavan is renowned for building strong relationships with vendors, stakeholders, and cross-functional teams, fostering collaboration to achieve common goals. He periodically writes for a LinkedIn series titled Cyber Security: The Design Perspective. He holds a PhD in Computer Science and specialise in Digital Forensics and Cyber Security. linkedin.com/in/sriramraghavan

Quantum computers promise extraordinary computational power. While they hold enormous potential in fields such as medicine and scientific research, they will also challenge widely used cryptographic algorithms that underpin today’s digital infrastructure.

Modern cybersecurity has relied on strong cryptography to protect financial transactions, secure communications and safeguard digital identities. Actual risks and opportunities are emerging that could reshape how organisations approach their short- and long-term security, driven in part by innovations in quantum computing.

“Harvest now, decrypt later”: A real threat or just tech industry hype? A post-quantum future presents interesting challenges, including the threat of future quantum computers that can break current encryption algorithms (RSA, ECC) – potentially rendering digital security, financial systems and confidential data vulnerable to “harvest now, decrypt later” attacks. In theory, these advanced computers could bypass current encryption within hours, rather than many years, posing an enormous risk to data privacy and digital infrastructure. This is where the impact of post-quantum cryptography (PQC) comes in to address these challenges, and progress is underway globally.

There is currently a lot of discussion about preparing for a post-quantum computing future – including from global technology vendors and Gartner, which has positioned post-quantum computing in its June 2025 Hype Cycle for Enterprise Networking

towards the end of the ‘peak of inflated expectations’ and predicts it will reach its plateau in five to ten years.

Even if commercial quantum computers are not here until 2030, the personal information collected today could still be valuable to the bad actors when those capabilities arrive. Healthcare records, financial transactions, government communications and intellectual property often require long-term protection. If adversaries are already collecting encrypted information, the risk horizon extends well beyond the present.

Government Advice on PQC

The Australian Government’s Australian Signals Directorate (ASD) advises that by the end of 2026, organisations should have a refined plan for their transition to post-quantum. The transition plan should account for organisations’ security goals, risk tolerances, dependencies and the value of their data.

Preparing well in advance for postquantum means organisations need to act now by assessing their cryptographic exposure and, if required, invest in a digital uplift of all applications and services to ensure they are quantum-resilient. It’s not about predicting the exact arrival of quantum computers, but about building resistance to attacks in the first place by

deploying phishing-resistant authentication to stop 99.9% of attacks and adopting technology that is crypto-agnostic and can accommodate future developments with ease.

A critical step for organisations will also be establishing a clear cryptographic bill of materials (CBOM). Many existing solutions lack support for emerging PQC algorithms, making it critical to identify early which platforms will require updates and which vendors will need to be engaged. This will require close collaboration across the industry and with standards bodies to evolve underlying protocols, including the FIDO PIN protocol and attestation, PIV and OpenPGP algorithms, and related specifications to address the unique characteristics and requirements of PQC.

Ultimately, the adoption of post-quantum cryptography will be an evolution rather than a sudden transition. The goal is to ensure digital identities remain secure against future quantum threats without sacrificing the usability and trust that have comprised our foundation from the start.

The ASD’s recent Quantum technology primer for Communications advises that “Organisations should consider adopting quantum-resistant authentication mechanisms (such as post-quantum digital signatures), multi-factor authentication and secure key storage.

A similar conundrum to Y2K

For those who remember Y2K, PQC presents a similar challenge, but here there is no specific deadline. Many of the global technology giants, including IBM, Microsoft, Google and Apple, have already made quantumsafe infrastructure and applications available to their customers.

For organisations managing sensitive information such as financial data, intellectual property or personal identity records, this risk cannot be ignored. However, I firmly believe that while quantum computing will affect cryptography and therefore, security, post-quantum preparedness is only part of the strategic priority organisations should be considering.

Prevent data theft now

Organisations cannot afford to wait for the quantum threat to materialise before acting. The risk of data theft is immediate and attackers are already exploiting weak authentication methods to gain access to sensitive systems and information.

The most effective step organisations can take now is to implement phishing-resistant multi-factor authentication (MFA), such as passkeys or hardware security keys like YubiKeys.

By strengthening authentication now, organisations can shut down the most common attack vectors, protect their most valuable data assets, and build a stronger foundation for future quantumresilient security.

Plan the PQC transition immediately

The transition to quantum-resistant cryptography will take time and will require significant coordination across the technology ecosystem. Encouragingly, standards bodies, including the US Government’s National Institute of Standards and Technology (NIST), have already released encryption tools designed to withstand attacks from quantum computers. NIST is encouraging system administrators to begin transitioning to the new standards immediately.

Organisations should begin implementing PQC-ready security measures now, including future-proofing their

authentication through subscription-based security key services, such as YubiKeyas-a-Service. This approach enables a smoother transition to quantum-resilient security, ensuring organisations can rapidly adopt the latest PQC protections as they become available, without the need for large-scale infrastructure overhauls.

Quantum resilient capabilities in development

At the Authenticate 2025 event, organised by the FIDO Alliance, we demonstrated an early prototype of post-quantum signatures running on a YubiKey security key. This demonstration highlights an important principle: stronger security need not come at the expense of usability.

From a user’s perspective, the process remains simple. A user touches the device, generates a signature and continues their task. Behind the scenes, the cryptographic algorithms are designed to withstand future quantum threats.

Our commitment to crypto-agility is vital Crypto-agility: the ability to adapt cryptographic systems as threats evolve, will become increasingly important and the industry’s commitment is vital. Organisations that begin assessing their cryptographic exposure now will be far better positioned for the transition.

While the momentum behind PQC is growing, the transition must be handled carefully. Security ecosystems must also evolve across multiple layers,

About the author

including authentication protocols, device attestation, registration processes and cryptographic infrastructure.

Secure standards-based authentication postquantum

Preparing for the postquantum era will take years of collaboration across standards bodies, technology providers and organisations. But one thing is clear: those who begin preparing now will be better positioned to secure digital trust in the decades ahead.

This is not simply a cryptographic upgrade. It is a broader shift towards stronger, phishing-resistant authentication models that are designed to withstand both current and emerging threats. As quantum capabilities mature, legacy approaches such as passwords and SMS-based MFA will become even more fragile, accelerating the need for hardwarebacked, standards-based authentication.

