Skip to main content

Women In Security Magazine Issue 1

Page 1

01

MARCH • APRIL

THE FUTURE FOR WOMEN IN SECURITY IS NOW P16-19

ARE WE DOING ENOUGH? P50-51

AUSTRALIA’S FEMALE SECURITY PIONEERS P6-10

THE BEST COMPANIES FOR WOMEN TO WORK IN SECURITY P106-108

W W W. W O M E N I N S E C U R IT Y M A G A Z I N E . C O M


FROM THE PUBLISHER

T

Raising the profile of women in security may be my passion, but it’s everyone’s job here’s a difference between reading about

growing passion to make a difference – to help

the lack of women in security, and doing

Australia’s cybersecurity industry overcome the built-in

something about it.

biases that are limiting businesses and keeping our best

I’ve worked both sides of that argument – first during 10 years as publisher of CSO Australia, and more recently

and brightest young women from an industry that is already primed to give them satisfying, flexible, rewarding careers.

in partnership with the Australian Women in Security

Empowering women to join the security community is

Network (AWSN) – and I assure you that doing

a core goal of AWSN, and in the seven years since I met

something about the situation is much harder, but also

founder Jacqui Lostau we have been working hard to

much more rewarding.

build a community capable of driving change.

As publisher, I read articles about how women in security

Yet for all its successes, I quickly realised that AWSN

were sparse; blog posts advising CSOs about how

could only do so much as an association. Staff were

to retain the few women already working in security;

all volunteers and most had full-time jobs. Some had

requests for female mentors or career advice; and social-

families and some did not, but all were working every

media posts from successful security women sharing

hour of their days – as colleagues, mentors, advisors,

advice about how to not be the only female in the room.

advocates, and more – to make a difference.

It was a great job, although I didn’t understand all the

Watching their commendable and ongoing efforts, I

security parts – but I managed to work through that part

realised that it is not AWSN’s burden alone to change the

with the help of a very supportive, patient network.

way females are seen within security, or to increase their

At the same time, the debate became more than academic when I was faced with teenage girls growing up in a school system where tech subjects were just not cool. Out in the real world of education, cybersecurity and STEM still don’t get much of a mention – and IT was always advocated for by the nerdy, uncool teacher. Can we really be surprised that teenage girls wouldn’t go for this? In recent years I have been working to explore my

numbers in the industry. It’s not the responsibility of any one committed group to show females the many exciting career paths in security, or to identify standout achievers and highlight them as paragons to inspire others. It is all of our responsibility – and this publication is one small step in the ongoing effort to provide a solid platform for women in the security industry. Looking back, the ingredients were all there: the industry knowledge. The wonderful relationships I have gained and nurtured with like-minded individuals over the


Abigail Swabey

years. The amazing women who are leading IT security, cybersecurity, physical security, security resilience and privacy teams. They’re out there, doing great work every day – and their stories need to be told. We have taken some concrete steps to do this in recent years, not only by growing the membership of AWSN into the many thousands but through steps such as establishing the annual AWSN Women in Security Awards in 2019 and running the second (albeit virtual) awards last year. This publication gives the industry a platform to recognise the work of all those amazing women – not only to recognise their achievements, but to motivate the next generation of students to ignore their school’s bias, and give cybersecurity a try. I hope you’ll continue to join us on this journey to hear these stories, share your thoughts, and help make that little bit of difference in your own way. It’s only together that we can balance the playing field – and help the security industry benefit from the amazing talents of some of Australia’s most capable, inspiring women.

Abigail Swabey PUBLISHER, Co-founder at Source2Create aby@source2create.com.au

WOMEN IN SECURITY MAGAZINE

3


CONTENTS Building cyber culture into the business from day one

12

Cybercrime is big business

14

The future for women in security is now

16

A Day in the Life

42

Diversity in security: Not just about men and women

44

CAREER PERSPECTIVES

2

What you need to know about cybersecurity careers

46

Three career tips to thrive as a woman in cybersecurity

48

Are we doing enough? A cybersecurity career perspective from a multipotentialite 53

PUBLISHER’S LETTER

7

Advice on joining the infosec industry

56

Things to remember for women in tech

61

Introduce yourself to leadership the power of a strong network

64

Security is not just about hacking

66

Why cybersecurity as a career

68

AUSTRALIA’S FEMALE SECURITY PIONEERS

WHAT’S HER JOURNEY?

4

WOMEN IN SECURITY MAGAZINE

Kate Monckton

22

Toni James

26

How parents can keep up with apps and online games

70

Joss Howard

28

Tales from the trenches

73

Skye Wu

30

Rachel Okoji

33

Nicole Neil

34

Diversity, like security, should be built in from the ground up

80

Mary Attard

36

Jodie Vlassis

39

Bri Hadley

40

76

(CYBER) SECURITY CULTURE EATS (CYBER) SECURITY STRATEGY FOR BREAKFAST


MARCH • APRIL 2021

TECHNOLOGY PERSPECTIVES 2021 and Beyond the future of cybersecurity is promising 86 Security as basic hygience Running a digital cyber security treasure hunt

INDUSTRY PERSPECTIVES

88

90

Behind the scenes of an ICT woman during and post COVID 72

Social Media Security

94

Driving a slow car fast and a driving a fast car slow

Cybersecurity in companies and the protection of fundamental rights

80

The heroes of AusCERT2020 the women in security who made it happen 82

Infosec and RM working together for safer sharing

ADVERTISING Charlie-Mae Baker JOURNALISTS

92

Diversity, like security, should be built in from the ground up

Abigail Swabey

Abigail Swabey

Mitigating against online Social Engineering

74

FOUNDER & EDITOR

David Braue Stuart Corner SUB-EDITOR Stuart Corner

96

DESIGNER Jihee Park

99

Helping businesses safely embrace digital

102

The Privacy Paradox

104

Women in Security magazine is published by Source2Create ABN 25 638 094 863

www.womeninsecuritymagazine.com contact@source2create.com.au

110

WOMEN IN SECURITY MAGAZINE CONTRIBUTORS

Source2Create Pty Ltd is the publisher of this magazine and its website (www.womeninsecuritymagazine.com). AWSN is the official partner of Women in Security Magazine

TURN IT UP

114

OFF THE SHELF

118

106

THE BEST COMPANIES FOR WOMEN TO WORK IN SECURITY

©Copyright 2021 Source2Create. All rights reserved. Reproduction in whole or part in any form or medium without express written permission of Source2Create is prohibited.


SUBSCRIBE TO OUR MAGAZINE Never miss an edition, subscribe for the magazine today for exclusive updates on upcoming events and future issues, along with bonus content.

SUBSCRIBE NOW


F E AT U R E

AUSTRALIA’S FEMALE SECURITY PIONEERS by David Braue

For Australia’s female security pioneers, cyber is all in a day’s work

WOMEN IN SECURITY MAGAZINE

7


FOR AUSTRALIA’S FEMALE SECURITY PIONEERS, CYBER IS ALL IN A DAY’S WORK

enhance the

Different career paths, different responsibilities – and

“While amazing

a shared love of cyber’s challenges

women have always been working in cybersecurity,”

Culture change, that time-worn bon mot goes, starts

Bilal says, “it’s only recently that many of them are

nation’s threat sharing.

at the top – and Australia’s cybersecurity industry is

being publicly recognised.”

no exception.

Bilal, who actively participates in the Defence

As recent years saw the world waking to the

internship program and enjoys mentoring interns

increasing prevalence of cybersecurity threats and their real-world impact, the industry has been led by – and inspired by – a slew of talented women whose mighty efforts might have gone unnoticed but for

every year, noted the preponderance of “really supportive and high profile female leadership figures” at organisations such as the Australian Signals Directorate (ASD), Australian Cyber Security Centre

concerted efforts to bring them into the spotlight.

