Skip to main content

Women in Security Magazine Issue 28

Page 1

28

JANUARY • FEBRUARY 2026

W W W. W O M E N I N S E C U R I T Y M A G A Z I N E . C O M


FROM THE PUBLISHER Pivoting isn’t just a career move, it’s an act of courage.

A

s professionals we often find ourselves deeply rooted in familiar roles, confident in our expertise and secure in what we know. It took me 15 years to pivot from my job! But stepping away from that comfort

zone and taking an entirely new direction, especially in the fast-evolving world of security, can be daunting. It’s completely natural to wonder. Will I catch up? Will I ever feel truly proficient? Will people think I’m a fraud? These questions are common for anyone considering a career shift, particularly for those who come to cybersecurity later in life. The trends show you’re not alone. In 2023, 16 percent of new entrants to cybersecurity were between 50 and 59, showing that mid-life pivots aren’t just possible but increasingly common. Fifty-nine percent of hiring managers are seeing more candidates from outside traditional cyber backgrounds, and more than half are changing their hiring practices to welcome career changers. With 457,398 cybersecurity job openings in 2025 alone and a predicted 33 percent growth rate ahead, opportunity in security is abundant for those willing to embrace change. But the journey is as much about mindset as skillset. Up to 70 percent of security professionals report imposter syndrome, reminding us that learning and doubt are universal, no matter your experience level. Adapting to this reality can turn discomfort into opportunity and nervousness into confidence, fuelling personal and professional growth. As we close out the year, this final issue is packed: deep dives on risk versus reward, advice on pivoting with no experience, honest discussions about age and transition, and stories of people who have made the

2

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


Abigail Swabey

leap into both cyber and physical security. You’ll also find our trusted regular columns, the inspiring What’s Her Journey features and the Student in Security spotlight. There’s something for everyone in our community, whether you’re just starting out, in the middle of a transition or looking to upskill. And remember, anyone can contribute. If you have an experience to share, a journey, some career advice or a unique perspective on tech or the sector, reach out to us (Jane jane@source2create.com.au). We’re always open to fresh voices and stories that align with our themes. You can request submission guidelines if needed. Also, if you’re interested in advertising with us, Women in Security Magazine now reaches a global audience of over 9,000 subscribers, making it a fantastic platform to put your brand in front of engaged, passionate readers. And, finally, the whole team at Source2Create and Women in Security Magazine, wish you a safe and happy holiday season. Whether you’re pivoting into something new or continuing in your current role, stay curious, confident and resilient. Here’s to new beginnings and our shared journey in security.

Abigail Swabey PUBLISHER, and CEO of Source2Create www.linkedin.com/in/abigail-swabey-95145312

aby@source2create.com.au

I S S U E 28

WOMEN IN SECURITY MAGAZINE

3


CONTENTS GETTING INTO CYBERSECURITY WITH NO EXPERIENCE: YOUR ROADMAP FOR 2026

2

FROM THE PUBLISHER

8 WHAT’S HER JOURNEY?

COLUMN

Tara McNally

14

Krity Kharbanda

16

Nkiruka Joy Aimienoho

18

Aneesa Chothia

20

Opeyemi Olaifa

22

Fathima Mohamed Thaseen

24

Ako Otudor

26

Jaime Schrepfer

28

Fiona Martin

30

DeArne McWhirter

32

Soledad Antelada Toledano

36

Cassandra Mack

38

Prime time for cybercrime

12

Simon says “freeze”

42

The ‘pivot’ secrets you didn’t know

76

Pivot: the shift from reacting to anticipating

86

INDUSTRY PERSPECTIVES Pivot: turning pain into purpose through technology

46

Pivoting with purpose: Women redefining leadership in cybersecurity’s next era 50

131 THE LEARNING HUB 134 JOB BOARD

Social media age assurance for children under 16: what it means for Aussie parents

54

The seven pivots that define a successful cybersecurity career (and why women excel at making them) 58 Emotional intelligence in security: the shift from physical presence to psychological awareness

66

Building an inclusive cyber club playbook and pitfalls

68

AI and data: protecting what powers us

72


JANUARY • FEBRUARY 2026

CAREER PERSPECTIVES The FSD risk: accountability for the autonomous workforce 80 Getting into cybersecurity with no experience

Support the Future of the

AUSTRALIAN WOMEN IN SECURITY AWARDS

®

We need your support to continue this important initiative into its 8th year.

FOUNDER & EDITOR Abigail Swabey

ADVERTISING

82

Abigail Swabey Jane Saafi

SURFING THE NET 124

The 2026 Awards will be hosted in Melbourne. To ensure this initiative continues, we invite you to partner with us as a sponsor.

ONSORSH

I

Packages ava ilable from $6,000 to $50,000 Custom packa ges tailored to your organisa tion’s needs

PP

O

Your sponsorship will help us continue to celebrate and elevate the achievements of women in security across Australia.

SP

P

JOIN US IN MELBOURNE FOR 2026

ORT

U NIT

IE

S

M A G A Z I N E C O O R D I N ATO R Jane Saafi

JOURNALISTS Stuart Corner

118

To discuss how you can support and sponsor next year’s awards, please reach out to Aby at Aby@source2create.com.au. We look forward to partnering with you to make the 2026 Australian Women in Security Awards our best yet.

SUB-EDITOR Stuart Corner

DESIGNER Rachel Lee

STUDENT IN SECURITY SPOTLIGHT

TURN IT UP 126

Paige Haines

90

Prajoti Rane

94

Tanvi Badghare

98

Amy Koralis

102

Ashley Mathew

106

Queeneth Onyike

110

Danah Mohammed Alkhan

114

Source2Create Pty Ltd is the publisher of this magazine and its website (www.womeninsecuritymagazine.com).

©Copyright 2025 Source2Create. All rights reserved. Reproduction in whole or part in any form or medium without express written permission of Source2Create is prohibited.

OFF THE SHELF 128


ASSOCIATIONS & GROUPS SUPPORTING THE WOMEN IN SECURITY MAGAZINE


Thank You

TO OUR SUPPORTING ASSOCIATIONS


GETTING INTO CYBERSECURITY WITH NO EXPERIENCE: YOUR ROADMAP FOR 2026 by Abigail Swabey

Have you ever clicked 'send’ on a job application, heart pounding, certain you’d be rejected for lacking the right experience? In cybersecurity, this experience is more common—and more surmountable—than you think. Today, the fastest-growing field in tech isn’t just seeking codebreakers with fancy degrees; it’s searching for determined, curious problem-solvers from all walks of life.

C

ybersecurity is often portrayed as an

willingness to build new skills. Here’s how you can join

exclusive realm for tech wizards and

them, no tech degree required!

computer science graduates. Yet, the reality is far more optimistic, inclusive and practical. In 2025 the demand

for cybersecurity professionals soared, and hiring

MYTHS ABOUT BREAKING INTO CYBERSECURITY • Myth 1: you need a four-year tech degree.

managers are increasingly looking for passion,

Not true. Practical skills, hands-on learning and

aptitude and adaptability rather than just formal

industry certifications can get you an interview

qualifications or previous experience.

and often the job.

If you’re eyeing a career in cybersecurity but feel intimidated by your lack of direct experience, you’re not alone. Many successful professionals in the industry started their journey from non-technical backgrounds, armed only with curiosity and a

8

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


F E A T U R E

• Myth 2: you must start as a programmer.

The industry’s urgent demand for talent means many

Many roles do not require advanced coding;

organisations are open to hiring people for their

analytical, risk management or compliance

potential and willingness to learn, not just for their

positions seek different strengths.

current skill sets.

• Myth 3: the field is only for the young. Mid-life and late career pivoters are increasingly

BREAKING IN WITH NO TECH EXPERIENCE

common, and valued for the diversity of

Many successful cybersecurity professionals began

experience they bring.

their journeys without knowledge of networking, programming or operating systems. The most

WHY CYBERSECURITY? WHY NOW?

important first step is a mindset shift: curiosity,

Cybersecurity job openings hit a record high in 2025,

persistence and a commitment to lifelong learning are

with over 450,000 positions available globally. The

more valuable than prior expertise.

sector is projected to grow 33 percent by 2033, making it one of the fastest-expanding areas in tech.

WHERE TO BEGIN

As organisations face escalating threats to their

• Start with cybersecurity awareness training. Free

digital assets the spectrum of roles continues to

and beginner-level online programs introduce key

diversify; from technical jobs like penetration testing

concepts like phishing, password safety and data

to governance, risk management, compliance and security awareness.

protection without requiring any technical skills. • Explore free resources. Many organisations, including government agencies, offer

Moreover, there is no single path into cybersecurity.

cybersecurity foundations courses aimed at the

A recent survey found that 56 percent of

public rather than specialists. These provide

cybersecurity professionals started in roles outside

foundational knowledge and confidence to

of IT, highlighting the value of transferable skills and

learn more.

fresh perspectives. Individuals without any technical background or prior understanding of cybersecurity still have real opportunities to enter the field.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

9


• Focus on transferable skills. Problem-solving,

If you are going to try and pivot into the cybersecurity

critical thinking, communication and ethics are all

workforce and don’t have any transferable skills, these

vital in security roles and often developed in non-

are the ones you need.

technical fields. Even simple acts like being a security ambassador

THE ESSENTIAL SKILLS— AND HOW TO BUILD THEM

at your workplace, organising awareness events or

Technical skills

helping develop security policies can build relevant

While you don’t need to be a coding genius, a solid

experience.

understanding of technology fundamentals is

• Volunteer for security-related tasks.

• Find a supportive community. Online forums,

indispensable. Employers typically look for:

local meetups and women-in-security groups offer encouragement, mentorship and learning paths for absolute beginners.

• networking basics: understanding how data moves across systems and the fundamentals of TCP/IP, DNS, firewalls and VPNs.

ENTRY ROLES FOR COMPLETE BEGINNERS Some security roles are especially welcoming to those starting from zero.

• operating systems: comfort working with Linux and Windows environments. • programming and scripting: learning Python, Bash or PowerShell helps automate tasks and

• Security awareness co-ordinator: focuses on training and education, ideal for teachers or communicators. • Compliance analyst: involves policy work

understand vulnerabilities. • cloud security: familiarity with AWS, Azure, or Google Cloud is increasingly valuable as businesses move to the cloud.

and documentation more than hands-on technical tasks. • Junior risk analyst: primarily assesses business

Cybersecurity fundamentals An understanding of core security principles such

processes and helps implement security

as authentication, encryption, malware types and

best practices.

common attacks like phishing or ransomware, is crucial.

Cybersecurity is not just for ‘techies’; it is a field defined by curious minds, critical thinkers and people

Soft skills

committed to making a difference. With dedication

Employers are also looking for:

and access to learning resources anyone, regardless of their starting point, can find a place in this dynamic industry.

• problem-solving and attention to detail: the ability to spot irregularities and analyse risk. • communication skills: explaining complex issues to non-technical audiences. • curiosity and willingness to learn: the drive to keep up with rapidly evolving threats and tools.

HOW TO BREAK IN: ACTIONABLE STEPS 1. Start with online courses There is an abundance of beginner-friendly online courses and boot camps. Many are free or affordable and cover cybersecurity basics, networking, operating systems and cloud principles. Platforms like Coursera, edX and Cybrary are excellent starting points.

10

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


F E A T U R E

2. Experiment with hands-on learning Employers increasingly value proof of skills over formal education. • Set up a home lab using free or low-cost virtualisation software (e.g. VirtualBox, VMware). Experiment with operating systems, networking and open-source security tools. • Join gamified learning platforms such as Hack The Box or TryHackMe which offer experiential, challenge-based learning and virtual capture the flag (CTF) competitions. • Contribute to open-source projects on GitHub, especially those related to security.

6. Seek internships, volunteering and open roles Many organisations offer entry-level internships or apprenticeships that don’t require prior experience. Volunteering for security initiatives in your community

3. Pursue entry-level certifications

or at nonprofits can help build your resumé and

Certifications signal to employers your commitment

network while contributing meaningfully.

and baseline knowledge, even if you haven’t worked in the field.

7. Tailor your application When you’re ready to apply:

• Top entry-level certifications in 2025: CompTIA Security+, eJPT, Cisco’s CCNA Cyber Ops and SSCP. • Gaining certifications can make you up to 2.5 times more likely to land an entry-level job.

• identify entry-level job titles like security analyst, security operations centre (SOC) analyst, or risk/ compliance associate. • highlight hands-on projects, certifications and

4. Leverage transferable experience

transferable experience.

Experience in IT support, network administration,

• be prepared to discuss your self-directed learning,

risk management or compliance offers a significant

home labs or any challenge-based activities you’ve

edge. Even previous work in customer service or

completed in interviews.

project management develops transferable skills in troubleshooting, communication and process documentation that are valuable in security roles.

FINAL WORDS: YOUR CYBERSECURITY JOURNEY BEGINS NOW Breaking into cybersecurity with no experience is

5. Build your professional network

not a fantasy; it’s a reality for thousands every year.

Engage with cybersecurity communities online

The field welcomes newcomers with curiosity,

and offline.

commitment and a passion for continuous learning. Start with what you have, build core skills, connect

• Join professional organisations like ISACA, (ISC)²,

with the community and be persistent. The world

OWASP, AISA, ACS etc. and attend local meetups

of cybersecurity isn’t closed off. In fact, it needs

or conferences.

you now more than ever, whether you come from

• Seek a mentor—seasoned professionals are often willing to share advice and guidance, accelerating

IT, management, education, healthcare or any other background.

your learning and helping you navigate challenges. • Leverage platforms like LinkedIn to connect with

The only wrong move is never to start at all.

practitioners and follow career paths similar to

Your journey can begin today, one step, one course,

your interests.

one connection at a time.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

11


AMANDA-JANE TURNER Cybercrime is big business, thanks to technical advancement and interconnectivity creating more opportunities. This regular column will explore various aspects of cybercrime in an easy-to-understand manner to help everyone become more cyber safe.

C O L U M N

Prime time for cybercrime The transition from the old year to the new is prime

• Secure your devices. Only download apps from

time for cybercrime! Alliteration aside, this time of

official app stores like the Apple App Store or

year is ripe for cyber scams with increased financial

Google Play, and keep your digital devices updated

activity from holiday shopping, vacations, end of

with relevant security patches.

year bonuses, seasonal sales and reduced vigilance

• Be cautious with public Wi-Fi. Avoid accessing

resulting from a focus on holidays, or added stressors

sensitive information or making online purchases

at work as the year winds up.

over public networks. Use a VPN if public Wi-Fi is your only option.

Cyber criminals exploit this time of year to trick

• Enable multifactor authentication. This adds an

people into paying faked invoices, clicking phishing

extra layer of security to your accounts, making

links or paying for heavily discounted items that do

it harder for criminals to get in, even if they have

not exist. It is a great time for scammers thanks to

your password.

increased online activity from people booking holidays

• Stay vigilant. Be suspicious of any unsolicited

online, buying presents for others, making charitable

requests for information or texts about delayed

donations and looking for discounts. Additionally,

packages. And don’t let urgency or holiday

people can be more distracted at this time of year:

excitement override your security instincts.

they may be in holiday mood, letting their guard down and relaxing their usual vigilance. How to protect yourself from seasonal cybercrime. • Verify charities before you donate. If you want to

Stay safe everyone. www.linkedin.com/in/amandajane1

www.empressbat.com

donate to a charity, first verify it is legitimate, and go direct to the website yourself by searching for it. Confirm it is genuine and has secure payment methods. Then donate through one of these. • Shop from verified and reliable sources. Go direct to a website by typing the address or searching for it instead of clicking links in emails, texts or social media. • Think critically about discount offers. Be wary of “too good to be true” offers: they can be a way for criminals to compromise your accounts or trick you into paying for a product that you will never get.

12

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


WHAT’S HER JOURNEY?


Tara McNally Manager Cybersecurity

T

ara McNally never expected a three-hour

months before my start date I was asked to defer for

evening lecture to change the course

a year due to the early impacts of COVID-19.” Rather

of her life. Yet, as she recalls, “During

than viewing the delay as a setback, she turned it into

my undergraduate studies I spent a

an opportunity. “I decided to make the most of that

semester in Washington D.C where I

time by pursuing a master’s degree in cyber risk, an

enrolled in a Cyber Risk module, surprisingly, I found

area I’d always been interested in but hadn’t had the

myself genuinely looking forward to it each week.”

opportunity to explore in depth.” When she completed

The class ran from 5 to 8pm prime hours for college

her degree, she approached HR with a request that

fatigue but Tara found the content “engaging enough

would shape her future: “I reached out to HR to see if I

to keep me focused (no small task for a college

could join the Cybersecurity team instead. They were

student sitting in class from 5-8pm!). Despite the

supportive of the switch and that’s how my career in

odds it sparked a real interest in the field and an

cybersecurity began.”

eagerness to learn more.” That spark would eventually lead her into a career she hadn’t originally planned but

Today, as a Manager in Cybersecurity, Tara

now can’t imagine not pursuing.

recognises the complexity of working in a field that evolves faster than most industries can keep up with.

14

Her transition into cybersecurity unfolded organically.

“Staying ahead of the evolving market dynamics

Tara explains, “I had accepted a graduate offer to

and threat landscape is challenging. Attackers

join the Technology Advisory team at one of the big

are becoming increasingly sophisticated and fast

consulting firms in Ireland. However, about three

moving, while regulatory demands continue to grow in

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

“Be curious, ask lots of questions (especially when you’re unsure) and don’t be afraid to put yourself out there. You don’t need to have all the answers or the perfect skillset from the start. Showing genuine interest, being willing to learn and giving things a go is equally as valuable. If you’ve got the passion, the rest will come.”

J O U R N E Y ?

big priority for me, knowing I’ll be able to keep building my skillset and continue delivering quality work is important.” Equally essential is the freedom to choose how she works. “I genuinely enjoy being in the office but also really value the option to work from home when it suits. Being part of an organisation that trusts you to decide makes a big difference.” Her own development is front of mind, and the next milestone is a significant one. “The next certification I’m aiming for is my CISSP. It covers a huge amount of content and will take lots of study, but this comes with a lot of learning, deeper knowledge and new opportunities, which I’m really looking forward to.” Despite the challenges and demands of cybersecurity, it’s the human element that brings Tara the greatest

complexity.” Her approach is proactive: “Engaging with

fulfilment. “The collaboration and connection with

industry leaders, attending key events, and proactively

others, It’s not just about the work itself but also

staying informed are critical to remaining effective

the energy and ideas that come from being around

and resilient in such a rapidly changing environment.”

smart, motivated people.” She thrives on variety too. “Whether it’s diving into a new challenge, exploring

Despite her expertise, Tara would reassure her

a different industry or picking up new skills there’s

younger self that she didn’t need to have it all figured

always something to grow from.”

out from the start. “Be curious, ask lots of questions (especially when you’re unsure) and don’t be afraid to

Maintaining balance is non-negotiable in her life. “By

put yourself out there. You don’t need to have all the

ensuring my day isn’t solely centred around work,”

answers or the perfect skillset from the start.” What

she says. From morning gym sessions to ocean

matters most, she emphasises, is mindset. “Showing

swims and sprint training after hours, her routine

genuine interest, being willing to learn and giving

is intentionally energising. “Starting early gives me

things a go is equally as valuable. If you’ve got the

time to go to the gym, grab a coffee with a friend or

passion, the rest will come.”

go for a walk before logging on… staying active and spending time outdoors helps reduce stress and

Looking ahead, Tara sees emerging technologies

keeps things in perspective.” Having hobbies she

reshaping the threat landscape. “AI and Quantum

genuinely loves, she adds, is key to recharging.

are two areas that will continue to make security difficult and solutions more complex.” AI, she notes,

Tara’s journey is a testament to following curiosity,

is accelerating social engineering at scale, putting

embracing unexpected turns, and trusting that

everyday users at heightened risk. Quantum, while

passion and perseverance will lead the way. Her path

not an immediate danger, presents long-term

may have begun in an evening lecture in Washington

implications: “Being able to get ahead is something

D.C., but her impact on the cybersecurity landscape

organisations should be thinking about.”

continues to grow far beyond the classroom.

For Tara, career decisions extend far beyond salary

www.linkedin.com/in/taramcnally

considerations. “Opportunities to learn and grow are a

I S S U E 28

WOMEN IN SECURITY MAGAZINE

15


Krity Kharbanda Application Security Professional | Advocate of women in cybersecurity

F

rom being a biology student in India to

new city, new culture, unfamiliar surroundings. She

becoming a cybersecurity professional

quickly realised that adapting was as important

in the United States, Krity’s journey has

as studying. Learning to navigate challenges

been anything but linear. To every stage

independently became a skill that would define the

she brought something from the phase

next chapter of her life.

before a skill, a mindset or a perspective that helped her take that step with greater confidence and clarity.

Graduation brought clarity of passion, but not

She pivoted constantly, taking opportunities that

opportunity. With global layoffs on the rise and

pushed her out of her comfort zone and building on

her master’s program on hold due to COVID-19,

lessons from previous experiences. Her story offers

she kept applying for roles in cybersecurity. That

insight into what it takes to navigate change, seize

persistence eventually paid off with an internship

opportunities and grow in a field as fast-moving as

at a startup. It was soon converted into a full-time

cybersecurity. For Krity, each new role is more than

role. That year became her crash course in bridging

a career progression; it’s a new opportunity to better

theory and practice. She moved beyond academic

understand how people, technology and environments

problem-solving into real-world application, tackling

interact. She is learning every day.

both technical and business challenges. She gained exposure to social engineering exercises, cloud

Krity’s academic path took her from northern

security and compliance frameworks like NIST, ISO

India to southern India to study electronics and

and GDPR. This exposure confirmed cybersecurity

communications engineering. Beyond circuits and

as the right path and made her keen to broaden the

signals she discovered a fascination with networks,

depth and breadth of her experience.

security and databases. The transition wasn’t easy:

16

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

Krity realised that technical problems are only part of the story. The bigger challenges to meaningful progress are often reading the room, navigating team dynamics and adapting to the organisational environment. Overcoming these challenges shaped both her professional approach and personal growth.

Driven to expand her skills, Krity moved to the United

Outside of work she finds joy in reading, exploring

States to pursue a master’s in information science,

cafés, dancing and cooking. Her personal mantra

focusing on information security. Graduate school

is simple but effective: ‘React’. She allows herself

tested her in ways she hadn’t anticipated. She had to

to process and immediately release emotions, then

constantly juggle the competing priorities of multiple

steps back to reflect and plan. Setbacks are not

part-time jobs and, for the first time, independent

failures; they’re lessons that inform the next move.

living. She worked as a research assistant under a

Her story demonstrates that growth is ongoing; even

business school professor, supported the university

when you reach new milestones, there’s always more

IT help desk and contributed to the Computational

to explore, understand and master.

Biology department. She drew on lessons from her undergraduate days to adjust, persevere and make

Today, Krity works in application security, and

her own way. She turned these challenges into

volunteers to give back to the community through

growth opportunities and showed how resilience and

mentoring and working with a non-profit organisation

adaptability can transform pressure into opportunity.

the Breaking Barriers Women in CyberSecurity (BBWIC) Foundation. She is always on the hunt for

During this time she landed an internship with

opportunities to learn and grow.

ServiceNow, her first exposure to corporate America. Living in a new city and facing unfamiliar professional

Krity’s journey is defined by curiosity, adaptability and

expectations, she learned quickly. The internship

the courage to pivot when needed. Every challenge,

sharpened her technical skills, expanded her

obstacle and leap into the unknown has shaped

perspective and ultimately enabled her to transition

her into someone who continues to grow both her

into a full-time role. She tackled projects she had long

technical expertise and her understanding of how

found intimidating; from penetration testing exercises

people and environments influence outcomes. While

to identifying vulnerabilities and presenting actionable

she often says her cybersecurity journey began during

reports to stakeholders.

her undergraduate studies, she believes it truly started even earlier. Because, at its core, cybersecurity is

Krity realised that technical problems are only part

about mindset and adaptability. A strong security

of the story. The bigger challenges to meaningful

mindset goes beyond technical tools; it demonstrates

progress are often reading the room, navigating

critical thinking, anticipates human behaviour

team dynamics and adapting to the organisational

and uses psychological insights to help develop

environment. Overcoming these challenges shaped

technical strategies.

both her professional approach and personal growth. www.linkedin.com/in/krity-kharbanda-0b9bb1133

I S S U E 28

WOMEN IN SECURITY MAGAZINE

17


opportunity with the Information Systems General Manager… who listened as I painted a vivid picture

Nkiruka Joy Aimienoho Chief Information Security Officer (ScB)

of the value I wanted to create.He advised that I join a niche Cyber Security and IT GRC company. I took the advice, and my journey into Information Security advisory began.” From there, she built intentionally and relentlessly. “I diligently built competence, worked hard, and cultivated a large appetite for knowledge.” She embraced complex, uncharted projects, pursued global certifications, and strengthened both her technical depth and leadership maturity. These early

N

decisions carved the path toward the executive she has become. kiruka Joy Aimienoho’s cybersecurity journey was never a coincidence; it

Professional communities have been another

was an early calling. Long before she

cornerstone of her journey. Linked with ISACA, ISC2,

became a Chief Information Security

The BCI, EC-Council, and several women-centric

Officer, the foundation had been laid.

groups such as WiCyS, WiR, SheSecures, and

“I have always been interested in the field. I got my

SheLeadsTech, Nkiruka credits these networks for

first degree in Electrical and Electronics Engineering,

being part of her journey. “I always strived to hone

my first job was on the Information Systems Service

my craft” she says, and these organisations gave

Desk at Africa’s telecom giant, MTN Nigeria, and I

her access to global best practices, world class

was particularly fascinated by the dynamics of the

thought leadership, and supportive networks that

Information Security space after interacting with

continue to uplift women across cybersecurity and

different professionals and parts of the business

resilience. They also provided a platform for her to

from the IS service desk.” That early spark matured

mentor others, a role she sees as both responsibility

into a passion not only for solving complex

and privilege.

technical problems but for shaping enterprise resilience, influencing executive cyber strategy, and

Yet the path was not without moments of doubt.

nurturing Africa’s rapidly growing cybersecurity

As a young woman navigating male-dominated

talent landscape.

environments, she often found herself having to prove her worth repeatedly. “I was one of the few women

18

Her transition from curiosity to a distinguished career

passionate about Information Security, Cybersecurity

was fuelled by decisive, courageous steps. One

or even Business Continuity, with limited support.

pivotal moment stands out vividly to her: “seizing an

I had to read ferociously, learn on the job, and learn

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

from my mistakes.” When her capabilities were

work consistently overnight but that has changed

questioned, she met it with excellence and clarity.

significantly now.” Today, she prioritises family, faith,

“I responded by going back to the drawing board,

and health acknowledging that personal grounding is

building competence, and in scenarios this was

essential for sustainable leadership. “Balance is not

required, confidently describing my portfolio and the

accidental; it is a discipline.”

remarkable feats and experience garnered. Instead of allowing these things to discourage me, I continued

Nikiruka’s journey has been shaped by extraordinary

to give my best. With time, the questioning soon

influences, leaders, thinkers, mentors, and global

turned to admiration.” For her, competence, faith, and

voices who challenged her thinking and refined

community “my tribe” formed the backbone of her

her leadership. Mikko Hyppönen remains a major

resilience. “We rise by lifting others, and your tribe will

intellectual inspiration, admired for his clarity and

be there to spur you on in times of self-doubt.”

ability to simplify complex concepts. She also draws strength from trailblazers such as Ngozi Okonjo-

Looking ahead, she anticipates a period of profound

Iweala, Adedoyin Odunfa, Tope Aladenusi, Ope

change in the cybersecurity landscape. Increased

Onifade,Nkiru Olumide Ojo, and Dr. Nneka Abulokwe.

use of AI in both attack and defence, heightened

Industry mentors and visionary executives have

regulatory scrutiny, more automation, widespread

shaped her strategic approach and resilience. And her

adoption of zero-trust, and cyber resilience becoming

community, her enduring “tribe” remains her anchor.

a board-level priority. In her words, “cybersecurity

“It is rewarding to mentor and be mentored and

must be treated as a business issue, not just an

nurturing those relationships often progresses them

IT issue.” She warns that the greatest threats will

to sponsorship.”

emerge from AI-enabled attacks, supply-chain compromise, cloud misconfigurations, deepfakes,

Staying effective in a rapidly evolving field demands

geopolitical tensions, and the persistent neglect

what she describes as “an enormous appetite for

of basic cyber hygiene. “CISOs face tremendous

knowledge.” She continuously invests in certifications,

pressure, and without balance, organisations risk

engages with global bodies, participates in cyber

over-investing in tools while under-prioritising basic

drills, attends industry conferences, and experiments

cyber hygiene — including patch management

with emerging technologies. Guided by curiosity,

and effective use of existing threat intelligence

humility, and discipline, her advice to the next

for foresight. Left unaddressed, this significantly

generation is simple: invest in yourself. Leverage

increases the likelihood of successful cyber

the many free resources available from platforms

incidents.” For her, thriving organisations will be

and podcasts to wargaming exercises and actively

those that strengthen foundational controls while

network with those already in the roles you aspire to.

embracing next-generation defence capabilities. Nkiruka’s journey is defined by purpose, resilience, Nikiruka’s career decisions are guided by purpose,

faith, and service. Rooted in a deep appetite for

values, and cultural alignment, with a strong

learning to sharpen her expertise, and driven by an

preference for environments that treat cybersecurity

unwavering commitment to uplift others, her story

as a strategic enabler and prioritise long-

continues to inspire a new generation of cybersecurity

term resilience

leaders across Africa and beyond.

