01
MARCH • APRIL
THE FUTURE FOR WOMEN IN SECURITY IS NOW P16-19
ARE WE DOING ENOUGH? P50-51
AUSTRALIA’S FEMALE SECURITY PIONEERS P6-10
THE BEST COMPANIES FOR WOMEN TO WORK IN SECURITY P106-108
W W W. W O M E N I N S E C U R IT Y M A G A Z I N E . C O M
FROM THE PUBLISHER
T
Raising the profile of women in security may be my passion, but it’s everyone’s job here’s a difference between reading about
growing passion to make a difference – to help
the lack of women in security, and doing
Australia’s cybersecurity industry overcome the built-in
something about it.
biases that are limiting businesses and keeping our best
I’ve worked both sides of that argument – first during 10 years as publisher of CSO Australia, and more recently
and brightest young women from an industry that is already primed to give them satisfying, flexible, rewarding careers.
in partnership with the Australian Women in Security
Empowering women to join the security community is
Network (AWSN) – and I assure you that doing
a core goal of AWSN, and in the seven years since I met
something about the situation is much harder, but also
founder Jacqui Lostau we have been working hard to
much more rewarding.
build a community capable of driving change.
As publisher, I read articles about how women in security
Yet for all its successes, I quickly realised that AWSN
were sparse; blog posts advising CSOs about how
could only do so much as an association. Staff were
to retain the few women already working in security;
all volunteers and most had full-time jobs. Some had
requests for female mentors or career advice; and social-
families and some did not, but all were working every
media posts from successful security women sharing
hour of their days – as colleagues, mentors, advisors,
advice about how to not be the only female in the room.
advocates, and more – to make a difference.
It was a great job, although I didn’t understand all the
Watching their commendable and ongoing efforts, I
security parts – but I managed to work through that part
realised that it is not AWSN’s burden alone to change the
with the help of a very supportive, patient network.
way females are seen within security, or to increase their
At the same time, the debate became more than academic when I was faced with teenage girls growing up in a school system where tech subjects were just not cool. Out in the real world of education, cybersecurity and STEM still don’t get much of a mention – and IT was always advocated for by the nerdy, uncool teacher. Can we really be surprised that teenage girls wouldn’t go for this? In recent years I have been working to explore my
numbers in the industry. It’s not the responsibility of any one committed group to show females the many exciting career paths in security, or to identify standout achievers and highlight them as paragons to inspire others. It is all of our responsibility – and this publication is one small step in the ongoing effort to provide a solid platform for women in the security industry. Looking back, the ingredients were all there: the industry knowledge. The wonderful relationships I have gained and nurtured with like-minded individuals over the
Abigail Swabey
years. The amazing women who are leading IT security, cybersecurity, physical security, security resilience and privacy teams. They’re out there, doing great work every day – and their stories need to be told. We have taken some concrete steps to do this in recent years, not only by growing the membership of AWSN into the many thousands but through steps such as establishing the annual AWSN Women in Security Awards in 2019 and running the second (albeit virtual) awards last year. This publication gives the industry a platform to recognise the work of all those amazing women – not only to recognise their achievements, but to motivate the next generation of students to ignore their school’s bias, and give cybersecurity a try. I hope you’ll continue to join us on this journey to hear these stories, share your thoughts, and help make that little bit of difference in your own way. It’s only together that we can balance the playing field – and help the security industry benefit from the amazing talents of some of Australia’s most capable, inspiring women.
Abigail Swabey PUBLISHER, Co-founder at Source2Create aby@source2create.com.au
WOMEN IN SECURITY MAGAZINE
3
CONTENTS Building cyber culture into the business from day one
12
Cybercrime is big business
14
The future for women in security is now
16
A Day in the Life
42
Diversity in security: Not just about men and women
44
CAREER PERSPECTIVES
2
What you need to know about cybersecurity careers
46
Three career tips to thrive as a woman in cybersecurity
48
Are we doing enough? A cybersecurity career perspective from a multipotentialite 53
PUBLISHER’S LETTER
7
Advice on joining the infosec industry
56
Things to remember for women in tech
61
Introduce yourself to leadership the power of a strong network
64
Security is not just about hacking
66
Why cybersecurity as a career
68
AUSTRALIA’S FEMALE SECURITY PIONEERS
WHAT’S HER JOURNEY?
4
WOMEN IN SECURITY MAGAZINE
Kate Monckton
22
Toni James
26
How parents can keep up with apps and online games
70
Joss Howard
28
Tales from the trenches
73
Skye Wu
30
Rachel Okoji
33
Nicole Neil
34
Diversity, like security, should be built in from the ground up
80
Mary Attard
36
Jodie Vlassis
39
Bri Hadley
40
76
(CYBER) SECURITY CULTURE EATS (CYBER) SECURITY STRATEGY FOR BREAKFAST
MARCH • APRIL 2021
TECHNOLOGY PERSPECTIVES 2021 and Beyond the future of cybersecurity is promising 86 Security as basic hygience Running a digital cyber security treasure hunt
INDUSTRY PERSPECTIVES
88
90
Behind the scenes of an ICT woman during and post COVID 72
Social Media Security
94
Driving a slow car fast and a driving a fast car slow
Cybersecurity in companies and the protection of fundamental rights
80
The heroes of AusCERT2020 the women in security who made it happen 82
Infosec and RM working together for safer sharing
ADVERTISING Charlie-Mae Baker JOURNALISTS
92
Diversity, like security, should be built in from the ground up
Abigail Swabey
Abigail Swabey
Mitigating against online Social Engineering
74
FOUNDER & EDITOR
David Braue Stuart Corner SUB-EDITOR Stuart Corner
96
DESIGNER Jihee Park
99
Helping businesses safely embrace digital
102
The Privacy Paradox
104
Women in Security magazine is published by Source2Create ABN 25 638 094 863
www.womeninsecuritymagazine.com contact@source2create.com.au
110
WOMEN IN SECURITY MAGAZINE CONTRIBUTORS
Source2Create Pty Ltd is the publisher of this magazine and its website (www.womeninsecuritymagazine.com). AWSN is the official partner of Women in Security Magazine
TURN IT UP
114
OFF THE SHELF
118
106
THE BEST COMPANIES FOR WOMEN TO WORK IN SECURITY
©Copyright 2021 Source2Create. All rights reserved. Reproduction in whole or part in any form or medium without express written permission of Source2Create is prohibited.
SUBSCRIBE TO OUR MAGAZINE Never miss an edition, subscribe for the magazine today for exclusive updates on upcoming events and future issues, along with bonus content.
SUBSCRIBE NOW
F E AT U R E
AUSTRALIA’S FEMALE SECURITY PIONEERS by David Braue
For Australia’s female security pioneers, cyber is all in a day’s work
WOMEN IN SECURITY MAGAZINE
7
FOR AUSTRALIA’S FEMALE SECURITY PIONEERS, CYBER IS ALL IN A DAY’S WORK
enhance the
Different career paths, different responsibilities – and
“While amazing
a shared love of cyber’s challenges
women have always been working in cybersecurity,”
Culture change, that time-worn bon mot goes, starts
Bilal says, “it’s only recently that many of them are
nation’s threat sharing.
at the top – and Australia’s cybersecurity industry is
being publicly recognised.”
no exception.
Bilal, who actively participates in the Defence
As recent years saw the world waking to the
internship program and enjoys mentoring interns
increasing prevalence of cybersecurity threats and their real-world impact, the industry has been led by – and inspired by – a slew of talented women whose mighty efforts might have gone unnoticed but for
every year, noted the preponderance of “really supportive and high profile female leadership figures” at organisations such as the Australian Signals Directorate (ASD), Australian Cyber Security Centre
concerted efforts to bring them into the spotlight.