For all organisations, the opportunity is to treat post-quantum readiness as part of a wider cyber resilience strategy. That means investing in authentication methods that are already aligned with zero trust principles, while ensuring systems are flexible enough to incorporate new cryptographic standards as they become available. .

At Yubico, Alex Wilson, Director of Solutions Engineering, has been translating complex technical concepts into language most people can understand throughout his 40-year career in IT. Alex enables people to visualise achievable goals while laying the foundation for robust and valuable outcomes. With Yubico, Alex provides thought leadership and technical knowledge to organisations across Asia Pacific and Japan. In this role, he advises leading organisations on Enterprise Authentication strategies and adoption, and helps his clients secure their identities and information through robust security.

linkedin.com/in/alex-wilson-cissp-yubico

STILL CALLING HUMANS the weakest link IN

CYBERSECURITY?

For years, organisations have viewed cyber failures as the result of careless users. However, many so-called human errors are actually better understood as design flaws in systems that expect perfect judgment from people working under imperfect conditions.

If a company’s security depends on flawless behaviour from distracted, busy, and overloaded employees, the real vulnerability may be the system itself. Cybersecurity has always favoured simple explanations. Few have proved more durable than the claim that humans are the weakest link. The phrase appears so regularly in breach commentary, awareness campaigns, and executive briefings that it now passes for settled wisdom. People click on malicious links. They reuse passwords. They send the wrong file to the wrong person. They approve a login request they should have denied. Attackers exploit trust, urgency, and habit. The conclusion seems obvious. It is also incomplete.

Human action does contribute to cyber incidents. That much is true. But the weakest link’s language does more than describe a risk. It frames how organisations interpret failure, where they assign responsibility, and what they choose to fix. And too often, it points them in the wrong direction.

In many cases, the more consequential weakness is not the person who makes the mistake, but the system that makes the mistake likely. The user who clicks a phishing email is usually not acting in a vacuum. They operate in a maze of

overloaded inboxes, ambiguous requests, cumbersome authentication prompts, fragmented workflows, inconsistent policies, and constant pressure to move quickly. The error is human. The conditions are organisational. That distinction matters. If security depends on thousands of employees making perfect decisions in environments defined by urgency, distraction, and complexity, then the problem is not simply human fallibility. It is a design philosophy that mistakes hope for resilience.

A convenient explanation for a deeper problem

The appeal of blame is its efficiency. Once an incident has been labelled human error, the response practically writes itself: more awareness training, more reminders, more warnings, more compliance language. It is an administratively neat answer to a structurally messy problem. However, “human error” is often less a diagnosis than a stopping point. It explains just enough to avoid the harder questions. Why are secure workflows so difficult to follow? Why do employees still receive requests that are hard to distinguish from legitimate ones? Why are reporting channels underused? Why do staff find it easier to work around a control than within it? Why, after years of awareness efforts, do the same categories of mistakes recur?

These questions are more uncomfortable because they shift attention from the end user to the institution. They force organisations to examine how they configure systems, allocate responsibility, manage trade-offs, and design daily work. It is easier to ask employees to be more vigilant than to simplify access management, reduce process friction, improve user experience, or rethink how security requirements interact with actual operations.

That easier path has become familiar across industries. After a phishing incident, an organisation often responds with another round of simulated attacks and refresher training, even when the email closely resembled a routine internal request or exploited a business process already known to be confusing. After a data-handling mistake, the emphasis may fall on employee non-compliance, while the underlying file permissions, unclear information architecture, or overly broad access rights remain untouched. After an executive is impersonated in a message requesting an urgent transfer or document review, the lesson is too often reduced to “be more careful,” as though caution alone were a sufficient defence against well-crafted deception delivered into fastmoving operational environments.

The pattern is familiar because the logic is familiar: if people are the weakest link, then people are where the correction effort should begin.Nevertheless, that framing assumes the human being is the primary source of fragility rather than the point at which deeper design weaknesses become visible.

The myth of the endlessly vigilant user

Other safety-critical disciplines have spent decades moving away from this kind of thinking. In aviation, healthcare, and industrial operations, mature risk analysis no longer treats frontline error as the whole story. When mistakes happen repeatedly, investigators ask what conditions made them more likely: fatigue, poor interfaces, weak process design, ambiguous authority, time pressure, and inconsistent communication. Human action still matters. But it is understood within a broader system. Cybersecurity still often lags. In many organisations, it continues to rely on an unrealistic model of the user: alert, rational, informed, and perpetually attentive. This imagined employee is expected to spot deception on sight, interpret warnings correctly, recall prior training at the point of decision, and choose the secure path even when it is slower or more cumbersome than the insecure one.

That is not a description of human behaviour. It is a wish.

Real employees work in crowded digital environments. They are interrupted. They skim. They defer. They multitask. They trust familiar names and established routines. They respond quickly because the modern workplace often rewards responsiveness over caution. A finance manager rushing through quarter-end approvals, a clinician opening messages between appointments, or a senior executive clearing prompts between meetings is not behaving irresponsibly. They are simply being human. Yet many security systems are

designed as though ordinary cognitive limitations were an edge case rather than the baseline.

Attackers understand this better than defenders. Social engineering succeeds not because people are uniquely gullible, but because human cognition is finite and organisational life runs on trust. A fraudulent invoice that looks close enough to a legitimate supplier request, a spoofed message that appears to come from a known executive, or an MFA prompt sent at the exact moment someone is trying to log in from another device does not need to be perfect. It only needs to arrive when attention is thin and verification feels costly. That creates an uncomfortable asymmetry. Adversaries design for how people actually behave. Defenders too often design for how they wish people behaved.

This is one reason awareness training, while still necessary, so often disappoints. Training can improve baseline knowledge. It can remind employees what to watch for. But awareness is not the same as resilience. A person may know the rule and still fail under pressure if the environment around them makes the secure action difficult, slow, or uncertain. Training can tell employees not to approve suspicious prompts. It cannot, by itself, fix authentication designs that generate

prompt fatigue. It can warn staff about phishing. It cannot fully compensate for communication systems saturated with urgency and imitation.