Despite the intensity of her field, balance remains non-negotiable. Earlier in her career, she navigated

www.linkedin.com/in/nkirukacyberandresilience

long nights, late client calls, and constant demands. But with experience came perspective: “There were days when clients would call at 11 p.m. or I’d

I S S U E 28

x.com/InfosecAmazon

WOMEN IN SECURITY MAGAZINE

19


Aneesa Chothia Information Security Officer

A

neesa Chothia, an Information Security

and resilience. “Working in cybersecurity is an exciting

Officer at Discovery in Sandton,

and demanding role. One of the biggest challenges

discovered her passion for cybersecurity

is navigating a male dominated environment

in a way that underscores how pivotal

finding the confidence to be heard and recognised

real world experience can be. “My

for my expertise. I’ve learned that self-awareness,

interest in cybersecurity was first sparked when my

preparation, and authenticity are key. Investing

previous organisation experienced a major breach.

in leadership and personal mastery courses has

We spent many days operating a 24/7 incident

helped me strengthen my voice and presence in the

war room alongside executives, employees, and

room,” she explains. She emphasises the importance

vendors to contain the threat. This showed me how

of collaboration and mentorship: “I also believe

cybersecurity impacts technology, people, brand, and

in the power of mentorship both being mentored

trust,” she recalls. “In the aftermath, I became actively

and mentoring others. It creates room for growth,

involved in various streams to strengthen overall

confidence, and connection especially for women

defenses. The more involved I was, the more this field

entering this space.”

fascinated me. I wanted to understand the layers of protection, the risks that emanate, the potential

Aneesa is candid about the uncertainties that arise

controls that could be implemented, the processes

when forging a career in a dynamic field. Reflecting on

and technology. My interest has evolved from incident

advice she would give her high school self, she says,

response to governance, risk, and consulting. The

“I’d tell my high school self that cybersecurity is one of

constant evolution of this field continues to inspire

the most meaningful, exciting, and rewarding careers

me to continuously grow, protect, empower myself,

to embark on. It’s not just about technology, but about

and inspire others.”

protecting people, information, and the systems that keep our digital world running. Every click,

20

Early in her career, Aneesa recognised that turning

transaction, or connection requires someone behind

interest into a professional pursuit required courage

the scenes who understands how to keep it secure.”

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

She encourages curiosity and persistence, noting

“For individuals in similar roles, Security+ builds a solid

that the field accommodates a range of mindsets

foundation. Certifications like CISM, CCSP, CISSP, and

and strengths: “There are vast specialisations

ISO27001 provide deeper insights into governance,

within cybersecurity from ethical hacking, forensics,

risk management, and strategic leadership. Personally,

risk management, incident response so there is

I’m particularly interested in exploring AI certifications

room for individuals with different mindsets and

to understand how to protect AI systems and assess

personal strengths.”

risks responsibly and ethically.”

Looking forward, Aneesa identifies emerging trends

Despite the demands of her profession, Aneesa

and threats in cybersecurity that professionals

prioritises balance. “Maintaining work/life balance

cannot ignore. “We will see an escalation in AI-driven

is crucial. I use meditation apps like Mindspace to

attacks, where hackers leverage AI to create more

manage stress, spend time with my daughter and

sophisticated attacks such as phishing, deep fakes,

family to create meaningful memories, and start each

and adaptive malware. Supply chain vulnerabilities are

day with prayer and walks to bring calm and gratitude.

also a growing concern, especially with reliance on

These moments keep me grounded and allow me to

third-party vendors and cloud providers. The human

show up fully, personally and professionally.”

element remains the weakest link, not from lack of awareness but because attacks exploit emotions,

Finally, Aneesa offers encouragement to those

trust, and urgency. And then there’s quantum

transitioning into cybersecurity from other fields.

computing, which poses both incredible opportunities

“Cybersecurity isn’t limited to those with technical

and risks for data security.”

backgrounds, it welcomes diverse skills like analytical thinking, problem-solving, and risk

When considering career moves, Aneesa weighs

awareness. Start somewhere, be curious, commit

factors beyond remuneration. “The culture of the

to learning, surround yourself with mentors, and join

organisation, flexibility, reporting lines, leadership

professional associations. Don’t doubt the value or

style, and brand reputation are all critical. A

skills you bring. The field needs people who combine

supportive leader will encourage growth and

technical expertise with strategic thinking, empathy,

accelerate your career,” she observes. She credits

and confidence.”

her former manager, Sachin Surajbali, as a major influence, saying, “He created a space where I could

Aneesa Chothia’s journey is a testament to how

question, challenge, and contribute, which built my

passion, resilience, and mentorship can transform

confidence and guided my thinking. His leadership

curiosity into a thriving cybersecurity career. Her story

style continues to guide how I mentor others and

continues to inspire women in the field to be bold,

show up in the cybersecurity space today.”

stay curious, and shape the future of cybersecurity with confidence.

Aneesa is also committed to continuous learning, emphasizing the value of certifications.

I S S U E 28

www.linkedin.com/in/aneesa-chothia-b4251716/

WOMEN IN SECURITY MAGAZINE

21


Opeyemi Olaifa Manager & Team Lead Cybersecurity & Compliance Advisory At Digital Encode Limited

Since that moment, her initial curiosity has evolved into a deep passion. “Over the years, my interest has shifted from just wanting to understand how attacks happen to actually helping organizations

O

prevent them, respond to incidents, meet compliance requirements, and build stronger security practices. peyemi Olaifa’s journey into

It has become more than a career switch; it is

cybersecurity began from a place of

something I genuinely enjoy and feel connected to

restlessness. “After University, I worked

every day.”

as a Project Manager in an Information Technology company for about 18

Opeyemi emphasises that the early stages of her

months. I picked up good management experience

career required dedication and courage. “The biggest

and even some programming skills, but I just wasn’t

turning point was deciding to actually do the work.

fulfilled. I have always known I am more technically

I stayed up late most nights trying to learn about

inclined, so project management alone didn’t feel like

cybersecurity, burning the midnight candle just to

the right path for me.”

catch up. I asked a lot of questions honestly; I think everyone around me eventually got tired of me

Her curiosity about cybersecurity emerged as she

because I was always asking ‘why?’ or ‘how does this

explored the rising threats in the digital world. “While

work?’ But that curiosity really pushed me forward.”

trying to figure out what to do next, I started reading

22

a lot about how online threats were becoming

She recalls taking on tasks even when uncertain of

more serious and how attackers kept changing

her abilities. “I did many things afraid, but I still did

their techniques. That really caught my attention. I

them anyway because I knew the only way to grow

became curious about how these attacks could be

was to try. All these little steps, the late nights, the

detected early and how information could be properly

constant learning, the endless questions, and the

protected. I even reached out to a friend already in

courage to take on tasks outside my comfort zone

cybersecurity, and that conversation was what finally

helped me move from simply being interested in

made everything click for me. I knew this was the

cybersecurity to actually building a career in it. It

direction I wanted to go.”

wasn’t easy, but it was worth it.”

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

Reflecting on her path, Opeyemi notes that her career

become more central as organizations continue to

unfolded organically rather than according to a rigid

rely on cloud services, remote work, and a growing

plan. “When I started my journey in cybersecurity,

number of devices. Supply chain security and

I definitely did not have a clear picture of the exact

ransomware will remain major challenges. The next

roles I wanted. I just knew I wanted something

couple of years will require adaptability, continuous

more technical and challenging. I began by learning

learning, and a proactive approach to security.”

whatever I could, taking on any task that came my way, and gradually discovering the areas I enjoyed

Mentorship and professional experiences have been

the most, like digital forensics, compliance, security

central to her growth. “The most substantial influence

assessments, and advisory work. Over time, the more

on my cybersecurity career has been a combination

I explored, the clearer the picture became.”

of my mentors, peers, and especially my bosses. Even when I doubted myself, they believed in me more than

If she could advise her younger self, Opeyemi would

I did, constantly pushing me to take on challenging

focus on curiosity, patience, and hands-on learning.

tasks and step outside my comfort zone. Each

“Start exploring early, stay curious, and don’t be afraid

challenge, success, and even mistake has shaped

to ask questions, even the ones that might annoy

the way I approach problems, make decisions, and

people. Dive into learning the basics now. Embrace

mentor others.”

hands-on learning, take certification exams, and get practical experience. It’s okay to be afraid when

Despite moments of uncertainty, persistence and

trying new things; some of the best growth happens

support guided her forward. “There were times I

when you step into tasks that feel challenging or

doubted myself, wondered if I was doing the right

uncomfortable. Follow your curiosity, trust the

thing, or felt like I wasn’t learning fast enough. What

process, and never stop pushing yourself. Even small

helped me navigate those doubts was a mix of

steps taken consistently add up to a big career.”

persistence and support. My bosses believed in me even on days when I didn’t believe in myself, and

In her current role as Manager & Team Lead for

that pushed me to keep going. Over time, small wins

Cybersecurity & Compliance Advisory at Digital

helped build my confidence, and those moments of

Encode Limited, Opeyemi finds fulfillment in both

uncertainty became part of the journey that made me

problem-solving and mentorship. “The aspect of my

more determined to grow.”

current role that brings me the most satisfaction is knowing that the work I do directly helps

For those transitioning into cybersecurity from

organisations stay secure and resilient. I enjoy

other fields, Opeyemi emphasizes curiosity and

analysing risks, identifying vulnerabilities, and finding

courage. “Embrace curiosity and be willing to

practical solutions that make a real difference. I

start from the ground up. Don’t be afraid to ask

also find fulfillment in guiding and mentoring others,

questions. Take advantage of hands-on experiences

whether it’s helping a team member understand a

and certification. Don’t let fear hold you back.

complex issue or advising clients on best practices.

With persistence, curiosity, and the willingness to

Being able to combine technical expertise with

learn, you can successfully pivot into a rewarding

advisory work gives me a sense of purpose.”

cybersecurity career.”

Looking ahead, Opeyemi anticipates rapid

Opeyemi Olaifa’s story is a testament to how curiosity,

developments in cybersecurity driven by technology

courage, and continuous learning can transform

and evolving threats. “AI will continue to change the

uncertainty into a fulfilling career in cybersecurity.

game, both in how attackers craft more sophisticated attacks and in how defenders detect and respond to

www.linkedin.com/in/opeyemi-olaifa-1b6b6114a

them. Staying ahead will mean using AI to anticipate threats rather than just react to them. Zero Trust will

I S S U E 28

WOMEN IN SECURITY MAGAZINE

23


Fathima Mohamed Thaseen Account Executive at Havas NZ

F

athima Mohamed Thaseen, an Account

immersed in cybersecurity. Each session expanded

Executive at Havas NZ, discovered her

my perspective and slowly built my confidence,

passion for cybersecurity long before she

helping me recognise that this was not just an

formally entered the field. “Growing up, I

interest, but a path I wanted to commit to.” A pivotal

was always drawn to technology; curious

decision came when she pursued a Master’s in

about how systems worked, how people interacted

Cybersecurity and Digital Forensics at Auckland

with them, and how easily they could be influenced

University of Technology, alongside professional

or manipulated,” she recalls. However, it was through

development through anti-fraud masterclasses and

her husband’s work in fraud risk management within

live training sessions in Dubai. “Each step reaffirmed

the banking sector that her curiosity transformed

my decision and strengthened my determination

into purpose. “Watching him navigate complex fraud

to build a meaningful career in cybersecurity,”

investigations, respond to emerging scams, and

she reflects.

protect customers from financial harm opened my eyes to the hidden battlegrounds of the digital world.

The journey has not been without challenges.

I saw how a single oversight could lead to significant

Balancing academic pursuits, part-time work in a new

loss, and how the right expertise could prevent it.

industry, and responsibilities at home as a mother

What started as curiosity slowly transformed into

to a three-year-old has tested her resilience. “These

motivation; I wanted to understand the mechanisms

challenges have shaped me just as much as my

behind these threats, not just observe them from

academic and professional achievements. They’ve

the sidelines.”

taught me resilience, discipline, and the importance of being intentional with my time. I approach my days

24

Fathima’s early steps into the field were deliberate

with structured planning, clear prioritisation, and a

and thoughtful. “In the beginning, I joined online

commitment to continuous learning. Instead of seeing

masterclasses, attended workshops, and surrounded

obstacles as setbacks, I view them as opportunities

myself with professionals who were already

to grow stronger, more adaptable, and more focused.”

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

Fathima candidly admits that doubt has been part

threats are identified and mitigated, making security

of her journey. “Yes, like many people transitioning

operations faster and more predictive. At the same

into a highly technical field, I faced moments where I

time, emerging technologies like quantum computing

wondered whether I could truly keep up with the pace

and advanced deepfakes will challenge existing

of change. Cybersecurity moves fast, and at times

security models, pushing organisations to rethink

that felt intimidating. But instead of letting those

authentication, encryption, and digital trust.” She also

doubts define me, I turned them into motivation.

warns that AI-driven social engineering and phishing

I leaned into continuous learning, connected

attacks will become increasingly sophisticated,

with professionals who generously shared their

and securing digital identities in IoT and cloud

insights, and immersed myself in workshops and

environments will be more complex than ever.

masterclasses. Over time, I realised that uncertainty is part of growth; and that determination matters far

Fathima stresses the importance of professional

more than having all the answers from the start.”

growth and ethical work environments. “Beyond remuneration, I prioritise opportunities that support

Her path, she explains, unfolded organically. “My early

growth and long term development. Mentorship,

exposure to fraud risk activities and learning through

strong research involvement, exposure to advanced

real-life experiences opened my eyes to the powerful

tools and casework, work-life flexibility, and ethical

link between cybersecurity and fraud prevention. As I

leadership are all key factors for me.” She attributes

learned more, I started to realise where my strengths

much of her inspiration to her husband, whose work

and passions aligned. Over time, that clarity shaped

in fraud prevention gave her a front row seat to the

my goals, guiding me toward specialisation in digital

real world impact of cybersecurity. “His experience

forensics and cyber fraud investigation; fields where I

handling high stakes investigations inspired me

felt I could create meaningful impact.”

to pursue a career where I could contribute in a meaningful way.”

When asked what advice she would give her younger self, Fathima is resolute: “I would tell my younger

For aspiring professionals entering the field from

self to nurture curiosity without hesitation; to explore

other backgrounds, Fathima has clear guidance:

technology boldly and trust in the learning process.

“Cybersecurity thrives on diversity; people enter this

Cybersecurity rewards those who are persistent,

field from countless backgrounds, and each brings

ethically grounded, and willing to solve difficult

unique strengths. Stay curious, be patient with your

problems. Every challenge is a stepping stone, and

learning, and build strong foundational knowledge.

the confidence to ask questions and try new things

Your previous experience is not a disadvantage; it’s

matters just as much as technical skill.”

an asset that can shape your perspective and enrich your contributions.”

In her current role, she finds fulfilment in applying knowledge to real-world scenarios. “The most

Fathima Mohamed Thaseen’s journey exemplifies

satisfying aspect of my work is seeing how theory

the blend of curiosity, resilience, and purpose that

comes alive through practical application. Whether

defines a modern cybersecurity professional. Her

it’s analysing digital evidence, interpreting network

story is a testament to the impact that dedication

behaviour, or uncovering traces of a cyber incident,

and continuous learning can achieve, proving that a

each task reinforces the importance of cybersecurity

meaningful career in cybersecurity is not just about

in protecting individuals and organisations.”

protecting systems, it’s about safeguarding people and making a tangible difference in the digital world.

Looking ahead, Fathima anticipates transformative developments in the field. “Artificial intelligence

www.linkedin.com/in/fathima-thaseen-b92620375

and machine learning will continue to change how

I S S U E 28

WOMEN IN SECURITY MAGAZINE

25


Ako Otudor Cybersecurity Analyst

A

ko Otudor’s cybersecurity journey started

something far more human. “The most complex

with a heartbreak, her first computer was

aspect is navigating imposter syndrome,” she

infected, ruined, files wiped like they’d

shared. Her approach has been both grounded and

never existed. “I became interested in

compassionate. To navigate, I read, ask questions,

cybersecurity after I got a virus on my

talk to my family and friends, pray and accept that it

1st ever computer,” she recalled. “I was devastated

is ok to not be perfect or not feel worthy of situations.

because my files were gone and I had to rewrite

Also, I have learnt not to feel bad about how I feel at

my university assignment paper from scratch.” The

any point in time. The goal is to keep moving even if it

frustration that came from that moment grew into

is one small step at a time.”

something far bigger. “Over time, my interest has grown from knowing about cybersecurity to helping

Her doubts weren’t limited to specific moments, they

others understand and protect themselves.”

showed up regularly along the way. “There were a lot of moments,” she said. “I got through them by

Curiosity quickly became her defining trait. Ako

talking to my family, seeking advice from mentors,

remembers the early phase of her journey as one

and praying”. She didn’t begin with a carefully plotted

powered by questions, persistence and boldness.

path, either. “My path unfolded organically. I started

“I asked a lot of questions. Nothing was too small

cybersecurity in the early days in my country so

for me to ask questions about,” she said. “I also

everyone was still trying to figure it out as a group

shadowed people. If you did something I was

and individually.”

interested in learning, I would hound you. I still do these things even now.”

If she could speak to her younger self, she knows exactly what she would say. “Read and make nerdier

26

As her career developed, she found herself wrestling

friends. Stop worrying, close your eyes and just go

not with firewalls or code libraries, but with

for it. No one is perfect.” She also believes aspiring

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

cybersecurity students need one thing above all hands-on practice. “Practicals In my country, unless you have guidance and steady access to the internet for personal study, you mostly get theory.” Looking at the future of the field, Ako doesn’t hesitate. “Quantum computing,” she said, when asked which developments will be most impactful in the next two years. As for threats, she’s watching two trends closely. “Use of AI in attacks and 3rd party attacks.”

"The most complex aspect is navigating imposter syndrome... I have learnt not to feel bad about how I feel at any point in time. The goal is to keep moving even if it is one small step at a time.”

Career progression, for her, is about more than a salary bump. “Company values, work culture, the job expectations as well as the company’s unofficial

prompt properly and it can be fun to see what I can do

reputation,” she said, are essential considerations. The

in such short periods of time.”

people who shaped her career run like a throughline across her journey. “My bosses over the years,” she

Her professional network has expanded through

reflected. “They have shown me how to manage

industry organisations. “I’m a member of ISC2, EC-

situations, people, and myself. I have learnt and I

Council and a bunch of others,” she noted. “These

am still learning how to balance all these factors in

associations have broadened my awareness of

decision making.”

current issues, given me access to training and events that have taught me so much as well as opened my

As she looks ahead, she sees leadership on the

social circle.”

horizon. “Managerial and business certifications,” she said, are next on her list. “A point comes when you

Ako has seen firsthand how the talent shortage

have to learn how to direct people to properly patch

impacts organisations. “There were projects and

the server and ensure that others understand how or

tasks that could not be done or done well because

can do the same.”

there weren’t enough skilled people,” she said. “An example was forensics.”

Despite everything she has achieved, what brings Ako the most joy is simple. “Learning something new,” she

For those transitioning into cybersecurity from other

said. “Cybersecurity is a fast paced field that always

fields, she offers reassurance rooted in experience.

has something to teach you.” To maintain balance,

“Every experience is valid. There is no such thing as

she relies on boundaries. “I have a mental start and

wasted time,” she said. “Cybersecurity is so broad and

closing time based on my work schedule.”

getting broader that there is a place for you even if others don’t see it yet.”

Staying sharp is a deliberate practice, shaped by constant input. “I subscribe to newsletters, LinkedIn

Ako Otudor’s journey is shaped by curiosity,

pages, social media pages as well as podcasts,”

persistence, humility and a deep desire to learn. Her

she explained. A typical day brings variety and

path may have started with a virus on a long lost

responsibility. “I am responsible for managing several

computer, but it has grown into something far more

platforms ranging from staff training, email security,

enduring: a career dedicated to protecting others,

cloud security as well as risk management. My

expanding knowledge and making space for the next

priority is ensuring that all tasks run smoothly.”

generation of cybersecurity professionals.

These tasks are increasingly supported by emerging

www.linkedin.com/in/ako-otudor

tools. “Right now, AI,” she said. “I am learning how to

I S S U E 28

WOMEN IN SECURITY MAGAZINE

27


continues to offer guidance and, at times, even push me beyond my comfort zone, which has led me to my current position as a CISO.” That leap into the CISO role, however, was not without hesitation. “My only uncertainty in my cybersecurity career was whether to apply for and accept the CISO position,” she admits. “I was quite content and enjoyed the position of Information Security Analyst for its technical and investigative aspects.” Ultimately, it was the encouragement of her support system that convinced her to take on the challenge. “I have

Jaime Schrepfer Chief Information Security Officer

a wonderful support system that reminded me that I have never backed down from a challenge and advised me to ‘get out of my own way’ and accept the natural progression of my professional journey.” Part of that challenge has been stepping into the business oriented responsibilities that come with

J

leadership. “My career path has primarily been technical in nature, so for me, the business aspects aime Schrepfer’s journey into cybersecurity

of my CISO role I find to be more challenging,” she

began not with a single defining moment,

explains. “Budgeting, employee performance reviews,

but with a growing fascination that

and vendor relations are areas of this job that I

blended technology and human behaviour

continue to work on and improve. Having a mentor to

in equal measure. “Cybersecurity is a

guide me through these aspects of the job has been

dynamic field of interest from both a technological

quite helpful for me.”

and psychological standpoint,” she reflects. “The

28

constant evolution of technology fuels my passion

Jaime’s path into cybersecurity was anything but

for continuous learning.” Her curiosity quickly grew

linear. She started in medical transcription before

beyond the technical, drawing her into the human

pivoting to IT, expecting a future in help desk roles.

side of cyber how people think, behave, and become

But her passion for learning pulled her deeper. “My

both targets and defenders. “I find the psychological

career has unfolded organically,” she recalls. “When

side of cyber particularly fascinating, from analysing

I pivoted away from medical transcription to IT, I

threat actor motivations and techniques to observing

envisioned a career of help desk-type roles. However,

end-user behaviours and patterns. This understanding

my passion for learning seemed to naturally progress

of the human aspect of cybersecurity enhances my

beyond help desk roles into more system and network

cyber defence skills.

administration and eventually to cybersecurity.”

Her career, however, was never the product of a

Today, she champions the importance of

rigid plan. Instead, it unfolded through opportunity,

building strong technical foundations for aspiring

guidance, and the courage to evolve. In the early

professionals. “My recommendation is to build a solid

years, she credits one person above all others for

foundation of IT knowledge. Understanding various

helping shape her trajectory. “I was fortunate to have

aspects of technology, from operating systems to

had a mentor who provided guidance as I navigated

networking concepts, is important when analysing

my early career,” she says.”To this day, my mentor

cybersecurity events or architecting security systems.”

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

She also recognises that cybersecurity is not a

I am interested in pursuing several certifications, such

one-size-fits-all industry. “This ultimately depends

as the CISA and CRISC from ISACA, which I believe

on the individual’s area of interest,” she says. “For

would be beneficial in my current role as CISO.”

example, a penetration tester needs to understand operating systems, software vulnerabilities, and

Balancing her demanding role with personal wellbeing

networking concepts, whereas a GRC analyst needs

remains an ongoing effort. “Work-life balance is

to understand regulations, human psychology, risk

indeed a challenge, particularly when balancing a

probabilities, and their associated impacts.”

full-time job with a full-time doctoral program,” she says. Her escape is found in creativity. “I try to find

As she looks ahead, Jaime is both optimistic and

time, even if just 30 minutes to an hour a day, for non-

cautionary about the future of cyber. She warns

technology activities. I grew up crafting, and counted

that organisations must finally shift from reactive

cross stitch is my favorite non technology outlet.”

to proactive defence. “Analysis of successful cyberattacks reveals that many organisations are

Professional growth also requires staying sharply

falling short in their cybersecurity fundamentals. I

informed. Jaime dedicates time every day to keeping

believe we can do better.” She also points to the rapid

up with the cyber landscape. “I have integrated

emergence of transformative technologies like AI and

research and threat intelligence into my daily work

quantum computing. “Governance of this emerging

activities. I dedicate a minimum of one hour a day

technology has been slow and has been unable to

to reading all the current news, trends, and threat

keep pace,” she notes. “Looking ahead, we must

intelligence feeds.”

anticipate the emergence of quantum computing and begin developing secure governance now, before our

She also invests heavily in her team, especially

current security mechanisms are rendered obsolete.”

in an environment where recruitment is difficult. “Staffing in local government is a challenge. Public

Quantum computing, she says, is poised to become

service typically cannot match the salary offerings

one of the most significant threats and opportunities

that private sector opportunities provide,” she

in the coming years. “This emergent technology

explains. “However, I have been fortunate to have

will bring forth significant positive advancements in

staff who have chosen public service.” To support

many areas of research, but it will also be utilized for

their development, she gets creative. “We analyze

malicious intent, as we have seen many times before.”

and discuss cybersecurity news articles as a team, random pop quizzes for certification study, and most

When evaluating new career opportunities herself,

recently, I hosted a game of Backdoors and Breaches,

Jaime looks far beyond the salary line. “I evaluate

which resulted in an immediate request for another

several factors,” she explains. “Company culture,

game session.”

work-life balance, commute time, remote work options, education reimbursement, training

For those entering cybersecurity from other careers

investments, employee turnover rates, and the

much like she once did Jaime offers reassurance

stability of the organisation.”

through her own lived experience. Her journey shows that there is no single “right path,” only the willingness

Her mentor continues to be a defining influence.

to learn, adapt, and stay curious. And above all,

“He was one of my favourite instructors during my

her story reinforces a truth she lives daily: growth

early IT education and has continued to mentor me

happens when you embrace the challenge.

over the past 13 years. In fact, we are both currently pursuing our doctorate degrees in cybersecurity

www.linkedin.com/in/jaimeschrepfer

together.” Her own professional development remains a priority. “Once my university journey is complete,

I S S U E 28

WOMEN IN SECURITY MAGAZINE

29


Fiona Martin Associate Director, Business Resilience

always encouraged to say ‘yes’ to new challenges, especially if they pushed my out of my comfort zone, which helped me to open doors and gain exposure to different aspects of the field.” She adds, “Putting yourself forward helps you build valuable connections

F

with new stakeholders. I found that building strong relationships and demonstrating a willingness iona Martin, Associate Director of

to work hard were key factors in advancing my

Business Resilience, describes her entry

career journey.”

into cybersecurity as “a happy accident.” Having started her career in finance within

Fiona candidly recalls moments of uncertainty in

the UK’s largest retail and commercial

her transition into cybersecurity. “Coming from an

bank graduate scheme, Fiona explored a variety of

operational background, I initially struggled with

operational roles before joining the Cyber Security

imposter syndrome when moving into cybersecurity.

team. “By happy accident I was introduced to the

I often felt underqualified, not technical enough, or

fascinating and complex world of cybersecurity,”

not intelligent enough for a career in this field. I also

she explains. Since then, her career has spanned

think, especially in the early days being a woman

policy, risk & controls, data, governance, engagement,

in a traditionally male-dominated environment

cloud adoption readiness, and ultimately Operational

also contributed to these doubts” Overcoming this,

Resilience. “It is within Operational Resilience that

she says, was largely thanks to mentorship. “I had

I have found my passion, bringing together the

fantastic role models and mentors, both male and

increasingly complicated worlds of technology,

female, who coached me to believe in my abilities,

security, critical third party risk and data, to build

recognize my unique skill set as a strength, and help

stronger, more reliable financial services for

me to deepen my knowledge of the field. I focused

customers,” she says.

on learning, building relationships and leveraging my strengths in strategic thinking and delivery. Over time,

30

Reflecting on the early stages of her career, Fiona

I realised that diverse experiences are an asset in

highlights the importance of actively pursuing

cybersecurity, and my passion for the subject helped

opportunities. “Once I discovered my interest in cyber

me adapt and thrive. Now, as I progress in my career, I

and resilience, I actively sought opportunities that

hope to support emerging cyber talent in finding their

would expand my knowledge and experience. I was

own confidence as they begin their journeys.”

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

Her career path has unfolded organically rather

and that’s okay. Learning is a journey that never stops

than following a pre-set plan. “When I started my

and pushing yourself to be uncomfortable is how you

career in cybersecurity, I didn’t have a clear vision of

grow and develop.”

exactly where it would take me and I still don’t! As new technologies like AI, quantum computing, IoT,

Maintaining balance and wellbeing is also important

and extended reality continue to reshape the digital

to Fiona. “My happy place is outdoors, and when I’m

landscape, the nature of cybersecurity and the roles

not at work I spend as much time as possible in the

within it are constantly evolving. Many of the most

fresh air! I am a keen runner, having completed three

important cybersecurity jobs of the future probably

marathons this year, including my first ultra, and find

don’t even exist yet. That’s one of the most exciting

this a huge stress reliever and balancer in my life. I

things about this career path, you never quite know

also keep boundaries between life and work, ensuring

what opportunities or challenges will come next!”

my time is my time and making sure I get outside before work, during my lunch breaks, and when I’ve

Fiona acknowledges the significant influence of her

finished to help shut off from the day.”

mentors, particularly her previous Chief Security and Information Officer, Sharon Barber. “Her presence was

Fiona’s advice for those transitioning into

remarkable; she was strong, passionate, and highly

cybersecurity from other backgrounds is rooted in

knowledgeable, yet always kind and genuinely people

adaptability and curiosity. “Embrace adaptability and

focused. As a strong female leader in a predominantly

a mindset of continuous learning. Leverage your

male environment, she stood out and inspired many,

transferable skills, whether technical or interpersonal,

including myself. She played a pivotal role in shaping

and seek out mentorship and networking

my career, offering guidance and advice, and I

opportunities. Don’t be afraid to challenge yourself

continually aspire to emulate her leadership. On top

and the status quo; curiosity and resilience are

of her professional achievements, she also won an FA

essential. Diverse experiences enrich the field and

Cup Final!”

drive innovation.”