(ACSC) and industry-development body AustCyber.

Through awards programs, media coverage and

Ongoing support from both men and women

networking through bodies like the Australian Women in Security Network (AWSN), cybersecurity practitioners have rapidly come to learn about the significant work of women like Rania Bilal, a former

across the sector has helped Bilal advance her “exciting and rewarding” career, which has seen her working in research and development, C# software development, firmware coding, and now as a cyber

officer in CERT now working in the Australian Cyber

threat intelligence technologist.

Security Centre (ACSC) cybersecurity team to

She hopes ongoing recognition of female industry pioneers will inspire even more women to join

8

WOMEN IN SECURITY MAGAZINE


F E AT U R E

the industry: “It’s great to see women increasingly recognised through awards and greater leadership,” she says.

challenge and engage her. “My formal qualifications have nothing to do with computing,” she says, “but I worked in a cybercrime

“I hope this becomes normal practice so that

intelligence role. I’ve written a few books now, and

more women are inspired to join the cybersecurity

when I speak at conferences I’m trying to make

profession and discover everything this exciting

people understand that cybercrime is not something

career path has to offer.”

weird and elusive; it’s just like any other crime type, and anyone can be a victim.”

MANY ROADS TO CYBER Indeed, for many women in cybersecurity that career path has taken all manner of twists and turns – and continues to do so as they progress through the broad and deep range of options that it offers.

Her goal in working in cybersecurity likely resonates with many other women who have found the industry’s allure irresistible: “I want to help harden our community, harden our nation, and harden the world against becoming victims of cyber crime,” she

Mandy Turner, for one, wasn’t expecting to end up

explains.

in cybersecurity: her first degree was a Bachelor of

“That is something I really do care about – because

Music, for example, and she recently completed a Bachelor of Dementia Care before entering a 20-year career with a government agency before moving laterally into cybersecurity. Now, Turner works as manager of the University of Queensland Cyber Security Operations Centre (CSOC) – the latest step in a career arc that continues to

it’s never going away.” As well as advocating for better cybersecurity understanding, Turner has watched in dismay as popular media representations of shadowy hackers pollute the discussion – making everyday users believe “there’s this shadowy supervillain behind all of

WOMEN IN SECURITY MAGAZINE

9


this, so there’s no hope for them and they no longer help themselves.” “We need to stop that narrative of the supervillain,” she says, “because it isn’t a super villain. It’s just a criminal.”

STEPPING UP DURING A PANDEMIC Many of cybersecurity’s most high-profile women share a passion for cybersecurity that keeps them actively engaged on myriad fronts at the same time. For cybersecurity consultant Jo Stewart-Rattray, her deep fascination with the industry, and engagement with the sector, have kept her engaging with a broad range of roles – whether as director of information security and IT assurance with BRM Advisory,

the deployment of two national call centres staffed by home workers, as well as managing a widely distributed security team that was facing similar challenges from home working. It wasn’t her first secondment – and it was, she recalls, an eye-opener to the many ways that cybersecurity impacts everyday business and the operations of essential services. “I found that when I did that, it really made me recognise the needs of my clients and what they face,” she explains, “and what CIOs face on an everyday basis. It

“I hope more women are inspired to join the cyber security profession and everything this exciting career path has to offer”

puts you back in touch with the real world of security – and it’s good for the soul to not just be dropping the report and leaving.” Managing security during a pandemic meant addressing both technological and business issues, she pointed out, as well as the additional people-

vice president of communities with the Australian

management skills involved in keeping people

Computer Society, recent president of the Association

communicating across the distance.

for Intelligent Information Management (AIIM), member of ISACA’s information-security advisory board, and even part of the Australian government’s official delegation to the United Nations’ 62nd Session of the Commission of the Status of Women. Never one to gather moss, when the COVID-19 pandemic hit last year Stewart-Rattray began thinking about how she could help – and ended up seconded to health and in-home care organisation Silver Chain Group as chief security officer. Given the challenges that had descended on the entire health and aged-care industry almost overnight, she says, it became clear “the bad guys aren’t going to wait so we can’t wait.” Working with Silver Chain four days a week, StewartRattray found herself at the front line, helping secure

10

WOMEN IN SECURITY MAGAZINE

“It’s about the people aspect, and looking at how I can keep the team feeling connected,” Stewart-Rattray explains. “The face of work has changed, I think permanently, and we’ve seen that many organisations that I work with will continue to encourage people to work from home.” “And while I hear some people having a bit of a whine about how you can’t collaborate, I think you can. It just requires a different mindset.”


CONNECTING - SUPPORTING - INSPIRING

AWSN Membership Benefits: Mentoring Community Support

Education Careers Events

Visit awsn.org.au for information about exclusive events, programs, and content. Join Australia's largest community of women in cyber and physical security.


AMANDA-JANE TURNER Author of the Demystifying Cybercrime series and Women in Tech books Conference Speaker and Cybercrime specialist

C O L U M N

Cybercrime is big business Cybercrime is big business, thanks to technical advancement and interconnectivity creating more opportunity for cybercrime. This regular column will explore various aspects of cybercrime in an easy to understand manner to help everyone become more cyber safe. TECH SUPPORT SCAMS Tech Support scammers are very active, and highly organised. They operate from rented office spaces, just like a traditional call centre. They lure their victims in several ways: website popups, cold calling, fake virus alert popups, or with websites that spoof well-known tech or telecommunications vendors. The cold call version starts with the scammer telling a target there is an issue with the target’s Windows computer that must be fixed immediately. If this ploy is successful, the victim is directed to install legitimate remote viewing software that gives the scammer full access to the victim’s computer. The scammer might then open the computer’s event log or use commands in the Windows Command Prompt screen to present information to the victim as evidence of malware on the computer. If the victim is now convinced the computer has a serious problem the scammer persuades the victim to pay to have the computer ‘repaired’. While in the system, the scammer may also configure back doors so they can surreptitiously return to the computer later and steal account credentials. Sometimes the scammer will also install malware into the victim’s computer disguised as essential repair software. It doesn’t end there. The scammer may make a follow up call offering the victim a refund for the ‘services’ provided earlier.. Their aim is to gain financial account details and steal more money from the target.

14

WOMEN IN SECURITY MAGAZINE

What to do if you are the victim of a tech support scam If you paid a tech support scammer with your credit or debit card, contact your bank immediately as you may be able to stop the transaction. If the payment was made using a gift card or voucher, immediately contact the organisation that issued the card and explain the situation. If the scammer gained access to your computer, scan it with up-to-date and reputable anti-virus software and change passwords to any accounts you accessed from that computer. In Australia report the crime via https://www.cyber. gov.au/acsc/report,. In another country, report it to your local police or through the relevant cybercrime reporting mechanism. Tech support scams are big business – stay safe.


20th Annual AusCERT Cyber Security Conference

11th - 14th May 2021 // The Star Hotel, Gold Coast, Australia

4

DAYS

50+ SPEAKERS

IN PERSON & VIRTUAL

Keynote Speakers

Ciaran Martin

Maddie Stone

UNIVERSITY OF OXFORD

GOOGLE PROJECT ZERO

REGISTER NOW

conference.auscert.org.au WOMEN IN SECURITY MAGAZINE

15


2021 AND BEYOND What to expect from the Australian Women in Security Network (AWSN) AWSN was founded in 2014 as an open network of people aiming to grow the number of women in the

2022 AND BEYOND: INCREASING FUTURE PIPELINE OF WOMEN IN SECURITY

security community in Australia.