When people work around security

The mismatch becomes most visible when users bypass controls. From the security team’s perspective, this may look like carelessness or resistance. From a user’s perspective, it is often an adaptation. If password rules are onerous, people create memory aids or reuse patterns. If official collaboration tools are cumbersome, teams migrate sensitive work to consumer apps that are faster and easier. If obtaining

This is one reason awareness training, while still necessary, so often disappoints. Training can improve baseline knowledge. It can remind employees what to watch for. But awareness is not the same as resilience. A person may know the rule and still fail under pressure if the environment around them makes the secure action difficult, slow, or uncertain.

This reframing changes where attention goes. If people are the core problem, then the obvious response is to train them harder and monitor them more closely. If the deeper problem is that predictable human limitations are interacting with poorly designed systems, then the task is broader and more demanding.

access to a critical system takes too long, someone shares credentials informally so the work can continue. None of these behaviours is defensible as good security practice. But all of them reveal something important: people usually route around controls when those controls obstruct the work the organisation expects them to do.

That makes workarounds diagnostically valuable. They are not merely failures of compliance. They are evidence that the formal security model may be colliding with operational reality. An enterprise that treats every workaround as proof of human weakness overlooks the possibility that its own systems are too brittle, too performative, or too detached from how work actually happens. The same is true of incident reporting. In many organisations, the official line is that staff should report mistakes immediately. In practice,

employees often hesitate. They worry about embarrassment, blame, managerial reaction, or simply not knowing whether what they saw was serious enough to escalate. When reports arrive late, organisations may describe this as a failure of vigilance. But delay is often cultural as much as individual. People speak up faster in systems that make reporting easy and psychologically safe.

That has implications well beyond frontline operations. Boards and executives are routinely shown incident summaries in which user error, awareness gaps, or policy violations appear as the proximate cause. Those may be descriptively accurate, but they are often analytically thin.

They identify who made the mistake without asking why the system made that mistake foreseeable, consequential, and difficult to recover from. A better question is not simply, who clicked? It is, why did the organisation rely on perfect behaviour, when a better design could have reduced the cost of ordinary human error?

Designing for reality, not perfection This reframing changes where attention goes. If people are the core problem, then the obvious response is to train them harder and monitor them more closely. If the deeper problem is that predictable human limitations are interacting with poorly designed systems, then the task is broader and more demanding. It means reducing unnecessary complexity, strengthening phishing-resistant controls, improving interface design, intelligently

narrowing access, simplifying reporting pathways, and aligning policy with how work actually gets done.

It also means rethinking culture. The weakest-link narrative is not just reductive; it can be corrosive. In environments where cyber mistakes are moralised, employees become less likely to admit uncertainty, ask basic questions, or report errors quickly. Fear rarely eliminates mistakes. It usually delays their discovery. A more serious cybersecurity culture starts from a more realistic premise: people are not the enemy of security. They are part of the system; security is supposed to protect and enable. Good design does not demand heroism from ordinary users. It assumes distraction, ambiguity, overload, and occasional misjudgment, then builds resilience around those conditions. It makes the secure choice easier, not merely available. It treats usability as part of security, not a concession against it.

None of this removes individual responsibility. Some users are careless. Some insiders are malicious. Some people ignore clear warnings despite strong design. Human agency remains part of the risk equation. Instead of treating that fact as

the whole explanation, it is precisely what weakens cyber thinking. It turns a complex socio-technical problem into a familiar cliché and invites institutions to confuse blame with understanding. Cybersecurity will not become more effective by insisting that people be flawless. It will become more effective when organisations build systems that remain resilient even when people are rushed, distracted, interrupted, or wrong.

The human element in cybersecurity is real. But the lesson is not that people are the weakest link. It is that systems designed without serious regard for how people actually behave are inherently weak. .

About the author

Dinesh is a seasoned technologist and business leader with over 20 years of global experience in Cybersecurity, Artificial Intelligence (AI), and IT Service Management (ITSM). He is currently pursuing a PhD and holds Master’s degrees in IT and Cybersecurity, seamlessly integrating academic insight with practical application. As a GRC Specialist at Wurth Australia, Dinesh leads cybersecurity initiatives, drives IT compliance, promotes user education, and cultivates strategic external partnerships. His work is grounded in aligning governance frameworks with innovation and resilience. Dinesh, a recognised thought leader in policy development and technology entrepreneurship, bridges the gap between emerging technologies and business outcomes. As a lecturer, startup mentor, and advocate for democratising AI, he is deeply committed to fostering innovation and building capabilities across industries. Dinesh is widely regarded for his ability to align technical expertise with strategic vision and is a sought-after speaker on digital strategy, technology entrepreneurship, and cybersecurity leadership. linkedin.com/in/dineshdino

THE BLAME GAME: Moving beyond a human-centric approach CYBERSECURITY TO

In the current digital and Artificial Intelligence (AI) landscape, cybersecurity is often framed as a battle between sophisticated threat actors and the “weakest link”: the human user.

However, this narrative is shifting and for the good reasons. Organisations are increasingly recognising that security is not merely a technical challenge but a human-centric one. We have seen shift in the recent times as cyber security is a board agenda topic, rather than merely an IT problem. By moving away from the assumption that users are the source of failure and instead designing systems that support human behaviour, organisations can significantly improve their resilience.

The Myth of the “Stupid User” (NIST, 2022) proposes a common pitfall in cybersecurity is the tendency to blame employees for security breaches. How many times have we heard and still is the hot news? Cyber disasters are one-click away. It has been proved by the research that when users bypass security protocols, it is rarely due to a lack of intelligence or malicious intent. Instead, it is often a common response to a poorly designed systems/architectures that disrupt their workflow.

When security tools are cumbersome or unintuitive or interfere with the established processes, users will naturally seek the path of least resistance to complete their tasks. By acknowledging that users are not “stupid,” organisations can identify the systemic design flaws that lead to workarounds, turning a blame-based culture into one of collaborative improvement

Building a Learning Culture

As per quote associated with Peter Drucker “Culture eats strategy for breakfast”. It is imperative to have a robust security culture within an organisation. An effective security requires more than just technical controls. It requires ongoing organisational effort and must have a robust learning program – A no-blame culture and training and learning opportunities.

According to the National Institute of Standards and Technology (2024), a successful cybersecurity and privacy learning program must be integrated into the organisation’s broader mission. Rather than relying on annual, generic training sessions, organisations should implement ongoing, role-based education. This ensures that employees understand the specific risks associated with their roles— whether they are managing health records or handling sensitive financial data.