Discussing the challenges of her current role, Fiona

For Fiona, cybersecurity is not just a career it’s a

reflects on her recent relocation from the UK to

journey of continuous learning, resilience, and impact.

Australia and her transition from the financial sector

Her path demonstrates that success in the field is

to consultancy. “One of the harder elements of

built not only on technical knowledge but on curiosity,

changing industry is learning how to operate in a new

strategic thinking, and the courage to step into

environment, with new people, new goals, new ways

the unknown.

of working, in a new industry and new regulations. A lot of new! One thing I always try to do is embrace the chaos, remind myself I don’t know all the answers

www.linkedin.com/in/fionamartin2023

" Over time, I realised that diverse experiences are an asset in cybersecurity, and my passion for the subject helped me adapt and thrive. Now, as I progress in my career, I hope to support emerging cyber talent in finding their own confidence as they begin their journeys.”

I S S U E 28

WOMEN IN SECURITY MAGAZINE

31


DeArne McWhirter Associate Director KPMG

D

eArne McWhirter’s journey into

Her current work in the banking and financial services

cybersecurity did not begin with a single

sector brings complexity at scale. “Integrating GRC

defining moment, but rather through a

adherence across multiple risk domains and uplifting

series of roles across technology and

enterprise reporting has been complex,” she says.

software enterprises, financial services,

Her approach is grounded in strategic planning,

and banking sectors where M&A transformation,

stakeholder engagement, and the continuous

risk and compliance were always close at hand.

embedding of governance and risk transformation.

“My interest was sparked through early roles in

These challenges strengthened the toolkit she now

financial services, where technology partnering

uses to guide organisations through regulatory and

with business strategy, risk and compliance were

operational pressures.

central,” she reflects. “Over time, this evolved into a deep specialisation in Financial Services Regulation

Despite a career built on expertise and continuous

and Licensing, outsourcing services, Fintech/

growth, DeArne acknowledges that uncertainty

Regtech, cybersecurity, regulatory engagement and

has been part of the journey. “Transitions between

operational resilience across finance, government and

sectors, such as from consulting to government or

consulting sectors.”

fintech, were challenging,” she shares. “I navigated these by upskilling, adapting to regulatory changes,

As her career gained momentum, DeArne made

and aligning my work with emerging cybersecurity

intentional choices to transform that early curiosity

needs.” Those shifts delivered both resilience and

into a clear professional path. “I pursued formal

perspective, shaping a career that grew organically

education and certifications in GRC, Technology,

but always with an underpinning of leadership

information management and cybersecurity” she

and GRC focus. “By joining industry and volunteer

explains, crediting her progression through financial

membership that collaborates in specific research

services and consulting roles with exposing her

and development I have found instrumental support

to M&A transformations, global standards and

in my journey.”

regulations, and digital transformation programs.

32

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

Reflecting on what she might tell her high school self, DeArne emphasises the value of starting early. “Start with foundational IT and risk knowledge, pursue certifications, and seek roles that offer exposure to both technical and regulatory aspects of cybersecurity,” she says. She highlights the joy of constant learning: “There is always something new to review and take into account in the cybersecurity landscape and how the environment is required

“By joining industry and volunteer membership that collaborates in specific research and development I have found instrumental support in my journey.”

to adapt.” Her perspective on education remains grounded

challenges signal growth: “Problems and challenges

in multidisciplinarity. “Always focus on the key

provide us with opportunities to investigate, improve

technology building blocks and top up on specialised

and advise.”

areas you have the most interest in or see the emerging industry need,” she advises. For her, the

Her professional influences span global banking and

combination of risk and compliance frameworks, data

consulting. “Roles in these sectors exposed me to

analytics, tooling, regulatory compliance, and risk

large-scale transformation, executive engagement,

management has proven essential.

and regulatory frameworks,” she explains. She credits exceptional leaders with shaping her strategic

Looking ahead, DeArne anticipates seismic shifts

approach: “I have been very fortunate to work with

across the cybersecurity landscape. “The integration

some incredible founders and forward-thinking CROs

of AI-driven risk management tools will become

that have been mentors of mine.”

increasingly mainstream, enabling faster threat detection and response but also introducing new

Her own development continues, guided by a

complexities in governance and oversight.” She

blend of academic and professional ambition.

also points to quantum computing’s economic and

“I’m continuing my academic journey with a Juris

security implications, noting that regulators must

Doctor and a Bachelor of IT specialising in AI

“find new ways to stress test systems and anticipate

and ICT,” she shares. Earlier studies, including

vulnerabilities in real time.”

an MBA with concentrations in Six Sigma Black Belt, Innovation, and Entrepreneurship, laid the

With acceleration comes risk. “AI-enabled attacks,

foundation. Certifications like CPRM, CRISC, and

particularly those leveraging generative models, will

CCSP have fortified her expertise. Her advice: “Formal

become more sophisticated and harder to detect,”

qualifications provide foundational knowledge, while

she warns. She sees supply chain vulnerabilities

targeted certifications offer agility and relevance in a

and regulatory lag as additional pressure points.

fast-evolving landscape.”

“The intersection of quantum computing, AI, and regulatory complexity will demand a proactive,

The greatest fulfilment in her role comes from

resilient approach, one that prioritises adaptability,

working at the intersection of technology, law, and

collaboration, and continuous learning.”

leadership. “I’m actively involved in research and implementation of emerging technologies particularly

When considering future opportunities, she

AI and quantum computing and their implications

looks beyond salary alone. “I would consider the

for cybersecurity, regulatory compliance, and ethical

organisation’s GRC maturity, leadership support,

governance,” she says. Shaping enterprise-wide GRC

scope for strategic influence, and alignment with

frameworks and influencing board-level governance

regulatory and innovation goals.” For DeArne,

are among her most rewarding responsibilities.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

33


Balancing such a demanding career requires

For those transitioning into cybersecurity, DeArne’s

grounding. “I maintain balance through physical

guidance is encouraging and pragmatic. “Start by

activity and community involvement, such as surf

identifying and leveraging your transferable skills,

lifesaving and competitive ocean paddling,” she says.

particularly in governance, risk management,

Off the water, she is an avid AFL fan. “Having grown

legal compliance and strategic communication.”

up in a non-AFL state and supporting the Sydney

Certifications and short-form courses can help

Swans since 1982, I’ve gone to most games, including

build credibility, and understanding frameworks like

seven grand finals.”

Cybersecurity Risk Institute (KPMG Strategic Partner), NIST and ISO 27001 is essential. “Cybersecurity is

Her days are structured around strategic

no longer just a technical function, it’s a board-level

engagement and risk alignment. “A typical day

priority,” she says. “The most successful transitions

involves coordinating with internal and external

happen when individuals combine their domain

stakeholders, reviewing and refining enterprise-

expertise with a commitment to continuous learning,

wide GRC frameworks, and translating regulatory

collaboration, and ethical leadership.”

developments into actionable practices,” she explains. She stays current through academic research,

DeArne’s journey is a testament to adaptability, vision,

emerging technology insights, and participation in

and the power of weaving together multidisciplinary

industry forums.

expertise. Her career path may have unfolded organically, but her purpose has remained clear: to

Technology remains central to her effectiveness.

strengthen resilience, elevate governance, and guide

“GRC platforms, SIEM tools, data analytics

organisations through the evolving complexities of

technologies, and compliance systems aligned

cybersecurity with integrity and insight.

with standards and regulations (global and local) are pivotal,” she says. She also continues to draw value from professional networks and associations.

www.linkedin.com/in/dearne-m-91903817a

“I gain access to thought leadership, training, and regulatory updates.”

34

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


Want to get matched with Lead Gen experts but dont know where to start?

Our solution experts can help you find the right supplier, Looking to streamline your B2B lead generation process?

Want to use multiple suppliers but dont have time to coordinate? Need a consistent stream of leads coming into the sales team? Looking to tap into new markets? Need end-to-end lead nurture programs?

LET US HELP YOU OVERCOME YOUR LEAD GEN CHALLENGES REACH OUT TODAY FOR AN INSTANT QUOTE. The team at Source2Create has all the necessary skills to get the job done for you, so your time can be reserved to focus on other things.

With:

aby@source2create.com.au charlie@source2create.com.au source2create.com.au


Soledad Antelada Toledano Security Advisor, Office of the CISO, Google Cloud

F

or Soledad Antelada Toledano, Security

“I quit my job, packed my bags, and bought a ticket

Advisor in Google Cloud’s Office of the

to San Francisco in 2010 after enrolling in a Network

CISO, cybersecurity wasn’t a career

Security degree from CCSF,” she recalls. “I invested all

she selected, it was a destination she

my savings into a future I couldn’t even see yet.”

arrived at by relentlessly following her

own curiosity. “I didn’t plan to enter cybersecurity, it

Arriving in the United States stripped her back to the

happened because I kept asking questions no one

essentials. She was learning English and hacking

around me could answer,” she reflects. What began as

simultaneously, translating concepts as fast as she

an instinctive need to understand how systems work

was absorbing them. “I wasn’t just learning how to

and how they fail eventually became the backbone

execute a buffer overflow; I was learning how to say

of her professional purpose. Over more than two

‘buffer overflow’ in English.” The hands-on nature of

decades, she has moved through technical, strategic,

the program was exactly what she craved breaking

and leadership roles, shaping security practices that

things, experimenting, understanding through doing.

are transparent, collaborative, and designed to scale

That intensity paid off when a professor recognised

safely in an increasingly complex world.

her drive and recommended her for an internship at Lawrence Berkeley National Laboratory (LBNL).

The turning point in her career came with a leap that

“I went from learning about networks to defending a

most would have considered impossible. After nearly

network used by Nobel Prize winners,” she says. She

ten years as a software developer in Spain, she felt

became the first woman in the lab’s cybersecurity

boxed in, staring at a career that was comfortable

department, an intimidating milestone that taught her

yet uninspiring. The hacker culture she saw in films

a value she carries today: “Audacity is a security skill.

sparked something deeper, a fascination with the

You have to be willing to ask questions and admit what

unknown world beneath the surface of technology.

you don’t know so you can fix it.”

But access to that world didn’t exist where she was.

36

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

Her journey, however, was not without uncertainty, just not in the way many expect. “There were many challenges along the way but I decided to stop trying to be the ‘smartest’ person in the room and decided to be the most persistent,” she says. That

J O U R N E Y ?

“ Audacity is a security skill. You have to be willing to ask questions and admit what you don’t know so you can fix it.”

persistence became her anchor. Navigating unfamiliar environments, working alongside scientists exploring the origins of the universe, and securing data of global importance required humility and grit. “The

Tomorrow’s cyber leaders will be interdisciplinary

moment I accepted that ‘I don’t know, but I will find

by necessity.

out’ is a perfectly acceptable answer, it helped a lot.” It also reinforced a truth of cybersecurity: nobody

Despite the scale of her work and the high-pressure

knows everything, but everyone must be willing to

environments she has operated in, what fulfills her

keep learning.

most is profoundly grounded. “The most profound source of satisfaction for me is the undeniable impact

Her career path unfolded not through rigid planning

that comes with securing the public sector,” she

but through following her intellectual instincts. “If I

says. “We are safeguarding the critical infrastructure,

had stuck to a rigid plan, I would have limited myself,”

the power grids, water systems, and transportation

she says. What emerged instead was a web of

networks that underpin civil society.” Knowing

roles spanning ethical hacking, penetration testing,

her work helps keep communities safe gives her

vulnerability management, security operations, and

a sense of purpose that transcends job titles or

leading a High-Performance Computing security

technical achievements.

team. She has managed hundreds of incident responses, implemented device security programs,

But sustaining that impact requires balance,

and even led security for a U.S. presidential political

something she had to learn deliberately after years

campaign, an unexpected pivot that demanded both

of high-intensity incident response. “Taking care of

technical depth and strategic resilience. With most

yourself should be a part of the job description for

of her career dedicated to serving or supporting the

every security role,” she insists. Chronic, unspoken

public sector, she remains committed to that mission.

stress is a quiet hazard in the industry. She learned to rest before burnout, to step away without guilt,

Looking ahead, Soledad is clear-eyed about the

and to trust her team through intentional delegation.

forces reshaping cybersecurity. The rapid evolution

“Delegating doesn’t just save you; it empowers

of agentic AI, capable of autonomous reasoning

greater impact.”

and action, will fundamentally transform the speed of defence. Attacks on critical infrastructure water

Soledad’s journey is defined by courage, the courage

systems, power grids, transportation networks will

to uproot her life, to enter rooms where she was the

escalate, pushing governments toward stricter

only woman, to admit what she didn’t know, and to

resilience mandates. And with quantum-resistant

follow curiosity over certainty. Her career stands

cryptography on the horizon, organizations must

as a testament to what happens when persistence

urgently catalogue and protect their cryptographic

becomes a discipline and audacity becomes a tool

assets before adversaries exploit the window of

for change.

vulnerability. These shifts, she believes, demand professionals who understand not just networks but code, policy, human behavior, AI, and data science.

I S S U E 28

www.linkedin.com/in/soledad-antelada-toledano

WOMEN IN SECURITY MAGAZINE

37


Cassandra Mack Chief Information Security Officer (CISO), TensorWave

I

n the world of cybersecurity leadership, few stories

and they tell me a similar story. We’re all working to

capture resilience, reinvention, and unapologetic

get past our imposter syndrome and make a dent in

determination quite like that of Cassandra Mack,

the work we need to do.”

Chief Information Security Officer at TensorWave. Her journey did not begin with firewalls, threat

Transforming this interest into a real career required

hunting, or penetration testing. Instead, she started

grit. Cassandra spent years studying for what she

in risk management and compliance at a time when

describes as the “gold standard” certification failing

“cybersecurity” wasn’t yet a household term.

it four times. Many would have stopped there; Cassandra did not. “I finally figured out that the

Cassandra recalls a defining moment early in her

journey of a thousand miles was the thing I needed

career, when self doubt nearly convinced her that

to get enough confidence to go for my first CISO job,”

transitioning from project management into security

she says. Ironically, once she landed the job, she

was beyond her reach until a mentor pulled her aside.

realised the certification itself wasn’t the key. “I didn’t

“She told me, ‘you’re better than this!’” Cassandra

need the cert. I just needed to realise I had what it

says. “It took me a while to take her words to heart, but I eventually made my way over and haven’t looked back since.” Her early curiosity transformed into something deeper as the field evolved. “I find it more fascinating now that it’s moving and evolving so fast,” she says. And even as a seasoned CISO, she’s quick to acknowledge a universal truth among peers: “Sometimes I think I’m

“ I finally figured out that the journey of a thousand miles was the thing I needed to get enough confidence to go for my first CISO job.”

getting way behind, and then I talk with another CISO

38

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


W H A T ’ S

H E R

J O U R N E Y ?

“ I truly believe the hands-on real-world experience I got made all the difference. Technical expertise helps you speak the language of engineers. There’s a certain level of respect that comes when you can speak their language.”

took to get started and build on my knowledge over

world experience I got made all the difference,”

time. Perseverance is what made the difference.”

she says. “Look for programs with professors who actually work in the field. Technical expertise helps

Like many in the field, Cassandra faced periods

you speak the language of engineers. There’s a certain

of uncertainty none more challenging than the

level of respect that comes when you can speak

moment the calls simply stopped coming. “For the

their language.”

first time, I genuinely doubted if I was still worthy of the ‘CISO’ title,” she says. To support her family, she

Looking ahead, Cassandra sees seismic shifts

took on multiple smaller jobs at once and revived

on the horizon. “AI is going to severely speed up

her consultancy. “It was a grind,” she admits. “But I

implementation, analysis, and actioning of alerts,”

compressed four or five years of experience into two.”

she predicts. “It’s going to make enterprise-level tools affordable for small businesses. But it’s also speeding

That difficult chapter brought an unexpected reward:

up the abilities of the bad guys.” She also warns that

community. “I started getting invited to boards and

quantum computing is nearing the ability to crack

councils, and I eventually became a host for the

modern encryption: “We’re a few years at most away

National and Virtual Cyber Breakfast Clubs,” she

from breaking RSA.”

explains. The experience rebuilt her confidence and expanded her influence. “Sometimes, you have to take

When asked about emerging threats, she points again

a step back to sprint forward.”

to AI-powered attackers. “The bad guys now have more power to do stupid things really fast,” she says.

Her ambition to become a CISO had always been

She also highlights the need for stronger vulnerability

clear even before she knew how to get there. “I’ve

management and the rising importance of cyber

always had my eye on the C-suite,” she says. “I

risk quantification. “It’s a matter of prioritisation and

meandered my way there over time, with a lot of

understanding how to use tools to identify what is

guidance and a lot of monkey-see, monkey-do.”

most important. CRQ will help direct spending where

Training, conferences, and hands-on consulting roles

it’s needed most.”

steadily shaped her into the leader she is today. For CISOs evaluating new roles, she urges caution If she could speak to her high-school self, Cassandra

beyond salary. “You want to look at whether you’re

knows exactly what she’d say: “Your outright belief in

covered under D&O insurance,” she says, pointing to

yourself paid off. It took longer for you to climb the

real-world cases that have devastated executives.

ladder, but that broad skillset helps you every day. I

She’s equally candid about mental health. “Burnout in

have no regrets. I appreciate what it took to get here.”

cyber is real. I developed a bit of a drinking problem myself and successfully sought treatment. My biggest

Education played a major role in that development.

advice: develop healthy coping mechanisms, and seek

Her time at DeVry and Keller Graduate School stands

help if you need it.”

out as formative. “I truly believe the hands-on real-

I S S U E 28

WOMEN IN SECURITY MAGAZINE

39


“ Sometimes you have to take a step back to sprint forward.”

Her typical day spans contracts, questionnaires, tool analysis, vendor conversations, audits, security events, and team development. Strategy and planning remain weekly priorities. “Revisiting budgets is important to gain and keep the top-down support I

Her greatest career influence is her mentor, Dasha

need,” she says.

Davies. “She believed I was better than what I was doing,” Cassandra says. “She encouraged me through

Her most valued tools are those that offer an

failed CISSP attempts, difficult projects, and set a

aggregated organisational view, automate compliance

great example of what an expert should strive to be:

work, or support risk quantification. “Justifying

resilient, always learning, excellent, and humble.”

spending based on real-world scenarios is crucial,” she explains.

Cassandra holds several ISACA certifications, with CISM standing out as the most impactful.

Cassandra stays deeply involved in the industry

In her current role, she finds joy in teamwork and

through ISACA, The Cyber Breakfast Club, The CISO

meaningful progress. “I especially enjoy putting tools

Society, Carnegie Mellon’s Executive CISO Group,

and processes in place that work for the business, not

and ISSA.

just for compliance. And I love when someone brings a security concern to me that means our hard work to

When it comes to the skills shortage, she points to

educate is actually working.”

infrastructure security architects with DevSecOps knowledge as particularly hard to find as well as

To stay balanced, she prioritises reading, friendships,

professionals who can say “yes, and” instead of being

sobriety, time with her children, and travel. “Getting

the classic “Doctor No.”

away and seeing new things really inspires me to do better,” she says.

To career changers, she offers firm but encouraging guidance: “Don’t be scared. Commit and go. You

Professionally, she stays informed through peer

absolutely can do it, but don’t expect it overnight.

Slack groups, industry bulletins, white papers, and

You need a few years, potentially a degree or

an unexpected resource. “Admittedly, I use Google

certifications. You’re not going to transition with a

Gemini on a daily basis,” she says. “It helps me

weekend bootcamp.” She also advocates for strategic

understand how things work and put explanations

mobility: “Keep moving every 18 months if you aren’t

into simple terms.”

getting challenged. It’s ok to move when you’re growing just remember that at senior leadership levels, we want to see staying power.” Cassandra’s journey is a testament to persistence, courage, and the power of taking the long way around. As she says herself, “Sometimes you have to take a step back to sprint forward.” And in her case, every step forward or back has led her exactly where she was always meant to be. www.linkedin.com/in/cassandramack-lasvegas

40

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


EXCLUSIVE

ADVERTISING PACKAGE For the past four years, Source2Create has proudly delivered Women in Security Magazine to the industry free of charge, championing diversity, inclusion, and the incredible contributions of women in cybersecurity. As we continue to grow, we now need partners to help us sustain and expand this vital platform. By supporting this package, you’re not just backing us—you’re investing in the magazine, its community, and the future of women in security. To ensure we can keep delivering this high-value publication, we’re introducing a nominal fee for $900 Ex GST, an exceptional package that provides extensive coverage and visibility.

WHAT'S INCLUDED? OFFICIAL PARTNER RECOGNITION Your logo will be prominently displayed at the beginning of the magazine in our “Partner of the Issue” panel.

GLOBAL AUDIENCE REACH Your brand will be seen by 5,000+ global subscribers through our free, bi-monthly digital publication, dedicated to supporting and showcasing women in security.

2 FULL-PAGE ADVERTS Feature your brand in two issues of your choice between March and December.

2 JOB POSTINGS Advertise up to two job opportunities in the magazine and across our social media platforms, reaching a highly engaged cybersecurity audience.

ONLINE BANNER ROTATION on WomenInSecurityMagazine.com

This high-value package ensures maximum visibility for your brand while directly supporting the continuation of Women in Security Magazine.

Join us in making an impact—partner with us today!

EMAIL JANE@SOURCE2CREATE.COM.AU


CRAIG FORD Craig is an experienced cyber security professional with various qualifications including two master’s degrees. He is the Head Unicorn (co-founder and director) of Cyber Unicorns, in which he acts as a vCISO to clients such as Baidam Solutions, Wesley Mission, PCYC, Hungry Jacks and Ipswich City Council. He was CTO (Chief Technology Officer) for Baidam Solutions between January 2022 to June 2023, where he led the technical services team, helping to build out the internal services capability for Baidam. Craig was QLD chair for AISA for two years until he was appointed to the national board of directors in December 2022.

Simon says “freeze” I am not sure if you all know this game. Many moons

Now, close your eyes and try to imagine a common

ago, when I was in primary school here in Australia,

scenario in the cybersecurity industry.

we would play the game Simon Says. In the game you have someone who is ‘Simon’ who directs all other

You are a new graduate or career changer. You have

players to do things. For example: “Simon says touch

spent years, or maybe, if you have been lucky, just

your nose,” or “Simon says stand on one leg.”

months preparing for your change. You score that elusive position. It could be in GRC, red teaming or

Simon would try to trick people by saying, for example

SOC. You get your foot in the door.

“Touch your toes” without preceding this instruction with “Simon says.” Those who followed such an

Now, Simon says “freeze,” and you do not move

instruction would be kicked out of the game, and

a muscle.

the game would continue in this way until only one person remained.

You have made it, you are in, and it’s very common for people to freeze at this point. They will not change

You are all probably reading this, thinking: “Craig,

path. They will not pivot to another area for 5-10

have you lost your marbles? What has Simon Says

years. They pigeonhole themselves. They will commit,

got to do with cybersecurity or the theme of this

even if they hate the first position they have gained.

edition, Pivot?” I get the reservation. I get the instinct to become that Well, honestly, nothing (shoulder shrug emoji).

statue, I really do. I have been there myself. You get the opportunity you have been working so hard to get,

But, like my article in which I connected cybersecurity

one you have put so much investment into gaining.

to the story of the three little pigs, just because there

You don’t want to do anything to jeopardise your

is no direct link, doesn’t mean I can’t be a little creative

success in any way.

and pull us all in for some entertainment and a bit of nostalgia.

Now, I am going to give you some advice, which you can take or leave. If you get that first job and you don’t

Okay, so my link to Simon Says: I want to draw your

love it, don’t quit. That isn’t the best thing to do. What

attention to one common command or request in

I suggest is: make the most of your opportunity. You

Simon Says, and that is “Simon Says Freeze.” Given

are now on the inside. Things can get easier from this

this command, everyone would have to freeze in the

point. What you need to do in this situation is to make

exact, current, position . (Definitely easier said than

sure you do not pass up opportunities to step outside

done, I can tell you from experience. Especially if you

your lane in the organisation you have joined. Allow

are at a strange angle and you have a few directions

yourself to be seen as someone who will step up to

to trick you without the Simon Says).

the plate and give things a go, to put everything you have into it and learn fast.

42

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


Craig is a published author with three different book series – ‘A Hacker I Am’ cyber education series, ‘Foresight’ is his Cyberpunk/hacker fantasy novel series and then there is ‘The Shadow World’, a co-authored kids cyber education book. He is a freelance cyber security journalist and is a regular columnist with the Women in Security Magazine, as well as a freelance contributor for Cyber Today, Top Cyber News, SecureGov, Careers with STEM and Cyber Australia magazines.

C O L U M N

Then, keep doing that, over and over again. You will

Maybe you do not wear as many hats as I, but do you

gain new skills. You will discover other roles in which

get where I am going with this? Be open to pivoting.

you excel, and can explore to see if pivoting in the

Be open to opportunities as they arise, and don’t be

industry is something you want to do.

afraid to say you don’t like something. Adapt, change your path and keep moving forward.

Being open to pivoting instead of being frozen as in Simon Says, or in the game of Statues (another you

Simon (Craig) says “Go and be amazing. You all have

may have played as a child). You can be flexible and

it in you to break through, to succeed. So go do it.”

find your happy place. I know you might be sitting there thinking: “Craig, that

www.cyberunicorns.com.au

is easier said than done.” Yes, it is. Look at my career. Look at the different things I have done, and still do. I

www.linkedin.com/in/craig-ford-cybersecurity

write. I teach. I have done pentesting and SOC work. I am a CISO. I talk on the stage almost every week. I

www.facebook.com/CyberUnicorns

love the variety and the difference I can make through these diverse activities.

I S S U E 28

www.instagram.com/cyberunicorns.com.au

WOMEN IN SECURITY MAGAZINE

43


INDUSTRY PERSPECTIVES


ADRIANA JONES

PIVOT: TURNING PAIN INTO PURPOSE THROUGH TECHNOLOGY by Adriana Jones, engineer, cybersecurity advocate and founder of The Innocent Souls Project (TISP)

There are moments in life that split you in two: the

This was the turning point that transformed my story

person you were before and the person you become

into a mission to protect children.

after. For me, that moment was created as a result of reality I never chose, but one that set the path I would

FROM ENGINEERING TO CYBERSECURITY: A JOURNEY OF REINVENTION

take for the rest of my life.

My journey began in Guatemala, where in 2016 I

surviving child sexual abuse many years prior. It’s a

became the first woman in my intake to graduate with

46

For years, I wrestled with silence. Then one day, I

a degree in civil engineering. At the time, my focus

decided silence wouldn’t protect me, but speaking up

was on infrastructure; how to design and build safer

might protect someone else. That decision became

environments in the physical world. I didn’t know that

my pivot, the turning point where pain met purpose,

one day I’d be designing systems of a different kind;

and purpose found its voice in technology.

ones that would protect children in the digital world.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

After moving to Australia, I found myself navigating both a new country and a new chapter in my life. I continued to learn and grow, completing advanced diplomas in leadership and ministry (2017–2019) and in project management (2022). These studies helped me build not just technical skills, but resilience, empathy and vision; qualities that would later shape my approach to technology and leadership. In 2024 a major opportunity arrived. I was selected as one of just 34 women across Australia to receive a national cybersecurity scholarship from the Institute of Applied Technology (IAT), an incredible initiative empowering woman to enter and excel in cybersecurity. That scholarship became the doorway to further micro credentials in security management leadership, human aspects of cybersecurity and other fields that aligned perfectly with my growing mission:

What began as a personal mission quickly evolved

to protect children through education, awareness

into a professional ecosystem. I realised that, while

and innovation.

the digital world offers many benefits to humanity, it also exposes the most vulnerable, children, to dangers

I’m now completing my master’s in cybersecurity,

that many adults aren’t equipped to recognise

deepening my expertise and sharpening my ability

or avoid. These range from online grooming,

to lead ethical, practical and people-focused

cyberbullying and exposure to harmful content to

safety technology projects. Each qualification and

cybersecurity threats, data misuse and the growing

scholarship has been a stepping stone, not just in my

issue of AI-generated child sexual material.

career, but in my calling.

BUILDING SAFETY THROUGH EDUCATION AND TECHNOLOGY

THE BIRTH OF THE INNOCENT SOULS PROJECT (TISP)

Under TISP, I developed Cybersafety, a cybersecurity

In 2025, I founded The Innocent Souls Project (TISP),

awareness program tailored specifically for childcare

an initiative born from conviction, innovation and

professionals, educators and parents. Unlike generic

courage. TISP is more than an organisation; it’s a

online safety training, Cybersafety connects three

movement designed to bridge the gap between the

essential pillars: cybersecurity, eSafety and physical

online world and the physical world.

safety, showing how digital threats can quickly translate into real-world risks.