• Future plans of the network are to establish new programs focusing on high school students and a

Since it’s formulation, the network has come a

return-to-work offering for women in security who wish

long way and has continued to inspire, support and

to re-enter the workforce after a career break or hiatus.

connect women in the industry to those looking to enter the field with the tools, knowledge, network and platforms needed to build each members’ confidence and interest. As we look towards embracing a new phase of the network, here are are some key focus areas on the AWSN agenda in 2021 and beyond:

UPLIFTING CURRENT PROGRAMS • The network is committed to the quality delivery of its core capabilities which span across networking events,

HOW TO CONNECT, SUPPORT AND INSPIRE WOMEN IN SECURITY As the network continues to mature, AWSN is absolutely in need of supportive colleagues, champions, women and men, to be part of our cause and vision. Let’s support women in every step of their career journey, inspire them to pursue a career in security and help build the Australian pipeline of talented security professionals.

its AWSN Cadets Program and the annual AWSN Awards programs. • The network aims to optimise and uplift the National

YOU CAN DO THIS BY:

AWSN Cadet Program, increasing the number of

Becoming an AWSN member or

participants, workshops and study groups.

encouraging someone to be a member

Signing up to be a mentor

2021 FOCUS: SUPPORTING WOMEN IN SECURITY

The network recognises that we must focus on

initiatives to help retain and support the current

women working in this industry. • The network is committed to the goal of retention and

union of women working across the sector. • The network is implementing various programs to

Nominating someone for an award Speaking, or encouraging someone to speak at one of our events

Writing, or encouraging someone to write for the magazine

advancing women in security across • Australia by understanding the current state-of-the-

Hosting or attending one of our AWSN events

Post internship or jobs with us

Volunteering, Sponsoring, Supporting the organisation

support and help the cohort of women in security grow; these include: a Mentoring Pilot program (sponsored by ASD and powered by OK RDY), a

Come and join our AWSN community. To find out

series of Women in Leadership programs, a Women

more about the network’s initiatives, please visit:

in Security Study survey, a and a Small Business

awsn.org.au

Mentoring Pilot program. • The network sees itself as the conduit between other great initiatives and partners within industry aiming to achieve the same mission. For example partnering with companies such as Source2Create who have produced this incredible magazine.

20

WOMEN IN SECURITY MAGAZINE

The AWSN would like to thank their sponsors, volunteers, members and supporters who have helped shape the community into what it is today.


WHAT’S HER JOURNEY?


On a Symantec trip to Hawaii I met my future husband, who lived in Sydney. Three months later I quit my job and being just shy of 30 was still eligible for a backpacker visa so I came to Australia to have some time off and see what happened. Within two months I had landed a role as the Security and Privacy Initiatives Lead for Australia at Microsoft. Around 2010 my then boss at Microsoft became the first permanent CISO hired by nbn. When he was building out the team a role came up that looked like a great new challenge in an exciting young company doing something great for the country. So I made the move, along with a few of my Microsoft colleagues.

Kate Monckton

I started at nbn in July 2011 when the company was

General Manager Security and Privacy Assurance, Risk and Consulting at nbn

years, because of the speed at which the company

planning a full FTTP rollout. Over the next nearly 10 grew, I had a huge array of amazing professional experiences and challenges. I doubt there are many companies where I would have had similar opportunities.

M

I’ve always been in the security group at nbn in y journey into cybersecurity started very far away: with a degree in German and philosophy from the University of Leeds in the North of England.

My first job after graduating was in the European arm of an American boutique management consulting company that specialised in helping IT and CE vendors with their retail and SMB sales and marketing strategies. One of the company’s major clients was McAfee, and working with McAfee sparked my interest in cybersecurity. That was back in the mid 2000s when people were becoming more connected and threats were becoming more mainstream. After four years with that consultancy I fancied a stint client side and went to work in Symantec’s marketing team. Much of my work at Symantec was on the consumer side and that was when I became really interested in

security and cyber safety influence/culture programs. My current, recently created, role is a fantastic professional opportunity. It encompasses the privacy, information security consulting, risk and assurance. I am presently on parental leave but normally I share the role with Sarah Hosey with each of us working four days a week. I’m unaware of any other GM level job share arrangements in the industry. Sarah and I are really proud to role model how effective it can be and I hope that these kind of things become more the norm for everyone. Our portfolio comprises everything to do with managing the privacy program at nbn, from helping the operational front end of the business understand and manage its privacy risks to developing the long term strategy and policy for handling personal information. We also lead the teams that provide hands-on security consulting support to the business, and the teams that manage security risk and provide

cybersecurity, cyber safety and privacy. Looking back

internal and third party security assurance.

I bored a lot of people in my personal life with stories

My typical day has a lot of meetings (most of them

about protecting themselves online!

22

various leadership roles, generally in privacy and

WOMEN IN SECURITY MAGAZINE

remote at present). Most mornings we have a senior


W H AT ’ S

H E R

J O U R N E Y ?

need for a trusted and secure network that’s reliable and readily available to all Australians. We have an amazing culture within the Security Group that cuts across all levels of the organisation. Last year we came second and highly commended in the Australian Women in Security Network awards for the Best Place for Women to Work. I try to be offline by 5:30 so I can have some family time before my daughter goes to bed and only log on after 7pm if it’s absolutely needed. I spent the first 10 or so years of my career smashing out 80 hour weeks but since I got a handle on my work/life balance by prioritising much better I have had more success professionally and personally. leadership team (SLT) stand-up and once a week we have a longer SLT half day meeting with Darren Kane, nbn’s Chief Security Officer. On the days Sarah and I both work we have a 1:1 meeting first thing to make

When I was younger I felt I had to know everything to be credible professionally, especially in my first role with the consultancy. Over the years I’ve learned that is just not true. Pretending to know more

sure we’re clear on our plan of attack for the day and

than you do is incredibly detrimental.

the week ahead.

But you do need people around you whose knowledge

When you work in security what you think your week

and judgement you trust and can draw upon when

is going to look like is often not the way your week goes. So clear and open communication with Sarah, with the wider leadership team and with our direct

you need some help. I am lucky to have a great professional support network, many of whom are also good friends. I run things by them and sanity check

team is critical.

when I doubt myself.

The rest of the day is generally a mix of formal and

I also got really lucky with some amazing mentors

informal meetings that includes meetings with individual teams and leaders who report into our function, meetings with the cross-company Steering Commitees and project meetings. I am a natural early

who challenged me and helped build my confidence by throwing me in the deep end and letting me figure out that I can swim pretty well when given the chance. It’s also a great relief when you realise that it’s OK to

riser so I tend to spend an hour or two before my

make the wrong call sometimes.

toddler wakes up clearing email and reading through

If a decision you make is what you think is the best

reports etc. before having breakfast with her and doing the day care run. From 8:30 onwards it’s pretty much go go go in meetings.

at the time based on the information at hand, it’s not the end of the world when things change. How you respond to and acknowledge those changes is far

We all work incredibly hard but have a lot of fun every

more important.

day. We challenge each other constantly so there

I have had some great advice from past and current

is no scope to stagnate or stop learning. I also feel strongly about the mission of the company and the

colleagues and mentors. When this was critical

WOMEN IN SECURITY MAGAZINE

23


of how I had handled things it was really hard to

It is important to have diversity, with representation

swallow. But, without fail, with hindsight I have totally

of different genders, cultures, nationalities, abilities

agreed with the feedback.

and socio-economic backgrounds in all walks of life.