The principles from Information Security Manual (ISM) further assists with NIST guidance. Privilege users training should be different to the standard user training and cater to their roles and responsibilities. That gives them an opportunity to fulfill their work obligations without any guess work and with security focussed directives

Human-Centred Cybersecurity (NIST, 2024) points out at the shift toward “Human-Centred Cybersecurity” emphasises that technology should be designed with the user’s cognitive

load and behavioural patterns in mind. This approach seeks to align security requirements with the way people work. For example, if a security policy requires a password change every 30 days, it may lead to users writing passwords on sticky notes, which decreases the real security effect that can be achieved by regular password changes. By focusing on user experience, security professionals and policy creators can create systems that are easier to use correctly than to bypass, thereby reducing the probability of human error.

Another extension to the password change is the “journey towards password-less” state. With a valid and robust multi-factor authentication systems, password-less is a low friction manner of ensuring password hygiene across the organisation is maintained. Organisations must offer Password Managers to reduce the friction of passwords as misuse of passwords is one of the biggest attack vectors.

The Global Readiness Landscape (Cisco, 2025) report highlights the necessity of this shift in its 2025 Cisco Cybersecurity Readiness Index. The report notes that while organisations are investing heavily in security infrastructure however, the gap between readiness and actual resilience remains significant Many organisations struggle to keep pace with the evolving threat landscape, often because their security strategies are disconnected from the daily realities of their workforce. Bridging this gap requires

By focusing on user experience, security professionals and policy creators can create systems that are easier to use correctly than to bypass, thereby reducing the probability of human error.

a holistic view that integrates technology, policy, and, most importantly, the human element. So right from threat intelligence that feeds into SOC and present the information about digital risks, and up to the user’s cyber behaviour is what dictates how resilient the organisation is against the threat actors.

Practical Cyber Hygiene

For many organisations maintaining strong “cyber hygiene” is the first line of defence. This involves the consistent practice of fundamental security tasks, such as keeping software updated including Operating system and all applications – especially the applications that interact with the Internet, using multifactor authentication (phishing resistant if possible), tested and rehearsed incident response plan and backing up data at offsite location. ISM has list of 1000+ controls, but its Essential Eight (E8) mitigation strategies could be considered as a starting point for minimum baseline requirements from the technical lens. Use ISM principles of Govern, Protect, Detect, Respond and Recover for the full coverage.

Conclusion

The future of cybersecurity lies in empathy, user experience, technical controls and strategic cyber trainings. By viewing employees as partners rather than liabilities, organisations can foster a security-first culture that is both resilient and sustainable. Whether it is through improved training, intuitive system design, or consistent cyber hygiene, the goal remains the same, to empower users to protect the organisation effectively. As we move forward, the most secure organisations will be those that prioritise the human experience, ensuring that security enables, rather than hinders, the business mission. Ending with Bruce Schneier quote “Security is not a product, but a process”. So, as lack of cyber security impacts both business and the society, everyone is required to be responsible and accountable for their actions and inactions. .

References

1. NIST (2022), Users are not stupid: Six cyber security pitfalls overturned. https://csrc.nist. gov/csrc/media/Projects/usable-cybersecurity/ documents/Final_Proof_Users_are_not_stupid.pdf

2. National Institute of Standards and Technology. (2024). Building a Cybersecurity and Privacy Learning Program (NIST Special Publication 80050). https://csrc.nist.gov/pubs/sp/800/50/r1/final

3. National Institute of Standards and Technology. (2024). Human-Centred Cybersecurity (General) https://csrc.nist.gov/Projects/human-centeredcybersecurity/research-areas/human-centeredcybersecurity-general

4. Cisco. (2025). 2025 Cisco Cybersecurity Readiness Index https://newsroom.cisco.com/c/ dam/r/newsroom/en/us/interactive/cybersecurityreadiness-index/2025/documents/2025_Cisco_ Cybersecurity_Readiness_Index.pdf

5. Cybersecurity and Infrastructure Security Agency. (2026). Cyber hygiene services. https://www.cisa. gov/cyber-hygiene-services

6. Information Security Manual (March 2026). https://www. cyber.gov.au/businessgovernment/asdscyber-securityframeworks/ism

About the author

Puneet Tikoo is Information Security leader at Cisco, recognised for his exceptional ability to bridge the gap between intricate technical requirements and overarching business objectives. With a career defined by strategic foresight and technical rigor, he serves as a pivotal advisor, helping organisations navigate the complexities of the modern digital threat landscape. His approach to cybersecurity is rooted in the implementation of resilient security initiatives, underpinned by comprehensive risk management strategies and industry-standard control frameworks. By prioritising long-term operational success alongside robust defence mechanisms, he ensures that security remains an enabler of business growth rather than a hurdle. Puneet’s professional standing is reinforced by a rigorous commitment to continuous learning and industry excellence. As a qualified IRAP Assessor, he brings a high level of scrutiny and expertise to security assessments. His extensive portfolio of global certifications—including CISSP, CCSP, CISA, A|CISO, and GAICD— demonstrates a deep, multidisciplinary understanding of security governance, risk, and compliance. Beyond his technical acumen, Puneet is a strong, collaborative leader. He excels at translating complex security challenges into actionable business insights, fostering a culture of security awareness and resilience within the organisations he supports. His unique blend of strategic leadership and hands-on technical proficiency makes him an invaluable asset in any highstakes environment. Whether architecting secure frameworks or guiding teams through evolving threats, Puneet remains dedicated to maintaining the highest standards of integrity and excellence, ensuring that organisations are well-positioned to thrive in an increasingly connected and challenging global environment linkedin.com/in/puneettikoo

This is an opinion piece. I didn’t know I was neurodivergent until I started working in a western society.

Growing up in a strict Chinese family, the things that later got labelled were just expectations. You sat still. You read. You memorised. You didn’t make small talk with adults because what could you possibly have to say to them. You answered the question that was asked, not the one around it. Focus for hours on a single problem wasn’t a quirk. It was Sunday morning. Direct, unsoftened speech wasn’t rude. It was efficient.