Our mission is simple yet profound: to equip parents, childcare providers, educators and carers with the knowledge and tools to keep children safe in the digital age.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

47


Pro te ct in g O

n re ild ch

nl

in

e

an

do

f fli n

e

WE HAVE ESTABLISHED A NEW STANDARD FOR CHILD PROTECTION THAT INTEGRATES CYBERSECURITY, ESAFETY, AND PHYSICAL SAFETY TRAINING. Contact Us www.theinnocentsoulsproject.com.au


I N D U S T R Y

P E R S P E C T I V E S

The content is concise, practical and continuously

This approach has allowed TISP to engage with

updated to reflect emerging cyber threats and eSafety

students, professionals and government officials,

challenges. Most importantly, it’s accessible We’ve

sparking powerful discussions about how technology,

partnered with a leading cybersecurity awareness

creativity and ethics intersect in child protection. It

platform to make the program compliant, scalable

has also shown that innovation doesn’t have to be

and easy to use across the childcare industry.

cold or corporate; it can be human and heart driven.

In parallel, I began creating free digital books for

THE RIPPLE EFFECT OF PURPOSE

children, written in a way that makes learning about

Since founding TISP I’ve witnessed how one story,

safety approachable and engaging. Every child

when told with authenticity, can inspire many others.

deserves to understand how to protect themselves

I’ve seen survivors find strength in knowing their

online, no matter their background or resources.

voices matter. I’ve seen educators and parents realise

Through storytelling, I’m ensuring no child is left

that cybersecurity isn’t just an IT issue, it’s a child

behind in learning how to stay safe.

safety issue.

LEADING WITH INNOVATION, EMPATHY AND VISION

And I’ve seen professionals from across sectors unite

My leadership philosophy is rooted in one belief:

for good.

around one shared belief: technology can be a force

technology must serve humanity. My call to action is this: let’s continue building a world At TISP our technology strategy is built on three

where technology protects, not harms.

key pillars. Let’s design systems that reflect our values, not only 1.

2. 3.

Protection: ensuring every initiative actively

our capabilities. Let’s ensure that every child grows

safeguards children and empowers adults to

up in a digital world that is safer, smarter and kinder,

become effective first line protectors.

because we made it so. For me, protecting children

Accessibility: making education and awareness

isn’t just a profession, it’s a purpose and the pivot that

tools simple, inclusive, and widely available.

changed my life forever.

Innovation: applying creativity and forwardthinking technology to prevent harm.

These pillars guide every project and partnership we undertake. Whether we’re designing new safety modules or consulting with cybersecurity leaders, our focus is always the same: protect children, empower

au.linkedin.com/company/tisp-the-innocent-souls-project

www.instagram.com/tisp_project

theinnocentsoulsproject.com.au

carers with the right tools, and drive cultural change.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

49


JO STEWART-RATTRAY

PIVOTING WITH PURPOSE: WOMEN REDEFINING LEADERSHIP IN CYBERSECURITY’S NEXT ERA by Jo Stewart-Rattray, Oceania Ambassador, ISACA A pivot isn’t a U-turn. It’s defined as a deliberate

bias (and still do), managed limited representation

realignment to stay balanced while things change

(and still do) and juggled competing demands (and

around you. Over three decades working in technology

still do), all while continuing to advance, advocate

and security, I’ve watched the industry pivot over

for and mentor one another. In the face of these

and over again. We’ve gone from cleaning up after

challenges our ability to adapt became one of our

a virus strike to hunting threats before they appear;

greatest strengths, especially for those of us on the

from defending the perimeter with simple firewalls

frontline during the pandemic, which produced lasting

to questioning every user and device in a zero-

changes to how we work.

trust world. ISACA’s 2025 Tech Workplace and Culture Study

50

Meanwhile, threats have grown more sophisticated.

shows how far we’ve come and how far there is to go.

What began as simple mischief has evolved into

More than a quarter of women surveyed (27 percent)

targeted ransomware and supply chain attacks that

said they faced gender or diversity bias when entering

can bring an organisation to its knees. And, where

the tech industry, compared with just four percent of

defence was once manual and rules-based, we

men. More than one in three women say they have

now use AI-based toolsets to detect anomalies and

experienced gender discrimination at work, a rate four

respond in real time.

times higher than for their male peers.

HOW WOMEN HAVE ALWAYS PIVOTED

These numbers paint a picture that many of us

For women in cybersecurity, the act of pivoting is

already know firsthand. For years, women were

nothing new. Many of us have forged careers in an

discouraged or excluded from STEM pathways,

industry that wasn’t built with us in mind. We’ve faced

denied access to the same resources as men, and

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

left without visible role models in leadership. Even

more accurately and bring broader perspectives to

today, women in tech are more likely to feel isolated,

newer technologies like AI and quantum computing.

to question whether they belong, and to struggle with

Companies that understand these benefits of diverse

re-entry after taking time out of the workforce to raise

teams are tying inclusion to leadership accountability.

the next generation. Pay gaps, long hours and a lack

In my opinion, this has the potential to create long-

of flexibility still drive many talented women to leave

lasting change.

the workforce.

FROM COMPLIANCE TO INFLUENCE A PIVOT IS UNDERWAY

One of the most important pivots we’re seeing in

However, the industry is pivoting, slowly.

the industry is the slow shift from compliance to

Educational institutions now offer more programs for

influence. Boards still ask, “Are we compliant?” and

women and girls in STEM, companies are introducing

rightly so, but the conversation is beginning to

mentorships and leadership pathways, and more

broaden. Increasingly, they’re also asking, “Are we

women are stepping into governance, privacy and risk

resilient?” and “What is the risk of...?”

roles where they can influence policy and culture. The more progressive boards are starting to ISACA’s 2025 Tech Workplace and Culture Study

recognise that resilience requires decisions to be

validates this. It shows 41 percent of employers now

made well before a crisis hits. For example, whether

have programs to hire more women into technology

to pay or not to pay a ransom is a governance

roles, and almost half have initiatives to promote

question that must be settled long before an

women into leadership roles.

attack occurs. Yet, in many organisations, those conversations still haven’t happened. Real leadership

The barriers women face in technology did not

in this space means developing a clear risk appetite,

form overnight, and they won’t disappear without

defining where responsibility sits and ensuring boards

sustained effort. I applaud organisations that realise

understand the implications of their choices before

diverse teams make better decisions, anticipate risk

the pressure is on.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

51


ISACA’s focus on digital trust reflects this

women’s contributions while building pathways for

transformation. It recognises that cybersecurity

the generations to follow. The program connects

cannot be siloed from ethics, privacy, risk

women through mentoring, networking and leadership

and sustainability.

development, equipping women at every stage of their career with confidence and skills.

Pivoting from compliance to influence means translating technical issues into language business

PIVOTING TOWARD PURPOSE

leaders understand. It’s about showing not just how

When I think about my own career, and the many

to manage risk, but why it matters to customers,

women I’ve had the privilege to mentor, the pivots that

investors and the wider community.

mattered most were never just about technology, they were about people and purpose. After decades in this

TECHNOLOGY PIVOTS

field I’ve learnt that the most resilient professionals

AI has been the most profound pivot point of the past

are those who stay true to their values while pursuing

few years. ISACA’s 2025 AI Pulse Poll found that,

their professional goals.

while 81 percent of professionals report AI is already being used in their workplace, only 28 percent of

For women in security, pivoting with purpose means

organisations have a formal AI policy. The speed of

embracing change as an opportunity to shape what

adoption has outpaced the frameworks designed to

comes next, whether that’s by leading, influencing or

keep it safe.

ensuring trust sits at the centre of technology.

This is where the ability to learn quickly becomes a mark of real leadership. ISACA’s Advanced in AI

ABOUT THE AUTHOR

Security Management (AAISM) credential is one

Jo has over 25 years’ experience in the security

way our profession is formalising how we govern AI.

sector. She consults in risk and technology issues

It’s equipping leaders to handle AI-related security

with a particular emphasis on governance and

risk, ensure transparency and make sound ethical

cybersecurity as a director with BRM Advisory.

decisions. For women looking to broaden their

Jo is the Oceania Ambassador for global IT

influence, becoming well versed in AI governance and

professional association, ISACA, and an ISACA

AI-centric security management represents a natural

Hall of Fame inductee. Jo is the former Vice

pathway to do so.

President, Communities of the Australian Computer Society and Ambassador of the

The next pivot will arrive with quantum computing.

National Rural Women’s Coalition. She regularly

The encryption methods that protect our data today

provides strategic advice and consulting to the

may be obsolete tomorrow. Forward-thinking leaders

banking and finance, utilities, healthcare, tertiary

are already scenario-planning for that disruption.

education, retail and government sectors.

PIVOTING THE PIPELINE The industry’s future depends on our ability to pivot

www.linkedin.com/in/jo-stewart-rattray-gaicd-4991a12

the pipeline itself. To attract, retain and uplift a more diverse generation of professionals. Mentoring programs, scholarships and rural outreach initiatives are part of that effort, but so is visibility. When young women see leaders who look like them at the helm of security teams and boards and committees, they see possibility. At ISACA, initiatives such as SheLeadsTech continue to spotlight

52

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


UNLEASHed

? us in jo to y ad re . 26 20 . ne ur bo Mel Step into the spotlight as a champion of Australia’s vibrant, diverse, and resilient security sector. By joining the Australian Women in Security Awards as a sponsor, you’ll be recognised as a leader driving innovation and inclusion—while supporting the remarkable trailblazers shaping cyber, IT, and protective security. Help foster a future where everyone can thrive.

Become a sponsor. Register your interest today! Contact Aby at aby@source2create.com.au womeninsecurityawards.com.au


JOANNE COOPER

SOCIAL MEDIA AGE ASSURANCE FOR CHILDREN UNDER 16: WHAT IT MEANS FOR AUSSIE PARENTS By Joanne Cooper, Founder - ID Exchange

In today’s hyperconnected world children are growing

The trial is being led by the Australian eSafety

up with smartphones in their pockets and social

Commissioner, Julie Inman Grant, and is focused on:

media accounts before they can legally drive. While the internet offers incredible opportunities to learn,

• keeping children safe from online harm.

connect and play it also presents serious risks for

• limiting access to adult or inappropriate content.

our children and teens, especially from online data

• reducing exposure to advertising and profiling.

collection, surveillance and manipulation of young

• ensuring social media platforms comply with

forming minds.

online safety laws.

That’s why the Australian Government’s Age

This is a starting point. More measures need to be

Assurance Technology Trial (AATT) to introduce a

considered to develop powerful, legally recognised

social media ban for children under 16 is a vital step

data rights mechanisms to control how a child’s

forward, and why parents need simple, enforceable

personal data is shared, sold or used in both online

tools to stay in control and protect their children from

and offline systems.

harmful online situations. My firm, ID Exchange, has been working since 2015

WHAT IS THE AUSTRALIAN AGE ASSURANCE TECHNOLOGY TRIAL?

to design and implement simple privacy controls

The Australian Age Assurance Technology Trial is

participating in the AATT to help parents prevent the

part of a world leading national initiative to explore

oversharing of personally identifiable information on

technologies and frameworks to block users below

themselves and their children and enable them to opt

16 years of age from certain online services without

out of unwanted online communications.

and consent mechanisms for parents. We are now

compromising their privacy.

54

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

THE REAL RISK: YOUR CHILD’S DATA

PARENTAL CONSENT: WHAT THE LAW SAYS

Age assurance is about more than limiting access to

Under the Online Safety Act (2021) and upcoming

content; it’s about controlling who can collect data on

reforms to the Australian Privacy Act, organisations

your child, where it goes and how it’s used.

will have stricter obligations to:

I often reflect on attending a primary school

• obtain parental consent before collecting data

cybersecurity session to inform parents on how to protect their children. When the police officer addressing the session asked parents to raise their hand if their child had a personal computer in their bedroom, less than 10 percent did so. This request

from children under 16. • allow for easy opt out from marketing, tracking and data sales features. • provide clearer explanations of what data is being collected and why.

was followed by “raise your hand if your child has a mobile phone.” Now, around 70 percent of parents

But, as a parent, you will need practical tools to make

raised a hand, and the officer said: “If your child

these rights work.

takes that mobile into their bedroom, they have a computer in their safe space bedroom, and a world

That’s why, at ID Exchange, we are in the process

of predators can reach them without your knowledge

of building under 16 child eSafety apps that offer

or awareness.”

the child and the parent automated services with a biometrically verified mechanism that is under

Right now, most platforms:

parental control. We don’t like facial images or other personal information such as the child’s address

• ask for age but don’t verify it.

being used to verify their age. Our aim is to do the

• allow easy opt in for tracking but make opting out

legal and compliance heavy lifting to make this a

very difficult. • profile children’s behaviour to feed them targeted ads.

simpler, auditable and reuseable service for parents and place them in greater, more transparent and use case appropriate control.

• share, or sell, children’s data with third-party advertisers or data brokers. • have gaps in security that predators or bad actors take advantage of.

HOW PARENTAL CONTROLS HELP WITH AGE ASSURANCE Verified parental consent uses the latest in digital identity technologies, including:

Even well-meaning platform operators often fail to provide parental control mechanisms that are verified, easy to use or aligned with Australia’s privacy and safety laws.

• self-governed and private tools to allow you to action and confirm parental or guardian roles. • verifiable credentials to prove your relationship to the minor. • biometric test approaches to validate the age of a child in real-time. • tokenised consent receipts that record your decisions in real time. • Alias linkages for online pseudonyms your child can use. The tools enable you to act with authority, digitally and legally, to control who has access to your child’s

I S S U E 28

WOMEN IN SECURITY MAGAZINE

55


data even when that data is collected in seemingly

Here’s what you can do:

anonymous ways. They also give you the ability to opt out easily with confidence.

• read about eSafety initiatives in your home country to be informed about the changes occurring.

Imagine this scenario: your child signs up for a new

• hold discussions with your children about what

gaming app. You want to ensure their location, usage

they access, what they like and dislike about

habits and chat logs are not being shared or profiled

online services and who/what they regularly

by the company behind the app, or being sold to

interact with.

third parties.

• ask about mental health impacts, issues with sleeping or concentration or online bullying

With better parental controls you can:

at school. • start to monitor and audit your child’s consent

• act as the verified parent or guardian to deactivate the service for the child. • link the child’s account (even if it uses

actions to remove harms. • learn the signs of your child’s behaviour being impacted by their connection to the digital world.

a pseudonym). • send a legal opt out instrument to the platform to block access. • receive proof that the opt out was sent and recorded. • follow up if the platform fails to comply.

YOUR CHILD’S DIGITAL FUTURE STARTS WITH YOU The Australian Age Assurance Technology Trial is gaining pace. However, real protection comes from empowered parents using tools built for the digital age.

These are not preference settings, they are legally mandated options supported by Australian and many

It’s not all bad news. Online connectivity opens a

international privacy laws.

plethora of learning pathways, peer connections and amazing digital experiences. However, taking

PART OF A GLOBAL MOVEMENT

advantage of these requires taking the guesswork out

Australia is not alone in facing these challenges.

of online safety and turning legal rights into simple,

Countries like:

meaningful actions backed by leading partners and technologies.

• the UK with the Age-Appropriate Design Code, • the EU, with the GDPR and Digital Services Act,

SPREAD THE WORD

• the US, through COPPA and the California Privacy

Let’s make the internet safer, smarter and

Rights Act,

fairer together.

are also advancing the protection of children online

If you’re part of a school, youth organisation or

while preserving digital rights.

parenting group, share this article to help other parents take control of their children’s data and

ID Exchange is actively working with regulators, civil

privacy online.

society and technology partners to ensure Australia leads the way in human-centric, family-first digital consent solutions.

www.idexchange.me

WHAT PARENTS CAN DO NOW

www.linkedin.com/in/joanne-cooper-50369734

If you’re a parent or guardian of a child under 16, it’s time to prepare for the shift.

56

W O M E N I N S E C U R I T Y M A G A Z I N E

x.com/idexchange_me

J A N U A RY • F E B R U A RY 2026


LISA VENTURA

THE SEVEN PIVOTS THAT DEFINE A SUCCESSFUL CYBERSECURITY CAREER (AND WHY WOMEN EXCEL AT MAKING THEM) by Lisa Ventura MBE FCIIS, Chief Executive and Founder, Unity Group Solutions Limited/AI and Cyber Security Association

When I look back at my journey into cybersecurity,

I’ve noticed that women often excel at making these

I can’t help but laugh at how unconventional it’s been.

pivots, perhaps because we’re used to navigating

From working in entertainment with Chris Tarrant, the

complex situations and adapting to environments that

first host of Who Wants to be a Millionaire in the UK,

weren’t originally designed for us.

to founding the UK Cyber Security Association/Cyber Security Unity and more recently founding the AI and

In this article I want to share the seven critical

Cyber Security Association and Unity Group Solutions

pivots that define successful cybersecurity careers.

Limited, to receiving an MBE for services to the

These are lessons learnt from my own journey,

industry and being made a Fellow of the Chartered

from the incredible women I’ve met over my years

Institute of Information Security, my career has been

in the cybersecurity industry, and from countless

anything but linear, and I have pivoted so many times.

conversations I’ve had.

And you know what? That’s exactly what makes it valuable.

THE EDUCATION PIVOT: FORMAL VERSUS INFORMAL LEARNING

The truth is, a successful career in cybersecurity isn’t

Let’s start with a truth the industry doesn’t talk about

about following a straight path. It’s about knowing

enough: you don’t need a degree to have a brilliant

when to pivot, how to adapt, and having the courage

career in cybersecurity. I know this because I have

to change direction when needed: something I have

lived it.

had to do on more than one occasion. Over the years

58

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

My original career choice was journalism, and I was

classroom and group settings where I could make

all set to embark on a degree pathway, but for various

notes and do things my own way. Neurodivergent

reasons I was unable to take that path because I

individuals often thrive in informal learning

could not move away from home. Instead, I stayed

environments, so don’t let anyone tell you there’s only

in my hometown and studied for a higher national

one ‘right’ way to learn.

diploma in business and finance. It was equivalent to a first degree, but it wasn’t the education or career pathway I had planned for myself.

THE SPECIALISATION PIVOT: CHOOSING YOUR NICHE Cybersecurity is vast. You’ve got penetration

The education pivot isn’t about choosing between

testing, security architecture, governance, incident

formal and informal learning; it’s about recognising

response, threat intelligence, security operations,

that both have value and knowing when to leverage

cloud security, application security and dozens of

each of them. Formal education provides foundational

other specialisations. When you’re starting out,

knowledge and industry recognition. Certifications

cybersecurity can feel overwhelming.

like CISSP or CISM open doors and demonstrate commitment, but informal learning is where the

The specialisation pivot is about finding your niche

magic happens.

without boxing yourself in permanently. Early in your career, I recommend being a generalist. Learn

It’s the blog posts you read at midnight because

a bit about everything. This foundation is invaluable,

you’re fascinated by a new attack vector. It’s the

because cybersecurity doesn’t happen in silos.

YouTube tutorials, the conversations at security meetups, the hands-on experimentation in your

But, at some point, you need to choose a direction.

home lab. Women often excel at this pivot because

This is where women often hesitate. We’re taught to

we’re used to being self-directed learners. Many of

keep our options open, to be flexible. We worry that

us have had to teach ourselves twice as much to be

specialising will close doors. But here’s the truth:

considered half as competent.

specialisation opens doors. It makes you the go-to person for specific problems. It builds your reputation.

My advice? Start where you are. Don’t let the lack of a specific degree stop you from entering this field. I’ve seen people without degrees excel in the industry and those with degrees in subjects such as psychology, English literature and varied backgrounds become exceptional cybersecurity professionals. What matters is that you never stop learning. The threat landscape evolves daily. Embrace informal learning as a core part of your professional identity. Follow thought leaders, read security blogs, join communities like the Australian Women in Security Network, and attend webinars amongst other things. And always, always stay curious. As someone diagnosed with autism, ADHD, dyspraxia and dyscalculia, I can tell you that traditional classroom settings aren’t always designed for how my brain works best. I always learnt better away from

I S S U E 28

WOMEN IN SECURITY MAGAZINE

59


How do you choose your specialisation? Follow your

Imposter syndrome often strikes hardest when you’re

energy. What aspects of security make you lose track

about to do something important: when you’re being

of time? What problems do you find yourself thinking

considered for a promotion, asked to speak at a

about even when you’re not at work?

conference or offered an exciting opportunity. Your brain, trying to protect you from failure, starts listing

For me, it became clear my strength was in

all the reasons you’re not qualified.

cyberpsychology and the human aspects of cybersecurity, in building communities and in

The confidence pivot happens when you recognise

cybersecurity awareness training, communications

those thoughts for what they are and do the thing

and bringing people together. That specialisation

anyway. Women excel at this pivot because we’ve

led me to found the UK Cyber Security Association/

had practice. We’ve spent our entire careers proving

Cyber Security Unity and, recently, the AI and Cyber

ourselves in spaces that weren’t designed for us.

Security Association and Unity Group Solutions. Eventually, it led me to receive an MBE from King

Here’s my practical advice.

Charles III in 2023 for services to cybersecurity and to diversity, equity, inclusion and belonging (DEIB), and

First, collect evidence. Keep a folder of positive

to being made a Fellow of the Chartered Institute of

feedback and accomplishments. When imposter

Information Security.

syndrome strikes, review this evidence. It’s hard to argue with facts.

Here’s the beautiful thing: a pivot is not permanent. You can pivot again. Maybe you start in penetration

Second, talk about it. Silence gives it power. When we

testing, move into security architecture and

share our doubts, we discover that everyone feels this

eventually into leadership. The skills you develop

way. I’ve had CEOs tell me they feel like impostors.

in one specialisation often transfer to others in surprising ways.

Third, reframe your inner dialogue. Instead of “I don’t know enough to deserve this opportunity,” try “I don’t

Women excel at these pivots, because we tend to

know everything yet, but I’m capable of learning.”

think holistically. We see connections others miss. We understand that technical skills alone aren’t enough.

Fourth, act as if. Sometimes you need to fake

These qualities make us adaptable specialists who

confidence until you feel it. Take that speaking

can pivot when the industry or our interests change.

engagement. Apply for the promotion. Action creates confidence, not the other way around.

THE CONFIDENCE PIVOT: OVERCOMING IMPOSTER SYNDROME

Being openly neurodivergent has taught me

If I had a dollar for every time I’ve felt like an

something important: there’s no single ‘right’ way to

impostor in this industry, I’d be rich enough to retire.

be confident. Confidence doesn’t have to look like

Imposter syndrome is so prevalent among women in

what you see on television. It just has to be authentic

cybersecurity that I co-founded International Imposter

to you.

Syndrome Awareness Day with Nat Schooler and Kim Adele in 2021.

The confidence pivot also means becoming comfortable with not knowing everything. In

The confidence pivot isn’t about eliminating

cybersecurity this is crucial, because none of us can

self-doubt. Instead, it’s about transforming your

know everything. Real confidence includes saying

relationship with imposter syndrome from something

“I don’t know, but I’ll find out,” without feeling like

that paralyses you into something that propels

a failure.

you forward.

60

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

THE LEADERSHIP PIVOT: TECHNICAL TO STRATEGIC

From being technical to being strategic: can be

This pivot is where many brilliant technical

validation. Leadership is messier. Success is harder to

professionals get stuck. They’re exceptional at the

measure. The feedback loop is longer.

challenging because technical skills provide concrete

hands-on work but hesitate when opportunities arise to move into leadership.

But the cybersecurity industry desperately needs more women in leadership. We need diverse

The leadership pivot isn’t about abandoning your

perspectives at the decision-making table. We

technical skills. It’s about leveraging them in service of

need leaders who understand that security is about

bigger goals. It’s about moving from solving problems

protecting people, not just systems.

yourself to empowering others to solve problems. If you’re considering this pivot, start small. Mentor Coming from a non-technical background, I couldn’t

someone. Lead a project. Volunteer to present to

rely on deep technical expertise alone. I had to

senior leadership. Each experience builds your

develop strategic thinking, communication skills and

leadership muscles.

the ability to bring people together. In some ways, not being the most technical person in the room forced me to develop leadership skills earlier.

THE ADVOCACY PIVOT: INDIVIDUAL SUCCESS TO COMMUNITY BUILDING There’s a moment in many a successful career when

Women often excel at this pivot because many of the

you realise your own success is no longer sufficient.

skills required for effective leadership are skills we’ve

This is when the advocacy pivot happens.

been developing our entire lives. Active listening, empathy, seeing multiple perspectives, building

The advocacy pivot is about leveraging your

consensus, creating psychological safety. These

platform and experience to lift others up. It’s about

aren’t ‘soft’ skills, they’re essential leadership skills.

moving from “How do I succeed?” to “How do we all succeed?”

The technical-to-strategic pivot requires several shifts. From individual contributor to team enabler: your success is measured by what your team achieves. From operational focus to strategic vision: instead of “How do we fix this specific vulnerability?” you ask “How do we build a security culture that prevents vulnerabilities?” From technical communication to business communication: you translate security concerns into business language, talking about business risk rather than CVE scores. From knowing all the answers to asking the right questions: leadership is about creating an environment where smart people can do their best work.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

61


The advocacy pivot requires vulnerability. You must share your struggles, not just your successes. You must risk criticism from those who don’t understand why advocacy is necessary. But here’s what I’ve learned: advocacy is one of the most fulfilling pivots you can make. When someone tells you that your story inspired them to enter cybersecurity, when you see a mentee achieve something they didn’t think possible, that impact outlives any individual achievement. Advocacy also keeps you connected to the human side of this industry. We’re not just protecting systems, we’re protecting people, communities and ways of life.

THE RESILIENCE PIVOT: SETBACKS TO COMEBACKS If there’s one pivot I understand deeply, it’s this one. In 2012 and 2013 I experienced some of the darkest I made this pivot when I rebranded the UK Cyber

periods of my life. My marriage ended suddenly in

Security Association as Cyber Security Unity. I’d

2012, and that meant leaving behind the cybersecurity

achieved things I never thought possible, but I kept

software development company my ex-wife and I

seeing the same problems: lack of diversity, women

worked in together. I remarried in April 2012, but I

leaving the industry, talented people being overlooked.

lost my only son, Francesco, who was stillborn at 33

I realised I could either complain or do something

weeks. I had to rebuild my career from scratch. There

about them.

were days when getting out of bed felt impossible.

Women excel at this pivot because we understand

The resilience pivot is about transforming setbacks

what barriers look like. We’ve experienced being the

into comebacks. It’s about finding the strength to

only woman in the room, being interrupted, having our

continue when everything in you wants to give up.

ideas attributed to men. Women often excel at this pivot because we’ve Advocacy takes many forms. It might mean

had to develop resilience just to exist in this

starting or joining organisations like the

industry. We face microaggressions, unconscious

Australian Women in Security Network, speaking

bias and, sometimes, outright discrimination.

publicly about our experiences, mentoring and

These experiences build resilience that gives us

sponsoring others, creating content that amplifies

competitive advantage.

underrepresented voices, or advocating for policy changes organisations.

But resilience isn’t about being invulnerable. The resilience pivot happens when you acknowledge the

When I decided to be openly neurodivergent in a

pain, learn from the experience and choose to move

professional context, it wasn’t easy. But I knew

forward anyway.

visibility mattered. Every time someone like me

62

succeeds and talks about it, it makes the path slightly

Resilience in practice means accepting that failure

easier for the next person.

is part of growth. The best penetration testers fail

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

hundreds of times before finding the vulnerability. It

The legacy pivot requires shifting from short-term to

means building a support network, because I couldn’t

long-term thinking. It means making decisions that

have survived my darkest periods alone. It means

might not benefit you directly but will benefit others in

finding meaning in suffering. I channelled my grief

the future.

into creating Frankie’s Legacy, supporting parents who’ve experienced pregnancy loss.

For me, this pivot meant focusing on diversity, inclusion, and supporting neurodivergent people

It means taking care of your mental health. As a

in cybersecurity. When I’m no longer active in the

qualified mental health first aider, I’m passionate

industry, I want to know I helped make it more

about normalising mental health support in

accessible and welcoming.

cybersecurity. Burnout is endemic in this field. Resilience means recognising when you need help,

The legacy pivot also changes how you measure

and seeking it without shame.

success. Instead of “What did I achieve?” you ask “What did I enable others to achieve?” This doesn’t

It means maintaining perspective. When you’re in the

mean you stop caring about your own career

middle of a crisis, you feel the world is ending. The

development, but it adds a dimension that makes

resilience pivot helps you see this as one chapter in a

your career more meaningful.

longer story. The cybersecurity industry needs resilient

WHY WOMEN EXCEL AT MAKING THESE PIVOTS

professionals because the work is hard. You’re

We excel not because we’re inherently better at

constantly fighting adversaries, dealing with high-

adapting, but because we’ve had to be. Every woman

stress situations and tight deadlines. But every

in cybersecurity has had to navigate an industry that

time you make this pivot, your sense of self, your

wasn’t designed with us in mind.

values and your commitment to your purpose become stronger.