(ACSC) and industry-development body AustCyber.
Through awards programs, media coverage and
Ongoing support from both men and women
networking through bodies like the Australian Women in Security Network (AWSN), cybersecurity practitioners have rapidly come to learn about the significant work of women like Rania Bilal, a former
across the sector has helped Bilal advance her “exciting and rewarding” career, which has seen her working in research and development, C# software development, firmware coding, and now as a cyber
officer in CERT now working in the Australian Cyber
threat intelligence technologist.
Security Centre (ACSC) cybersecurity team to
She hopes ongoing recognition of female industry pioneers will inspire even more women to join
8
WOMEN IN SECURITY MAGAZINE
F E AT U R E
the industry: “It’s great to see women increasingly recognised through awards and greater leadership,” she says.
challenge and engage her. “My formal qualifications have nothing to do with computing,” she says, “but I worked in a cybercrime
“I hope this becomes normal practice so that
intelligence role. I’ve written a few books now, and
more women are inspired to join the cybersecurity
when I speak at conferences I’m trying to make
profession and discover everything this exciting
people understand that cybercrime is not something
career path has to offer.”
weird and elusive; it’s just like any other crime type, and anyone can be a victim.”
MANY ROADS TO CYBER Indeed, for many women in cybersecurity that career path has taken all manner of twists and turns – and continues to do so as they progress through the broad and deep range of options that it offers.
Her goal in working in cybersecurity likely resonates with many other women who have found the industry’s allure irresistible: “I want to help harden our community, harden our nation, and harden the world against becoming victims of cyber crime,” she
Mandy Turner, for one, wasn’t expecting to end up
explains.
in cybersecurity: her first degree was a Bachelor of
“That is something I really do care about – because
Music, for example, and she recently completed a Bachelor of Dementia Care before entering a 20-year career with a government agency before moving laterally into cybersecurity. Now, Turner works as manager of the University of Queensland Cyber Security Operations Centre (CSOC) – the latest step in a career arc that continues to
it’s never going away.” As well as advocating for better cybersecurity understanding, Turner has watched in dismay as popular media representations of shadowy hackers pollute the discussion – making everyday users believe “there’s this shadowy supervillain behind all of
WOMEN IN SECURITY MAGAZINE
9
this, so there’s no hope for them and they no longer help themselves.” “We need to stop that narrative of the supervillain,” she says, “because it isn’t a super villain. It’s just a criminal.”
STEPPING UP DURING A PANDEMIC Many of cybersecurity’s most high-profile women share a passion for cybersecurity that keeps them actively engaged on myriad fronts at the same time. For cybersecurity consultant Jo Stewart-Rattray, her deep fascination with the industry, and engagement with the sector, have kept her engaging with a broad range of roles – whether as director of information security and IT assurance with BRM Advisory,
the deployment of two national call centres staffed by home workers, as well as managing a widely distributed security team that was facing similar challenges from home working. It wasn’t her first secondment – and it was, she recalls, an eye-opener to the many ways that cybersecurity impacts everyday business and the operations of essential services. “I found that when I did that, it really made me recognise the needs of my clients and what they face,” she explains, “and what CIOs face on an everyday basis. It
“I hope more women are inspired to join the cyber security profession and everything this exciting career path has to offer”
puts you back in touch with the real world of security – and it’s good for the soul to not just be dropping the report and leaving.” Managing security during a pandemic meant addressing both technological and business issues, she pointed out, as well as the additional people-
vice president of communities with the Australian
management skills involved in keeping people
Computer Society, recent president of the Association
communicating across the distance.
for Intelligent Information Management (AIIM), member of ISACA’s information-security advisory board, and even part of the Australian government’s official delegation to the United Nations’ 62nd Session of the Commission of the Status of Women. Never one to gather moss, when the COVID-19 pandemic hit last year Stewart-Rattray began thinking about how she could help – and ended up seconded to health and in-home care organisation Silver Chain Group as chief security officer. Given the challenges that had descended on the entire health and aged-care industry almost overnight, she says, it became clear “the bad guys aren’t going to wait so we can’t wait.” Working with Silver Chain four days a week, StewartRattray found herself at the front line, helping secure
10
WOMEN IN SECURITY MAGAZINE
“It’s about the people aspect, and looking at how I can keep the team feeling connected,” Stewart-Rattray explains. “The face of work has changed, I think permanently, and we’ve seen that many organisations that I work with will continue to encourage people to work from home.” “And while I hear some people having a bit of a whine about how you can’t collaborate, I think you can. It just requires a different mindset.”
CONNECTING - SUPPORTING - INSPIRING
AWSN Membership Benefits: Mentoring Community Support
Education Careers Events
Visit awsn.org.au for information about exclusive events, programs, and content. Join Australia's largest community of women in cyber and physical security.
AMANDA-JANE TURNER Author of the Demystifying Cybercrime series and Women in Tech books Conference Speaker and Cybercrime specialist
C O L U M N
Cybercrime is big business Cybercrime is big business, thanks to technical advancement and interconnectivity creating more opportunity for cybercrime. This regular column will explore various aspects of cybercrime in an easy to understand manner to help everyone become more cyber safe. TECH SUPPORT SCAMS Tech Support scammers are very active, and highly organised. They operate from rented office spaces, just like a traditional call centre. They lure their victims in several ways: website popups, cold calling, fake virus alert popups, or with websites that spoof well-known tech or telecommunications vendors. The cold call version starts with the scammer telling a target there is an issue with the target’s Windows computer that must be fixed immediately. If this ploy is successful, the victim is directed to install legitimate remote viewing software that gives the scammer full access to the victim’s computer. The scammer might then open the computer’s event log or use commands in the Windows Command Prompt screen to present information to the victim as evidence of malware on the computer. If the victim is now convinced the computer has a serious problem the scammer persuades the victim to pay to have the computer ‘repaired’. While in the system, the scammer may also configure back doors so they can surreptitiously return to the computer later and steal account credentials. Sometimes the scammer will also install malware into the victim’s computer disguised as essential repair software. It doesn’t end there. The scammer may make a follow up call offering the victim a refund for the ‘services’ provided earlier.. Their aim is to gain financial account details and steal more money from the target.
14
WOMEN IN SECURITY MAGAZINE
What to do if you are the victim of a tech support scam If you paid a tech support scammer with your credit or debit card, contact your bank immediately as you may be able to stop the transaction. If the payment was made using a gift card or voucher, immediately contact the organisation that issued the card and explain the situation. If the scammer gained access to your computer, scan it with up-to-date and reputable anti-virus software and change passwords to any accounts you accessed from that computer. In Australia report the crime via https://www.cyber. gov.au/acsc/report,. In another country, report it to your local police or through the relevant cybercrime reporting mechanism. Tech support scams are big business – stay safe.
20th Annual AusCERT Cyber Security Conference
11th - 14th May 2021 // The Star Hotel, Gold Coast, Australia
4
DAYS
50+ SPEAKERS
IN PERSON & VIRTUAL
Keynote Speakers
Ciaran Martin
Maddie Stone
UNIVERSITY OF OXFORD
GOOGLE PROJECT ZERO
REGISTER NOW
conference.auscert.org.au WOMEN IN SECURITY MAGAZINE
15
2021 AND BEYOND What to expect from the Australian Women in Security Network (AWSN) AWSN was founded in 2014 as an open network of people aiming to grow the number of women in the
2022 AND BEYOND: INCREASING FUTURE PIPELINE OF WOMEN IN SECURITY
security community in Australia.