Then I moved to the land down under and became a Citrix architect working across multiple domains. The job: see ten steps ahead, describe reality to people still finding step one. Apparently, this is “difficult to work with.” Telling a room what’s coming counts as negativity. The collaborative version, I gather, is letting them get there themselves six months later. I wasn’t allowed to say, “I told you so.”

Cybersecurity has a well discussed retention problem. Burnout, skills shortages, and quiet attrition. What gets discussed far less often is culture as a cost centre. Not the work itself, but the performance of a narrow set of workplace behaviours layered on top of it.

The gap between what a culture treats as normal and what it pathologises is the part of the neurodiversity conversation cyber tends to skip. Neurodivergence is measured against a baseline, and the baseline in most cyber teams is a very specific version of Western office sociability. Open plan floors. Small talk

at the coffee machine. Findings padded with apologies before the finding itself. Eye contact as a proxy for trustworthiness. None of this is the work. All of it is the culture.

The fixes usually discussed are framed as accommodations. Written agendas. Quiet environments. A preference for darkness. They aren’t, really. They’re just how a lot of the world already operates. What is being accommodated is the office norm.

Take the board paper I wrote on lifting our security posture. The work itself was choose-your-own-adventure: dozens of paths, each with their own risk, cost, and dependency trees, all of which I could hold in my head at once. The board couldn’t. So I made the choice for them and spent weeks simplifying the rest down to a version where the board got to feel like they were reducing risk and increasing opportunity, as long as none of it cost very much. The board is still discussing it. Several people told me I’d done a good job. Well done. None of them saw the cost of holding the full picture in one hand and the legible-to-them version in the other and never letting the two touch.

The cost of the current setup is the second job. You do the technical work, then you translate yourself into a version the organisation can digest. That translation work is invisible. Nobody measures it. It shows up later, as quiet resignations, as “not a culture fit,” as a string of high performers the org swears it just couldn’t retain.

The credibility tax, with extras Being a woman in cyber gets you one tax. Being a woman from a culture that didn’t raise you to perform C-suite confidence gets you a second one stacked on top. The advice circulating about “owning the room” assumes you started with a baseline you could amplify. Plenty of us didn’t. The instinct trained into me was to listen before speaking, to defer to the most senior person, to make sure I was correct before I was loud. Useful instincts in most of life. Read as weakness in a stand-up.

The credibility tax is real, but it has diminishing returns. A second cert helps.

A fifth doesn’t. Past a point, the same energy spent on visible output (a public writeup, a tool published under your own name, a finding documented properly before anyone else paraphrases it back) compounds faster than another acronym after your job title.

Mentors are over-supplied in this industry. Sponsors are not. A mentor explains the room. A sponsor puts your name in rooms you aren’t in. Most women in cyber, and most people from cultures that taught them self-promotion is undignified, are heavily over-mentored and badly under-sponsored. Worth knowing which one you’re asking for.

A nuance often left unsaid is that for neurodivergent women, the most effective mentor is sometimes a man. Not because men mentor better, but because the women in tech mentorship circuit heavily emphasises navigating the social layer. For many of us, the social layer is the cost. A mentor who treats the work as the main event, communicates directly, and doesn’t ask you to translate yourself first is the one who actually shifts your career. Often, in cyber, that mentor is male, partly because senior cyber leadership still is.

Peter Dowley has never officially been my mentor. He’s a friend who listens, supports, and trusts, and somehow the magic happens anyway. Co-presenting a workshop at AISA CyberCon 2025 was one of those moments. And no, it’s not about the free ice creams. It went both ways, which is the part the textbook version of mentorship usually misses.

The leveller

The thing AI has actually changed, for me, is the social tax on doing technical work.

I write everything faster now. Architecture documents, spreadsheets, any written requirement. Not because the technical content was the problem, but because the

model handles the layer I always found exhausting. The accurate version still gets written. The translated version comes out concise, direct, and to the point.

Same goes for threat statements. The model writes the framework mapping faster than I can. What I add on top is the judgment about whether any of it applies to this organisation today.

Somewhere along the way I became the AI ambassador. A senior PM who once dismissed chatbots now uses one daily: scanning deliverables for gaps, getting through repetitive work, writing BLUF for incredibly verbose emails. Same translation problem I’ve spent years on. Going the other way.

The same effect is happening across cyber, mostly for people the industry has been quietly losing. Non-native English speakers writing with perfect grammar. People who weren’t raised to small-talk drafting the social layer of an email in seconds so they can spend their attention on the work. None of this is the model doing the job. It’s the model removing a tax that was never evenly distributed.

The shadow side is real. Voice flattens when everyone routes through the same tools. Junior people short-circuit the writing muscles they actually need. The properly human moments (the apology, the credit,

About the author

the difficult acknowledgement) lose something when outsourced. The skill the industry now has to develop is knowing when to use the tool and when not to.

What it adds up to Neurodiversity. Women in cyber. AI in communication. These look like separate conversations. They aren’t. They’re the same conversation from different angles.

Cyber spent decades selecting for a particular kind of person and assuming that person was selecting for the work. It wasn’t. It was selecting for who could perform a specific culture loudly enough to be heard over it. Neurodivergent people paid the tax in masking. Women paid it in not saying no. People from cultures the industry didn’t grow up inside paid it in translation. The work got done anyway. The cost just landed unevenly.

What’s changing isn’t dramatic. Structured interviews. Circulated agendas. Senior women sponsoring junior ones. A model that takes the social tax off an executive email. None of these are revolutionary. All of them, together, are.

The human factor in cybersecurity used to mean the people who clicked the phishing link. It’s starting to mean the people in the chairs. The ones the industry already has, and the ones it has been quietly turning away. About time. .

Sharin Yeoh is a senior cyber and AI leader, as well as a Technical ISO known for turning complex technical challenges into solutions people can genuinely use. Her work spans ethics, capability, and emerging technologies, with a focus on making the future feel accessible, practical, and engaging. Inspired by collaborations with industry leaders such as Peter Dowley, Sharin believes clarity strengthens security and that some of the most important conversations still happen over two scoops of ice cream.

Discover Sharin Yeoh’s cyber security graphic novel. Click here to read the full PDF, then let us know if you’d like to see more! linkedin.com/in/syeoh linkedin.com/in/peter-dowley

PARADOX The hiring

WHY CYBER CAN’T FIND PEOPLE WHO ARE ALREADY THERE

What the evidence says about who the industry hires, who it misses, and what it costs when it gets it wrong.