These challenges have made us exceptionally good at pivoting. We’re used to reading situations, adapting

THE LEGACY PIVOT: CAREER TO LASTING IMPACT

our approach and finding creative solutions. We’re

The final pivot is when you start thinking beyond

had role models. We’re used to building communities

your own career and asking: what impact will I

because we’ve often felt isolated.

used to learning on the job because we haven’t always

leave behind? But these skills aren’t just valuable for our own Legacy in cybersecurity takes many forms. It might

careers; they’re exactly what the cybersecurity

be the people you’ve mentored who become leaders

industry needs. We need professionals who can pivot

themselves. It might be the organisations you’ve

quickly as the threat landscape evolves. We need

founded that continue serving the community. It

leaders who can adapt their communication. We

might be the policies you’ve implemented, the content

need advocates who understand that diversity makes

you’ve created or the culture you’ve helped shape.

us stronger.

Women excel at this pivot because we often think

Women don’t excel at these pivots despite the

in terms of relationships and impact rather than

challenges we face. We excel at them because of the

just individual achievement. We understand that

challenges we face.

real success is about the difference we make in people’s lives.

MAKING YOUR OWN PIVOTS If you’re wondering where you are in your own pivot journey, here’s my advice.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

63


First, recognise that pivots are normal. A successful

LISA ON SOCIAL MEDIA

career isn’t a straight line. Don’t judge yourself for pivoting. Celebrate it as evidence that you’re growing.

www.lisaventura.co.uk

Second, give yourself permission to pivot. Your

@cybergeekgirl

career belongs to you. www.linkedin.com/in/lisasventura/

Third, seek support. Every pivot is easier with people who believe in you. Join communities like

www.facebook.com/lisasventurauk

the Australian Women in Security Network or Cyber Security Unity.

www.instagram.com/lsventurauk

Fourth, be patient with yourself. Pivots take time.

bsky.app/profile/cybergeekgirl.bsky.social

Trust the process. You can find examples of the talks she done Fifth, remember why you’re here. Reconnect with

previously and of interviews, panel discussions and

that purpose when pivots feel difficult.

moderating/chairing events on her YouTube channel here https://www.youtube.com/@CyberSecurityLisa/

THE JOURNEY CONTINUES I’m still making pivots in my own career. The difference now is that I recognise pivots for what they

ABOUT LISA VENTURA MBE FCIIS

are. They are not signs of failure or indecision, but

Lisa Ventura MBE FCIIS is an award-winning

evidence of a dynamic, evolving career. Every pivot

cybersecurity specialist, published writer/author,

I’ve made has added something valuable to who I

journalist and keynote speaker. She is the chief

am and what I can offer. Your pivots will do the same

executive and founder of Unity Group Solutions

for you.

Limited and of the AI and Cyber Security Association, a membership body and trade

The cybersecurity industry needs you. It needs your

association set up as the global voice of AI and

unique perspective, your skills, your resilience and

cybersecurity and to promote the safe, secure,

your ability to pivot and adapt. Don’t let anyone tell

responsible and ethical use of AI. In addition,

you your unconventional path is a weakness. It’s your

she is the founder of Cyber Security Unity, Neuro

greatest strength.

Unity and AI Unity.

What I want to leave you with is this: make the pivots.

As a consultant Lisa also provides cybersecurity

Take the risks. Change direction when needed. Build

awareness and culture change training along

your career on your own terms. And when you’ve

with neurodiversity in the workplace training,

made your pivots and found your success, reach

and works with cybersecurity leadership teams

back and help the next woman make hers. That’s how

to help them collaborate more effectively. She

we change this industry: one pivot, one person, one

has specialist knowledge in the intersection

success at a time.

of AI and cybersecurity, the human factors of cybersecurity/social engineering, cyber

64

The journey is long, but you don’t have to take it alone.

psychology, neurodiversity and in diversity, equity,

We’re building this future together and I, for one, can’t

belonging and inclusion (DEIB). More information

wait to see where your pivots take you.

about Lisa can be found on www.lisaventura.co.uk.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


MARINA TOAILOA

EMOTIONAL INTELLIGENCE IN SECURITY: THE SHIFT FROM PHYSICAL PRESENCE TO PSYCHOLOGICAL AWARENESS By Marina Toailoa, Founder- Mummy Safety Security Project Security incidents are rarely just physical. They

to assess emotional cues, maintain composure and

are human events driven by stress, fear, anger

communicate empathy under pressure. The most

and confusion. Whether it’s an altercation, a

successful responders are trained not only to act fast

medical emergency or an act of aggression, how

but to have emotional awareness of the event.

a responder reads and manages emotions can determine the difference between de-escalation and

Emotional intelligence is the ability to recognise,

disaster. If responders focus only on procedures and

understand and manage one’s own emotions while

not people they risk missing critical emotional cues

influencing the emotions of others.

that could indicate an imminent escalation of the situation. Emotional intelligence allows responders to recognise those cues and adjust their approach. For instance, lowering their tone, giving space or showing empathy to help calm and stabilise others. In the past, the focus was on command presence: appearing to be in control, assertive and ready to act. While that remains important, today’s environment demands something deeper: the ability

66

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

IN PHYSICAL SECURITY, EMOTIONAL INTELLIGENCE TRANSLATES INTO FIVE ESSENTIAL COMPETENCIES.

In essence, emotional intelligence doesn’t replace

1.

Self-awareness: recognising one’s emotional

Emotional intelligence enhances a responder’s ability

triggers and physiological responses

to listen actively, speak clearly and build rapport

under stress.

quickly, even in tense moments.

2.

4.

in an incident often matters as much as what is said.

Self-regulation: maintaining control over one’s Motivation: remaining mission-focused even in

TRAINING FOR THE MIND AS WELL AS THE MUSCLE

emotionally charged environments.

To embed emotional intelligence in physical security

Empathy: understanding the perspectives and

operations, organisations must invest in developing it

emotions of others, including victims, aggressors

intentionally. This means:

impulses to avoid escalating a tense situation. 3.

tactical ability, it amplifies it. How something is said

and bystanders. 5.

Social skills: communicating clearly, calmly and respectfully to de-escalate tension.

• integrating emotional intelligence into incident response training, not just soft-skills workshops. • using scenario-based learning to simulate high-

Each of these skills contributes directly to operational

stress emotional environments.

outcomes. A guard who can detect fear or confusion

• encouraging reflection and feedback after every

early can tailor their approach, reducing the likelihood

incident - not just on what happened, but on how

of physical confrontation. A supervisor who models

people felt.

calm emotional control helps set the tone for an entire

• recognising and rewarding calm, empathetic

team’s response. Empathy doesn’t make a responder

responses as much as quick or forceful ones.

weak; it makes them effective. It creates cooperation instead of resistance.

The future of security training isn’t about replacing toughness: it’s about redefining it. True strength lies in

THE REAL-WORLD IMPACT OF EMOTIONALLY INTELLIGENT RESPONSES

composure, understanding, connection and the ability to turn chaos into calm.

Consider two security officers responding to an agitated individual in a lobby. The first relies on

Emotional intelligence represents the evolution

physical authority, using a raised voice and physical

of physical security from reactive enforcement to

posturing to assert control. The second takes

proactive, human-centred protection. In a world where

a moment to assess the situation, noticing the

every incident involves emotion the smartest and

individual’s shaking hands and rapid breathing. They

safest responders are those who can manage their

speak slowly, maintain distance and acknowledge the

own emotions while understanding others, and those

person’s distress. The result? The first scenario risks

who do not take things personally.

escalation. The second opens the door to rapport building, de-escalation and resolution.

Because, at the end of the day, security isn’t just about keeping people safe; it’s about keeping people whole,

EMOTIONALLY INTELLIGENT RESPONDERS CAN:

emotionally, physically and psychologically. In short, embrace your human side as a strength.

• de-escalate volatile situations faster and with fewer physical interventions. • build trust with the public and with stakeholders.

www.linkedin.com/in/mia-azar-toailoa-66259511a

• reduce legal and reputational risk to their organisation.

www.instagram.com/mummysafetysecurityproject

• improve team cohesion and morale through emotional modelling.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

67


RYAN FOX

BUILDING AN INCLUSIVE CYBER CLUB PLAYBOOK AND PITFALLS By Ryan Fox, Security Engineer When I arrived at university I imagined the campus

to make friends and build essential industry skills

would be loud, collaborative and curious. In reality, it

in cybersecurity.

felt quiet and fragmented. I loved cybersecurity, but

68

the spaces around me didn’t feel designed for learning

THE HARD NUMBERS

out loud, or for making friends. So, I started the

Our Discord group launched in October 2024 with

Deakin University Cybersecurity Association (DUCA)

10 members and grew month by month, reaching

to build the community I wished I’d found: a place

750+ by November 13, 2025 (see graph below).

where people could be themselves, learn together

That’s an average of ~60 new members per month.

and belong. My one line mission today is simple:

We’re now formalising a retention baseline, tracking

give people the supportive environment they need

30/60/90 day engagement and trimester renewals so

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

we can publish a clear renewal percentage after our

judgement space where new students step out,

December cycle. Early signals are strong: members

learn, and feel supported in the environment we

are coming back for second and third events,

wished we had and building it has been incredible.”

and many are transitioning from being members

• Sham: “DUCA exists so belonging isn’t accidental:

to being on the committee, some even taking on

we design events and communication to remove

leadership tasks.

friction so people can connect and grow; that intentionality powers the community, and seeing

WHO BELONGS, AND HOW WE INCLUDE

people realise they belong keeps me going.”

Diversity is a series of design choices. Thirty three

• Paige: “Partnerships, diverse panels, empowering

percent of our members identify as women or non-

women-presenting committee members, and

binary, and approximately 60 percent are international

ongoing care across learning, collaboration,

students. Because not everyone can attend in

and support—via education, mentorship, and

person—Deakin has students across multiple

CTFs—drive our diversity and build an inclusive,

campuses and countries—we record or pre-record

representative club where everyone feels valued

learning content so no one has to miss out. We also

and grows.”

make our session materials available in advance,

• Kat: “Empowering diverse voices, DUCA

add captions to recordings and keep Q&A logs so

shapes cybersecurity’s future and values

quieter voices are heard. We track opt-in identity

every perspective; that first step opens doors,

data and simple post-event feedback to make our

confidence to speak helps us grow, and its

events increasingly welcoming. Policies reflect our

inclusive, transformative support shows every

inclusiveness with a zero tolerance for any anti-

voice matters.”

social behaviour online or in-person. All these design

• Chloe: “As someone outside cybersecurity, I’ve

choices shape an environment where students from

never felt out of place at DUCA; openness and

diverse backgrounds feel comfortable, and we act

support let you show up as you are and grow

when they give us feedback.

academically and personally, and diversity isn’t a checkbox—you feel it in how people welcome,

THE FEMALE MAJORITY EXECUTIVE TEAM

include, and lift each other.”

I’m grateful to lead alongside Chloe Fok, Sham with their consent). Roles adjust as we grow, but this

WHAT WORKED: FIVE REPEATABLE PROGRAMS

leadership core sets the tone: empathetic, organised

1.

Polavarapu, Paige Haines and Kat Ho (named here

Rotating roster (what/why/how). We run a four-

and unafraid to experiment. Short quotes from the

week cycle: pentesting lab, cyber theory, industry

team we’ll confirm before publication:

guest, beginner-friendly CTF. All these were made by students, for students. This cycle serves

• Ashley: “DUCA is more than cybersecurity it’s

mixed skill levels and avoids fatigue. A shared

community, connection, and growth: a no-

template (agenda, assets, comms copy) makes

I S S U E 28

WOMEN IN SECURITY MAGAZINE

69


2.

it easy to rinse and repeat. If you’d like a copy of

cochair was a surprise and a responsibility. ACUCyS

our materials, feel free to reach out.

connects 15+ universities, giving us a platform to

Majority interactive sessions. Our rule of thumb

share playbooks, cohost CTFs and lift inclusion

is one third talk, two thirds doing. A session

standards across campuses.

could be a live Q&A with a guest, a step-by-step micro challenge. Interactivity raises confidence

A 90-DAY PLAYBOOK YOU CAN RUN ANYWHERE

and retention.

1.

exploit walkthrough, or pairing up to solve a

3.

coffee chats with students from outside your

vary speakers, backgrounds, roles and journeys

immediate circle. Define two or three personas

so students meet many versions of “what

you’re serving (eg, absolute beginner, switcher,

success looks like.” We keep a rotating shortlist and an outreach script so we don’t over invite the 4.

deep diver). 2.

Ship a starter series (Weeks 3-6). Four

same voices.

events: pentest lab, theory talk, industry AMA,

Celebrations that close the loop. End of

beginner CTF. Publish the slides, code and recap

trimester socials, tiny awards and highlight posts give the community a sense of momentum.

5.

Listen (Weeks 1-2). Short survey plus three

Industry invitations with equity. We intentionally

each week. 3.

Make it interactive by default (Weeks 3-12).

Celebrating effort (not just results) keeps

Add a ‘do together’ segment to every session and

volunteers energised.

a take home artifact (a tiny writeup, a report or

Food and beverages. It sounds simple, but shared meals change the room. We budget per

a checklist). 4.

Recruit and support (Weeks 4-10). Fill explicit

head, label dietary options and use “structured

roles, events, ops, comms, partnerships. Use

mingle” prompts so people leave with at least

one shared task board and a 20 minute weekly

three new names.

standup to keep momentum. 5.

Celebrate and iterate (Weeks 11-12). Close

PITFALLS, AND HOW WE COURSE CORRECTED

the loop with a social, thanks to speakers and

• Burnout. Passionate students often overcommit

sponsors, tiny awards and a public post that

or get placed away from their strengths. We

invites the next cohort.

added role-fit check-ins, capped concurrent responsibilities and created mandatory rest

LET’S CONNECT

windows around exams. The goal: protect

If you believe DUCA can help you, or if you’d simply

people first.

like to chat, we’d love to hear from you. We care

• Rejecting rather than adopting ideas. Early on,

deeply about this community. We’re happy to

we were quick to say “No” to rough ideas. Now we

help however we can: sharing resources, running

say, “Yes, if…” and codesign small pilots. Treating

a workshop, connecting mentors or co-hosting

ideas as drafts has unlocked more ownership and

something fun. And if you have opportunities,

better programs.

speaking spots, sponsorships, internships or joint

• Under-management. With too few executives, subcommittees stalled. We introduced clear

events, we’re excited to collaborate. Let’s build the bridge together.

scopes, sub-team leads and a weekly 20 minute standup to unblock quickly. Lightweight structure

ryanfox0005@gmail.com

beats heroic effort. www.linkedin.com/in/ryanrfox-cybersecurity

PARTNERSHIPS AND BRIDGES Joining the Australian Council of University Cyber

duca.au

www.instagram.com/deakincyber

Societies (ACUCyS) was a dream. Being elected

70

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


INTERESTED IN WORKING TOGETHER? Contact Aby Aby@source2create.com.au www.source2create.com.au

MEDIA

CONTENT

EVENTS

ADVERTISING

CUSTOM AS-A-SERVICE


JAY HIRA

SHRUTI KAMATH

ERIN CARROLL

AI AND DATA: PROTECTING WHAT POWERS US by Jay Hira, Cyber Director – Financial Services, KPMG Shruti Kamath, Consultant, Business Resilience, KPMG Erin Carroll, Consultant, Business Resilience and Cyber Risk, KPMG

There’s a special kind of energy at the start of a

and opportunities to innovate. But with speed comes

journey. We all remember standing on a platform

risk. The value of AI is dependent on the quality and

at dawn, the city still quiet, watching the first train

security of the data underpinning it.

of the day glide into the station. Around us, people gather, some eager, some anxious, all with their own

We have seen what happens when governance is

destinations in mind. As the train doors open, we step

overlooked. Data breaches, regulatory penalties and

aboard together, trusting the tracks ahead to carry

reputational damage are no longer distant threats.

us safely.

They become real, and they can derail us in moments. The lesson is clear: we must build our foundations

In many ways, this is precisely how we find ourselves

with care.

with AI and data. The technology is undeniably

72

powerful, and the possibilities vast. We’re all building

We often hear data called ‘the new oil’. But data is

those modern data lakes, brimming with potential,

more like passengers in high-speed trains: volumes

and the excitement is real. Yet, as we prepare to set

are growing, and movement is at an astonishing

off, we must pause and consider whether the tracks

speed. AI amplifies both the benefits and the dangers

beneath are ready to carry us at speed. If they are

of ever increasing data volumes. Yes, high quality

misaligned, neglected or left unsecured, the train will

data helps us understand our customers, improve our

not reach its destination safely. In our world, those

services and drive growth, but, on the flip side, low-

tracks are data governance.

quality data exposes us to risk.

AI is the engine driving us forward, and we are

Data is both an asset and a liability. It powers our

accelerating. We see opportunities everywhere.

businesses, but it also brings risk. Protecting it is not

Data lakes offer us new insights, better decisions

just a technical challenge, it is a shared responsibility.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

We would never leave the train doors open nor allow anyone to tamper with the tracks. We must safeguard our data with the same care.

BUILDING THE TRACKS: THREE PILLARS OF DATA GOVERNANCE Good governance is like a well-designed rail network. It ensures that every part of our organisation receives

" Data is both an asset and a liability. It powers our businesses, but it also brings risk. Protecting it is not just a technical challenge, it is a shared responsibility."

what it needs, safely and reliably, as we move together toward our destination. Our governance framework rests on three strong pillars; just as a

2. Quality and integrity

train relies on its engine, tracks and crew to keep the

Reliable data forms the foundation of sound

journey smooth and secure.

decisions, and clean data ensures fewer errors and smoother processes. It helps us build trust with

1. Ownership and accountability

our stakeholders and unlocks the full potential

When we know who is responsible for each data

of analytics and AI.

asset we act with confidence. Clear roles reduce confusion and prevent mistakes. Accountability builds

3. Security and compliance

trust with our customers, those inside and outside

Security is our digital lock and alarm, protecting our

our organisation. When responsibilities are mapped,

valuable assets with access controls, encryption

everyone knows where they fit, allowing all to move in

and monitoring. Compliance is not optional; it is the

the same direction. This collective clarity enables us

framework that guides us to manage data responsibly

to achieve collective wins.

and that protects us from unnecessary fines. We must regularly review and improve our compliance practices, because technology and regulations constantly change.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

73


• Clear policies for data access and use. It’s critical

" By making governance the train that unites our efforts, we move from ambiguity to clarity, ensuring our AI journey is effective, responsible and tailored to our needs."

to know who can access what, and why. • Controls for prompts and outputs. These prevent misuse and allow for monitoring of results. • Continuous monitoring and review. AI is in no way a set-and-forget solution, and monitoring is thus non-negotiable. • Transparency and explainability. We must ensure decisions are auditable and understandable, although not necessarily in that order. Keeping these guardrails in mind, we acknowledge that true success isn’t measured solely by our arrival

FACING THE CHALLENGES: THE GOVERNANCE GAP

at the destination, but by the care, integrity and

Many organisations focus on the AI engine and

Our stations along our journey include:

vigilance we demonstrate throughout the journey.

overlook the train itself: the governance that carries everything forward. Without clear governance as

• Accurate, consistent and complete data.

our foundation, AI models can easily veer off track,

• Compliance with laws and standards, with neither

delivering unsafe or unintended outcomes. Just as a

penalties nor breaches.

train needs sturdy rails to stay on course, we require

• Effective risk management and mitigation.

robust measures for data quality, input prompts,

• Trust from stakeholders, built on transparency

output controls and ongoing monitoring. Risk

and ethics.

management is not just the job of a single team; it’s a

• Streamlined processes and reduced inefficiencies.

shared responsibility for everyone on board.

• Authorised access to the right data at the right time.

We’ve all witnessed the consequences when policies and procedures are unclear. Having rules is not sufficient; the entire crew must know them, understand them and follow them. By making governance the train that unites our efforts, we move from ambiguity to clarity, ensuring our AI journey is effective, responsible and tailored to our needs.

STAYING ON TRACK: GUARDRAILS FOR SUCCESS Just as a train relies on sturdy rails to travel safely so must we establish practical safeguards to ensure our progress remains steady and secure. These safeguards include: • Standards for data quality: well defined and enforced. After all, low-quality data leads to low-quality outcomes.

74

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


I N D U S T R Y

P E R S P E C T I V E S

• Governance that supports our strategic goals.

the weight of our ambitions. We have set clear

• Regular reviews and improvements.

guardrails to keep us on course, empowered our

• Clear metrics and reporting on performance.

teams to act with integrity and fostered a culture where ethics and accountability are as important as

If our safeguards are our guardrails and our measures

performance. Each checkpoint station—ownership,

of success the stations, then governance is the

quality, security and transparency—has ensured we

train that carries us forward, uniting our customs,

do not just move quickly, but move wisely.

accountability and leadership as we journey together toward responsible and resilient AI. Governance is

But the journey does not end at the first destination.

more than just a set of technical controls, it is the

The landscape ahead will continue to shift, with

culture that shapes how we travel together. True

new technologies, regulations and risks emerging

progress relies on accountability and leadership

on the horizon. To remain resilient we must commit

at every level, empowering our teams to question,

to ongoing maintenance, regularly reviewing our

challenge and continuously improve our practices.

practices, learning from each experience and adapting

By fostering an environment where ethics and

our governance to meet tomorrow’s challenges. This

integrity are valued as highly as performance we

means investing in our people, strengthening our

ensure our journey remains not only efficient but also

processes and keeping our values at the heart of

principled and resilient.

every decision.

REACHING THE DESTINATION: A RESPONSIBLE AND RESILIENT AI FOR THE FUTURE

Ultimately, the true measure of success is not

As our train slows and we approach the end of this

our customers and our communities. By making

journey it’s worth reflecting on what has brought us

governance the train that carries us, we ensure our

here safely. Every successful arrival is the result of

AI journey is not only fast and innovative, but also

careful planning, shared vigilance and a steadfast

responsible, ethical and repeatable.

how well we achieve our goals but the confidence and trust we build along the way; with our teams,

commitment to doing things right. The speed and innovation of AI may be our engine, but it is governance—the train itself—that carries us forward,

www.linkedin.com/in/jayhira

keeping us aligned, secure and resilient.

www.linkedin.com/in/shruti-kamath

Throughout our journey we have relied on strong

www.linkedin.com/in/erinlouisecarroll

tracks—our data governance framework—to support

" To remain resilient we must commit to ongoing maintenance, regularly reviewing our practices, learning from each experience and adapting our governance to meet tomorrow’s challenges. This means investing in our people, strengthening our processes and keeping our values at the heart of every decision."

I S S U E 28

WOMEN IN SECURITY MAGAZINE

75


KAREN STEPHENS Karen Stephens is the co-founder and CEO of BCyber. After more than 25 years in financial services, Karen moved into SME cybersecurity risk management. She works with SMEs to protect and grow their businesses by demystifying the technical aspects of cybersecurity and helping them to identify and address cybersecurity and governance risk gaps. She was recently named inaugural Female Cyber Leader of the Year at the 2023 CyberSecurity Connect Awards in Canberra.

C O L U M N

The ‘pivot’ secrets you didn’t know Well. My Spidey senses must be working overtime,

KNOCK IMPOSTOR SYNDROME ON ITS HEAD.

because my last article touched on how important

Don’t underestimate the value of your background.

change has been for our company, and now I find

My former career focused on risk management,

myself once again revisiting my career pivot.

compliance and business development for small and medium enterprises. Cybersecurity intersects with all

I first wrote about my move from financial services

these fields, yet it often gets pushed aside. Hint: good

into cybersecurity in this very magazine way back in

cyber resilience isn’t just about the ‘tech’; it’s about

2021. The experiences of Covid lockdown and home

business risk as a whole.

schooling were still too fresh a memory to laugh about, and we were a fledgling company. My, how the

ZERO TRUST.

pivot has been pivoting.

We need to blame my financial services GRC background for this one. We all know what zero

Before launching into my learnings, I need you to keep

trust means in the tech sense, but in cyber risk

in mind one overarching theme: that the pivot itself

management you should “go beyond the tech” and

is not a linear process, it is more a wild ‘three steps

expand the usual definition to incorporate evidence

forward two steps back followed by a twirl around’

of what is really in place. Don’t trust something is in

process. But, that is why we pivot. You can say many

place, being actioned or configured, have evidence to

things about my pivot into cyber risk management

substantiate it. Hint: just saying something is in place

work, but that it is boring is not one of them.

doesn’t always make it so. A ‘snapshot’ as evidence is a start, but nothing beats regular ongoing monitoring

So, what are my key learnings all these years later?

and supervision.

BE THE TRANSLATOR.

GOD IS IN THE DETAILS.

It doesn’t sound like a biggie, but, trust me, it is.

The movies would have us believe that cyber risk

I came from financial services where terms are

management is all about hunting down bad guys

standardised (sometimes even dictated by law), and I

from darkened rooms while surviving on chips and

found this not to be the case in cyber. For example, in

energy drinks. Perhaps, for a few, it is. While flashy

finance, an assessment and an audit are significantly

ransomware breaches may grab attention, it’s the

different, but in my new world, these terms are used

basics that truly matter. Think of them as your ticket

interchangeably. They shouldn’t be. This was a bit

to playing the game of cyber resilience. Hint: the

of a shock. My suggestion: have your stakeholders

basics aren’t sexy, but they are the proverbial ‘pay to

describe what they want to achieve when scoping

play’ in cyber resilience, eg good password hygiene (for

work rather than, for example, assuming terms are

everyone), patching (for everything), cyber education

being used in their purest sense. Hint: the ‘tech’ and

(for all) and MFA (where possible). These are a good

the ‘business’ people may use the same terms, but

start, but not an end game on the cyber resilience road.

they may not carry identical meanings.

76

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


BAD NEWS BEAR.

promotion). I’ve found everyone I’ve encountered to

And, yes, I have been called that. Sometimes in cyber

be incredibly generous with their insights and time.

risk management you have to deliver news that is bad

The challenge often lies in having the courage to ask

or unpalatable. Once again, blame it on my financial

for help.

services GRC background, but I hold a firm belief that, if you know about a gap or vulnerability you need to

So, go and be bold. Give cyber a whirl!

raise it ASAP. After all, when an ‘unknown’ becomes ‘known’ a business can actively choose to either

And may 2026 bring you and yours only peace, joy

address it, mitigate it or accept it. If you don’t raise it,

and happiness.

you take away their agency to make a decision. Hint: it’s the hidden surprises—the unknown unknowns—that can truly catch you off guard and ‘bite you on the butt’.

www.linkedin.com/in/karen-stephens-bcyber

Transitioning into cyber risk management is daunting

www.bcyber.com.au

x.com/bcyber2

karen@bcyber.com.au

youtube.bcyber.com.au/2mux

but having a mentor and joining supportive groups like the AWSN, Insurtech Australia, the RegTech Association, ISACA and the like has made a world of difference for me (and note this is not a paid

I S S U E 28

WOMEN IN SECURITY MAGAZINE

77


CAREER PERSPECTIVES


RAJANI ARJULA

JAY HIRA

THE FSD RISK: ACCOUNTABILITY FOR THE AUTONOMOUS WORKFORCE by Rajani Arjula, Director, Cyber Delivery at Anchoram Jay Hira, Cyber Director – Financial Services, KPMG

There is a rhythm to the early morning. I find it

technical question; it is about trust, responsibility

grounding to step outside as the city stirs, watching

and leadership.

the first cars on the road. The streetlights are still on. The air is fresh. I often pause to take in the

THE PARADOX OF DIGITAL IDENTITY

predictability of human action. For decades there was

Our old security playbooks were built for a world

comfort in knowing a human was at the wheel on

of static roles and human pace. They assumed a

those cars, adhering to a clear set of rules. We trusted

predictable human user. With agentic AI, the ‘user’ is a

that driver.

machine. The gap in accountability is wide.

Now, that predictability is changing; on the road and

• Actions happen at machine speed. No human can

in the digital world. On the road we have full selfdriving (FSD) and, in the digital world, its equivalent:

keep up. • The ‘confused deputy hazard’ is real. Imagine

Agentic AI. These systems plan, decide and act on

an agent needing to access a simple database.

their own. and, like self-driving cars, learn and improve

If the backend system is configured with broad

with every journey. They deliver faster services

privileges the agent can do far more than

and smarter operations in banking, healthcare and

intended; not by design, but because the trust

government. The transformation is real.

boundaries were never clear.

But, as we hand over more control, a question sits

When things go wrong, the accountability lands on us.

with every leader: if the car is driving itself, how

Even if an autonomous agent took the action, it is our

do we guarantee control, and who is accountable

name on the line.

when the route goes wrong? This is not just a

80

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


C A R E E R

P E R S P E C T I V E S

THE UNSEEN COST OF LOST CONTROL

2. The principle of least privilege

We are seeing more AI project failures. Often, the

Agents must be given only the minimum access

cause is not poor technology, but poor governance.

needed for the task: no master keys for routine jobs.

The cost of a single flawed decision from an unaccountable agent is not just a technical glitch, it is

3. Dynamic trust, earned not assumed

a direct threat to our revenue and reputation.