• Future plans of the network are to establish new programs focusing on high school students and a
Since it’s formulation, the network has come a
return-to-work offering for women in security who wish
long way and has continued to inspire, support and
to re-enter the workforce after a career break or hiatus.
connect women in the industry to those looking to enter the field with the tools, knowledge, network and platforms needed to build each members’ confidence and interest. As we look towards embracing a new phase of the network, here are are some key focus areas on the AWSN agenda in 2021 and beyond:
UPLIFTING CURRENT PROGRAMS • The network is committed to the quality delivery of its core capabilities which span across networking events,
HOW TO CONNECT, SUPPORT AND INSPIRE WOMEN IN SECURITY As the network continues to mature, AWSN is absolutely in need of supportive colleagues, champions, women and men, to be part of our cause and vision. Let’s support women in every step of their career journey, inspire them to pursue a career in security and help build the Australian pipeline of talented security professionals.
its AWSN Cadets Program and the annual AWSN Awards programs. • The network aims to optimise and uplift the National
YOU CAN DO THIS BY:
AWSN Cadet Program, increasing the number of
Becoming an AWSN member or
participants, workshops and study groups.
encouraging someone to be a member
Signing up to be a mentor
2021 FOCUS: SUPPORTING WOMEN IN SECURITY
The network recognises that we must focus on
initiatives to help retain and support the current
women working in this industry. • The network is committed to the goal of retention and
union of women working across the sector. • The network is implementing various programs to
Nominating someone for an award Speaking, or encouraging someone to speak at one of our events
Writing, or encouraging someone to write for the magazine
advancing women in security across • Australia by understanding the current state-of-the-
Hosting or attending one of our AWSN events
Post internship or jobs with us
Volunteering, Sponsoring, Supporting the organisation
support and help the cohort of women in security grow; these include: a Mentoring Pilot program (sponsored by ASD and powered by OK RDY), a
Come and join our AWSN community. To find out
series of Women in Leadership programs, a Women
more about the network’s initiatives, please visit:
in Security Study survey, a and a Small Business
awsn.org.au
Mentoring Pilot program. • The network sees itself as the conduit between other great initiatives and partners within industry aiming to achieve the same mission. For example partnering with companies such as Source2Create who have produced this incredible magazine.
20
WOMEN IN SECURITY MAGAZINE
The AWSN would like to thank their sponsors, volunteers, members and supporters who have helped shape the community into what it is today.
WHAT’S HER JOURNEY?
On a Symantec trip to Hawaii I met my future husband, who lived in Sydney. Three months later I quit my job and being just shy of 30 was still eligible for a backpacker visa so I came to Australia to have some time off and see what happened. Within two months I had landed a role as the Security and Privacy Initiatives Lead for Australia at Microsoft. Around 2010 my then boss at Microsoft became the first permanent CISO hired by nbn. When he was building out the team a role came up that looked like a great new challenge in an exciting young company doing something great for the country. So I made the move, along with a few of my Microsoft colleagues.
Kate Monckton
I started at nbn in July 2011 when the company was
General Manager Security and Privacy Assurance, Risk and Consulting at nbn
years, because of the speed at which the company
planning a full FTTP rollout. Over the next nearly 10 grew, I had a huge array of amazing professional experiences and challenges. I doubt there are many companies where I would have had similar opportunities.
M
I’ve always been in the security group at nbn in y journey into cybersecurity started very far away: with a degree in German and philosophy from the University of Leeds in the North of England.
My first job after graduating was in the European arm of an American boutique management consulting company that specialised in helping IT and CE vendors with their retail and SMB sales and marketing strategies. One of the company’s major clients was McAfee, and working with McAfee sparked my interest in cybersecurity. That was back in the mid 2000s when people were becoming more connected and threats were becoming more mainstream. After four years with that consultancy I fancied a stint client side and went to work in Symantec’s marketing team. Much of my work at Symantec was on the consumer side and that was when I became really interested in
security and cyber safety influence/culture programs. My current, recently created, role is a fantastic professional opportunity. It encompasses the privacy, information security consulting, risk and assurance. I am presently on parental leave but normally I share the role with Sarah Hosey with each of us working four days a week. I’m unaware of any other GM level job share arrangements in the industry. Sarah and I are really proud to role model how effective it can be and I hope that these kind of things become more the norm for everyone. Our portfolio comprises everything to do with managing the privacy program at nbn, from helping the operational front end of the business understand and manage its privacy risks to developing the long term strategy and policy for handling personal information. We also lead the teams that provide hands-on security consulting support to the business, and the teams that manage security risk and provide
cybersecurity, cyber safety and privacy. Looking back
internal and third party security assurance.
I bored a lot of people in my personal life with stories
My typical day has a lot of meetings (most of them
about protecting themselves online!
22
various leadership roles, generally in privacy and
WOMEN IN SECURITY MAGAZINE
remote at present). Most mornings we have a senior
W H AT ’ S
H E R
J O U R N E Y ?
need for a trusted and secure network that’s reliable and readily available to all Australians. We have an amazing culture within the Security Group that cuts across all levels of the organisation. Last year we came second and highly commended in the Australian Women in Security Network awards for the Best Place for Women to Work. I try to be offline by 5:30 so I can have some family time before my daughter goes to bed and only log on after 7pm if it’s absolutely needed. I spent the first 10 or so years of my career smashing out 80 hour weeks but since I got a handle on my work/life balance by prioritising much better I have had more success professionally and personally. leadership team (SLT) stand-up and once a week we have a longer SLT half day meeting with Darren Kane, nbn’s Chief Security Officer. On the days Sarah and I both work we have a 1:1 meeting first thing to make
When I was younger I felt I had to know everything to be credible professionally, especially in my first role with the consultancy. Over the years I’ve learned that is just not true. Pretending to know more
sure we’re clear on our plan of attack for the day and
than you do is incredibly detrimental.
the week ahead.
But you do need people around you whose knowledge
When you work in security what you think your week
and judgement you trust and can draw upon when
is going to look like is often not the way your week goes. So clear and open communication with Sarah, with the wider leadership team and with our direct
you need some help. I am lucky to have a great professional support network, many of whom are also good friends. I run things by them and sanity check
team is critical.
when I doubt myself.
The rest of the day is generally a mix of formal and
I also got really lucky with some amazing mentors
informal meetings that includes meetings with individual teams and leaders who report into our function, meetings with the cross-company Steering Commitees and project meetings. I am a natural early
who challenged me and helped build my confidence by throwing me in the deep end and letting me figure out that I can swim pretty well when given the chance. It’s also a great relief when you realise that it’s OK to
riser so I tend to spend an hour or two before my
make the wrong call sometimes.
toddler wakes up clearing email and reading through
If a decision you make is what you think is the best
reports etc. before having breakfast with her and doing the day care run. From 8:30 onwards it’s pretty much go go go in meetings.
at the time based on the information at hand, it’s not the end of the world when things change. How you respond to and acknowledge those changes is far
We all work incredibly hard but have a lot of fun every
more important.
day. We challenge each other constantly so there
I have had some great advice from past and current
is no scope to stagnate or stop learning. I also feel strongly about the mission of the company and the
colleagues and mentors. When this was critical
WOMEN IN SECURITY MAGAZINE
23
of how I had handled things it was really hard to
It is important to have diversity, with representation
swallow. But, without fail, with hindsight I have totally
of different genders, cultures, nationalities, abilities
agreed with the feedback.
and socio-economic backgrounds in all walks of life.