Introduction: Not a Pipeline Problem—A Question of Strategy

Leaders in cybersecurity have long lamented a “talent shortage,” claiming key roles go unfilled for lack of qualified people. Yet how can there be a shortage when dozens of candidates apply to each opening? Improbably, the same organisations reporting dire talent gaps have often themselves frozen hiring, cut roles, or turned away applicants who didn’t meet some arbitrary “fit.” So the research question arises: Why do companies still experience persistent cybersecurity staffing shortfalls, even as capable professionals line up to join?

This article contends that the “not enough people” narrative is largely a hoax – or at least a misdiagnosis. The evidence points to a self-inflicted paradox: cybersecurity’s staffing gap stems not from a total absence of talent, but from how organisations recruit, develop, and value that talent. In effect, it’s a hiring problem, a budget problem, and a culture problem – not simply a pipeline problem. The sections below tackle each facet in turn, outlining what’s really happening, how to fix it, and the significant stakes for boards and executives.

Problem

One: Hiring for the Wrong Qualities

Imagine a hospital complaining of a doctor shortage while turning away qualified medics for not smiling enough

in interviews. That, in a sense, is what’s happening in cybersecurity hiring today. Traditional approaches emphasise formal credentials and polished interviews over practical capabilities. Many security job descriptions read like certification checklists (CISSP, CEH, Security+), and panel interviews focus on generic behavioural questions instead of realworld challenges. This mis-hiring results in candidates being filtered out for lacking the “right” pedigree or bravado – even when they have the skills needed to do the work.

In reality, the most crucial skills for modern cyber roles often go beyond technical prowess. Communication, influence, negotiation, systems thinking, emotional intelligence – these are no longer “nice to have” afterthoughts but core competencies in effective cybersecurity teams (Muncaster, 2025; Mani Masood, 2025). For example, what does influence mean in a cyber context? It’s the security architect who convinces an operations leader to patch a critical vulnerability despite disruption, or a CISO who translates a technical risk into a financial scenario so clearly that the CFO proactively funds mitigation. Such outcomes require more than technical know-how: they demand (Venables, 2024).

Yet these capabilities are rarely screened. A typical hiring process selects for those who “credential well” or can navigate a contrived Q&A – missing those with less

conventional CVs but strong practical acumen. The result can resemble a talent shortage even when one doesn’t exist. Consider an anonymised case: a mid-sized firm recently advertised a cybersecurity analyst role expecting few responses. Instead, it received 45 applications in two weeks. Under a true scarcity, it might have seen five. The large pool of interested candidates suggests the talent is out there – the bottleneck lies in aligning hiring filters with actual job needs. Overly rigid criteria (e.g. requiring 5+ years’ experience for an “entry-level” role) and cultural bias in selection can artificially shrink the “qualified” pool. Studies confirm this dynamic: thousands of certified newcomers struggle to land jobs because postings demand experience they couldn’t yet have (ACSMI, 2025). In other words, companies often create “unfillable” jobs by defining them too narrowly (Masood, 2025).

What skills should organisations prioritise?

Broadly, the critical success factors in cybersecurity roles today include:

Clear communication – to distil complex threats into business terms for decisionmakers and cross-functional teams.

Influence and negotiation – to persuade stakeholders and build consensus on security measures, even when they cause short-term inconvenience (e.g. system downtime for patching).

(EQ) – to sense organisational dynamics, build trust, and navigate high-pressure situations with empathy and composure.

Systems thinking – to grasp interdependencies across technology, processes, and people, enabling foresight and holistic risk management.

Decision-making under uncertainty –to act swiftly during incidents without complete information, balancing imperfect options to minimise damage.

Ethical judgement – to ensure actions align with legal obligations and company values, especially when handling sensitive data and ambiguous scenarios.

According to IBM’s global analysis, organisations with persistent security skill gaps suffered average data breach losses of $5.74 million – compared to $3.98 million for those without major skill shortages (IBM, 2024)

Notably, these “soft” skills are typically developed via experience, mentorship, and practice rather than formal training alone. Top security leaders foster them by giving staff opportunities to rotate through cross-functional projects, simulating crisis scenarios, pairing juniors with experienced mentors, and emphasising learning from both successes and failures. For example, regular tabletop exercises and red team/ blue team drills can sharpen decisionmaking and communication under stress in a safe setting. It’s largely through these mechanisms that an incident responder learns poise under pressure or a security analyst gains the confidence to brief executives – not through a certification exam.

How can hiring better assess these capabilities?

The key is to re-focus selection on performance, not proxies. That means using work sample tests, simulated incident response exercises, structured scenario interviews, and role-specific tasks to see candidates in action (Venables, 2024). For a governance role, ask how a candidate would persuade a resistant business unit to adopt a security control – and probe for examples of past wins and losses in influencing change. For a technical lead, provide a realistic breach scenario and have them walk through triage and stakeholder communication. Such methods reveal whether someone can actually do cybersecurity work under real conditions, rather than just talk about it abstractly. Organisations like Microsoft and IBM have shifted to competency- and scenario-based interviews, leading to stronger hires and more diverse talent pools (Masood, 2025).

The payoff is tangible. Companies that align hiring with true job requirements have better-performing security teams and avoid the costly consequences of mis-hires or vacant roles. According to IBM’s global analysis, organisations with persistent security skill gaps suffered average data breach losses of $5.74 million – compared to $3.98 million for those without major skill shortages (IBM, 2024). That $1.76 million delta is effectively the price of mishiring or under-hiring. For the C-suite, the message is clear: hiring better is not just a talent strategy – it’s a risk management strategy with direct financial impact.

Problem Two: The False Economy of Budget Cuts

If misguided hiring is one cause of the talent paradox, short-sighted budgeting is another. In 2024, amid macroeconomic pressures, 37% of organisations cut cybersecurity budgets and 25% laid off security staff (ISC2, 2024). On the ledger, these cuts looked like easy savings. For a time, nothing catastrophic happened; the lights stayed on. But security is like building maintenance – cut corners, and you accumulate risk out of sight until something breaks. Understaffed and overburdened teams inevitably miss more incidents, respond slower, and suffer burnout. The pipeline of threats doesn’t shrink because your budget did.