Darren Kane, my current boss, always talks about the key to success being to get the right people working with you. It can be easy to hire people because you have a need and they have the skills, but if their attitude and approach does not compliment the culture you want to promote they will cause you more

Without this we are limiting ourselves to an incredibly narrow way of thinking and acting. By harnessing the power of a wider variety of experiences we open the door to some really exciting opportunities to do things better, which in security and privacy can only be positive.

pain in the long run. I’ve definitely learned this the

I really love the human side of my role, helping grow

hard way over the past 15 years.

and develop the team. I’d say I have a reasonably

In the early days I often felt like my lack of technical or vocational training was a huge negative and felt out of my depth in many a product discussion. Over time I started to see how my background and strengths in communication and strategy were very complimentary to those of the technical people I worked alongside.

high level of emotional intelligence that helps me build genuine trust with the people I work with. I gave up trying to have a work ‘persona’ many years ago when it became too tiring trying to be who I thought I should be professionally versus allowing my ‘at home’ self to come with me to work. I don’t shy away from hard conversations with people, because I think if you’re honest and straightforward people will

“When I was younger I felt I had to know everything to be credible professionally, especially in the consulting role. Over the years I’ve learned that is just not true. Pretending to know more than you do is incredibly detrimental.”

respect you and want to keep working with you. I really encourage people into careers in security and privacy. The need is growing and there are some amazing roles out there, and you never stop learning or being challenged. Get involved in as many

I have really seen a shift over the past ten years

professional groups as you can, such as the

towards the industry being much more welcoming of

Australian Women in Security Network (AWSN), the

people who don’t have tech backgrounds, which has

Security Influence and Trust Group, the Australian

been a huge benefit by promoting diversity of thought

Information Security Association (AISA), etc. Join the

and approach. Early on I definitely felt judged for not

virtual meet-ups, or even better, offer to help with the

having a computer science degree and not being able

organisation behind the scenes. This is where you will

to make jokes about TCP/IP.

meet people in the industry and figure out what you

I’ve often been the only woman and the only nontechnical person in leadership teams within security

If anyone reading this wants to chat to me about how

groups (although thankfully that has changed a great

to move into the industry I’m always very happy to

deal over the past five or so years). At times it’s made

do so (via LinkedIn message is probably best), but

things harder, but more often than not there have

maybe give me a couple of months to get this new

been benefits to being able to provide a different take

baby into some kind of routine!

on things.

24

enjoy.

WOMEN IN SECURITY MAGAZINE


Mentoring Pilot AWSN is pleased to launch the 2021 Australian Women in Security Network Mentoring Pilot.

Looking for ways to give back? We need you Learn more at awsn.org.au/initiatives/mentoring/ Sponsored by

Powered by


IT’S NEVER TOO LATE TO CHANGE YOUR STARS

I

started my security journey long before I knew the security industry to be an option. My daughter was three years old and I was working a job I absolutely loved in the snowboard industry, but the pay was low and jobs were

seasonal. Life was stressful because money was tight and I wanted more options: more freedom for my family, more opportunities for my daughter. I knew there was so much more I could do with my life. I grew up with computers, playing video games and learning programming in school, so I knew tech was an option. I even started down that path straight out of high school, before being quickly derailed by the lure of the snowboard industry. Don’t get me wrong, getting into that industry was

Toni James Product Owner | Security Advisor | ChCon.nz Organiser | Diversity Advocate | Speaker SafeStack Limited

26

WOMEN IN SECURITY MAGAZINE

the right decision at the time. It brought me around the world to New Zealand from my home in the USA, and led me to meet my husband (in the lift line while snowboarding). I regret nothing about choosing that path in life.


W H AT ’ S

H E R

J O U R N E Y ?

What I do regret is getting stuck, doubting I could

I didn’t win the first scholarship I applied for, but I was

take a new path or pursue a different career when I

a finalist, which got me a trip to Sydney and training

had no guarantee of success. It was the absolute fear

in diversity and inclusion initiatives. This opened

of failure that held me back. It was far easier to just

up further pathways into research and leadership

apply for another job, settle for the best pay you could

opportunities. I applied for a software engineering

get, and make ends meet. Believe me, it took me nearly five years and a bout of depression to realise this and work up the courage to change my stars. When I finally worked up the courage to change my stars and do something different, I didn’t know what I wanted to be. I really

“What I do regret is getting stuck, doubting I could take a new path or pursue a different career when I had no guarantee of success. It was the absolute fear of failure that held me back”

envy people who can answer the question “What do you want to be when you grow up?” They seem so driven and confident, so clear on what they want in life, and so focused on achieving it. I’m not one of those people. I want to be happy. I want to be financially stable and have time to enjoy life with my friends and family. I want to contribute to society in a positive way. I want to help others through the tough times in life. I want to share my story, to help others find their place in the world, and support them along the way. One thing I did know was that a job in the tech industry could give me opportunities to be all those things. So I chose to study for a degree in computer science. It’s an extremely versatile degree, the study

internship at a local software company, and got one for two years. Many things I applied for I did not get, but the key here is: I applied, and when the opportunity was right, I said yes. The opportunities I’ve followed have taken me to Australia, India, Singapore, Argentina, and the United States, and I’ve learned so much along the way. Eventually, those opportunities led me to the security industry. When I was working as a software engineer in a healthcare software company, I found security to be a high priority. This sparked my interest, and the more I learned about security, the more I wanted to know.

regime was flexible enough to accommodate my

I applied for diversity funds so I could go to security

childcare options, and I was able to choose classes

conferences. I spoke at security conferences and

that interested me.

meetups, and I studied security “for fun”. And when

One notable benefit it gave me was being able to take opportunities as they presented themselves. I’m still limited by where I live, and by my education and training, but when someone says “Hey you’d be great at X! Have you ever thought of working in Y?”, it opens options I never knew existed. During my first month at university Google visited my campus on a recruiting mission and hosted a Women

someone said “Hey, you’d be great at this! Ever thought about working in security?” I took that opportunity, and I changed my stars again. I still don’t know what I want to be when I grow up, but right now, I love where I am. www.linkedin.com/company/safestack/ academy.safestack.io/about-safestack/

in Tech event. I met several Googlers who were interested in my story and encouraged me to apply for

twitter.com/safestack

scholarships, internships and programs.

WOMEN IN SECURITY MAGAZINE

27


M

y journey into cyber security started in the early 1990’s with a recalcitrant computer. I was in the Royal Air Force and helped my commanding officer prepare PowerPoint

presentations for his meetings. The computer I used kept breaking down, so I took it upon myself to learn how computers worked and fix it. Then a friend who worked in a new area in the RAF called ‘computer security’ told me she was leaving and suggested I apply for her position. I did. I got it, and I’ve never looked back. At that time information and systems security was a very new area. Few of us understood what was needed. But we worked together as a team (all male, except for me) and we evolved with the industry.

Joss Howard

Our managers encouraged us to research, to learn,

Cyber Security Senior Advisor, NCC Group APAC

Support and guidance from them were available

and to try and resolve issues as best we could. in abundance. A mistake wasn’t a mistake, but an opportunity to learn and try again. Today there seems to be too much pressure to get things right first time, and too much emphasis on blame, which is such a shame. In those early days computer security conferences were male dominated. I found them tiresome: it was hard to find anyone who looked or thought like I did. There were men who would champion the cause of equality, but they were few and far between. Things are much better today. There are opportunities to discuss security and share opinions with a wider audience, and long may that continue. The inclusion of different cultures and backgrounds in cybersecurity is important. Diversity breeds

“The inclusion of different cultures and backgrounds in cybersecurity is important. Diversity breeds collaboration and innovation. Hackers don’t discriminate, so why should we? ”

28

WOMEN IN SECURITY MAGAZINE


W H AT ’ S

H E R

collaboration and innovation. Hackers don’t

J O U R N E Y ?

•

discriminate, so why should we? In security, to be effective we need to stop discrimination and take on the challenge of diversity.

Assisting sales in qualifying, proposing and designing solutions to bids and other responses.