Darren Kane, my current boss, always talks about the key to success being to get the right people working with you. It can be easy to hire people because you have a need and they have the skills, but if their attitude and approach does not compliment the culture you want to promote they will cause you more
Without this we are limiting ourselves to an incredibly narrow way of thinking and acting. By harnessing the power of a wider variety of experiences we open the door to some really exciting opportunities to do things better, which in security and privacy can only be positive.
pain in the long run. I’ve definitely learned this the
I really love the human side of my role, helping grow
hard way over the past 15 years.
and develop the team. I’d say I have a reasonably
In the early days I often felt like my lack of technical or vocational training was a huge negative and felt out of my depth in many a product discussion. Over time I started to see how my background and strengths in communication and strategy were very complimentary to those of the technical people I worked alongside.
high level of emotional intelligence that helps me build genuine trust with the people I work with. I gave up trying to have a work ‘persona’ many years ago when it became too tiring trying to be who I thought I should be professionally versus allowing my ‘at home’ self to come with me to work. I don’t shy away from hard conversations with people, because I think if you’re honest and straightforward people will
“When I was younger I felt I had to know everything to be credible professionally, especially in the consulting role. Over the years I’ve learned that is just not true. Pretending to know more than you do is incredibly detrimental.”
respect you and want to keep working with you. I really encourage people into careers in security and privacy. The need is growing and there are some amazing roles out there, and you never stop learning or being challenged. Get involved in as many
I have really seen a shift over the past ten years
professional groups as you can, such as the
towards the industry being much more welcoming of
Australian Women in Security Network (AWSN), the
people who don’t have tech backgrounds, which has
Security Influence and Trust Group, the Australian
been a huge benefit by promoting diversity of thought
Information Security Association (AISA), etc. Join the
and approach. Early on I definitely felt judged for not
virtual meet-ups, or even better, offer to help with the
having a computer science degree and not being able
organisation behind the scenes. This is where you will
to make jokes about TCP/IP.
meet people in the industry and figure out what you
I’ve often been the only woman and the only nontechnical person in leadership teams within security
If anyone reading this wants to chat to me about how
groups (although thankfully that has changed a great
to move into the industry I’m always very happy to
deal over the past five or so years). At times it’s made
do so (via LinkedIn message is probably best), but
things harder, but more often than not there have
maybe give me a couple of months to get this new
been benefits to being able to provide a different take
baby into some kind of routine!
on things.
24
enjoy.
WOMEN IN SECURITY MAGAZINE
Mentoring Pilot AWSN is pleased to launch the 2021 Australian Women in Security Network Mentoring Pilot.
Looking for ways to give back? We need you Learn more at awsn.org.au/initiatives/mentoring/ Sponsored by
Powered by
IT’S NEVER TOO LATE TO CHANGE YOUR STARS
I
started my security journey long before I knew the security industry to be an option. My daughter was three years old and I was working a job I absolutely loved in the snowboard industry, but the pay was low and jobs were
seasonal. Life was stressful because money was tight and I wanted more options: more freedom for my family, more opportunities for my daughter. I knew there was so much more I could do with my life. I grew up with computers, playing video games and learning programming in school, so I knew tech was an option. I even started down that path straight out of high school, before being quickly derailed by the lure of the snowboard industry. Don’t get me wrong, getting into that industry was
Toni James Product Owner | Security Advisor | ChCon.nz Organiser | Diversity Advocate | Speaker SafeStack Limited
26
WOMEN IN SECURITY MAGAZINE
the right decision at the time. It brought me around the world to New Zealand from my home in the USA, and led me to meet my husband (in the lift line while snowboarding). I regret nothing about choosing that path in life.
W H AT ’ S
H E R
J O U R N E Y ?
What I do regret is getting stuck, doubting I could
I didn’t win the first scholarship I applied for, but I was
take a new path or pursue a different career when I
a finalist, which got me a trip to Sydney and training
had no guarantee of success. It was the absolute fear
in diversity and inclusion initiatives. This opened
of failure that held me back. It was far easier to just
up further pathways into research and leadership
apply for another job, settle for the best pay you could
opportunities. I applied for a software engineering
get, and make ends meet. Believe me, it took me nearly five years and a bout of depression to realise this and work up the courage to change my stars. When I finally worked up the courage to change my stars and do something different, I didn’t know what I wanted to be. I really
“What I do regret is getting stuck, doubting I could take a new path or pursue a different career when I had no guarantee of success. It was the absolute fear of failure that held me back”
envy people who can answer the question “What do you want to be when you grow up?” They seem so driven and confident, so clear on what they want in life, and so focused on achieving it. I’m not one of those people. I want to be happy. I want to be financially stable and have time to enjoy life with my friends and family. I want to contribute to society in a positive way. I want to help others through the tough times in life. I want to share my story, to help others find their place in the world, and support them along the way. One thing I did know was that a job in the tech industry could give me opportunities to be all those things. So I chose to study for a degree in computer science. It’s an extremely versatile degree, the study
internship at a local software company, and got one for two years. Many things I applied for I did not get, but the key here is: I applied, and when the opportunity was right, I said yes. The opportunities I’ve followed have taken me to Australia, India, Singapore, Argentina, and the United States, and I’ve learned so much along the way. Eventually, those opportunities led me to the security industry. When I was working as a software engineer in a healthcare software company, I found security to be a high priority. This sparked my interest, and the more I learned about security, the more I wanted to know.
regime was flexible enough to accommodate my
I applied for diversity funds so I could go to security
childcare options, and I was able to choose classes
conferences. I spoke at security conferences and
that interested me.
meetups, and I studied security “for fun”. And when
One notable benefit it gave me was being able to take opportunities as they presented themselves. I’m still limited by where I live, and by my education and training, but when someone says “Hey you’d be great at X! Have you ever thought of working in Y?”, it opens options I never knew existed. During my first month at university Google visited my campus on a recruiting mission and hosted a Women
someone said “Hey, you’d be great at this! Ever thought about working in security?” I took that opportunity, and I changed my stars again. I still don’t know what I want to be when I grow up, but right now, I love where I am. www.linkedin.com/company/safestack/ academy.safestack.io/about-safestack/
in Tech event. I met several Googlers who were interested in my story and encouraged me to apply for
twitter.com/safestack
scholarships, internships and programs.
WOMEN IN SECURITY MAGAZINE
27
M
y journey into cyber security started in the early 1990’s with a recalcitrant computer. I was in the Royal Air Force and helped my commanding officer prepare PowerPoint
presentations for his meetings. The computer I used kept breaking down, so I took it upon myself to learn how computers worked and fix it. Then a friend who worked in a new area in the RAF called ‘computer security’ told me she was leaving and suggested I apply for her position. I did. I got it, and I’ve never looked back. At that time information and systems security was a very new area. Few of us understood what was needed. But we worked together as a team (all male, except for me) and we evolved with the industry.
Joss Howard
Our managers encouraged us to research, to learn,
Cyber Security Senior Advisor, NCC Group APAC
Support and guidance from them were available
and to try and resolve issues as best we could. in abundance. A mistake wasn’t a mistake, but an opportunity to learn and try again. Today there seems to be too much pressure to get things right first time, and too much emphasis on blame, which is such a shame. In those early days computer security conferences were male dominated. I found them tiresome: it was hard to find anyone who looked or thought like I did. There were men who would champion the cause of equality, but they were few and far between. Things are much better today. There are opportunities to discuss security and share opinions with a wider audience, and long may that continue. The inclusion of different cultures and backgrounds in cybersecurity is important. Diversity breeds
“The inclusion of different cultures and backgrounds in cybersecurity is important. Diversity breeds collaboration and innovation. Hackers don’t discriminate, so why should we? ”
28
WOMEN IN SECURITY MAGAZINE
W H AT ’ S
H E R
collaboration and innovation. Hackers don’t
J O U R N E Y ?
•
discriminate, so why should we? In security, to be effective we need to stop discrimination and take on the challenge of diversity.
Assisting sales in qualifying, proposing and designing solutions to bids and other responses.