By 2025, the impact of these cuts became apparent. That year’s Verizon Data Breach Investigations Report found 60% of breaches worldwide involved a major human element – errors or social engineering – often abetted by inadequate staff capacity (Verizon, 2025). The average time to identify a breach stretched to

181 days (Deepstrike, 2025), giving intruders half a year free reign inside networks. These failures are rarely due to incompetent staff; rather they reflect too few people wearing too many hats, or being spread too thin across sprawling attack surfaces. Underresourcing security may not show up immediately, but when it does, the price tag dwarfs the saved headcount costs. The global average cost of a data breach is now $4.88 million (IBM, 2024) – and higher still for organisations with acute security staff shortages, as noted earlier.

In executive terms, treating security as a cost centre is a false economy. A Chief Financial Officer wouldn’t knowingly accept a hidden £1.5 million risk to save £100k in salaries – yet that’s essentially what happens when cybersecurity budgets are slashed. The smarter approach is to reposition security funding as an investment in risk reduction. Boards and CFOs already speak the language of riskadjusted ROI: the CISO’s job is to clearly connect staffing levels to expected risk outcomes. For example, “By remaining two analysts short, we statistically raise our breach cost exposure by ~£1.4M over the next year,” is a far more persuasive argument than abstractly pleading for more headcount.

Meanwhile, organisations under financial constraints are finding creative ways to shore up capabilities without immediately hiring en masse. The most common move has been investing in internal talent: in

A Chief Financial Officer wouldn’t knowingly accept a hidden £1.5 million risk to save £100k in salaries – yet that’s essentially what happens when cybersecurity budgets are slashed.

2024, a full 76% of companies tackled security skill gaps by upskilling their existing employees (ISC2, 2024). These efforts range from formal bootcamps and certification sponsorships to mentorship and rotation programs that broaden an individual’s skill set. Some 24% of organisations also launched apprenticeships or “new collar” training schemes to bring in fresh talent via handson learning (ISC2, 2024). Such approaches recognise a fundamental truth: a capable defender grown in-house often ramps up faster and sticks around longer than an external hire, because they already know the business and see a future within it. In fact, industry averages show that internally trained security staff reach full productivity in 4–9 months, much faster than the recruitment and onboarding cycle of an external senior hire (ISC2, 2023).

Ultimately, right-sizing the security budget is a matter of risk appetite. Cutting back on cybersecurity may appease short-term financial pressures, but it increases the likelihood and cost of breaches in the long run. Conversely, targeting spending toward talent – whether through direct hires or developing the people you have – can save money by lowering incident odds and impact. Security-savvy boards are beginning to grasp this trade-off: many now ask management not “Why do you need more staff?” but “What is our risk exposure if we don’t invest in these skills?” (IBM, 2024).

Problem Three: Misattributing the Gap – Diversity as a Strategic Asset Another trap is misidentifying the source of the talent gap. It’s tempting to blame external factors, like “no one is graduating with these skills” or complaining that international hires are “taking all the jobs domestic candidates could fill.” Both are red herrings. The global need for cybersecurity professionals is so vast (over 3.4 million unfilled roles worldwide as of 2025) that even fully opening immigration

floodgates wouldn’t completely plug it (Morgan, 2023). And pipeline numbers show plenty of people entering the field – the bottleneck is that many can’t get hired or advanced, due to issues we’ve already covered.

Rather than finger-pointing, enlightened organisations are realising that casting a broader net for talent is a business necessity. Indeed, the very qualities prevalent in non-traditional candidates –whether from different countries, career paths, or demographic backgrounds – map closely to the soft skills the industry so badly needs (Masood, 2025; Chan, Stewart Gloster & Ringrose, 2025). Someone who has navigated cross-cultural environments or switched careers has typically honed adaptability, communication across disparate groups, and the ability to learn on the fly – all invaluable in cybersecurity. Moreover, higher team diversity means better performance on core security outcomes: multiple studies find that cognitively diverse teams identify risks and devise solutions faster and more accurately than homogenous teams (Reynolds & Lewis, 2017; Rock & Grant, 2016). One inclusive decision-making study across 200 business teams found diverse teams made better decisions 87% of the time and delivered 60% better results (Larson, 2017). Another study by ISACA observed that diverse security teams reported improved detection of social engineering attacks due to their broader perspective on human deception tactics (Bobbert, Djotaroeno & Van Gils, 2024). Plainly put, diversity isn’t just a moral cause – it’s a strategic advantage in managing cyber risk.

Cultural payoffs amplify the technical ones. Security teams that blend varied backgrounds and disciplines are more likely to challenge assumptions, avoid groupthink, and foster psychological safety – key ingredients for learning from near-misses and continuously improving

(Rock & Grant, 2016; NetDiligence, 2025).

A psychologically safe culture encourages junior analysts to speak up when they spot something unusual, or challenge a more senior colleague’s approach if they see a blind spot – without fear of reprisal. This “challenge without fear” dynamic is crucial in cybersecurity, where candid discussion and early error detection can pre-empt incidents. Google’s Project Aristotle famously identified psychological safety as the number-one trait of high-performing teams, more essential even than individual brilliance (Rozovsky, 2015). Diverse groups naturally introduce a wider range of ideas and potential objections, which – in an inclusive culture – leads to more thoroughly vetted decisions and stronger defences (Reynolds & Lewis, 2017).

At the same time, diversity initiatives are not without challenges. Bringing together people of different backgrounds can lead to cultural friction and “inclusion debt” if organisations don’t invest in ensuring everyone’s voice is heard and valued (Larson, 2017). Research shows diverse teams can experience more conflict or slower consensus when they lack inclusive leadership – for example, a study found that a homogenous group making a decision, then handing it to a diverse team to execute, underperformed by 15% (Larson, 2017). The lesson is that diversity must go hand-in-hand with inclusive practices and skilled leadership. Security leaders need to actively manage differences in communication styles, build mutual trust, and model how to

leverage disagreements productively. Another common challenge is how to measure inclusion beyond surface-level representation. Many firms track the percentage of women or minority staff, but few measure whether diverse voices actually influence decisions or how inclusive the culture truly is. Progressive organisations are addressing this by including inclusion metrics (such as diverse participation in key decisions and retention of under-represented talent) in their performance dashboards (NetDiligence, 2025).