Trust must be earned, not given. Future systems should incorporate trust scores that reflect policy

When an autonomous system encounters a blind

adherence. Permissions must be dynamic. If an agent

spot it exposes sensitive data or triggers cascading

acts out of character, its access must be restricted

failures in seconds. This erodes the very trust we

immediately.

have worked so hard to build with our customers and stakeholders. The risk is material, and the cost

4. Continuous oversight and response

of remediation far outweighs the investment in

Periodic audits are not sufficient. Oversight must

proactive governance.

be continuous and at machine speed. We need rapid response systems ready to revoke access or

BUILDING TRUST BY DESIGN

shut down an agent within seconds if its behaviour

We cannot treat identity as an afterthought. We

is unexpected.

must build it in from the start. Trust by design means establishing human accountability and turning risk

THE JOURNEY IS OURS TO SHAPE

into a strategic advantage. Here is how we earn trust

Agentic AI offers immense benefits. But every gain

in a machine-dominant world.

comes with the need for greater control. This is a strategic and cultural shift. It demands collaboration

1. Unique identity and ownership

across teams. If we are proactive and embed a

Every AI agent must have a unique digital identity

security model rooted in accountability and dynamic

similar to every car having a licence plate. This

control, our AI agents can become the most trusted

ensures traceability. A human owner must be

members of our digital workforce.

responsible for the agent’s behaviour and lifecycle. When I finish my walk, the city is fully awake. The roads are busy. The flow of traffic depends on shared vigilance and clear road rules. Our digital infrastructure is no different. The future is autonomous, but leadership is not. We must be the captains of trust, defining the rules and ensuring every autonomous action can be traced back to human responsibility. The future is autonomous. But trust still depends on access, identity and unwavering human accountability. www.linkedin.com/in/rajani-arjula

www.linkedin.com/in/jayhira

I S S U E 28

WOMEN IN SECURITY MAGAZINE

81


POOJA SHIMPI

GETTING INTO CYBERSECURITY WITH NO EXPERIENCE by Pooja Shimpi, Cybersecurity GRC Lead | AI Governance | Global Council for Responsible AI Ambassador for Australia

If there’s one question I hear more than any other,

Cybersecurity is not reserved for a chosen few. It

it’s this: “How can I get into cybersecurity if I have no

is accessible, learnable and full of opportunities for

experience?” And every time, my answer is the same:

beginners. Here’s what I’ve learnt from coaching

experience isn’t where you start, curiosity is.

people who successfully broke into the field without experience, and here’s what you can learn from

Cybersecurity has a reputation for being intimidating:

their journeys.

a field full of technical geniuses, complex tools, cryptic jargon and job descriptions that seem to have

YOU DON’T NEED TO BE TECHNICAL TO START

been written for superheroes. But, if you look closely

The biggest misconception is that cybersecurity

at the people working in this industry today, you’ll

requires deep technical skills from day one. It doesn’t.

notice a very different reality.

Cybersecurity is an ecosystem with 30+ career paths, and many don’t require you to code, configure

Many of them did not start in cybersecurity. Some

firewalls or analyse malware.

began in IT or operations, some in customer service, some in law, HR, finance, accounting or marketing.

Some of the most beginner-friendly areas include:

Some were career changers. Some felt completely lost in the beginning, yet they made it.

• governance, risk and compliance (GRC). • privacy.

82

I’ve personally mentored and guided several people

• cyber awareness and training.

who had no security background yet who, today, are

• security policy and documentation.

thriving security professionals. Not because they

• vendor risk management.

knew everything, but because they were willing to

• project security coordination.

learn, ask questions and take the next step.

• controls assurance and audit.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


C A R E E R

P E R S P E C T I V E S

These roles rely more on communication, logical

Once you understand the why, the how

thinking, curiosity, documentation, understanding

becomes easier. Cybersecurity isn’t about memorising

processes and analysing scenarios than on

tools, it’s about understanding behaviour, patterns

technical skills. You can build technical depth later,

and risk.

but these do not have to be your starting point. Your background isn’t an obstacle. It’s often your

One mentee described her breakthrough perfectly:

competitive advantage.

“I spent months trying to memorise technical details, getting more confused daily. Then I started reading

UNDERSTANDING CONCEPTS MATTERS MORE THAN TOOLS

about actual breaches: what happened, why it

When people start learning cybersecurity they often

everything connected.”

mattered, how it could have been prevented. Suddenly

think they need to master every tool, every framework, every attack type. But the truth is much simpler: you need only a solid conceptual foundation. When I mentor beginners, the first things I ask them to understand are: • what cyber risk actually means. • why organisations are targeted. • how breaches happen. • what security controls do. • the basics of frameworks like ISO 27001 or NIST CSF. • that the difference between threats, vulnerabilities, and risks matters. • essential concepts like encryption, authentication

" The biggest misconception is that cybersecurity requires deep technical skills from day one. It doesn’t. Cybersecurity is an ecosystem with 30+ career paths, and many don’t require you to code, configure firewalls or analyse malware."

and access control is more valuable.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

83


THE SKILLS YOU ALREADY HAVE ARE MORE VALUABLE THAN YOU THINK

given you something cybersecurity will always need:

One of the most powerful moments in mentoring is

background is relevant; it’s whether you can articulate

when someone realises their past experience isn’t

how it translates to security work.

transferable skills. The question isn’t whether your

irrelevant, it’s valuable. I’ve seen this repeatedly and I have guided:

START SMALL: BUILD MICRO-SKILLS AND MICRO-WINS I tell every mentee: “Start where you are. Use what

• a project manager who moved into governance, risk and compliance (GRC) because stakeholder

you have. Learn one thing at a time.” Small wins build confidence, and confidence builds momentum.

communication, documentation and structured thinking were already part of his daily routine.

Here are practical, beginner-friendly steps:

• a business analyst who shifted into security governance because she had experience mapping processes, identifying gaps and translating technical issues into business language. • a software tester (non-security) who transitioned

or blogs. • complete a beginner course on security fundamentals.

into application security because testing, breaking

• write a short summary of what you learnt.

things and thinking like an adversary were already

• practice conducting a cyber risk assessment for a

natural strengths. • an accountant who moved to assurance because controls, audits, checklists and compliance were already familiar concepts.

84

• learn basic cyber concepts through short videos

fictional small business. • try one hands-on lab from learning platforms like TryHackMe. • document your practice in a simple portfolio.

Cybersecurity is not only about technology, it’s

These ’micro-wins’ might feel small but employers

fundamentally about people, behaviour, risk,

notice initiative. They prove your mindset, not just

processes and decision-making. Your past career has

your skillset.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


C A R E E R

P E R S P E C T I V E S

more prepared than you think. Don’t wait for 100

" Small wins build confidence, and confidence builds momentum."

percent readiness. Many ‘required’ skills are actually preferences. Employers often value candidates with the right attitude and potential over those that check every box.

THE HUMAN SIDE OF STARTING FROM ZERO One mentee spent three months documenting in

Every mentee I’ve supported felt uncertain at the

simple blog posts everything he had learnt, never

beginning, until one small moment when something

expecting anyone to read them. When he started

finally clicked: a concept made sense, a vulnerability

applying for jobs those posts became tangible proof

scan became clearer, a framework felt logical, or a

of his seriousness and ability to explain complex

security interview went better than expected.

topics clearly. Multiple interviewers specifically mentioned his blog as a deciding factor in hiring him.

That moment changes everything. It’s the point where “I don’t know where to start” becomes “I can actually

NETWORKING OPENS MORE DOORS THAN CERTIFICATIONS

do this.” And if they could reach that moment, so can anyone reading this.

Certifications are helpful, but they are not the first ticket into cybersecurity, social skills are.

YES, YOU CAN START WITH ZERO EXPERIENCE

Every mentee I’ve worked with who transitioned

If you’re starting with no experience, remember:

successfully had these things in common. They connected with the cybersecurity community.

• you do not need a technical background.

They attended meetups.

• you do not need every certification.

They asked questions.

• you do not need permission.

They reached out to professionals.

• you do not need to know everything.

They joined discussions. They showed curiosity.

What you do need is:

In return, they received tips, referrals, guidance,

• curiosity.

confidence, opportunities and job leads. Cybersecurity

• consistency.

is a welcoming space because everyone remembers

• community.

what it felt like to start.

• confidence in your transferable skills. • willingness to learn.

When beginners take the initiative to show up, they get more support than they expect.

Cybersecurity has space for you: not ‘someday’, not when you’re ‘ready’, but starting today. The path won’t

YOU DON’T NEED PERMISSION TO BEGIN

be perfectly linear and you’ll encounter discomfort

Many aspiring professionals wait for ‘the perfect

along the way. But thousands of people before you

moment’ or ‘the perfect role or ‘the perfect skillset’

have walked this exact path and succeeded.

before applying for their first job. But the reality is that no one enters cybersecurity fully prepared. Not

Start learning. Start connecting. Start applying. The

even experienced professionals. The field evolves too

cybersecurity community is waiting for you, and your

quickly for anyone to feel ‘complete’.

unique perspective is exactly what the field needs.

If you understand the basics, have curiosity and

www.linkedin.com/in/poojashimpi

can communicate your strengths you are already

I S S U E 28

WOMEN IN SECURITY MAGAZINE

85


MADHURI NANDI Madhuri Nandi, Head of Security at Nuvei, AWSN Board Chair, Author of Cyber Smart book Madhuri is a cybersecurity leader with nearly 20 years of experience in cybersecurity across strategy, governance, risk, compliance, product and engineering. She holds a master’s degree in cybersecurity and serves as head of security at Nuvei and as chair of the AWSN Board. Madhuri is the author of the Cyber Smart book and creator of a cybersecurity awareness framework. She is known for her strong voice on inclusive leadership, mentorship and community building.

C O L U M N

Pivot: the shift from reacting to anticipating There’s a moment in every career when you realise

knew them. What it taught me was people. Clients

you’re no longer just ‘doing work’. You are carrying the

would talk for 30 minutes about a problem and only

weight of decisions. People look at you before you

at minute 31 tell me the thing that actually mattered.

even say anything. And sometimes, if you are honest,

I learnt to listen to the silences, to the politics, to the

you feel as if you are still catching up to the version of

way decisions really get made.

you everyone else sees. One client asked me, “Your report is great. But what My own pivot wasn’t a single lightning moment. It was

I actually need is for my CEO to understand the

a slow accumulation of discomforts, small wins and

human impact. Can you do that?” It was the first

those conversations that stay with you long after the

time I realised cyber is 50 percent controls and 50

meeting ends.

percent conversation.

WHEN YOUR SKILLS NO LONGER MATCH YOUR AMBITION

THE NEXT PIVOT: ENGINEERING AND PRODUCT

I started out hands-on, very hands-on; the kind of

Engineering taught me patience: that ‘fixing’ things

work where your day ends when logs stop shouting

is easy. Aligning teams? That’s a different world.

at you and alerts calm down. I loved that world: the

Product management taught me to think like the

clarity, the rush, the technical puzzles, the feeling that

business, not the security team. When you manage

I had ‘fixed’ something.

a product, you can’t hide behind ‘best practice’. You have to justify decisions with dollars, time, customer

Then something subtle started happening. People

impact and trade-offs.

stopped asking me how the attack happened. They started asking me questions like: “What does this

I remember sitting in a room with architects, arguing

mean for us?” “How do we stop this from happening

passionately for the control we absolutely needed.

again?” “Can you brief the CIO in 10 minutes?” It felt

One of them said, “Can you tell me what the business

as if I was being quietly pushed from the engine

case is in one sentence?” I froze, not because I

room onto the command deck. And I wasn’t ready. Or,

didn’t know the answer, but because I wasn’t used

maybe, I didn’t think I was.

to summarising information in such a way. That day changed the way I communicate. I stopped talking

86

THE FIRST MINI PIVOT: CONSULTING

about controls. I began discussing risk appetite, trust

Consulting didn’t teach me frameworks. I already

and growth.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


THE LEADERSHIP PIVOT: WHEN REACTING ISN’T ENOUGH

WHAT I WISH I KNEW EARLIER Here’s some truths no one told me.

Leadership comes gradually, then suddenly. You go from being the one doing the work to the one

1.

You don’t pivot once. You pivot constantly. Every

unblocking others, to the one people look to during a

new role, new program, new crisis and new team

crisis expecting calm, clarity and confidence. No one

is a pivot.

prepares you for that moment. Especially when you’re

2.

thinking, “I’m worried too.” I learnt that leaders don’t remove fear; they help the room breathe through it.

The higher you go, the fewer answers matter and the more alignment matters.

3.

Your technical confidence gets you into the room; your emotional intelligence keeps

And this is where anticipation enters. Leadership isn’t

you there.

“We fixed today’s problem.” It’s “What could tomorrow

4.

Strategy is not a document; it’s a way of thinking.

look like?” “How do I prepare my team emotionally,

5.

You can be decisive and still human. You can be

not just technically?” “How do we build resilience, not

strong and still vulnerable.

just maturity?”

WHY ANTICIPATION MATTERS NOW One of the most defining lessons for me was realising

Cybersecurity is moving faster than ever, but

that emotional intelligence is not a ‘soft’ skill but a

leadership hasn’t always kept pace. We don’t need

strategic skill: the kind that turns a team from reactive

more heroes running into fires. We need leaders

to proactive.

building cities that don’t ignite so easily.

THE REAL PIVOT: ANTICIPATION AS A MUSCLE

The future of cyber isn’t just tools and frameworks.

When you’ve lived in SOCs, consulting rooms,

It’s leaders who understand people, culture,

engineering floors and boardrooms, you start seeing

psychology and trust; leaders who can sense the

patterns. You anticipate tension before it escalates.

shift’; leaders who can pivot again and again. Maybe

You anticipate a breach pattern before the attacker

that’s the secret. Every pivot we make moves us

shifts. You anticipate burnout before your team

slightly closer to who we’re meant to become.

burns out. www.linkedin.com/in/madhurinandi

Anticipation isn’t fortune-telling. It’s experience plus empathy plus pattern recognition. It’s saying, “I’ve seen this movie before, but this time, I’m not just reacting to the plot twist.”

I S S U E 28

WOMEN IN SECURITY MAGAZINE

87


STUDENT IN SECURITY SPOTLIGHT


Given my background, and my passion for people, my ideal role would be a leadership position in the threat intelligence space. A role wherein I will be PAIGE HAINES

able to proactively identify and analyse potential threats before they impact our society. I’m especially motivated by my desire to protect vulnerable

Paige Haines is currently pursuing a Bachelor of Cyber Security at Deakin University. Bachelor of Cyber Security student at Deakin University.

members of our society, who often face the biggest risk from threat actors. In addition, I am someone who thrives on strategy, and pursuing a leadership role allows me to guide decisions and help shape effective mitigation strategies, further protecting my community.

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest? When speaking to those who are not within the field,

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?

I often take an anecdote based approach, where I

My decision to pursue cyber security didn’t come

discuss how threats in the field relate to threats that

from a single moment, but was rather shaped by a

the person may experience in their day to day life,

series of different experiences that slowly connected

such as the decision to drive somewhere and take

over time. I grew up surrounded by computers and

the risk of an accident, or going to the grocery store

90s game consoles as my parents loved collecting

at the end of the day and taking the risk that they

retro technology from their childhood. Being around

may have run out of roast chickens.

tech always felt very natural to me. After graduating high school in 2018, I spent a few years working

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

full-time while trying to figure out what I truly

When I was first entering the industry, one of the

entire identity stolen after falling victim to a phishing

biggest misconceptions I thought was that cyber

attack. I remember watching her bank accounts get

security had to be an incredibly technical field and I

drained, as she frantically spent hours on the phone

was ready to hone my skills in a specialised area. It

with multiple companies trying to recover anything

came as a surprise when I realised that it was still

she could. It was honestly heartbreaking that

very human-centric, and I could transfer a lot of the

something like this could happen to someone that I

skills I developed in my marketing career into cyber

worked with, someone who I was close with.

cared about. During this time, a close colleague of mine had her

security. I attribute a lot of my success to leaning into this aspect of cyber security and it has led to some

Not long after, I took a role at a technology company

fantastic industry connections.

in their marketing department. I was an avid gamer, and so this role was a lovely mixture of my love for

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

90

W O M E N I N S E C U R I T Y M A G A Z I N E

gaming and new technologies, as well as my love for writing. When I was later made redundant from this role, I suddenly found a space to pause and

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

think deeply about my future. In these four months,

and the potential of future use of AI in risk

I reflected on all those moments, and I constantly

management”. This was an incredible experience as

returned to technology, and my desire to help people.

it aligned perfectly with a goal I had set for myself.

Cyber security felt like such a natural fit for me. It was this moment that I decided to take a leap of

At the start of 2025, I promised myself that I would

faith and apply to the Bachelor of Cyber Security at

complete a speaking engagement before graduating

Deakin University as a mature-age student, finally

in 2026. Being able to achieve this goal at the end of

ready to pursue the field that brought all of the above

2025, a full 12 months ahead of schedule, made this

experiences together.

moment so significant to me. I was able to speak on a topic I am very passionate about, and accomplish a

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations.

career goal much earlier than anticipated.

network for all the opportunities I have been afforded

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

in my time as a student and as a professional in the

As part of my degree, I am currently undertaking

field. From my first trimester, I was determined to

an internship as a Cyber Security Analyst at

grow into the person I had always wanted to be, and

CAPA Intelligence. I work closely with the critical

carve out my own space in a new industry. Through

infrastructure sector, specifically in electricity. In

social anxiety and imposter syndrome, I had a feeling

this role, I have learned so much relating to industry

that this new chapter was made for me, and I was

tools, and domain knowledge that is an extension of

resolute in trying out a different approach.

my course.

I made a commitment to put myself out there at

Security Australia (WiCyS). It is within these spaces

The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?

that I have met so many incredibly driven individuals,

I have pursued many certifications, as these are

where I have formed friendships and connections

offered to high-achieving students in my degree. So

that have continued to support me both personally

far, I have obtained the Certified Secure Computer

and professionally. In my goal to embrace every

User (C|SCU) from EC-Council, and the

opportunity to connect with others, I attribute

Certified in Cyber Security (CC)

much of my success to the constant support and

from ISC2, which is one I

generosity of these individuals.

pursued personally, outside

I could never fully express how thankful I am to my

as many events as possible. I actively engaged in communities such as the Australian Women in Security Network (AWSN), and Women in Cyber

of study. Given my interest

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.

in threat intelligence, I was

Thus far, the most memorable event I have been

Forensic Investigator (C|HFI)

involved in was my recent contribution to the IEEE

from EC-Council which was a

Conference on Engineering Informatics. I was invited

certificate I was committed to

to join a panel discussing “Cyber risk quantification

obtaining. I am currently studying

I S S U E 28

able to have the opportunity to obtain the Computer Hacking

WOMEN IN SECURITY MAGAZINE

91


PAIGE HAINES

in your field of interest, and it is for this reason that

Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?

I have decided to pursue threat intelligence and

For me, the most challenging aspect of my own

forensic investigations-related certifications.

cyber security journey is balancing my current casual

for this certification, with an intended completion date of February 2026. I am a firm believer in choosing certifications that will open opportunities

role with my full-time studies as time management

What aspect of your cybersecurity studies excites you the most, and why?

can become quite complicated. To manage this,

The hands-on labs are the most memorable part of

sleep, as I found this has an extreme impact on

the course, and there are plenty of units that offer the

my ability to take on work and my productivity.

opportunity to develop skills in industry-related tools

By prioritising my overall health, I was then able

and investigation techniques which mirror real-world

to tackle both commitments without jeopardising

techniques closely. As I move into my third year of

my wellbeing.

I ensured that I was getting enough exercise, and

study, the units are becoming much more aligned with specialised cyber skills including malware analysis, and ethical hacking.

Conversely, which aspect of your studies do you find least interesting or useful, and how do you navigate through it?

Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus? There are so many fantastic niches within the cyber security industry, and I would love to see

I am not much of a coder, so many of the coding-

more people-centric units that go beyond simple

based units, particularly those involving C(++, #).

governance. In the future, I would love to see an

I really enjoyed utilising Python for my machine

entire governance, risk, and compliance unit, as I

learning units, as I found the language a bit more

have found I do quite a lot of compliance work in

intuitive and more aligned with my style of work!

my current role, and feel that I could have benefitted from a structured unit exploring these topics.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why? Communication is such an integral part of any job role, and given most IT and cyber security students are largely introverted, I do genuinely believe they could benefit drastically from a unit that dives into management, and interpersonal skills between employees of all different levels. Developing skills in translating more complex reports into a format that highlights business value over content is something that I think could benefit a lot of specialised cyber employees in the future.

92

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

What is your preferred source for staying informed about cybersecurity trends and general information?

S P O T L I G H T

with random companies if it is not needed. These proactive actions have allowed me to remain aware of new threats.

In my field, staying up to date is absolutely essential,

great for getting quick insights into threats that are

Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider?

actively unfolding in the wild. Because I work within

I would not make any changes to my trajectory,

the operational technology space, I also make a point

as I am incredibly proud of the things I have

of checking blogs from companies like Forescout

achieved thus far. I believe that I have achieved

and Dragos. Their updates help me stay connected

a lot despite only having just finished my second

to what’s happening in the OT world and ensure I’m

year of university, and I am eager to maintain this

always learning something new.

momentum even when I finish my degree. The

so I lean on a mix of reliable sources to keep my knowledge sharp. I regularly read the TLDR newsletter and follow the ACSC data feed. They’re

connections and knowledge that I have gained

Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.

throughout these last two years has been nothing short of life changing. instagram.com/bit.blondie

My experience in cyber security has been largely driven by my own enthusiasm and curiosity and I have found that the community, for the most part,

www.linkedin.com/in/paigehai

has been incredibly welcoming and supportive of newcomers and my peers. While there will always be occasional moments wherein my knowledge or dedication is underestimated, I try not to let these moments define what my journey looks like. Over time, I have realised that my consistent effort and passion speaks very loudly, and they have opened doors for me to collaborate within the community. I prefer to let my work, and the results of my dedication, speak for themselves.

What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? I have set up biometric authentication on almost every device and account I have to better my security posture. From my previous experiences, I have also learnt the importance of having conversations about cyber security with my family and friends to ensure they are taking it seriously as well. In addition, I often minimise the amount of personal data I share

I S S U E 28

WOMEN IN SECURITY MAGAZINE

93


PRAJOTI RANE

Prajoti Rane, a determined and inquisitive Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI) Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI)

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? Initially, my parents were very concerned. Their understanding of cybersecurity came from movies and social media, where hackers were portrayed negatively, so they thought what I was doing might be illegal. To change that perception, I started writing blogs that explained cybersecurity concepts in the simplest way possible. They didn’t read all of them, but over time, they realised that my work was about protecting cyberspace, not breaking it. Today, they

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

actively educate friends and family about online

My interest in cybersecurity started in a very real and my father’s credit card was hacked. Fortunately,

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.

multi-factor authentication saved him from what

One of the most memorable moments was attending

could have been a serious financial loss but that

a regional CTF hackathon alone. Everyone else was

moment lit a spark in me. I became determined to

in groups, and I felt intimidated and almost cried.

understand how these attacks happened and how

But I pushed through, competed solo, and finished

people could protect themselves.

strong. That experience taught me resilience and

unexpected way during the COVID lockdown, when

safety and are extremely vigilant, something that makes me proud.

self-belief qualities that continue to guide me in For the next six months, I threw myself into learning

this field.

everything I could. I even found myself pretending

hacker,” but I was naive and still building my skills.

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

Even so, every small breakthrough felt huge and

I have had the privilege of completing three

pushed me to keep going.

internships, each of which was a turning point in my

to be male in online forums because, as a woman, I wasn’t taken seriously and was often dismissed or mocked. At the time, I had this dream of being a “cool

career. These experiences taught me things I couldn’t

94

Now, after several internships and plenty of hands-

learn academically, such as working with SIEM tools

on experience, my mindset has changed completely.

and approaching problems calmly and strategically.

I’m no longer drawn to hacking out of curiosity; I’m

Most importantly, they improved my communication

focused on defending, protecting, and helping others

skills. For example, during my time at Agropur, an

stay safe. Looking back, I’m genuinely proud of how

elderly employee struggled with MFA and visited

far I’ve come and how much I’ve grown since those

my desk daily to complain. One day, I explained

early days.

MFA using a simple door analogy, and he finally

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

understood. After that, he never came back with

To overcome this, I created a structured approach: I

complaints. That moment reinforced how critical

dedicate specific blocks of time for labs and projects,

clear communication is in cybersecurity.

and then allocate separate time for certification prep. For example, I built a home lab using VirtualBox and

The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?

Kali Linux to practice penetration testing and network

One of the biggest challenges I face is balancing

you can do; certifications show what you know. Both

hands-on projects with certifications. In

matter, but hands-on experience has taught me to

cybersecurity, there’s no single roadmap; some

think critically and troubleshoot under pressure skills

people swear by certifications, while others

that no exam can fully replicate.

monitoring. These projects gave me confidence to explain concepts during interviews, which I believe is more impactful than just listing certifications. My philosophy is simple: projects demonstrate what

emphasize practical experience. Early on, I felt torn preparing for exams like Security+, CEH, or CISSP.

What aspect of your cybersecurity studies excites you the most, and why?

Certifications are important because they validate

What excites me most is the problem-solving aspect.

your knowledge and help you stand out in the job

Cybersecurity often feels like working through a

market, but they don’t always reflect real-world

complex puzzle every vulnerability is a clue, and

problem-solving skills.

every solution strengthens the system. I enjoy the

between spending time building home labs and

I S S U E 28

WOMEN IN SECURITY MAGAZINE

95


PRAJOTI RANE

challenge of thinking critically and creatively to stay

application vulnerabilities and how they handled

ahead of threats. It’s rewarding to know that the

them. Listening to their real-world stories gave me a

work I do has a real impact on protecting people and

perspective I could never get from a textbook.

organisations, which makes every solved problem feel meaningful.

I also take part in Capture the Flag (CTF) competitions and online communities. I’ll admit, I

Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus?

was pretty intimidated at first, but pushing through

My coursework is heavily focused on web security,

discovered on my own.

that fear really paid off. These experiences have sharpened my problem solving skills and introduced me to so many tools and techniques I wouldn’t have

which is important, but I believe network security deserves more emphasis. While some consider

But beyond the technical side, being part of this

networking old-fashioned, the reality is that nearly

community has boosted my confidence. It’s

75% of cyberattacks still occur through network

incredibly inspiring to meet people who share the

vulnerabilities. Networking is foundational; it’s the

same passion and to learn from their journeys. Some

backbone of cybersecurity. You can’t truly secure

of these connections even turned into mentorship

systems without understanding how networks

opportunities, which helped me make better career

operate. Because of this gap, I’ve had to pivot toward

decisions and focus on what truly excites me

certifications and hands-on projects to strengthen

in cybersecurity.

my networking knowledge.

Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience? Yes, I love being involved in the

Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences. Absolutely, and unfortunately, it’s been a recurring theme. In group projects, I’ve often been overlooked

cybersecurity community. I try to

by professors directing technical questions to my

attend as many meetups and

male teammates while ignoring me, even when I

conferences as I can,

contributed significantly. One memorable instance

especially around

was during a presentation where the professor asked

Boston, where

my male teammates a question about our project.

the tech scene

They struggled to answer, and I had to step in and

is incredibly lively

explain the solution. That moment was bittersweet; it

and welcoming.

proved my competence but also highlighted the bias.

These events have

96

helped me grow in

Early in my journey, I faced even harsher challenges

ways I never expected.

online. During CTF competitions, once participants

I still remember attending

discovered I was a woman, I became a target for

a local OWASP chapter

ridicule. It affected my confidence so much that I

meeting where experts

pretended to be male for six months just to learn

broke down real web

in peace. Looking back, that was a survival tactic,

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

but it also fueled my determination. Today, I’ve built

by revisiting core concepts like network security,

enough skills and confidence to demand respect

incident response, and cloud security, and practicing

for my work. My response to discrimination has

hands-on scenarios in my home lab.

always been to outperform expectations. I believe representation matters, and I want to be part of the

I’ve also learned that interviews aren’t just about

change that makes cybersecurity more inclusive.

technical skills, they test your ability to think under pressure and communicate clearly. For example,

What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape?

one interviewer asked me to explain MFA to a

I take my personal cybersecurity very seriously; it’s

That experience taught me that cybersecurity

second nature now. I never share live updates or my

professionals must bridge the gap between

location on social media; if I post, it’s after I’ve left the

technical complexity and user understanding. While

place. This habit started after a frightening incident

I’m nervous about the upcoming job search, I’m

in high school when a stalker tracked me through

confident that my mix of technical skills, practical

an Instagram post and followed me home. That

experience, and communication ability will help me

experience taught me how dangerous oversharing

stand out.

non-technical person, which reminded me of the elderly employee I helped during my internship.

can be. Today, I use multi-factor authentication (MFA) on

www.linkedin.com/in/prajoti-rane

every account that supports it, strong and unique passwords managed through a secure password manager, and I regularly monitor my digital footprint. I also avoid connecting to public Wi-Fi without a VPN and keep my devices encrypted. Beyond protecting myself, I educate friends and family about these practices because cybersecurity awareness is often the weakest link. For me, security isn’t just professional, it’s personal.

Have you actively sought employment opportunities in the cybersecurity field, and if so, what has been your experience with the application and interview process? Currently, I’m interning, but I’ll soon start applying for full-time roles. Honestly, the job market is daunting. Cybersecurity is competitive, and while demand is high, employers often seek candidates with years of experience. My past internship interviews were mostly situational focused on problem-solving and communication, but full-time roles demand deeper technical expertise. I’m preparing for that

I S S U E 28

WOMEN IN SECURITY MAGAZINE

97


learning, constantly adapting, constantly solving new mysteries. So when I talk about cybersecurity casually, I frame it as the modern-day version of TANVI BADGHARE

both a detective’s work and an architect’s vision: you investigate, you design, and you protect. And for me, that combination makes it one of the most exciting careers anyone can step into.

Tanvi Badghare is in her final year of a B. Tech in Computer Science and Engineering, specialising in Cyber Security and Digital Forensics at VIT Bhopal University, India. B. Tech in Computer Science and Engineering student at VIT Bhopal University, India.