No two days are the same. Regulatory changes, new cyber security standards, changes in technology, new
I have led and managed teams from diverse
cyber-attacks, sales and research, keep me very busy
backgrounds and each member brings a different
and out of trouble!
perspective based on their experience. These different experiences lead to pragmatic, flexible solutions that fit with an organisation, making that organisation an easier and, frankly, a more pleasant place to work. I’ve learnt much from team members that has helped me serve the team better. It’s been enjoyable to hear (and sometimes experience) other cultures. Today I consult to boards, senior management and department heads on how to reduce cyber risk and increase cyber resilience in their organisations. My consultancy can take the form of strategising, operational transformation, assessing an organisation’s current security posture, or providing security awareness. My role is diverse and continually changing. One day I might get to speak to the most senior people in the business and help solve their cyber security challenges. Next day I could be helping my client improve their cyber resilience.
I’ve been in information security – in one way or another – for 30 years. I have had great privilege of working in more than 10 countries in the EU, North America and APAC. I have had the honour of helping more than 60 clients ‘change the security dial’ for the better. I never expected this when I started out! I am an avid reader and apply what I learn. In the early days, I built my own computers and networks at home and tried to hack them. I would then build on that experience. I also set personal goals to see what I can achieve in a given time. Then I reflect on what I had achieved. I am also willing to take a risk and follow an opportunity. I have found there is usually a small drop when you take that initial step, but it’s followed by a rise. I have taken many courses over my career, generally around leadership and management, operating systems and networking, information and cyber risk management, and privacy. These have also included:
As an executive principal consultant my role covers
Certified Information Systems Security Professional
marketing, sales and delivery. My day could include:
(CISSP); Information Security System Management
•
Leading the client in defining their cyber security strategy;
•
Providing thought leadership through conducting webinars, delivery of blogs, articles and interviews with journalists;
•
Conducting control assessments of a client’s security posture and creating security roadmaps;
•
Recommending boards and C-level clients on options to reduce cyber risks in their organisation;
•
Conducting an incident response scenario exercise to improve a client’s cyber resiliency;
•
Writing and delivering policy;
•
Acting as the point of contact between sales, the
Professional (ISSMP); Certified Information Systems Auditor (CISA); Certificate in Information Security Management Principles (CISMP); Certified Data Privacy Solutions Engineer (CDPSE). So, if you are considering a career in cybersecurity my advice would be: go for it! Take risks and grab opportunities as they come along. Accept that there will be challenges along the way, but know you can overcome them. Be open to learning and put in the hard work needed to be successful. Get yourself a mentor or coach to help you along the journey, for either professional or personal development. They act as a great ‘sounding board’ and provide independent insight and guidance to help you along the way. www.linkedin.com/in/joss-h-5571981/
client and our business;
WOMEN IN SECURITY MAGAZINE
29
identify business risks that are unknown to the organisation.
Skye Wu
I see the most important part of my job being to
Cyber Security Investigator, Speaker, Mentor & Champion for Diversity
away from the team so its members can focus on
take mundane work, such as administrative tasks, the important tasks, like working with data to distil interesting findings that can be turned into actionable
I
fell into a career in security after I became interested in digital forensics at university for my bachelor’s in information systems degree. I enjoyed problem solving and working out how/why something happened. I realised that by doing digital
No two days are the same. Generally I like to start my day doing a bit of reflection and thinking, be it looking over the project we are working on, or the team’s annual plan and the goals we are hoping to achieve in the current financial year.
forensics for law enforcement I would also be able to
Most of my time is taken up with data analysis work,
do some good for society. So it became a no-brainer
asking questions of the data to distil interesting
for me to start my career there.
insights, and playing with visualisations so the insights
I was recruited into the computer crime squad with no practical experience, only knowledge gained from books (before YouTube!). The senior sergeant who hired me told me on my first day I would have a steep technical learning curve, but he hired me because I was
can be presented to and consumed by a range of audiences (technical and business). I also look for potential opportunities for continuous improvement, and document our findings and learnings in our growing knowledge base.
able to show I had the aptitude and thinking of a digital
I also work in the Australian Women in Security
forensic analyst.
Network (AWSN) where I lead the AWSN cadet
I spent years working in law enforcement, followed by several stints in consulting. I was fortunate to have worked with some of the best minds in the industry very early on, and I learnt much from my colleagues in law enforcement, and later those in consulting.
program. I became involved with AWSN after meeting founder Jacqui Loustau several times at networking events. I initially became an industry advisor to AWSN’s Melbourne chapter and ran a workshop for the Melbourne cadet members. I really believe in what the cadet program hopes to achieve. So when
However, my job was always to investigate something
the opportunity came to expand my role and lead the
after the fact; get involved after a litigation had already
program nationally, I jumped at it.
begun, and I became weary of being always on the responding side of the equation. I began to wonder if it were possible to move into an area where the work would be more preventative than reactive. I joined Telstra in 2014 as an open source security analyst and a few years later my boss, Chris, dropped me into the discovery team to help on a temporary secondment. I became really interested in the proactive nature of the role, so I decided I wanted to stay. Luckily the feeling was mutual! Since September 2019 I have been acting Discovery manager at Telstra. The Telstra discovery team uses data the company is already collecting to proactively
30
intelligence internally.
WOMEN IN SECURITY MAGAZINE
I work with AWSN leads, including other cadet leads, and with AWSN committee members to provide a safe environment in which our cadet members can learn, collaborate and interact with their peers and industry professionals. I dedicate a few hours each week to cadet work. This includes looking after the Slack channel where our members collaborate. Since COVID the security workshops for our cadet members have run virtually nationwide, and I also work with committee members to ensure our planned workshops go ahead. What I love most about both my roles is the opportunity to be proactive. In my day job, I can help the
W H AT ’ S
H E R
J O U R N E Y ?
business get on top of potential problems. As AWSN
Working in digital forensics, I was not taken seriously
cadet lead I help new talent prepare for careers in
and accepted as an equal by my male counterparts
cybersecurity. It’s an opportunity for me to reciprocate
who performed the same role. And I was sought after
the support I had on my journey.
for roles and opportunities because to my gender
The industry is an ecosystem; it’s important to help
rather than for my experience or qualifications.
develop others at the same time as you develop
I was then made to feel unworthy and undeserving
yourself. I have learnt a lot about myself through
of recognition for my skills and expertise, with
mentoring and supporting others.
discouraging comments from male colleagues in
In the early days of my career my self-doubt and lack of mentorship from leaders who were able to recognise
senior positions, such as “You only got recognised as a diversity stunt.”
my personality traits and how I worked limited my
Being female and also a first-generation migrant from
personal development.
China led to advice such as “you should not apply
My main personal challenge stems from traits I was, unfortunately, born with: self-doubt, self-defeat and
for federal government roles as you are Chinese and people won’t trust you.”
self-sabotage. For a very long time I would turn down
I’ve also been accused of not behaving as a member
opportunities unless I knew I could do 100 percent of
of the team, because I outed a “team-bonding”
the job. I would sometimes put myself down believing
competition that involved weight-lifting and other
it to be a sign of modesty. I experienced my most
weight-related gym exercises in which the whole team
personal development and growth only when I took a
could not participate equally.
leap into the unknown.