None of these efforts is about charity or compliance window-dressing. They are about building highperformance teams that are resilient in a dynamic threat environment. A homogeneous security department might find it easier to get along dayto-day, but it will likely have blind spots and can struggle to adapt to novel attack methods. In contrast, a team diverse in thought and background, led inclusively, will challenge itself and each other – identifying more potential threats, adapting quicker to change, and innovating more effectively (Chan et al., 2025). Put simply, the diversity and capability arguments are one and the same: expanding who you hire and grow expands what your security team is capable of seeing and doing.

Conclusion and Future Research: From Myth to Measurable Progress

The case is clear. The cybersecurity shortage, as commonly portrayed, is less a lack of people than a lack of the right approach. The talent exists – it’s been sitting in long applicant queues, adjacent departments, and non-traditional backgrounds that firms haven’t considered. To “find” those people, companies must

fix the filters: hire for true capabilities and potential, not just paper qualifications; invest in continuous development; and embrace diversity as a source of strength. The prize for getting this right is significant: stronger defences, fewer costly incidents, and teams that can both perform and endure.

Looking ahead, several pressing questions remain for business leaders, industry researchers, and policymakers: How can we better quantify a candidate’s capability to predict on-the-job performance, beyond guesswork like years of experience or certifications? What new measures or frameworks can link a security team’s cultural maturity – its inclusiveness, psychological safety, adaptability – to hard outcomes like breach frequency or response time? Additionally, what are the long-term returns on investments in talent development, such as the impact of upskilling programs on retention and incident reduction? These are the nextfrontier questions we must answer to cement cybersecurity talent management as a board-level priority and a competitive differentiator. Regulators and industry bodies might also consider standards for reporting on cyber workforce resilience, much as they do for financial health, spurring more accountability and innovation in closing the skills gap.

The bottom line for executives: addressing the cyber “talent crisis” isn’t about conjuring people from thin air – it’s about changing entrenched practices. The answers are already in the building: in the people you have and those eager to join. The organisations that recognise this and act – by aligning hiring with reality, resourcing teams properly, and tapping diverse talent – will not only fill roles, they’ll gain a security capability advantage in an increasingly perilous digital landscape. The cost of doing otherwise grows every year, as threats escalate and the latest breach headline reminds us. The talent hoax has

been exposed; the real work now is to develop and deploy the talent that’s been there all along. .

References

1. Bobbert, Y., Djotaroeno, M. and Van Gils, B. (2024). The Value of Diversity and Inclusion in Cybersecurity. ISACA Journal, 4. Available at: https://www.isaca.org/resources/isaca-journal/ issues/2024/volume-4/the-value-of-diversity-andinclusion-in-cybersecurity

2. Chan, B., Stewart Gloster, C. and Ringrose, K. (2025). Why DEI is Key for a Cyber Safe Future. CSO Online, April 2025. Available at: Why DEI is key for a cyber safe future | CSO Online

3. Cloverpop (2017). Research Shows Diversity + Inclusion = Better Decision Making at Work. Cloverpop Research (originally published in Forbes). Available at: https://www.cloverpop.com/ resources/research-shows-diversity-inclusionbetter-decision-making-at-work

4. Coker, J. (2022). Cybersecurity Workforce Gap Grows by 26% in 2022. Infosecurity Magazine, 20 October. Available at: https://www. infosecurity-magazine.com/news/cybersecurityworkforce-gap-grows/

5. Deepstrike (2025). Global Threat Report: Extended Dwell Times and Attack Trends. Deepstrike Labs. Available at: https://www. deepstrike.io/resources

6. Fortinet (2024). 2024 Cybersecurity Skills Gap Report. Fortinet. Available at: 2024-cybersecurity-skills-gap-report.pdf

7. House of Commons Library (2025). UK Immigration Policy and the Skilled Workforce. Research Briefing. Available at: https:// commonslibrary.parliament.uk/researchbriefings/

8. IBM Security (2024). Cost of a Data Breach Report 2024. IBM Security and Ponemon Institute. Available at: https://www.ibm.com/ reports/data-breach

9. International Information System Security Certification Consortium – (ISC)² (2023). Building Cybersecurity Talent: Time to Productivity. Available at: https://www.isc2.org/Research

10. International Information System Security Certification Consortium – (ISC)² (2024). Cybersecurity Workforce Study 2024. Available at: https://www.isc2.org/Research/WorkforceStudy

11. International Information System Security Certification Consortium – (ISC)² (2025). Cybersecurity Workforce Study 2025. Available at: https://www.isc2.org/Research/WorkforceStudy/2025

12. Masood, M. (2025). The Myth of the Cybersecurity Talent Shortage. Available at: https://manimasood.com/the-myth-of-thecybersecurity-talent-shortage/

13. Muncaster, P. (2025). Skills Shortages Trump Headcount as the Critical Cyber Challenge. Infosecurity Magazine, 4 December. Available at: https://www.infosecurity-magazine.com/news/ skills-shortages-trump-headcount/

14. NetDiligence (2025). Cybersecurity Diversity: How Inclusion Strengthens Security. Available at: https://www.netdiligence.com/resources

15. Reynolds, A. and Lewis, D. (2017). Teams Solve Problems Faster When They’re More Cognitively Diverse. Harvard Business Review, 30 March. Available at: https://hbr.org/2017/03/teams-solveproblems-faster-when-theyre-more-cognitivelydiverse

16. Rock, D. and Grant, H. (2016). Why Diverse Teams Are Smarter. Harvard Business Review, November. Available at: https://hbr.org/2016/11/ why-diverse-teams-are-smarter

17. Venables, P. (2024). Conducting the Security Interview – The Big 10. Available at: https://www. philvenables.com/post/conducting-the-securityinterview

18. Verizon (2025). 2025 Data Breach Investigations Report. Verizon Enterprise. Available at: https:// www.verizon.com/business/resources/reports/ dbir/

About the author

Asrar (Az) Ismail-Sparrow is a cyber security auditor, educator, and governance enthusiast who helps organisations turn compliance headaches into business-as-usual. Equally at home in the boardroom or the classroom, she’s a champion for practical security and stronger cyber communities. instagram.com/cyber.dame linkedin.com/company/cybrdame

Turn static files into dynamic content formats.

Create a flipbook
Cyber Connect Edition 2 2026 by source2create - Issuu