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice? Upon graduation, I hope to work in a research driven role in cybersecurity, with a strong focus on theoretical cryptography. I’ve always enjoyed exploring new ideas and uncovering patterns, and research gives me the freedom to follow that

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?

curiosity in a meaningful way.

When someone who isn’t from this field asks why

Every concept opens a new door. I genuinely find it

cybersecurity excites me so much, I tell them that

intriguing and fun, almost like solving a puzzle that

it feels like working at the intersection of puzzles,

could one day protect millions of people.

Cryptography, in particular, caught my eye because it feels like a place where discovery never stops.

protection, and possibility. We live in a world where nearly everything our conversations, our finances,

As a woman pursuing research in such a

our memories exist as data. Cybersecurity is the

mathematically intense and traditionally male-

invisible force that keeps that world trustworthy.

dominated area, I’m motivated by more than just the science. I’m motivated by the idea of taking up space

For me, the most thrilling part is that it’s not just

in rooms where women are still underrepresented,

about stopping attacks; it’s about outsmarting them

and contributing to knowledge that shapes the future

before they even exist. Especially in cryptography,

of secure communication.

which is my passion, there’s this beautiful blend of mathematics and creativity. You’re building systems

It’s a path that excites me both intellectually and

that allow people to prove things without revealing

personally, one where I can explore, innovate, and

them, or compute securely without ever exposing

help redefine what the next generation of women in

the underlying data. It feels almost magical, but

cybersecurity research looks like.

it’s grounded in real science that impacts billions

technical field, it’s a deeply human one. Every

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?

solution we build protects someone’s privacy, dignity,

The most influential factor in my cybersecurity

and safety. And because threats evolve so fast, the

journey has been discovering theoretical

field never becomes repetitive. You’re constantly

cryptography and especially the work of Shafi

of lives. I love explaining that cybersecurity isn’t just a

98

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

Goldwasser. I actually entered the field through

multiple branches of

zero-knowledge proofs, long before I knew how

cybersecurity AI-driven

deep and fascinating the landscape truly was. But

threat detection, STIX/

when I encountered Goldwasser’s work, it drew me

TAXII-based intelligence

in with a sense of possibility. It wasn’t the technical

sharing, and zero-

side that drew me in first , it was the feeling that

knowledge protocols. It’s still

this field had room for imagination, curiosity, and a

evolving, but taking the lead

kind of intellectual courage. Her contributions made

has allowed me not only to

cryptography feel less like a distant, rigid discipline

shape the technical direction,

and more like a world of ideas that could be explored,

but also to grow into the kind

questioned, and expanded. And the fact that this

of researcher and collaborator I want to become.

world was shaped so profoundly by a woman made it feel much more accessible to me.

For me, these experiences are more than stepping stones; they’re the beginning of a path I’m carving for

It made me realise that theoretical cryptography

myself as a woman in cybersecurity who hopes to

wasn’t just something I enjoyed in isolation, it was

contribute meaningfully to theoretical cryptography.

a place where I could build a future. And in many

Each project and opportunity helps me deepen my

ways, I’m still at the very beginning of that journey.

curiosity, strengthen my skills, and move one step

I’m constantly looking for opportunities to deepen

closer to the research future I envision.

my understanding, whether through research, of ideas that first drew me in. I hope to keep growing,

What aspect of your cybersecurity studies excites you the most, and why?

learning, and gradually shaping my own place in

The part of cybersecurity that excites me the most

this field.

is cryptography, especially zero-knowledge proofs

collaborations, or any chance to engage with the kind

and multi-party computation. For me, it feels less

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

like a subject and more like a place where all the

Beyond my academic studies, my practical

drawn to ideas that require patience and imagination,

experience has been a blend of industry exposure

and cryptography gives me that feeling every single

and self-driven exploration. I may still be at the early

time that sense of unlocking a concept that once

stages of my journey in cryptography, but I’ve already

felt impossible.

things I’ve loved since childhood finally converge: mathematics, theory, patterns, and the quiet joy of understanding something deeply. I’ve always been

worked as a Cyber Risk & Compliance Intern, where I spent a month understanding how organisations

Zero-knowledge proofs were my first doorway into

handle real-world security challenges. Even though

this world, and I still remember the moment they

it wasn’t directly cryptographic, it grounded my view

“clicked” for me. It felt almost poetic the idea that you

of the field and reinforced my desire to move toward

could prove something without revealing the thing

more research-oriented work.

itself. As I explored multi-party computation, that feeling only grew stronger. These fields have a kind

At the same time, I’ve been actively building my

of elegance and purpose that genuinely moves me.

experience through projects that push me closer

They show how pure theory can shape the real world

to the theoretical space I hope to contribute to. I’m

in profound ways, from privacy to trust to security

currently leading a team project that brings together

at scale.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

99


TANVI BADGHARE

The more I study cryptography, the more I realise

hand-holding; it’s about having someone there to

that this is where I see my future. It’s why I’m

nudge you forward at the right moments while letting

preparing to pursue my master’s in Fall 2026. I want

you explore independently.

the chance to go deeper, to contribute to research, and to be part of the community of people who are

Starting out can still feel daunting, but I’ve learned

quietly building the foundations of tomorrow’s secure

that I don’t need to change who I am to find my place

systems. For me, cryptography isn’t just the most

in cybersecurity. I just need to build my path in a

exciting part of cybersecurity; it’s the part where I feel

way that feels authentic to me guided by curiosity,

most at home challenged, inspired, and completely

small steps, and the occasional helping hand when it

certain that this is where I’m meant to be.

truly matters.

Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges? One of the hardest parts of my cybersecurity journey

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?

hasn’t been the concepts themselves, it’s been

Yes, definitely. I’ve come to realise that thriving

figuring out where to start, who to turn to, and how

in cybersecurity especially as a woman in a still-

to find guidance beyond the classroom. As someone

growing community takes more than just technical

who leans naturally toward introversion, stepping into

know how. Interpersonal skills, confidence, and the

wider technical communities can feel intimidating,

ability to connect with others are just as important,

and sometimes taking that first step seems tougher

because in a smaller community, every interaction

than anything that comes afterward.

counts. Networking isn’t just about creating opportunities; it’s also about finding your place and

What’s helped me is learning to take small,

feeling like you belong.

intentional steps. I often start quietly reading research papers, following work that inspires me,

I haven’t yet had the chance to meet the leading

or joining online spaces where conversations feel

researchers whose work inspires me, but that’s

meaningful rather than overwhelming. Along the

something I hope to change in the coming years. I

way, I’ve been lucky to have a mentor who

want to attend conferences, engage with the wider

offered guidance when I really needed

research community, and, with guidance from the

it. Even occasional check-ins showed

right mentors, one day present my own papers.

me that seeking help doesn’t require

Those spaces are where ideas grow, collaborations

being extroverted, it just means being

spark, and young researchers find their voice.

honest about where you are and where you want to go.

Building non technical skills like communication and leadership is a big part of that journey. Leading

Over time, these small

team projects, explaining complex ideas clearly, and

approaches have made it

forming meaningful connections all help amplify the

easier to ask questions, reach

impact of your technical work. For women in tech,

out, and build confidence

these skills also make it possible to claim space,

at my own pace. I’ve also realized that mentorship

share perspectives, and contribute confidently to shaping the future of cybersecurity.

isn’t about constant

100

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

So while my heart is in the theoretical and technical

distance ahead, but we can see plenty there that

side of cybersecurity, I’ve learned that the non-

needs to be done.” To me, that perfectly captures my

technical skills are just as crucial for the kind of

journey in cybersecurity.

researcher and the kind of professional I aspire to become.

Looking back, there are a few things I wish I had done differently, mainly starting earlier and engaging more

Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience?

actively with the cybersecurity community. If I could,

Yes, I’m actively involved in the broader cybersecurity

how important community engagement is not

and cryptography community, and I’m intentionally

just for opportunities, but for exposure to ideas,

working on expanding that involvement. So far,

collaborations, and mentorship.

I would have attended conferences, participated in workshops, and reached out to professionals sooner. Being naturally introverted, I underestimated

I’ve been part of my university’s WiCyS (Women in Cyber Security) Student Chapter, which has been

I now realise that building connections early

a fantastic way to get early exposure to peer-led

whether through forums, conferences, or university

discussions, workshops, and collaborative learning

chapters can accelerate learning and open doors

environments. I also follow and engage with the IACR

to research possibilities. I also wish I had explored

Cryptology e-Print archive to keep up with cutting-

research sooner, gaining hands-on experience and

edge research in cryptography, especially in areas

perhaps even contributing to papers before my

I’m passionate about, like zero-knowledge proofs and

later semesters.

homomorphic encryption. That said, these reflections have shaped my path While I’m still at the early stages of my community

moving forward. I’m now much more intentional

involvement, I’m gradually broadening it. Engaging

about expanding my network, joining global

with these communities has already enriched my

communities, seeking out conferences, and taking

learning, exposed me to diverse perspectives, and

initiative in research-focused work. Rather than

helped me stay in tune with industry trends. As I

seeing these earlier gaps as regrets, I view them as

grow, I hope to take a more active role attending

guidance that helps me move forward with clarity,

conferences, contributing to discussions, and

confidence, and purpose.

eventually presenting my own work with the guidance of mentors.

I’m also deeply grateful to Abigail Swabey and the team for creating spaces like this, where women in

For me, being part of the community isn’t just about

cybersecurity can share their journeys. These spaces

networking; it’s about growing as a researcher,

truly make a difference.

building confidence, and finding spaces where I can learn, contribute, and feel represented as a

For anyone who resonates with my journey or works

woman cybersecurity.

in cryptography, zero-knowledge proofs, multi-party computation, or theoretical cybersecurity research

Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider? As Alan Turing said, “We can only see a short

I S S U E 28

I’d love to connect on LinkedIn or by email. I’m always excited to learn, collaborate, and grow within this community. www.linkedin.com/in/tanvi-i

WOMEN IN SECURITY MAGAZINE

101


I had no prior IT experience or studies in school so cybersecurity was completely new to me. When I first considered studying cybersecurity, my preconceived idea was that it would be almost entirely technical AMY KORALIS

coding, networks and systems which honestly made me nervous about how I would progress. But that uncertainty is what pushed me to keep learning and

Amy Koralis is a dual-degree student at Macquarie University, currently pursuing a Bachelor of Cyber Security and a Bachelor of Laws. Bachelor of Cyber Security and a Bachelor of Laws student at Macquarie University.

embrace the challenge and as I progressed I quickly realised how much broader and diverse the field truly is. Alongside the technical foundations, I have been able to study areas like cybersecurity management, privacy, digital forensics, governance and the human factors that influence security decisions. What surprised me the most is how naturally cybersecurity has aligned with my legal studies and the intersections between regulation and digital systems has made my experience far richer than I expected.

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

I get genuinely excited when speaking to people

Once I graduate I would like to build a career as a

who aren’t familiar with cybersecurity because I get

cyber lawyer in advisory and litigation, supporting

to explain to them how it’s this dynamic blend of

organisations as they prepare and respond to

problem solving, creativity and real world impact.

cybersecurity incidents. I feel there is a growing

As someone studying the unique combination of

demand for lawyers who understand both the

cybersecurity and law, I often highlight that the field

legal and technical dimensions of cybersecurity

is far broader than traditional programming roles,

to guide organisations through every stage of

it opens doors to careers at the intersection of

incident response and confidently navigate complex

technology, governance, policy, ethics, investigations

technical matters. What motivates me the most

and human behaviour.

is the opportunity to bridge the gap between law and technology. Cybersecurity is not just about

What I love most is the ever-evolving nature of the

technology, it is about understanding people,

work; things change fast and the constant shift

organisations, behaviour, policy and risk.

creates challenges that push you to keep learning and thinking critically. Cybersecurity welcomes people from all kinds of academic and professional backgrounds, each bringing strengths that are technical, analytical or strategic. That diversity is what makes the field so exciting and accessible.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? When I was in Year 11 exploring different degree

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

102

W O M E N I N S E C U R I T Y M A G A Z I N E

options to combine with law, I knew I wanted something that used my strengths in maths and science as well. My dad works in the IT sector, so we had a lot of conversations about what that path

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

could look like, but IT felt too broad and technical

digital literacy and ensuring everyone has the skills

for what I wanted. It wasn’t until cybersecurity came

to stay safe online. Seeing how our work could

up in conversations with my dad and later with my

empower schools and give teachers and students

tutors that I realised it could be the right path for me.

foundational cybersecurity awareness made the

At the time, Macquarie University had just introduced

experience truly meaningful. That real world impact

a Cybersecurity degree, one of the only universities

is what has stayed with me the most.

offering it. The opportunity to combine law and

incredibly supportive, even though the degree was

Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?

new and none of us knew exactly where it would

I do feel that Macquarie University has made a

lead. Looking back five years later, cybersecurity

strong effort to keep pace with the rapid evolution

has exploded across every industry and specialised

of cybersecurity. From my very first unit, lecturers

cyber law roles are now in high demand. It’s

emphasised that there would be no traditional

incredibly rewarding to see how my decision to study

textbooks for this field because the landscape

cybersecurity has set me up for a strong future in the

changes too quickly. Most of our learning comes

field and I am genuinely excited about the learning

from analysing current articles, case studies and real

ahead and the career I am building.

world incidents which keeps the content relevant

cybersecurity and study in a field that blended governance, policy and technology really appealed to me. My family, peers and career advisors were all

and grounded in practice. Earlier in my degree, there

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.

was definitely a heavier weighting toward technical

The most memorable moment in my cybersecurity

units introduced that focus on communication,

journey so far was completing my placement project

people skills and management, recognising that

through Macquarie University, where I led a team

cybersecurity professionals need to translate

that developed cybersecurity training materials for

technical concepts to diverse audiences not just

teachers and hands-on activities for students. Our

work behind the scenes. It is important that the

project was so well received that we were invited to

degree continues to evolve alongside industry

deliver our activities to primary school students as

developments so it remains professionally relevant

part of Macquarie University’s outreach program.

and continues to prepare students for the realities of

What made this project so impactful was realising

cybersecurity work.

units but the balance has improved over time. I have noticed a shift in the curriculum, with more

that cybersecurity isn’t just about protecting big organisations or responding to high-profile incidents, it is also about sharing knowledge, closing gaps in

What aspect of your cybersecurity studies excites you the most, and why? The aspect of cyber security that excites me the most is exploring the intersection between technology, policy and human behaviour. I love understanding not just how incidents happen technically, but why they happen, what organisational decisions, governance gaps or behavioural factors contributed. I get excited by the constant problem solving cybersecurity demands and that there is never one approach to resolving problems.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

103


AMY KORALIS

Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?

Infosecurity Magazine, Cyber Daily, iT News, and

One of the areas I have found most challenging

threats. Social platforms like LinkedIn and GitHub

in my cybersecurity studies has been the more

are great for joining conversations, learning from

technical components. I enjoy the analytical

professionals, and seeing what’s happening in the

thinking and problem solving involved, but the

field right now.

CyberCX. I also keep an eye on reports from organisations such as ACSC and major cybersecurity firms to stay informed about the latest trends and

depth of programming and command line work can sometimes be more complex to grasp, especially

Beyond reading, I really enjoy attending seminars

without an IT background. There are moments I have

and university events. At Macquarie, the Computing

felt overwhelmed but I have learnt this is part of the

Society regularly hosts industry talks, which have

learning curve in cybersecurity. To work through a

been an incredible opportunity to hear directly

challenge, I focus on breaking down problems into

from cybersecurity professionals and see how the

smaller pieces and practicing regularly. I have also

concepts I learn in class come to life in real-world

found that collaborating with peers and working

situations. These experiences make my studies feel

through problems together has been invaluable and

more connected to the industry and inspire me to

has helped me see solutions I wouldn’t have found

keep growing.

on my own.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?

www.linkedin.com/in/amy-koralis-1848b122a

Yes, absolutely. Cybersecurity roles today require more than just technical skills and I have become increasingly aware of the importance of interpersonal communication, management and leadership skills. Whether you are presenting a risk assessment, explaining technical issues to non technical audiences or just supporting an organisation through a cyber incident, your ability to communicate clearly can make all the difference. For someone like me who aims to work at the intersection of cybersecurity and law, these skills are even more important.

What is your preferred source for staying informed about cybersecurity trends and general information? As a student, I make it a point to stay connected with the cybersecurity world by following trusted publications and subscribing to newsletters like

104

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


Join Us in Empowering

Future Leaders

! d e t n a W y it r u c e S in Students Are you a student passionate about shaping the future of security? Do you have innovative ideas and insights to share with a global audience? Join us in contributing to the Women in Security Magazine and become a voice for the next generation of security leaders!

Why contribute?

Gain valuable exposure: Reach over 11000 subscribers globally and showcase your expertise to industry professionals.

How to get involved

Make an impact: Share your experiences, challenges, and aspirations to inspire others and shape the future of security.

Let us know you are interested. We will send you a series of questions of which you can choose which ones you would like to answer. Submit those back to us in an email. We will then edit to be a concise and flowing edited Q&A.

Don't miss this opportunity to be part of a vibrant community of students driving change in the security industry. Contact us today to learn more about how you can contribute to the Women in Security Magazine!

Contact: jane@source2create.com.au


ASHLEY MATHEW

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare? When I first became interested in cybersecurity, I imagined it was all penetration testing, hacking

Ashley Mathew is currently pursuing a Bachelor of Cybersecurity at Deakin University in Melbourne. Bachelor of Cybersecurity student at Deakin University in Melbourne.

challenges, and constant coding. I think that’s the picture a lot of us start with when we hear the word “cybersecurity.” But once I actually stepped into the field, I realised how different and much broader it really is. There’s a huge amount of thoughtful analysis, documentation, and structured decision-making behind every technical move. Sometimes, simply

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?

paying close attention and understanding the bigger

When I explain why cybersecurity is exciting, I usually

One of the biggest mindset shifts for me was

start with something everyone understands. Our

discovering that not every cyber role requires heavy

whole world runs on technology now. For example,

coding. In fact, some barely touch it. You can build an

thinking about hospital records that were once

incredible career in areas like digital forensics, GRC,

handwritten are all sitting in electronic systems

policy development, threat intelligence, or auditing

today. Every bit of your personal information, from

with only basic Python knowledge. Cybersecurity has

your address to your emergency contacts, is just a

so many paths and that’s what makes it exciting.

picture matters just as much as (or even more than) the hands-on technical work.

click away.

gets a hand on it. One malicious person inside

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

that system and having full control over it. Your

I am aiming for a SOC analyst role, and my

details, your identity, everything that matters to

connection to it started in an unexpected way. While

you, suddenly at someone else’s leisure. That’s how

preparing a presentation on What is SOC for the

critical cybersecurity is in the world we live in. The

Deakin University Cybersecurity Association (DUCA),

world now thrives online, If you don’t know how to

I realised just how much the role resonated with me.

protect yourself or the people you care about, you are

Talking about it to others made me see the fast pace,

exposed without even realising it

the constant problem solving, and the responsibility

Now imagine someone with the wrong intentions

of monitoring and defending systems in real time in a

106

And that’s where cybersecurity becomes fascinating.

different light. Since then, I have been learning more

You get to understand what actually happens behind

about the role and developing personal skills to better

the scenes, the impact, the cause, the prevention, the

fit it. I am always eager to connect with anyone who

recovery and once you see how much of the world

can share advice or insights, as every conversation

depends on it, the importance and the excitement

sparks new ideas and motivates me to keep

speak for themselves.

improving. What excites me most is the combination

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

of technical work and analytical thinking. In this role,

few in the near future. Certifications are a great way

your actions have immediate impact, and you are

to bridge theory into practical knowledge. They help

constantly adapting and learning. At the same time,

you test yourself, keep your skills sharp, and build

I am open to exploring other areas if something

confidence. While they are especially useful later

sparks my interest more, but for now, SOC feels like

in your career to stay on your toes, they are also a

the perfect fit for me.

strong starting point. I believe in the current market you can pursue cybersecurity roles without a degree

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?

if you have the certifications and the knowledge

Multiple people have shaped my journey in

so far (ISC)² SSCP for operational security.

to back them up. For my goal of becoming a SOC analyst, some certifications I am considering include CompTIA Security+ for foundational knowledge and

cybersecurity so far. My family has been incredibly influential, giving me the freedom to pursue what I am passionate about, supporting my decisions unconditionally, and going above and beyond for my dreams.

Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape? Cybersecurity evolves at an incredible pace, and

The amazing cybersecurity community I have found

while my academic program provides a solid

through my university, particularly through creating

foundation in theory, principles, and best practices,

and being part of the Deakin University Cybersecurity

it cannot always keep up with the latest threats

Association (DUCA), has been a huge influence.

and tools in real time. The program does, however,

Being in an environment where we uplift each other,

challenge you, teach time management, and

learn together, and grow together has shown me

introduce concepts that encourage you to explore,

first-hand how the people you surround yourself with

learn, and discover solutions for yourself.

truly shape your path. Supplementing my studies with hands-on practice, Finally, the tutors and professionals I have met at

involvement in university clubs like the Deakin

conferences and events have been invaluable. Their

University Cybersecurity Association (DUCA),

guidance, advice, and quiet support have helped

attending industry events, and engaging with the

me navigate challenges and stay motivated. It has

wider cybersecurity community has been essential.

been an incredible journey so far, and I am genuinely

These experiences allow me to see the current

excited for what comes next.

threat landscape, explore new technologies, and stay up to date in ways that go beyond the classroom.

The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?

I S S U E 28

Ultimately, combining academic grounding with active engagement outside the classroom builds both confidence and adaptability, equipping me to handle the evolving challenges of the cybersecurity field

I have not completed any

What aspect of your cybersecurity studies excites you the most, and why?

cybersecurity certifications yet,

The aspect of my cybersecurity studies that excites

but I am planning to pursue a

me most is the practical, investigative nature of

WOMEN IN SECURITY MAGAZINE

107


ASHLEY MATHEW

the work. Working directly with tools like Kali Linux,

overwhelming. I make it a point to try and complete

Nmap, Metasploit, Wireshark, and SQL injection

all the higher tasks, and during break, I reflect on any

testing environments and being able to see how

missed work or areas where I could have improved.

vulnerabilities are exploited, how attacks unfold, and

Discussing my approach with high-achieving

how systems can be misconfigured or manipulated

peers has been particularly enlightening, seeing

has been incredibly engaging. Our assignments have

how they present their submissions and approach

taken this even further. I have worked on uncovering

problems has shifted my perspective and helped me

hidden data within images, analysing compromised

understand that sometimes the smallest details can

systems, tracing digital artefacts, and identifying

make a significant difference.

weaknesses before designing the fixes to prevent

combination of hands-on investigation, technical

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?

depth, and real-world problem-solving is what keeps

Absolutely. The truth is that cybersecurity is rarely a

the field constantly interesting for me.

one-person job; it is part of a much bigger system in

those issues from recurring. Understanding not only how to detect and solve a problem but also how to build long-term prevention strategies has been one of the most rewarding parts of the course. This

which multiple departments collaborate to protect

Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?

networks, systems, and data. You must be able

Some aspects of my cybersecurity studies,

effectively during incidents or projects.

to communicate coherently with colleagues from different roles, explain intricate security concerns to non-technical stakeholders, and collaborate

particularly practical labs, can be quite challenging. When I encounter difficulties, I first try to work

I’ve been actively honing these skills working with the

through the problem on my own, often revisiting it

Deakin University Cybersecurity Association (DUCA),

multiple times or taking a break and returning with

volunteering at events, participating in hackathons,

a fresh perspective. If I am still stuck, I reach out

coffee catchups and more. These experiences taught

to peers or tutors for guidance, using their hints

me how to collaborate in groups and learn from other

and insights to work through the

people’s perspectives.

problem collaboratively. I am not someone who can just give up on something, even if an assignment is past its due date or feels

Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience? Yes, I am actively engaged in the broader cybersecurity community through my involvement with the Deakin University Cybersecurity Association (DUCA). I was initially recruited by the club president over a year ago, and since then, my journey within DUCA has been incredibly enriching. I began as a Content Coordinator, creating blog posts, social media content, and promotional

108

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

a passionate community. Over time, I have taken on

Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.

more leadership responsibilities, serving as Social

Gratefully, I have not personally experienced

Media Co-Executive and now Secretary, where I

discrimination in cybersecurity. However, I have

lead DUCA’s social media strategy, coordinate with

noticed occasions, such as in lectures, where

research and content teams, and represent the club

I am often the only female student, which can

at events. Additionally, I have presented at events on

sometimes feel a bit intimidating. What has made

cybersecurity topics, sharing insights with peers and

a huge difference is having supportive lecturers

helping spark interest in the field. Being part of DUCA

and being part of communities like the Deakin

has enriched my experience in multiple ways. It has

University Cybersecurity Association (DUCA), AWSN,

allowed me to develop leadership, communication,

and WiCyS. These networks provide constant

and organisational skills while connecting with peers

encouragement and mentorship, showing that there

and industry professionals. Most importantly, it has

is nothing women cannot achieve in cybersecurity. I

shown me how surrounding yourself with passionate,

am extremely grateful for these experiences and the

motivated people can shape your growth, inspire

amazing people who continue to demonstrate that

curiosity, and push you to continuously learn and

gender is never a barrier in this field.

materials to raise awareness about cybersecurity. I actively participated in events, workshops, and O-Week stalls, helping engage students and foster

explore the field of cybersecurity.

What is your preferred source for staying informed about cybersecurity trends and general information?

What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? To maintain strong personal cybersecurity in today’s

I stay informed about cybersecurity trends and

digital landscape, I take a considered approach. I

general information through a combination

use strong, unique passwords managed through

of resources and active engagement with the

a secure password manager, enable multi-factor

community. I am subscribed to newsletters like

authentication on important accounts, and ensure

TDLRs, which provide concise updates on a wide

my devices and software are updated, carefully

range of the latest developments in the field. I also

evaluating the new updates before installation, not

regularly listen to cybersecurity podcasts, including

every new update is immediately the best one.

Lost in Cyberia, CyberWire Daily, and Darknet Diaries, which offer insights into real-world threats, emerging

In addition to technical measures, I remain vigilant

technologies, and industry perspectives.

in daily digital interactions. I carefully manage my privacy settings and exercise caution against

Additionally, I use LinkedIn to follow thought leaders

potential scams or suspicious activity. I approach

and analyse perspectives from other professionals

personal cybersecurity with a mindset of awareness,

and like-minded peers. I am an avid reader of blogs,

caution, and continuous learning, adapting to new

especially on new systems, tools and techniques.

challenges as they arise.

I also attend webinars or virtual events whenever possible to gain deeper insights depending on the company and topic. This combination of resources

www.instagram.com/deakincyber

helps me stay up to date, broaden my understanding, and continuously learn about both the technical and

www.linkedin.com/in/ashleyymathew

practical aspects of cybersecurity.

I S S U E 28

WOMEN IN SECURITY MAGAZINE

109


traditional path of getting accounting certifications and building experience in that field (and to be fair, I am still working toward those too). When I QUEENETH ONYIKE

mentioned cybersecurity, the reaction wasn’t exactly enthusiastic. To them, it sounded like a field “meant for men,” and the idea of me entering it without an

Queeneth Onyike studying Accountancy at the University of Nigeria, Nsukka. Accountancy student at the University of Nigeria, Nsukka.

IT background felt unrealistic. I won’t lie there were moments when their doubts made me question my own choices. It felt like I was trying to build a whole new career from scratch. But I’m very active on LinkedIn, so I started looking for people with backgrounds like mine finance and accounting who were thriving in cybersecurity. And I found them: Associates and Managers in the Big

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?

4, CISOs and CTOs across major African banks and

This comes up all the time. The moment I mention

viable, and sustainable path for me.

fintechs. Seeing their success gave me the evidence I needed, not just to reassure myself, but also to convince my parents that cybersecurity is a real,

cybersecurity, most people instantly picture a hacker. build a career in cybersecurity if they’re curious and

What aspect of your cybersecurity studies excites you the most, and why?

willing to keep learning. ”You’re never starting from

I honestly find myself torn between OSINT and

zero so many of the skills you already have can be

Compliance because both speak to different sides

transferred and shaped into something valuable in

of me. I’ve always been someone who pays close

the security space. And because cybersecurity is

attention to detail, and that skill fits perfectly in

always changing, there’s always something new to

either path.

I usually smile and tell them, “Honestly, anyone can

learn. It takes consistent effort to keep your skills sharp and your knowledge up to date, but it’s worth

With OSINT, I love the idea of gathering and analysing

it. It may sound like a lot at first, but trust me: it’s a

information from public sources, social media, news

deeply rewarding field, both financially and in terms

sites, online databases and turning it into something

of impact. Cybersecurity isn’t going anywhere, and

meaningful. It’s fascinating to see how much you can

the value of those who work in it will only continue

uncover from what people share online, even when

to grow.

they think they’re invisible.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?