I believe companies need to not only close the gender
Understanding what motivates you and why you do
gap, but also consider broader diversity, including
it will guide you on your career journey. And don’t be
diversity of skill, thinking, experiences, etc. Teams and
afraid to fail: sometimes our biggest setbacks are
organisations that do not take an interest in broad
opportunities to propel ourselves further.
diversity run the risk of applying tunnel vision to the
Over time I got comfortable with the idea of putting myself into situations that terrified me, like public speaking. I also started to get comfortable with making
work they do, the products and services they provide, and of missing opportunities to recruit and maintain talent that could help drive their organisation forward.
mistakes and failing. A very wise industry influencer
So, build yourself a solid support network, attend / seek
once told me “if you are feeling challenged, it means
out industry events, join industry groups such as AWSN,
you are growing!” Having that kind of support and
and the AWSN Cadets. There are many experienced
advice really helped me on my journey.
men and women in the industry who are supportive of
It took a great manager who recognised my abilities and prodded me in the right way to get me to move out
new talent entering the industry. Networking will help you connect.
of my comfort zone. That came after several years in
Be open to new opportunities, even if people and
different workplaces with different managers.
your own inner voice are telling you ‘no’. Be open
I also faced many challenges simply by being female. At university I was discouraged from pursuing a career in digital forensics because the industry is very maledominated. From the moment I decided I wanted to work for law enforcement doing digital forensics without any handson experience, I knew I had to grow a thick skin. I had to swim or drown, and drowning wasn’t an option.
to failure, own your mistakes; people aren’t likely to remember how you failed, but they will remember how you picked yourself up. Know who you are, know your values as an individual. Write them down on Post-it notes and put them somewhere you can see them whenever you need to. www.linkedin.com/in/skye-wu-ba390919/ www.skyewu.com
WOMEN IN SECURITY MAGAZINE
31
WHERE ARE MY LADIES AT? Bri Hadley Creative, connector, and knowledge vacuum
BREAKING ASSUMPTIONS, CHANGING OUR PERSPECTIVES, AND OWNING OUR PLACE For most of their existence public policing and private security have been a ’boys club‘. Social expectations, ideas of ’propriety‘, and fear all played a role in the assumption that women and security do not mix. Under these assumptions, men designed the security industry, from its aims to its ideal candidates. Arguably, these were smart, rational men. In most circumstances, though, they would not (or could not) challenge their underlying assumptions—including their assumptions about the role of women. Our post-modern culture, even with its focus on diversity and inclusion, still suffers from this assumption blindness. If we want to move forward as an industry, we need to find and challenge these assumptions, keeping what is useful and replacing what is not. I like to use my career as an example of the impact of assumptions. I have always been an investigator— always curious, always wanting to know why, and always making connections. I come from a long line of security workers and first responders—police, military, private security, firefighters, nurses. I initially resisted a career in both traditional public policing and in the private sector. Growing up, I could not see myself thriving in the regimented culture of public police services. Also, I did not want to spend my time serving legal paperwork and chasing down cheating spouses. I assumed that, if I wanted to be in security, I had to choose one or the other.
40
WOMEN IN SECURITY MAGAZINE
After many twists, turns and false starts, I landed in investigations in my late 20s—all thanks to a few months of rather dramatic mistakes. Fortunately, I had a brilliant manager with a plan. While both embarrassing and frustrating, this plan gave me the time and connections I needed to redefine what a career in security (in this case, investigations) could look like. I met women who would become mentors who showed me where my career could go. Just over a year after being hired into the unit I went from being bored and disengaged to finding fulfillment in my work, every day. Over the years my role has included investigations, data analysis, business intelligence, and consulting functions. I love it! I think most people still assume that security workers have uniforms and badges, carry guns, put themselves in harm’s way to protect (or control) people. This, at best, is an incomplete picture. In the years since I joined the security industry, I have developed a very different picture of what policing and security look like. I have learned that physical security and information analysis are interdependent parts of the same whole. We ask questions, assess risks, and identify threats. Some of us collect, compile and analyse large amounts of information from an increasingly complex array of sources. Some of us find connections across seemingly unrelated groups of information and create risk-mitigation plans. Some provide advice and write policy. Others protect physical assets. If we want to do our jobs well (and I believe we do), then we need to paint this picture of the security industry, in all its diverse roles and functions. We need to be willing to challenge even our most basic assumptions. We need to take on new perspectives, and find ways to incorporate those perspectives into our daily work and our organisational structures. This is how we own our place in security. Then perceptions and assumptions can shift, opening a window into the world of security. When more women see what a career in security has to offer, they will come.
CONTACT NOW
DO YOU WANT TO PROMOTE YOUR BUSINESS TO A NEW TARGETED AUDIENCE? Contact us today to find out how you can be a part of the Women in Security Magazine!
MARIE-EVE LAPLANTE
WHAT YOU NEED TO KNOW ABOUT CYBERSECURITY CAREERS by Marie-Eve Laplante, Cybersecurity Strategic Advisor
Starting a new career in cybersecurity can be a little
solutions, antivirus, vulnerability management
intimidating. Media coverage of data breaches and
and more. Incident response teams are needed
cybersecurity incidents is becoming more common.
to manage crises, coordinating all stakeholders
Movies and TV series tend to focus more on hackers
and working under pressure. Audit teams are also
than on all the other professionals essential for the
essential to give an organisation and its shareholders
protection of information in an organisation. So, if
reasonable assurance that the security measures
you are not a hacker spending your evenings and
deployed are adequate. Your skills may fit many of
weekends on the dark web and developing scripts,
these profiles and could lead to an interesting and
should you consider a career in cybersecurity? The
fulfilling career in cybersecurity.
answer is a resounding YES!
NOT EVERYBODY IN CYBERSECURITY STARTS WITH A HACKER PROFILE
Cybersecurity is constantly and rapidly evolving. A
Ethical hackers and people with the skills to penetrate
couple of years ago few organisations were talking
systems are important for cybersecurity defence,
about cloud security, about user behaviour analysis,
but there are many jobs in cybersecurity that do not
or discussing how artificial intelligence would impact
require these skills. For instance, an organisation
defence and offence capabilities. New threats, trends
needs people specialised in governance, risk and
and technologies are emerging all the time. This
compliance to help manage priorities, investments
means, as a cybersecurity professional, you must
and regulatory requirements.
stay informed and adapt and evolve to meet the new
Operational security teams are needed to implement access controls, network security, data protection
46
YOU WILL NOT BE DOING THE SAME THING ALL YOUR LIFE
WOMEN IN SECURITY MAGAZINE
risks and priorities facing your organisation. No time to get bored!
C A R E E R
P E R S P E C T I V E S
WOMEN IN CYBERSECURITY
line with their perceived risks. Hence, it is important to
Cybersecurity professionals are typically cast as
develop a risk mindset early in your career.
nerdy, hoodie-wearing males, but a wide spectrum of
Cybersecurity professionals can be frustrated by their
skills is needed, and people of any gender can find
difficulty securing budget to fix what they see as an
a place. Furthermore, cybersecurity is constantly
important security issue. This frustration may arise
being reinvented in response to new threats, trends
because they have been unable to communicate the
and technologies. The idea that only men can be
level of risk to higher management, or because they
interested or thrive in cybersecurity is completely
have inflated the level of risk.
outdated.
FIND A NICHE OR BECOME A GENERALIST There are many domains in cybersecurity. So take the time to familiarise yourself with the most used frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, or the Center for Internet Security (CIS)
Ask yourself not only if the vulnerability or weakness you identified could lead to a security incident, but also how it could hurt your organisation. A critical vulnerability that could give any malicious actor access to a system will represent a high risk only if the system itself contains sensitive information, is critical for the company’s operations, or can be used to gain access to another more important system. Being mindful of the actual risks faced by your organisation will help boost your
“If you are not a hacker spending your evenings and weekends on the dark web and developing scripts, should you consider a career in cybersecurity?”
credibility. In conclusion, there is no single profile of a cybersecurity professional. More than ever, organisations need your skills to help them enhance their security posture. They need analytical minds. They need coordinators.