No two days are the same. Regulatory changes, new cyber security standards, changes in technology, new

I have led and managed teams from diverse

cyber-attacks, sales and research, keep me very busy

backgrounds and each member brings a different

and out of trouble!

perspective based on their experience. These different experiences lead to pragmatic, flexible solutions that fit with an organisation, making that organisation an easier and, frankly, a more pleasant place to work. I’ve learnt much from team members that has helped me serve the team better. It’s been enjoyable to hear (and sometimes experience) other cultures. Today I consult to boards, senior management and department heads on how to reduce cyber risk and increase cyber resilience in their organisations. My consultancy can take the form of strategising, operational transformation, assessing an organisation’s current security posture, or providing security awareness. My role is diverse and continually changing. One day I might get to speak to the most senior people in the business and help solve their cyber security challenges. Next day I could be helping my client improve their cyber resilience.

I’ve been in information security – in one way or another – for 30 years. I have had great privilege of working in more than 10 countries in the EU, North America and APAC. I have had the honour of helping more than 60 clients ‘change the security dial’ for the better. I never expected this when I started out! I am an avid reader and apply what I learn. In the early days, I built my own computers and networks at home and tried to hack them. I would then build on that experience. I also set personal goals to see what I can achieve in a given time. Then I reflect on what I had achieved. I am also willing to take a risk and follow an opportunity. I have found there is usually a small drop when you take that initial step, but it’s followed by a rise. I have taken many courses over my career, generally around leadership and management, operating systems and networking, information and cyber risk management, and privacy. These have also included:

As an executive principal consultant my role covers

Certified Information Systems Security Professional

marketing, sales and delivery. My day could include:

(CISSP); Information Security System Management

•

Leading the client in defining their cyber security strategy;

•

Providing thought leadership through conducting webinars, delivery of blogs, articles and interviews with journalists;

•

Conducting control assessments of a client’s security posture and creating security roadmaps;

•

Recommending boards and C-level clients on options to reduce cyber risks in their organisation;

•

Conducting an incident response scenario exercise to improve a client’s cyber resiliency;

•

Writing and delivering policy;

•

Acting as the point of contact between sales, the

Professional (ISSMP); Certified Information Systems Auditor (CISA); Certificate in Information Security Management Principles (CISMP); Certified Data Privacy Solutions Engineer (CDPSE). So, if you are considering a career in cybersecurity my advice would be: go for it! Take risks and grab opportunities as they come along. Accept that there will be challenges along the way, but know you can overcome them. Be open to learning and put in the hard work needed to be successful. Get yourself a mentor or coach to help you along the journey, for either professional or personal development. They act as a great ‘sounding board’ and provide independent insight and guidance to help you along the way. www.linkedin.com/in/joss-h-5571981/

client and our business;

WOMEN IN SECURITY MAGAZINE

29


identify business risks that are unknown to the organisation.

Skye Wu

I see the most important part of my job being to

Cyber Security Investigator, Speaker, Mentor & Champion for Diversity

away from the team so its members can focus on

take mundane work, such as administrative tasks, the important tasks, like working with data to distil interesting findings that can be turned into actionable

I

fell into a career in security after I became interested in digital forensics at university for my bachelor’s in information systems degree. I enjoyed problem solving and working out how/why something happened. I realised that by doing digital

No two days are the same. Generally I like to start my day doing a bit of reflection and thinking, be it looking over the project we are working on, or the team’s annual plan and the goals we are hoping to achieve in the current financial year.

forensics for law enforcement I would also be able to

Most of my time is taken up with data analysis work,

do some good for society. So it became a no-brainer

asking questions of the data to distil interesting

for me to start my career there.

insights, and playing with visualisations so the insights

I was recruited into the computer crime squad with no practical experience, only knowledge gained from books (before YouTube!). The senior sergeant who hired me told me on my first day I would have a steep technical learning curve, but he hired me because I was

can be presented to and consumed by a range of audiences (technical and business). I also look for potential opportunities for continuous improvement, and document our findings and learnings in our growing knowledge base.

able to show I had the aptitude and thinking of a digital

I also work in the Australian Women in Security

forensic analyst.

Network (AWSN) where I lead the AWSN cadet

I spent years working in law enforcement, followed by several stints in consulting. I was fortunate to have worked with some of the best minds in the industry very early on, and I learnt much from my colleagues in law enforcement, and later those in consulting.

program. I became involved with AWSN after meeting founder Jacqui Loustau several times at networking events. I initially became an industry advisor to AWSN’s Melbourne chapter and ran a workshop for the Melbourne cadet members. I really believe in what the cadet program hopes to achieve. So when

However, my job was always to investigate something

the opportunity came to expand my role and lead the

after the fact; get involved after a litigation had already

program nationally, I jumped at it.

begun, and I became weary of being always on the responding side of the equation. I began to wonder if it were possible to move into an area where the work would be more preventative than reactive. I joined Telstra in 2014 as an open source security analyst and a few years later my boss, Chris, dropped me into the discovery team to help on a temporary secondment. I became really interested in the proactive nature of the role, so I decided I wanted to stay. Luckily the feeling was mutual! Since September 2019 I have been acting Discovery manager at Telstra. The Telstra discovery team uses data the company is already collecting to proactively

30

intelligence internally.

WOMEN IN SECURITY MAGAZINE

I work with AWSN leads, including other cadet leads, and with AWSN committee members to provide a safe environment in which our cadet members can learn, collaborate and interact with their peers and industry professionals. I dedicate a few hours each week to cadet work. This includes looking after the Slack channel where our members collaborate. Since COVID the security workshops for our cadet members have run virtually nationwide, and I also work with committee members to ensure our planned workshops go ahead. What I love most about both my roles is the opportunity to be proactive. In my day job, I can help the


W H AT ’ S

H E R

J O U R N E Y ?

business get on top of potential problems. As AWSN

Working in digital forensics, I was not taken seriously

cadet lead I help new talent prepare for careers in

and accepted as an equal by my male counterparts

cybersecurity. It’s an opportunity for me to reciprocate

who performed the same role. And I was sought after

the support I had on my journey.

for roles and opportunities because to my gender

The industry is an ecosystem; it’s important to help

rather than for my experience or qualifications.

develop others at the same time as you develop

I was then made to feel unworthy and undeserving

yourself. I have learnt a lot about myself through

of recognition for my skills and expertise, with

mentoring and supporting others.

discouraging comments from male colleagues in

In the early days of my career my self-doubt and lack of mentorship from leaders who were able to recognise

senior positions, such as “You only got recognised as a diversity stunt.”

my personality traits and how I worked limited my

Being female and also a first-generation migrant from

personal development.

China led to advice such as “you should not apply

My main personal challenge stems from traits I was, unfortunately, born with: self-doubt, self-defeat and

for federal government roles as you are Chinese and people won’t trust you.”

self-sabotage. For a very long time I would turn down

I’ve also been accused of not behaving as a member

opportunities unless I knew I could do 100 percent of

of the team, because I outed a “team-bonding”

the job. I would sometimes put myself down believing

competition that involved weight-lifting and other

it to be a sign of modesty. I experienced my most

weight-related gym exercises in which the whole team

personal development and growth only when I took a

could not participate equally.

leap into the unknown.