Controls Framework. From there you can decide to become a generalist, by getting basic knowledge and skills in all domains and controls, or you can develop your expertise in a specific niche. Generalists are needed for roles such as audit, governance, risk,
They need technology-oriented people. They need managers. They need auditors. They need businessfocused people. They need hackers. They need security developers. They need testers. They need you.
compliance and information security management that call for a good understanding of roles played by
www.linkedin.com/in/marieevelaplante/
niche experts who focus on a particular aspect of cybersecurity. Their specific skills will be sought after to maintain and improve an organisation’s defences against current and new threats.
DEVELOP A RISK MINDSET In an ideal world, organisations would be able to finance any initiative to enhance their security posture. In reality cybersecurity budgets are limited, and organisations must therefore prioritise their investments in resources (people, money and time) in
Marie-Eve Laplante is a strategic advisor in cybersecurity for Desjardins. With 20 years of experience in information technology, including 15 specifically in information security, she now specialises in governance, risk, strategy and compliance. Her expertise includes cybersecurity management and risk management, strategic security planning, cybersecurity governance, risk and performance measurement, maturity assessment, business continuity, privacy, IT risks and operational risks. She has also undertaken several engagements in finance, energy, media, aviation and retail, among others. She has also frequently given training sessions, conferences and presentations to management and has been a lecturer at the Polytechnique de Montréal.
WOMEN IN SECURITY MAGAZINE
47
GIULIA TRAVERSO
THREE CAREER TIPS TO THRIVE AS A WOMAN IN CYBERSECURITY by Giulia Traverso, PhD- Senior Consultant Cybersecurity, EY
talk about my journey to becoming a cybersecurity
TIP #1: PAY ATTENTION TO THE COMMUNICATION CULTURE OF THE COUNTRY YOU’RE IN
expert, and my experience in the role. The panel was
I am Italian and I did my PhD in cryptography in
Back in November I was invited to join an online panel organised by the European Space Agency (ESA) to
organised primarily for students of the prestigious École polytechnique fédérale de Lausanne (EPFL), in Lausanne (Switzerland) to promote working at ESA. In particular, the goal was to show students the many different types of expertise, including cybersecurity, needed in the space industry.
Western European countries there were many adjustments I had to make to integrate into the German community. The most evident difference between Italy and Germany is the way people communicate. Italians tend to use long sentences
During the Q&A session I was asked (probably by
and to provide a lot of background before saying the
a girl) whether I had encountered resistance in my
thing they really want to say. This, I suppose, is to
career because I was a woman, and if I had some
better justify their request or opinion. This type of
tips to offer. I greatly appreciated this question and
communication, which I later discovered is known as
my answer received some positive feedback. So, I
‘high-context culture’, is very different to Germany’s
would like to share with you three career tips to help
‘low-context’ culture. In Germany, you just go straight
women thrive in male-dominated environments such
to the point and say what you want to say, period.
as cybersecurity.
48
Germany. Even though Italy and Germany are both
WOMEN IN SECURITY MAGAZINE
C A R E E R
P E R S P E C T I V E S
rude and aggressive. Because I was working in a male-
TIP #3: KEEP IN MIND THAT NETWORKING IS STILL WORKING, ESPECIALLY DURING LOCKDOWN
dominated field, it was easy for me to blame the males
There is a very interesting book
In a discussion, Germans value clarity and brevity. As a result, unprepared Italians like me see them as being
for my not being at ease during discussions. After a more careful analysis, I realised that, although males tend to be more aggressive than women, my perception of them as being aggressive was the result of me being ignorant of the local culture.. This realisation was liberating. Also, I knew I could train myself to communicate in a more low-context manner, which is also the way scientists are supposed to communicate. As a result it became easier for me to join discussions at work and my discomfort disappeared.
called “Nice Girls Don’t Get the Corner Office” by Lois P. Frankel, PhD that I highly recommend. One of its suggestions that caught my attention was to consciously and actively dedicate at least five percent of your working time to networking. According to Frankel, many women tend to undervalue those breaks and chit-chat moments in front of the coffee machine, seeing them as time wasted. In the short-term that is certainly
“Communication is key, so use it wisely. You cannot thrive unless you own your value and make it visible to other people”
true, especially under tight deadlines, but in the long-term such behaviour is likely to harm their careers. In turns out that the people who get promoted the most are those who are more visible and to whom other people can relate. If
TIP #2: ASK QUESTIONS WITHOUT UNDERMINING YOURSELF
you never join social breaks, you never give yourself a
I have noticed over and over again that, during the Q&A
The move to working remotely established during the
sessions of seminars and presentations, we women
COVID-19 pandemic is likely to make things worse.
tend to begin our questions by saying things like:
People are less visible when they do not come to the
“I’m not sure I understood the key concepts of Slide
office. So please, set aside at least one hour each
12”, or “Correct me if I am wrong”, or “I might have
week to expand your network and make yourself
misunderstood, but it seems to me that”, etc.
visible through LinkedIn, remote coffee breaks in
No way! Undermining yourself before asking the actual question is not the right way. Just go straight to the
chance to stand out.
Zoom with your co-workers etc. The only way to get noticed is to make an effort to get noticed.
point and say instead: “Can you clarify again Slide
The bottom-line tip of this article is: communication is
12?”, or “This is what I got from what you just said, is
key, so use it wisely. You cannot thrive unless you own
that correct?”, or “Can you articulate again your last
your value and make it visible to other people.
argument?” This tip is somewhat related to tip #1 above, because
www.linkedin.com/in/giulia-traverso-phd-13a749150/
it cautions against adding words additional to those related to the question itself. And by the way, the
www.breakingthirty.com
implicit tip here is: do ask questions! Do not be afraid of looking stupid just because you want more information or clarification. It is likely that other people in the room also need additional information and clarification.
WOMEN IN SECURITY MAGAZINE
49
MELANIE NINOVIC
ADVICE ON JOINING THE INFOSEC INDUSTRY by Melanie Ninovic, DFIR Consultant, ParaFlare.
Credit: consultancy-me
56
WOMEN IN SECURITY MAGAZINE
C A R E E R
P E R S P E C T I V E S
The past few years in cybersecurity have been
Once you set these objectives, you can start focusing
everything from eye opening and rewarding to
on the skills you need to achieve them. When you
downright challenging. There have been challenges
focus on one or two related areas at a time, you are
you cannot begin to prepare for, even though you’re
likely to grasp them more efficiently and effectively.
ingesting copious amounts of new information every I’d like to offer some advice I wish I had been given at
TECHNICAL ABILITIES VERSUS SOFT SKILLS.
the start of my career. Hopefully it will provide some
Technical abilities will give you opportunities in the
day. I’m fairly new to the world of cybersecurity and
tips to anyone looking to join this industry.
YOU WON’T KNOW EVERYTHING. Take a look at the graphic below. Each time I come across it, I am overwhelmed by the range of disciplines in this industry. It’s quite common for people to become experts in one field, for example, digital forensics, and have knowledge in another field, such as penetration testing. Some of these disciplines go hand in hand. It’s useful for a forensic practitioner to think like a hacker, by learning how to exploit vulnerabilities. However, this is not a requirement for a career in forensics. It is easy to fall into the trap of striving for accomplishment in multiple domains. Trying to learn all there is to know about cybersecurity would be almost impossible. My first piece of advice is to understand, within your first year or two, where your interests lie, and how you want your career to progress.
cybersecurity industry, but are by no means the only skills you should focus on. Each security domain requires the following soft-skills, and I would argue that you would not last very long without them. Communication: how to speak and present professionally and effectively to your colleagues, manager and, most importantly, your clients. Collaboration: you will almost always be working in a team, assisting with reviewing your colleagues’ reports, and collaborating towards a common goal. Writing: writing reports and status updates is the pinnacle of a digital forensics and incident response, red-team/pentest, or governance, risk and compliance engagement with a client. Your findings must be communicated in a way that can be understood by both technical and executive level stakeholders. Business Acumen: knowing the drivers of a business, being able to present a case for new security tools or training, or advise clients on how to improve their
Henry Jiang: https://www.linkedin.com/pulse/map-cybersecurity-domains-version-20-henry-jiang-ciso-cissp/
WOMEN IN SECURITY MAGAZINE
57
security team and posture are all useful attributes
presentations and speaking with people who have
you can bring to an organisation.
more experience than I has assisted my professional
There is a place in cybersecurity for everyone, whether you have formal security training or not. This industry spans numerous, distinctive domains.
development in ways that would not have been possible during work hours. These activities were directly responsible for me landing a new job.