I believe companies need to not only close the gender

Understanding what motivates you and why you do

gap, but also consider broader diversity, including

it will guide you on your career journey. And don’t be

diversity of skill, thinking, experiences, etc. Teams and

afraid to fail: sometimes our biggest setbacks are

organisations that do not take an interest in broad

opportunities to propel ourselves further.

diversity run the risk of applying tunnel vision to the

Over time I got comfortable with the idea of putting myself into situations that terrified me, like public speaking. I also started to get comfortable with making

work they do, the products and services they provide, and of missing opportunities to recruit and maintain talent that could help drive their organisation forward.

mistakes and failing. A very wise industry influencer

So, build yourself a solid support network, attend / seek

once told me “if you are feeling challenged, it means

out industry events, join industry groups such as AWSN,

you are growing!” Having that kind of support and

and the AWSN Cadets. There are many experienced

advice really helped me on my journey.

men and women in the industry who are supportive of

It took a great manager who recognised my abilities and prodded me in the right way to get me to move out

new talent entering the industry. Networking will help you connect.

of my comfort zone. That came after several years in

Be open to new opportunities, even if people and

different workplaces with different managers.

your own inner voice are telling you ‘no’. Be open

I also faced many challenges simply by being female. At university I was discouraged from pursuing a career in digital forensics because the industry is very maledominated. From the moment I decided I wanted to work for law enforcement doing digital forensics without any handson experience, I knew I had to grow a thick skin. I had to swim or drown, and drowning wasn’t an option.

to failure, own your mistakes; people aren’t likely to remember how you failed, but they will remember how you picked yourself up. Know who you are, know your values as an individual. Write them down on Post-it notes and put them somewhere you can see them whenever you need to. www.linkedin.com/in/skye-wu-ba390919/ www.skyewu.com

WOMEN IN SECURITY MAGAZINE

31


WHERE ARE MY LADIES AT? Bri Hadley Creative, connector, and knowledge vacuum

BREAKING ASSUMPTIONS, CHANGING OUR PERSPECTIVES, AND OWNING OUR PLACE For most of their existence public policing and private security have been a ’boys club‘. Social expectations, ideas of ’propriety‘, and fear all played a role in the assumption that women and security do not mix. Under these assumptions, men designed the security industry, from its aims to its ideal candidates. Arguably, these were smart, rational men. In most circumstances, though, they would not (or could not) challenge their underlying assumptions—including their assumptions about the role of women. Our post-modern culture, even with its focus on diversity and inclusion, still suffers from this assumption blindness. If we want to move forward as an industry, we need to find and challenge these assumptions, keeping what is useful and replacing what is not. I like to use my career as an example of the impact of assumptions. I have always been an investigator— always curious, always wanting to know why, and always making connections. I come from a long line of security workers and first responders—police, military, private security, firefighters, nurses. I initially resisted a career in both traditional public policing and in the private sector. Growing up, I could not see myself thriving in the regimented culture of public police services. Also, I did not want to spend my time serving legal paperwork and chasing down cheating spouses. I assumed that, if I wanted to be in security, I had to choose one or the other.

40

WOMEN IN SECURITY MAGAZINE

After many twists, turns and false starts, I landed in investigations in my late 20s—all thanks to a few months of rather dramatic mistakes. Fortunately, I had a brilliant manager with a plan. While both embarrassing and frustrating, this plan gave me the time and connections I needed to redefine what a career in security (in this case, investigations) could look like. I met women who would become mentors who showed me where my career could go. Just over a year after being hired into the unit I went from being bored and disengaged to finding fulfillment in my work, every day. Over the years my role has included investigations, data analysis, business intelligence, and consulting functions. I love it! I think most people still assume that security workers have uniforms and badges, carry guns, put themselves in harm’s way to protect (or control) people. This, at best, is an incomplete picture. In the years since I joined the security industry, I have developed a very different picture of what policing and security look like. I have learned that physical security and information analysis are interdependent parts of the same whole. We ask questions, assess risks, and identify threats. Some of us collect, compile and analyse large amounts of information from an increasingly complex array of sources. Some of us find connections across seemingly unrelated groups of information and create risk-mitigation plans. Some provide advice and write policy. Others protect physical assets. If we want to do our jobs well (and I believe we do), then we need to paint this picture of the security industry, in all its diverse roles and functions. We need to be willing to challenge even our most basic assumptions. We need to take on new perspectives, and find ways to incorporate those perspectives into our daily work and our organisational structures. This is how we own our place in security. Then perceptions and assumptions can shift, opening a window into the world of security. When more women see what a career in security has to offer, they will come.


CONTACT NOW

DO YOU WANT TO PROMOTE YOUR BUSINESS TO A NEW TARGETED AUDIENCE? Contact us today to find out how you can be a part of the Women in Security Magazine!


MARIE-EVE LAPLANTE

WHAT YOU NEED TO KNOW ABOUT CYBERSECURITY CAREERS by Marie-Eve Laplante, Cybersecurity Strategic Advisor

Starting a new career in cybersecurity can be a little

solutions, antivirus, vulnerability management

intimidating. Media coverage of data breaches and

and more. Incident response teams are needed

cybersecurity incidents is becoming more common.

to manage crises, coordinating all stakeholders

Movies and TV series tend to focus more on hackers

and working under pressure. Audit teams are also

than on all the other professionals essential for the

essential to give an organisation and its shareholders

protection of information in an organisation. So, if

reasonable assurance that the security measures

you are not a hacker spending your evenings and

deployed are adequate. Your skills may fit many of

weekends on the dark web and developing scripts,

these profiles and could lead to an interesting and

should you consider a career in cybersecurity? The

fulfilling career in cybersecurity.

answer is a resounding YES!

NOT EVERYBODY IN CYBERSECURITY STARTS WITH A HACKER PROFILE

Cybersecurity is constantly and rapidly evolving. A

Ethical hackers and people with the skills to penetrate

couple of years ago few organisations were talking

systems are important for cybersecurity defence,

about cloud security, about user behaviour analysis,

but there are many jobs in cybersecurity that do not

or discussing how artificial intelligence would impact

require these skills. For instance, an organisation

defence and offence capabilities. New threats, trends

needs people specialised in governance, risk and

and technologies are emerging all the time. This

compliance to help manage priorities, investments

means, as a cybersecurity professional, you must

and regulatory requirements.

stay informed and adapt and evolve to meet the new

Operational security teams are needed to implement access controls, network security, data protection

46

YOU WILL NOT BE DOING THE SAME THING ALL YOUR LIFE

WOMEN IN SECURITY MAGAZINE

risks and priorities facing your organisation. No time to get bored!


C A R E E R

P E R S P E C T I V E S

WOMEN IN CYBERSECURITY

line with their perceived risks. Hence, it is important to

Cybersecurity professionals are typically cast as

develop a risk mindset early in your career.

nerdy, hoodie-wearing males, but a wide spectrum of

Cybersecurity professionals can be frustrated by their

skills is needed, and people of any gender can find

difficulty securing budget to fix what they see as an

a place. Furthermore, cybersecurity is constantly

important security issue. This frustration may arise

being reinvented in response to new threats, trends

because they have been unable to communicate the

and technologies. The idea that only men can be

level of risk to higher management, or because they

interested or thrive in cybersecurity is completely

have inflated the level of risk.

outdated.

FIND A NICHE OR BECOME A GENERALIST There are many domains in cybersecurity. So take the time to familiarise yourself with the most used frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, or the Center for Internet Security (CIS)

Ask yourself not only if the vulnerability or weakness you identified could lead to a security incident, but also how it could hurt your organisation. A critical vulnerability that could give any malicious actor access to a system will represent a high risk only if the system itself contains sensitive information, is critical for the company’s operations, or can be used to gain access to another more important system. Being mindful of the actual risks faced by your organisation will help boost your

“If you are not a hacker spending your evenings and weekends on the dark web and developing scripts, should you consider a career in cybersecurity?”

credibility. In conclusion, there is no single profile of a cybersecurity professional. More than ever, organisations need your skills to help them enhance their security posture. They need analytical minds. They need coordinators.

Controls Framework. From there you can decide to become a generalist, by getting basic knowledge and skills in all domains and controls, or you can develop your expertise in a specific niche. Generalists are needed for roles such as audit, governance, risk,

They need technology-oriented people. They need managers. They need auditors. They need businessfocused people. They need hackers. They need security developers. They need testers. They need you.

compliance and information security management that call for a good understanding of roles played by

www.linkedin.com/in/marieevelaplante/

niche experts who focus on a particular aspect of cybersecurity. Their specific skills will be sought after to maintain and improve an organisation’s defences against current and new threats.

DEVELOP A RISK MINDSET In an ideal world, organisations would be able to finance any initiative to enhance their security posture. In reality cybersecurity budgets are limited, and organisations must therefore prioritise their investments in resources (people, money and time) in

Marie-Eve Laplante is a strategic advisor in cybersecurity for Desjardins. With 20 years of experience in information technology, including 15 specifically in information security, she now specialises in governance, risk, strategy and compliance. Her expertise includes cybersecurity management and risk management, strategic security planning, cybersecurity governance, risk and performance measurement, maturity assessment, business continuity, privacy, IT risks and operational risks. She has also undertaken several engagements in finance, energy, media, aviation and retail, among others. She has also frequently given training sessions, conferences and presentations to management and has been a lecturer at the Polytechnique de Montréal.

WOMEN IN SECURITY MAGAZINE

47


GIULIA TRAVERSO

THREE CAREER TIPS TO THRIVE AS A WOMAN IN CYBERSECURITY by Giulia Traverso, PhD- Senior Consultant Cybersecurity, EY

talk about my journey to becoming a cybersecurity

TIP #1: PAY ATTENTION TO THE COMMUNICATION CULTURE OF THE COUNTRY YOU’RE IN

expert, and my experience in the role. The panel was

I am Italian and I did my PhD in cryptography in

Back in November I was invited to join an online panel organised by the European Space Agency (ESA) to

organised primarily for students of the prestigious École polytechnique fédérale de Lausanne (EPFL), in Lausanne (Switzerland) to promote working at ESA. In particular, the goal was to show students the many different types of expertise, including cybersecurity, needed in the space industry.

Western European countries there were many adjustments I had to make to integrate into the German community. The most evident difference between Italy and Germany is the way people communicate. Italians tend to use long sentences

During the Q&A session I was asked (probably by

and to provide a lot of background before saying the

a girl) whether I had encountered resistance in my

thing they really want to say. This, I suppose, is to

career because I was a woman, and if I had some

better justify their request or opinion. This type of

tips to offer. I greatly appreciated this question and

communication, which I later discovered is known as

my answer received some positive feedback. So, I

‘high-context culture’, is very different to Germany’s

would like to share with you three career tips to help

‘low-context’ culture. In Germany, you just go straight

women thrive in male-dominated environments such

to the point and say what you want to say, period.

as cybersecurity.

48

Germany. Even though Italy and Germany are both

WOMEN IN SECURITY MAGAZINE


C A R E E R

P E R S P E C T I V E S

rude and aggressive. Because I was working in a male-

TIP #3: KEEP IN MIND THAT NETWORKING IS STILL WORKING, ESPECIALLY DURING LOCKDOWN

dominated field, it was easy for me to blame the males

There is a very interesting book

In a discussion, Germans value clarity and brevity. As a result, unprepared Italians like me see them as being

for my not being at ease during discussions. After a more careful analysis, I realised that, although males tend to be more aggressive than women, my perception of them as being aggressive was the result of me being ignorant of the local culture.. This realisation was liberating. Also, I knew I could train myself to communicate in a more low-context manner, which is also the way scientists are supposed to communicate. As a result it became easier for me to join discussions at work and my discomfort disappeared.

called “Nice Girls Don’t Get the Corner Office” by Lois P. Frankel, PhD that I highly recommend. One of its suggestions that caught my attention was to consciously and actively dedicate at least five percent of your working time to networking. According to Frankel, many women tend to undervalue those breaks and chit-chat moments in front of the coffee machine, seeing them as time wasted. In the short-term that is certainly

“Communication is key, so use it wisely. You cannot thrive unless you own your value and make it visible to other people”

true, especially under tight deadlines, but in the long-term such behaviour is likely to harm their careers. In turns out that the people who get promoted the most are those who are more visible and to whom other people can relate. If

TIP #2: ASK QUESTIONS WITHOUT UNDERMINING YOURSELF

you never join social breaks, you never give yourself a

I have noticed over and over again that, during the Q&A

The move to working remotely established during the

sessions of seminars and presentations, we women

COVID-19 pandemic is likely to make things worse.

tend to begin our questions by saying things like:

People are less visible when they do not come to the

“I’m not sure I understood the key concepts of Slide

office. So please, set aside at least one hour each

12”, or “Correct me if I am wrong”, or “I might have

week to expand your network and make yourself

misunderstood, but it seems to me that”, etc.

visible through LinkedIn, remote coffee breaks in

No way! Undermining yourself before asking the actual question is not the right way. Just go straight to the

chance to stand out.

Zoom with your co-workers etc. The only way to get noticed is to make an effort to get noticed.

point and say instead: “Can you clarify again Slide

The bottom-line tip of this article is: communication is

12?”, or “This is what I got from what you just said, is

key, so use it wisely. You cannot thrive unless you own

that correct?”, or “Can you articulate again your last

your value and make it visible to other people.

argument?” This tip is somewhat related to tip #1 above, because

www.linkedin.com/in/giulia-traverso-phd-13a749150/

it cautions against adding words additional to those related to the question itself. And by the way, the

www.breakingthirty.com

implicit tip here is: do ask questions! Do not be afraid of looking stupid just because you want more information or clarification. It is likely that other people in the room also need additional information and clarification.

WOMEN IN SECURITY MAGAZINE

49


MELANIE NINOVIC

ADVICE ON JOINING THE INFOSEC INDUSTRY by Melanie Ninovic, DFIR Consultant, ParaFlare.

Credit: consultancy-me

56

WOMEN IN SECURITY MAGAZINE


C A R E E R

P E R S P E C T I V E S

The past few years in cybersecurity have been

Once you set these objectives, you can start focusing

everything from eye opening and rewarding to

on the skills you need to achieve them. When you

downright challenging. There have been challenges

focus on one or two related areas at a time, you are

you cannot begin to prepare for, even though you’re

likely to grasp them more efficiently and effectively.

ingesting copious amounts of new information every I’d like to offer some advice I wish I had been given at

TECHNICAL ABILITIES VERSUS SOFT SKILLS.

the start of my career. Hopefully it will provide some

Technical abilities will give you opportunities in the

day. I’m fairly new to the world of cybersecurity and

tips to anyone looking to join this industry.

YOU WON’T KNOW EVERYTHING. Take a look at the graphic below. Each time I come across it, I am overwhelmed by the range of disciplines in this industry. It’s quite common for people to become experts in one field, for example, digital forensics, and have knowledge in another field, such as penetration testing. Some of these disciplines go hand in hand. It’s useful for a forensic practitioner to think like a hacker, by learning how to exploit vulnerabilities. However, this is not a requirement for a career in forensics. It is easy to fall into the trap of striving for accomplishment in multiple domains. Trying to learn all there is to know about cybersecurity would be almost impossible. My first piece of advice is to understand, within your first year or two, where your interests lie, and how you want your career to progress.

cybersecurity industry, but are by no means the only skills you should focus on. Each security domain requires the following soft-skills, and I would argue that you would not last very long without them. Communication: how to speak and present professionally and effectively to your colleagues, manager and, most importantly, your clients. Collaboration: you will almost always be working in a team, assisting with reviewing your colleagues’ reports, and collaborating towards a common goal. Writing: writing reports and status updates is the pinnacle of a digital forensics and incident response, red-team/pentest, or governance, risk and compliance engagement with a client. Your findings must be communicated in a way that can be understood by both technical and executive level stakeholders. Business Acumen: knowing the drivers of a business, being able to present a case for new security tools or training, or advise clients on how to improve their

Henry Jiang: https://www.linkedin.com/pulse/map-cybersecurity-domains-version-20-henry-jiang-ciso-cissp/

WOMEN IN SECURITY MAGAZINE

57


security team and posture are all useful attributes

presentations and speaking with people who have

you can bring to an organisation.

more experience than I has assisted my professional

There is a place in cybersecurity for everyone, whether you have formal security training or not. This industry spans numerous, distinctive domains.

development in ways that would not have been possible during work hours. These activities were directly responsible for me landing a new job.