It needs professionals with diverse educational and career backgrounds.
BURNOUT IS REAL. According to healthguide.org, burnout can be defined as: a state of emotional, physical, and mental exhaustion caused by excessive and prolonged
We all have our different paths, challenges, hurdles and timelines. There is no point in comparing yourself to others. More important, is that we are all working towards the same goal: improving the security of those around us.
stress. It occurs when you feel overwhelmed, emotionally drained, and unable to meet constant demands.
Community: There is a curated list of Asia-Pacific
It is a common problem in the cybersecurity industry,
information/cyber security meetups here. I also
because we often feel the need to push ourselves
recommend the Australian Women in Security
to learn as much as we can. Even if you take the
Network (AWSN), and there’s a list of Asia-Pacific
sensible approach of focusing on one skill at a time,
infosec conferences here.
you can still suffer the effects of burnout. Studying on top of everything else in life — work, family, hobbies — can be overwhelming.
Online Learning Resources: As part of my InfoSec 101 series, I’ve provided a small inventory of places to start learning online. Most of these resources are
It is important to recognise the signs early on and
free. For more practical challenges such as capture
take preventative measures as soon as possible.
the flag events and running your own virtual machine,
The signs are different for everyone, and the site I’ve
have a read of this post.
linked to above does a good job at detailing them. It’s important to be transparent with your employer too, to ensure you are given time to recuperate and rest.
GET INVOLVED. Before landing my first full-time security-related role as a security operations centre analyst, I had spent the previous year studying to my heart’s content. I knew, without at least some knowledge of important security concepts, I would be unable to land an
We all have our different paths, challenges, hurdles and timelines. There is no point in comparing yourself to others. More important, is that we are all working towards the same goal: improving the security of those around us. Whether you decide to join the industry tomorrow, or next year, I hope this article helps you to manage your expectations, and I’m happy to answer any questions you may have. www.linkedin.com/in/melanie-cybers/
interview. There is an abundance of online resources that can help develop and fine-tune your skills, and an
www.darkdefender.medium.com/
online and physical community where you can meet like-minded individuals. Of course, this isn’t a necessary part of your job, we all have lives. However, I have found watching
58
WOMEN IN SECURITY MAGAZINE
twitter.com/_darkdefender_
Easy Reliable Resourceful No job is too big or too small. We look after your marketing & content needs so you can get on with what you do best. GET CONNECTED AND TAKE CONTROL OF YOUR BUSINESS SUCCESS TODAY!
charlie@source2create.com.au | aby@source2create.com.au
www.source2create.com.au
MARIANE C LOUVET
INTRODUCE YOURSELF TO LEADERSHIP, THE POWER OF A STRONG NETWORK AND CONNECTIONS by Mariane C Louvet, Channel leader - Cyber Security Over the past 20 years I have come to a realisation:
and to give me confidence in this new role. He
a title is just that, a title. It refers to a human being
introduced me to all of our partners and one thing I
with a function in their industry. We get hung up about
realised quickly was that relationships were key to
hierarchy and about who we are supposed to engage
success. I found ways to connect with our partners
with, or not.
and our vendors by engaging with them on topics
I was 23 and my career goal was to become a fashion buyer; I had taken college courses in fashion
senior leadership at events and during meetings.
merchandising and had plans to travel the world in
Within my first year in the role, I had won an award
search of the latest and greatest in apparel trends,
for top sales assistant, and as a team we won the top
until a market crash changed my destiny. Instead
sales award. Seven years later I had become a sales
I took a job as a sales assistant at a technology
rep with a sales assistant of my own.
distributor. Technology was an industry I knew nothing about, and had no interest in, but it paid well. So I jumped on it. My first manager should have been a stand-up comic, which made my job not only fun, but interesting. He made certain to take the time to help in my training
64
other than technology, and I presented myself to
WOMEN IN SECURITY MAGAZINE
I took a break from IT to raise my daughters. I kept in touch over the years with my partners and with vendors and stayed on top of technology trends and industry developments. The president of one of my old partners reached out to ask if I would be interested in a role supporting a
C A R E E R
P E R S P E C T I V E S
vendor from overseas, part time. He thought I would
ladder, to let them know I was available. I had four
be a great fit. Within a few weeks I had connected
offers. The hard part was deciding which one to take.
with their leadership team and introduced myself to
I opted for a director role at Forcepoint
them. I spent four years rebuilding and expanding my network and reconnecting with the industry.
Networking is not hard, however, you have to know how to approach people. I had the pleasure of
An opportunity came up as an executive account
attending an incredible charity event in New York
manager at Symantec, and during my new hire
in November of 2019. Dress for Success (a global
training at our corporate HQ, I made sure to listen
not-for-profit organisation that empowers women
carefully when leaders were speaking and reached
to achieve economic independence) had a fireside
out to many upon my return with questions on their
chat and their fearless, classy CEO, Joi Gordon made
presentations. This created visibility for me. Over
time to speak with me because I had sent her an
my six-year tenure I made sure to approach C-level
introductory email prior to attending. I also had the
executives at our sales kick-offs and at various
opportunity to chat with renowned US television and
industry events, in the hope they would offer me
online journalist, presenter, producer, and author, Katie
opportunities to grow my career.
Couric. These amazing women are now part of my network. All it took was a simple “hello” and some conversations.
“A title is just that, a title. It refers to a human being with a function in their industry. We get hung up about hierarchy and about who we are supposed to engage with, or not.volupicte cus aut ad”
Over the years I have created numerous connections, and many have become mentors, friends and part of my daily life. It does not matter if someone is C-level, SVP, senior- something or other. Those are just titles.. Doing your homework on who they are and what they do, and finding common interests are all great ways to start a conversation. I have no issue
I then decided I wanted to leave sales and move to
picking up the phone, texting or emailing anyone in
the channel. We were launching a new division and
my network to say hi, to recommend someone, to ask
they were looking for a leader to support the Canadian
a question, or to congratulate them on their success.
market, so I approached our SVP of global sales and told him I wanted the role. I then connected with the VP for EMEA who would be running my team. It took some time, but I was persistent, took a leap of faith and moved to our brand-new cloud channel team. I spoke with our CIO at an executive briefing in California and mentioned what I was doing. She was very supportive. Once again, had I not taken the time to get to know these people, I might have missed a
My nicknames over the years have been “fast talker”, “411”, or the “networker”. I embrace them all. They have opened doors for myself, my family, and friends; as much in my personal life as in my professional life. A final reminder that a title is simply a title. At the end of the day, effective communication and knowing who you are approaching are all it takes to make strong connections and create a solid network.
tremendous opportunity. When I was looking for a new position a little over a
www.linkedin.com/in/mariane-louvet-94340a6/
year ago following the sale of Symantec’s enterprise security assets to Broadcom, I reached out to my network, including some at the top of the leadership
WOMEN IN SECURITY MAGAZINE
65