It needs professionals with diverse educational and career backgrounds.

BURNOUT IS REAL. According to healthguide.org, burnout can be defined as: a state of emotional, physical, and mental exhaustion caused by excessive and prolonged

We all have our different paths, challenges, hurdles and timelines. There is no point in comparing yourself to others. More important, is that we are all working towards the same goal: improving the security of those around us.

stress. It occurs when you feel overwhelmed, emotionally drained, and unable to meet constant demands.

Community: There is a curated list of Asia-Pacific

It is a common problem in the cybersecurity industry,

information/cyber security meetups here. I also

because we often feel the need to push ourselves

recommend the Australian Women in Security

to learn as much as we can. Even if you take the

Network (AWSN), and there’s a list of Asia-Pacific

sensible approach of focusing on one skill at a time,

infosec conferences here.

you can still suffer the effects of burnout. Studying on top of everything else in life — work, family, hobbies — can be overwhelming.

Online Learning Resources: As part of my InfoSec 101 series, I’ve provided a small inventory of places to start learning online. Most of these resources are

It is important to recognise the signs early on and

free. For more practical challenges such as capture

take preventative measures as soon as possible.

the flag events and running your own virtual machine,

The signs are different for everyone, and the site I’ve

have a read of this post.

linked to above does a good job at detailing them. It’s important to be transparent with your employer too, to ensure you are given time to recuperate and rest.

GET INVOLVED. Before landing my first full-time security-related role as a security operations centre analyst, I had spent the previous year studying to my heart’s content. I knew, without at least some knowledge of important security concepts, I would be unable to land an

We all have our different paths, challenges, hurdles and timelines. There is no point in comparing yourself to others. More important, is that we are all working towards the same goal: improving the security of those around us. Whether you decide to join the industry tomorrow, or next year, I hope this article helps you to manage your expectations, and I’m happy to answer any questions you may have. www.linkedin.com/in/melanie-cybers/

interview. There is an abundance of online resources that can help develop and fine-tune your skills, and an

www.darkdefender.medium.com/

online and physical community where you can meet like-minded individuals. Of course, this isn’t a necessary part of your job, we all have lives. However, I have found watching

58

WOMEN IN SECURITY MAGAZINE

twitter.com/_darkdefender_


Easy Reliable Resourceful No job is too big or too small. We look after your marketing & content needs so you can get on with what you do best. GET CONNECTED AND TAKE CONTROL OF YOUR BUSINESS SUCCESS TODAY!

charlie@source2create.com.au | aby@source2create.com.au

www.source2create.com.au


MARIANE C LOUVET

INTRODUCE YOURSELF TO LEADERSHIP, THE POWER OF A STRONG NETWORK AND CONNECTIONS by Mariane C Louvet, Channel leader - Cyber Security Over the past 20 years I have come to a realisation:

and to give me confidence in this new role. He

a title is just that, a title. It refers to a human being

introduced me to all of our partners and one thing I

with a function in their industry. We get hung up about

realised quickly was that relationships were key to

hierarchy and about who we are supposed to engage

success. I found ways to connect with our partners

with, or not.

and our vendors by engaging with them on topics

I was 23 and my career goal was to become a fashion buyer; I had taken college courses in fashion

senior leadership at events and during meetings.

merchandising and had plans to travel the world in

Within my first year in the role, I had won an award

search of the latest and greatest in apparel trends,

for top sales assistant, and as a team we won the top

until a market crash changed my destiny. Instead

sales award. Seven years later I had become a sales

I took a job as a sales assistant at a technology

rep with a sales assistant of my own.

distributor. Technology was an industry I knew nothing about, and had no interest in, but it paid well. So I jumped on it. My first manager should have been a stand-up comic, which made my job not only fun, but interesting. He made certain to take the time to help in my training

64

other than technology, and I presented myself to

WOMEN IN SECURITY MAGAZINE

I took a break from IT to raise my daughters. I kept in touch over the years with my partners and with vendors and stayed on top of technology trends and industry developments. The president of one of my old partners reached out to ask if I would be interested in a role supporting a


C A R E E R

P E R S P E C T I V E S

vendor from overseas, part time. He thought I would

ladder, to let them know I was available. I had four

be a great fit. Within a few weeks I had connected

offers. The hard part was deciding which one to take.

with their leadership team and introduced myself to

I opted for a director role at Forcepoint

them. I spent four years rebuilding and expanding my network and reconnecting with the industry.

Networking is not hard, however, you have to know how to approach people. I had the pleasure of

An opportunity came up as an executive account

attending an incredible charity event in New York

manager at Symantec, and during my new hire

in November of 2019. Dress for Success (a global

training at our corporate HQ, I made sure to listen

not-for-profit organisation that empowers women

carefully when leaders were speaking and reached

to achieve economic independence) had a fireside

out to many upon my return with questions on their

chat and their fearless, classy CEO, Joi Gordon made

presentations. This created visibility for me. Over

time to speak with me because I had sent her an

my six-year tenure I made sure to approach C-level

introductory email prior to attending. I also had the

executives at our sales kick-offs and at various

opportunity to chat with renowned US television and

industry events, in the hope they would offer me

online journalist, presenter, producer, and author, Katie

opportunities to grow my career.

Couric. These amazing women are now part of my network. All it took was a simple “hello” and some conversations.

“A title is just that, a title. It refers to a human being with a function in their industry. We get hung up about hierarchy and about who we are supposed to engage with, or not.volupicte cus aut ad”

Over the years I have created numerous connections, and many have become mentors, friends and part of my daily life. It does not matter if someone is C-level, SVP, senior- something or other. Those are just titles.. Doing your homework on who they are and what they do, and finding common interests are all great ways to start a conversation. I have no issue

I then decided I wanted to leave sales and move to

picking up the phone, texting or emailing anyone in

the channel. We were launching a new division and

my network to say hi, to recommend someone, to ask

they were looking for a leader to support the Canadian

a question, or to congratulate them on their success.

market, so I approached our SVP of global sales and told him I wanted the role. I then connected with the VP for EMEA who would be running my team. It took some time, but I was persistent, took a leap of faith and moved to our brand-new cloud channel team. I spoke with our CIO at an executive briefing in California and mentioned what I was doing. She was very supportive. Once again, had I not taken the time to get to know these people, I might have missed a

My nicknames over the years have been “fast talker”, “411”, or the “networker”. I embrace them all. They have opened doors for myself, my family, and friends; as much in my personal life as in my professional life. A final reminder that a title is simply a title. At the end of the day, effective communication and knowing who you are approaching are all it takes to make strong connections and create a solid network.

tremendous opportunity. When I was looking for a new position a little over a

www.linkedin.com/in/mariane-louvet-94340a6/

year ago following the sale of Symantec’s enterprise security assets to Broadcom, I reached out to my network, including some at the top of the leadership

WOMEN IN SECURITY MAGAZINE

65


Turn static files into dynamic content formats.

Create a flipbook
Women In Security Magazine Issue 1 by source2create - Issuu