Compliance, on the other hand, feels almost like

At first, there was definitely some skepticism,

standards and policies just feels like something that

especially from my parents and friends. Since I’m

comes naturally to me.

home. I’ve held leadership roles since high school and university, and as the oldest child, I naturally grew up making sure rules were followed and things ran smoothly. Helping people stay aligned with

studying accounting, everyone assumed I’d follow the

110

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

S P O T L I G H T

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

Cyblack Cybersecurity Bootcamp. I received the

I want to land a role in IT Audit or GRC. These

say it changed the trajectory of my journey from

roles leverage my existing knowledge and skills in

a place of anxiety to confidence. The application

accounting. Additionally, it would be more ideal when

process required a video submission which initially

applying for jobs in the Big 4 or financial institutions.

discouraged me, but I had to remind myself to

I want to be that bridge in IT and Finance securing

maximize every opportunity to grow in this space.

financial data. In my region, finance scams are very

The next three months was a wholesome experience

popular, whether it’s a data breach, social engineering

from mentorship sessions by seasoned experts, to

or phishing. A lot of people do not understand

beginner-friendly classes and guided learning. Due

what it means to be cyber safe, especially in their

to the Bootcamp, I wrote the ISC2 CC exam which

finances and I need to fill in that gap, through

was a confidence booster passing an entry level

public awareness about risks, cyber education, and

Cybersecurity exam despite coming from a non IT

implementing robust safety measures especially in

background. Since then, I have taken more courses

financial institutions.

especially in GRC, actively journaling my learning

acceptance email on 1st May (my birth month) and it was that confirmation I was seeking. I’d

journey in public, and networking with seasoned

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.

professionals for guidance.

The most significant event in my Cybersecurity journey to date was getting accepted into the

I S S U E 28

WOMEN IN SECURITY MAGAZINE

111


QUEENETH ONYIKE

The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice? I currently hold the ISC2 CC certification, and I recently started Google’s Cybersecurity Professional Certificate this November. It’s been a great way to build momentum, especially as I prepare to take the Security+ next year. I’m also eyeing the CGRC from ISC2 because it’s such a strong certification for anyone interested in GRC so I’m keeping that on my radar.

I’m building, how long they’ll take me to complete,

What is your preferred source for staying informed about cybersecurity trends and general information?

and what skills or knowledge I’ll walk away with. And

I’m active on LinkedIn and X (formerly Twitter), so a

of course, cost definitely plays a role when planning

lot of my sources are Cybersecurity professionals

out these exams. Overall, I’m choosing certifications

and experts I follow. I’m subscribed to a few weekly

that make sense for my goals and help me grow

newsletters via email that cover news, trends and

steadily and confidently in the field.

recent developments in Cybersecurity.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?.

Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider?

Absolutely. There’s always a demand for non-

it’s releasing all the fear and doubt that made me

technical (soft) skills in Cybersecurity. You can’t

question if Cybersecurity was right for me. The

expect top-level decision makers or even the

occasional bouts of anxiety stalled my learning

average person to understand IT jargon. Directors

journey a lot. I’d also network with professionals,

may undermine or dismiss existent risks in the

asking for help, guidance and learning resources

organisation because of the inability of a GRC

from those who’ve successfully walked the path,

Analyst to clearly break down and explain the degree/

not trying to figure out everything on your own with

level of risk, consequences of non-compliance etc.

Google and ChatGPT.

When I choose certifications, I try to be really intentional. I look at how relevant they are to the path

Cybersecurity is a collective effort, just a breach from one computer can shut down the organisation’s entire system, thus interpersonal communication skills cannot be neglected.

112

W O M E N I N S E C U R I T Y M A G A Z I N E

If I would make any changes to my career trajectory,

www.linkedin.com/in/queeneth-onyike x.com/nnennabuilds

J A N U A RY • F E B R U A RY 2026


DANAH MOHAMMED ALKHAN

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice? I aspire to work as a penetration tester or cybersecurity analyst. These roles really appeal to me because they involve both technical and

Danah Mohammed Alkhan is currently pursuing a Bachelor’s degree in Cybersecurity at the University of Bahrain. Cybersecurity student at the University of Bahrain.

analytical thinking. I enjoy identifying vulnerabilities, understanding how attackers operate, and building stronger defenses. It’s like solving puzzles while helping organizations stay safe, which combines both my curiosity and sense of responsibility.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?

When I decided to study cybersecurity, my parents

When I talk about cybersecurity, I usually describe

were surprised at first since cybersecurity is still

it as being on the frontlines of the digital world like

a growing field, especially for women, but that

protecting an entire universe that exists online.

only motivated me more. I felt proud to take a

Every day, new challenges appear, and it’s our job

path that’s both challenging and meaningful, and

to stay one step ahead of attackers. It’s not just

their encouragement gave me confidence to keep

about coding or systems; it’s about solving real-

pushing forward.

and friends were thrilled and very supportive. They knew how much I’ve always loved technology, so they saw it as a perfect fit for me. Some people

world problems and protecting people’s privacy. The excitement comes from knowing that what you do genuinely makes an impact in keeping others safe.

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

114

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations? The biggest influence on my journey has been my curiosity and love for technology. I’ve always been fascinated by what happens behind the

At first, I thought cybersecurity was mainly about

scenes in digital systems, which led me to explore

hacking and coding. But as I progressed through

cybersecurity deeply. My professors, classmates,

my studies, I discovered it’s much broader, involving

and family have all played a major role in supporting

strategy, analysis, digital forensics, and even risk

and motivating me. Their encouragement reminds

management. The field is much more dynamic

me that I can excel and make a real impact in this

than I imagined. It requires continuous learning

field, strengthening my goal of becoming a skilled

and adapting, which makes it even more exciting

penetration tester who helps make cyberspace safer

and rewarding.

for everyone.

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.

S P O T L I G H T

One of the most memorable moments in my

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

cybersecurity journey was during my first ethical

I completed an internship at Daresni Company,

hacking lab, where I worked on solving the Natas

where I worked as an Administrative Executive.

wargames challenges. Each level pushed me to think

While it wasn’t purely a cybersecurity role, it gave

differently, from exploring hidden directories to using

me insight into managing information securely and

tools like Burp Suite and analyzing cookies to bypass

understanding data protection from an organizational

login restrictions. It was the first time I truly felt like

perspective. Additionally, I’ve worked on several

a problem-solver in a real hacking environment.

university projects related to cybersecurity,

Later, another defining experience came from a web

which helped me apply classroom knowledge to

security testing project where my team and I used

practical scenarios.

SQLMap to uncover vulnerabilities and deploy a PHP

yet responsible, cybersecurity work can be. Those

The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?

experiences confirmed that I’m on the right path

Yes, I’ve earned the AWS Cloud Practitioner

and made me even more eager to keep learning and

certification, and I’m currently working through

improving my technical skills.

Google’s Cybersecurity Professional Certificate. My

web shell for privilege escalation. The moment our script successfully executed and revealed admin access was incredibly exciting. It showed me how theory and practice come together and how powerful,

I S S U E 28

WOMEN IN SECURITY MAGAZINE

115


DANAH MOHAMMED ALKHAN

next goal is to pursue CompTIA Security+. I chose

memorization and not much hands-on work. When

these certifications because they give me practical,

that happens, I try to tie the concepts back to real-

hands-on knowledge that builds on what I’m learning

world examples or small projects of my own. Making

at university, and I appreciate that they’re widely

those connections helps me stay motivated, and it

recognised in the cybersecurity industry. For me, it’s

reminds me that even the driest theory has value

exciting to see how each one adds a new layer of

once you see how it plays out in real situations.

understanding and confidence as I grow in this field.

Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?

Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges? At times, balancing technical complexity with time

My university does a good job at keeping up with

management can be challenging. Some topics

modern cybersecurity trends, but I also believe

require a lot of practice. I overcome this by setting

there’s always more to learn beyond the classroom.

small, manageable goals, practicing consistently, and

The field evolves so fast that staying updated

seeking help from professors or online communities

requires self-learning and exploration. I make it a

when needed.

point to read articles, attend workshops, and follow cybersecurity communities to stay current with new threats and defense techniques.

What aspect of your cybersecurity studies excites you the most, and why?

I think more emphasis could be placed on hands-on

I’m most excited about learning how to protect

learning, labs, and penetration testing environments.

systems and networks from attacks. It’s fascinating

These practical experiences make the concepts more

to understand both sides how attackers think and

meaningful. Some overly repetitive theory based

how to counter their strategies. I love the idea of

courses could be condensed to make room for that

defending privacy and digital integrity,

practical exposure. Additionally, some university

especially as technology becomes

electives could be replaced with more practical,

more central to everyday life.

Conversely, which aspect of your studies do you find least interesting or useful, and how do you navigate through it?

116

Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus?

hands-on courses.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why? Yes, definitely. I believe that technical skills alone aren’t enough to succeed in cybersecurity.

Sometimes I struggle

Communication, teamwork, and problem-solving are

with the more repetitive

just as important. In many situations, cybersecurity

or overly theoretical parts

professionals have to explain complex issues to

of cybersecurity especially

people who don’t have a technical background. Being

when it feels like it’s all

able to do that clearly and confidently helps build

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


S T U D E N T

I N

S E C U R I T Y

trust and ensures that security becomes a shared responsibility across an organisation.

S P O T L I G H T

changes to your career trajectory? If yes, what adjustments would you consider? I’m genuinely happy with the path I’ve chosen.

Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience?

If anything, I would have started exploring

I try to join cybersecurity workshops, seminars,

digital safety.

cybersecurity earlier. It’s a field full of opportunities, and every step has taught me something new about technology, resilience, and the importance of

and conferences whenever I can. Even though I

professionals, hear about real challenges in the

Have you actively sought employment opportunities in the cybersecurity field, and if so, what has been your experience with the application and interview process?

field, and connect with people who share the same

Yes, I’ve started exploring internship and job

passion. Being part of those conversations makes

opportunities in cybersecurity. The process has been

me feel like I’m slowly finding my place in the wider

both exciting and educational.

haven’t taken part in formal clubs or competitions yet, these events have been incredibly valuable. They give me the chance to learn directly from

cybersecurity community.

Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.

www.linkedin.com/in/danah-mohammed-alkhan

Personally, I haven’t faced direct discrimination, but I am aware that women in cybersecurity often have to prove their expertise more than others. I see it as motivation to keep learning, performing, and showing that gender doesn’t define capability. I’ve also met many inspiring women in the field who remind me that representation matters.

What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? I make sure to use strong, unique passwords and enable multi-factor authentication on all my accounts. I also keep my devices updated and avoid sharing personal information carelessly. Cybersecurity starts with personal habits, and I try to apply everything I learn academically to my daily online life.

Reflecting on your journey thus far, would you, with the benefit of hindsight, make any

I S S U E 28

WOMEN IN SECURITY MAGAZINE

117


LISA ROTHFIELD-KIRSCHNER Author of How We Got Cyber Smart | Amazon Bestseller

Olivia and Jack chat about the new social media rules OLIVIA – 6:12pm Mum just sent that MASSIVE email about the new social media rules. You read it yet? JACK – 6:13pm Yeah Had to scroll for, like, three hours. Wait. So are we literally getting kicked off Snapchat and YouTube?

😑

OLIVIA – 6:14pm Not kicked off right now. But it sounds like, by 2026, we’re probs gonna have to prove our age or get Mum + Dad to say yes. And we’re both still under 16 then. JACK – 6:15pm So annoying. Like I’m 14, not 4. I use Snapchat to keep in touch with my friends. I’m not starting a revolution. OLIVIA – 6:16pm Yep. I use YouTube to learn a lot of interesting stuff about the world. I like watching cool basketball and bike tricks and cooking tips. But I kinda get the “people who aren’t who they say they are” bit. Remember that weird guy who DMed you last year?

OLIVIA – 6:18pm IDK. I guess it’s not about us personally. Mum said they’ve seen heaps of nasty stuff happening to kids our age. Also, the part about “no more typing in a random birth year and getting through” made me feel personally attacked.

😂

JACK – 6:19pm Look, 2000 is a great birth year, OK? Super realistic. Can’t believe they’re ruining my acting career as a 25-year-old. OLIVIA – 6:20pm RIP your fake adult life. But lowkey, if the apps actually verify ages properly, that might mean less 40 year olds pretending to be 15 in group chats. JACK – 6:21pm True. And less 10-year-olds on TikTok doing ‘what I eat in a day’ videos. That stuff is so boring. OLIVIA – 6:22pm I know. And the ‘pressure to look a certain way’ bit Mum mentioned. That’s real. That one girl in your class who edits all her pics so much she looks like an AI filter.

JACK – 6:17pm Yeah… OK true. That was creepy. Still, it feels like the government’s putting us all in the ‘too little, too dumb’ box.

118

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


JACK – 6:23pm Yeah. She literally cries when a post doesn’t hit 200 likes. I don’t want you to end up like that. So I do get why they’re trying to slow it down till people are a bit older. OLIVIA – 6:24pm It still sucks that we need ‘parent permission’ for everything though. Feels babyish. JACK – 6:25pm Mmm. But at least Mum’s not like “delete it all, play in the streets forever”. She said we can figure out together what makes sense. Maybe I can keep Snapchat if they can see it’s just me chatting to my friends. OLIVIA – 6:26pm She also said “it’s not about whether we trust you”. I actually believe her. They let me keep Discord after that whole convo about blocking people. JACK – 6:27pm Yeah. And remember when I showed Dad that hate comment I got? He didn’t freak out or delete my account. Just helped me report and block. So maybe this new rule is them getting backup from the law. OLIVIA – 6:28pm Backup parents “Now with added government support”

😂

JACK – 6:29pm LoL Shut up. What I’m still confused about: if I’m under 16 in 2026, can they just like pause my account? What happens to my photos??

I S S U E 28

OLIVIA – 6:30pm From what Mum said, accounts might need to be “paused or adjusted”. So maybe: • We can keep them if Mum and Dad approve. • Or they’re locked till we’re 16. • Or we get kicked but can download our stuff. We should ask. I don’t want my Grade 6 last day at school pics being lost in the void. JACK – 6:31pm Same. Also, she said they’ll use Apple Screen Time and Google Family Link. Are we getting fully stalked now? OLIVIA – 6:32pm She said, “keep an eye… without being intrusive.” I think it’s more like: • time limits. • to downloading dodgy apps. • seeing if some dodgy rando is spamming us. Not reading every single DM where you complain about me. Probably. JACK – 6:33pm Chill. I complain about you out loud. No DMs needed. But actually, it might be good for me. Sometimes I doomscroll for no reason and then feel anxious and find it hard to fall asleep OLIVIA – 6:34pm Yeah, same. Maybe if the app kicks me off after an hour, I’ll actually finish my homework on time or get to sleep quicker.

WOMEN IN SECURITY MAGAZINE

119


JACK – 6:35pm You? Finish homework? Ok now YOU sound like government propaganda. OLIVIA – 6:36pm “Sponsored by the eSafety Commissioner.” Speaking of…Mum said we can check out esafety.gov.au if we want more info. Wanna look later? Curious what the actual rules are versus what TikTok rumours are saying. JACK – 6:37pm Yeah, let’s. Everyone at school is already saying “they’re deleting ALL our accounts tomorrow,” which is obviously fake news. Would be nice to know the real deal. OLIVIA – 6:38pm Same. Also, she mentioned “shared accounts”. JACK – 6:39pm Depends. Would you ever do a shared TikTok with me or is that too crazy? OLIVIA – 6:40pm If you promise no Fortnite dances and no burping into the mic, maybe. Could be a ‘chaotic twin’ account. Baking fails, dog videos, that kind of thing. JACK – 6:41pm Deal. ‘Approved by Mum & Dad.’ Actually that might be kinda fun. So… we hate the rule, but also kind of understand it? Like: annoying now, maybe helpful later?

OLIVIA – 6:42pm Yeah. I’d rather be slightly annoyed than seriously messed up by some random online. And it’s not forever. Once we hit 16, we get to choose. JACK – 6:43pm Ok, let’s talk to them at dinner. Questions list. 1. What happens to our current accounts? 2. Can we keep some apps with their permission? 3. How much are they actually going to ‘watch’? 4. Can we set the limits together, not just them deciding? OLIVIA – 6:44pm Good list. Add 5. Can we make a shared sibling YouTube so I become famous for my amazing baking skills? JACK – 6:45pm Already added. Title: “Olivia makes the best chocolate fountain, and spills it all over herself.” OLIVIA – 6:46pm You’re the worst. Thanks for talking this through though. I felt heaps more panicked before. JACK – 6:47pm Same. At least we’re in the same boat till we hit 16. Now come help set the table for dinner before Mum makes a rule about that too.

www.linkedin.com/in/lisarothfield-kirschner

howwegotcybersmart.com

120

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


How We Got Cyber Smart addresses cyber safety, cyber bullying and online safety for elementary school-aged children. Lisa has partnered with Cool.Org, and her content is found on the Department of Education website.

READ NOW


WOMEN IN SECURITY MAGAZINE CONTRIBUTORS 01

02

1. AMANDA-JANE TURNER

Author of the Demystifying Cybercrime series and Women in Tech books. Conference Speaker and Cybercrime specialist

2. TARA MCNALLY

Manager Cybersecurity

03

04

3. KRITY KHARBANDA

Application Security Professional | Advocate of women in cybersecurity

4. NKIRUKA JOY AIMIENOHO

Chief Information Security Officer (ScB)

05

06

5. ANEESA CHOTHIA

Information Security Officer

6. OPEYEMI OLAIFA

Manager & Team Lead Cybersecurity & Compliance Advisory At Digital Encode Limited

07

08

7. FATHIMA MOHAMED THASEEN

Account Executive at Havas NZ

8. AKO OTUDOR

Cybersecurity Analyst

09

10

9. JAIME SCHREPFER

Chief Information Security Officer

10. FIONA MARTIN

Associate Director, Business Resilience

11. DEARNE MCWHIRTER

11

12

Associate Director KPMG

12. SOLEDAD ANTELADA TOLEDANO

Security Advisor, Office of the CISO, Google Cloud

13. CASSANDRA MACK

Chief Information Security Officer (CISO), TensorWave

13

14

14. CRAIG FORD

Head Unicorn – Cofounder and Executive Director, Cyber Unicorns. Australian Best Selling Author of A Hacker I Am, Foresight and The Shadow World book series. vCISO – Hungry Jacks, Wesley Mission, PCYC and Baidam Solutions

15

16

15. ADRIANA JONES

Engineer, cybersecurity advocate and founder of The Innocent Souls Project (TISP)

16. JO STEWART-RATTRAY

Oceania Ambassador, ISACA

17

18

17. JOANNE COOPER

Founder - ID Exchange

18. LISA VENTURA MBE FCIIS

Chief Executive and Founder, Unity Group Solutions Limited/AI and Cyber Security Association

122

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


19

20

19. MARINA TOAILOA

Founder- Mummy Safety Security Project

20. RYAN FOX

Security Engineer

21

22

21. JAY HIRA

Cyber Director – Financial Services, KPMG

22. SHRUTI KAMATH

Consultant, Business Resilience, KPMG

23. ERIN CARROLL

23

24

Consultant, Business Resilience and Cyber Risk, KPMG

24. KAREN STEPHENS

CEO and co-founder of BCyber

25. RAJANI ARJULA

Director, Cyber Delivery at Anchoram

25

26

26. POOJA SHIMPI

Cybersecurity GRC Lead | AI Governance | Global Council for Responsible AI Ambassador for Australia

27. MADHURI NANDI

27

28

Madhuri Nandi, Head of security at Nuvei, AWSN Board Chair, author of Cyber Smart

28. PAIGE HAINES

Bachelor of Cyber Security student at Deakin University

29. PRAJOTI RANE

29

30

Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI)

30. TANVI BADGHARE

B. Tech in Computer Science and Engineering student at VIT Bhopal University, India

31

32

31. AMY KORALIS

Bachelor of Cyber Security and a Bachelor of Laws student at Macquarie University

32. ASHLEY MATHEW

Bachelor of Cybersecurity student at Deakin University in Melbourne.

33

34

33. QUEENETH ONYIKE

Accountancy student at the University of Nigeria, Nsukka

34. DANAH MOHAMMED ALKHAN

Cybersecurity student at the University of Bahrain

35. LISA ROTHFIELD-KIRSCHNER

35

I S S U E 28

Author of How We Got Cyber Smart | Amazon Bestseller

WOMEN IN SECURITY MAGAZINE

123


SURFING THE NET

BREAKING BARRIERS IN CYBER: AN IMPACTFUL JOURNEY WITH WCS2 By Women cyber security Society Meet Attracta, an aspiring cybersecurity professional from Calgary, Alberta. Not long ago, Attracta was looking to pivot into the cybersecurity field but wasn’t sure how to break in. When she came across a post on LinkedIn about the Women CyberSecurity Society (WCS2) Scholarship Program, she felt a spark of hope.

READ BLOG

WHO OWNS THE CYBERSECURITY OF SPACE? By Maryam Shoraka As a cybersecurity professional, I have spent decades watching humanity build digital castles without moats. We did it with the internet, with artificial intelligence and with critical infrastructure. Now, we are doing it again, this time in orbit. We are racing to commercialize space to connect the unconnected and monetize orbit, yet we are ignoring the most important question: Who owns the cybersecurity of space?

READ BLOG 124

W O M E N I N S E C U R I T Y M A G A Z I N E

CYBERSECURITY IN THE DIGITAL AGE: THE ROLE OF WOMEN IN SHAPING TOMORROW'S SECURITY By Lisa Kearney In the spring of 2018, after more than 20 years in cybersecurity, I found myself questioning my place in the field. I wondered if I truly belonged, whether I should pursue something else, and why the journey felt so difficult and isolating.

CYBERSECURITY IN 2026: AI-DRIVEN ATTACKS, DEEPFAKES & MORE By CyberPedia (Satarupa Dutta) Hi Readers! The future of cybersecurity in 2026 is changing fast and frankly speaking, it is getting out of control. The digital world of humans is changing with AI-generated attacks that travel at a higher speed than humans can react to deepfakes that seem incredibly authentic. This is what the new threat age will appear like.

READ BLOG

READ BLOG

SOCIAL ENGINEERING TACTICS: HOW TO SPOT AND STOP THEM

FROM NETWORKING TO ETHICAL HACKING: THE BEST CAREER PATH TO CYBER SECURITY

By Ford Leadership & Cyber Resilience In the complex world of cybersecurity, the greatest vulnerability isn’t a piece of code; it’s human psychology. Social engineering is the art of manipulating people into divulging confidential information or performing actions that compromise security. These attacks bypass technical defenses by targeting the natural human tendencies to trust, help, and respond to urgency.

READ BLOG

By Network Bulls With increasing data breaches, ransomware attacks, and digital espionage – cybersecurity has become one of the most critical and rapidly growing career fields. Companies all over the world are hiring skilled professionals who can secure networks, mitigate threats, and outsmart cybercriminals.

READ BLOG J A N U A RY • F E B R U A RY 2026


THE INCREDIBLE SHRINKING SHELF LIFE OF IT SKILLS By CIO (Mary K. Pratt) The accelerating pace of technical innovation is driving rapid turnover in the skills necessary for organizational success, leaving IT leaders and individual professionals uncertain about where to place their upskilling bets.

READ BLOG

LOST IN THE CLOUD: WHAT HOME ALONE 2 TEACHES US ABOUT CLOUD SECURITY By (Red Canary) Laura Brosnan The festive season is in full swing, which means the Home Alone series is likely top of mind for many of us. It got me thinking about how Kevin McCallister really is a quintessential figure head of proactive defense. As I argued in my original blog, the pint-sized defender is masterful at analyzing his environment and preparing for the inevitable. Such wisdom can also apply to the cloud. So, I’m doubling down and leveling up. Think of this as his sequel adventure.

READ BLOG I S S U E 28

THE WIRED GUIDE TO DIGITAL OPSEC FOR TEENS By WIRED (Lily Hay Newman) Teenagers have always been formidable hackers. In fact, in recent years, some of the most high-profile and brazen digital attacks around the world have been carried out by teens. But even if you're not a hacker, you’re probably still a prolific user of digital tools and social platforms.

READ BLOG

MALWARE, ZERODAYS & NATIONSTATE INTRUSIONS By Openvpn ( Heather Walters) Cybersecurity has been especially active over the last 7 days. From new backdoors to critical zero-day patches and new ransomware trends — the threats keep coming. Here are the top stories you should know about.

READ BLOG

IT SECURITY IN TWO EASY STEPS

AI: LACKING GUARDRAILS, TALENT, AND RESOURCES?

By Acronym Solutions Inc.(Jeff Farley)

By Forta (Gina Cardelli)

It’s not just the frequency of attacks that’s escalating; it’s also the complexity and impact. According to Security Intelligence, we’re seeing more double extortion and even triple extortion strategies to ensure the success of a ransomware attack. These attacks first steal a copy of your data, such that not only are your systems and data held ransom, but your entire backup set and those who would not want to see it published are targeted.

AI adoption is accelerating faster than governance maturity can keep pace. Many companies are still integrating responsible AI practices rather than treating them as a standard operating discipline. Deloitte reported that nearly twothirds of entities have adopted generative AI without establishing proper governance controls. That ultimately means a growing field of more blind spots: unmonitored or unsanctioned usage, insufficient oversight, and compliance risks that surface only after the fact.

READ BLOG

READ BLOG WOMEN IN SECURITY MAGAZINE

125


TURN IT UP

INSIDE THE CYBER GUILD: HOW DEBBIE SALLIS EMPOWERS CYBER LEADERS With IMPACT Podcast Series In this episode of IMPACT: Women in Leadership, host Mary Ann Brown continues her conversation with Debbie Sallis, Founding Executive Director of The Cyber Guild Foundation, to explore how mentorship, leadership, and community are reshaping the future of cybersecurity.

With CLICK HERE PODCAST Recorded Future News’ awardwinning Click Here podcast tells stories about the people making and breaking our digital world. Hosted by former NPR Investigations correspondent Dina Temple-Raston, we introduce listeners to the shadowy characters behind ransomware attacks, disinformation campaigns, and hacks to the people trying to stop them.

CLICK TO LISTEN

CLICK TO LISTEN

MOLLIE BREEN: ACCELERATING OT SECURITY, RELIABILITY AND EFFICIENCY

WHY BUSINESSALIGNED SECURITY WINS

With The PrOTect OT Cybersecurity Podcast In a recent episode of PrOTect OT, Mollie Breen, the dynamic founder and CEO of Perygee, sat down to discuss her journey into the realm of OT (Operational Technology) security.

CLICK TO LISTEN 126

MIC DROP: A FORMER NORTH KOREAN HACKER SPEAKS OUT

W O M E N I N S E C U R I T Y M A G A Z I N E

With Be Fearless Podcast Coleen Coolidge, ex-CISO of Segment and Twilio and startup advisor, didn't start in cybersecurity - she was a new project manager who got thrown into the deep end, but that discomfort launched an 18-year career that would see her build security teams from scratch at companies like Segment and Twilio

CLICK TO LISTEN

POST-THANKSGIVING LEFTOVERS: A SMORGASBORD OF RANDOM TOPICS WITH LAURA AND KEVIN With That Tech Pod This week’s post-Thanksgiving episode is a full smorgasbord of random stories, internet rabbit holes, and tech-adjacent tangents. Laura and Kevin skip the usual guest and run through a pile of listener-requested topics.

CLICK TO LISTEN

CYBERSECURITY HAS LOST THE PLOT With Down the Security Rabbithole Podcast This week's pod features your favorite hosts reflecting on how security has lost its way. When everything is a catastrophe, nothing is. When every breach is world-ending, none of them matter. Have we completely lost the plot? Prepare to have a good think.

CLICK TO LISTEN J A N U A RY • F E B R U A RY 2026


AI-FIRST VULNERABILITY MANAGEMENT: SHOULD CISOS BUILD OR BUY? With Cloud Security Podcast Thinking of building your own AI security tool? In this episode, Santiago Castiñeira, CTO of Maze, breaks down the realities of the "Build vs. Buy" debate for AI-first vulnerability management.

CLICK TO LISTEN

BUILDING TRUST AND COMPLIANCE: GUIDING A CLIENT TO CMMC LEVEL 2 CERTIFICATION With SEISO podcast In this episode, we take you behind the scenes of how our team helped a client successfully achieve CMMC Level 2 certification. From assessing gaps and aligning controls to overcoming legacy system challenges and navigating the audit process, we break down each step of the journey. You’ll hear how collaboration, governance, and a clear security roadmap turned a complex compliance goal into a milestone achievement.

CLICK TO LISTEN I S S U E 28

WHEN CYBER CAMPAIGNS CROSS A LINE With Risky Business podcast Tom Uren and Patrick Gray discuss a new report proposing a framework for deciding when cyber operations raise red flags. It suggests seven red flags and could help clarify thinking about how to respond to different operations.

THE CYBERSECURITY DEFENDERS PODCAST With The Cybersecurity Defenders Podcast A podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe to the show wherever you listen to podcasts!

CLICK TO LISTEN

CLICK TO LISTEN

FROM FBI TO CYBERSECURITY LEADER: M.K. PALMORE'S CAREER JOURNEY | BREAKING INTO CYBERSECURITY

MEET THE INCIDENT RESPONSE CHAMPIONS

With Breaking Into Cybersecurity In this episode of Breaking Into Cybersecurity, M.K. Palmore, a cybersecurity leader and former FBI special agent, shares his journey from serving in the Marines and the FBI to leading his own consulting firm, Apogee Global RMS.

CLICK TO LISTEN

With Australian Cyber Voices: The Official AISA Podcast In this episode of Cyber Voices, David Willett chats with former participants of the Australian Women in Security Network (AWSN) and Retrospect Labs Incident Response Competition. The panelists, including competition winners and runnersup, share their transformative experiences in this hands-on, teamwork-based event.

CLICK TO LISTEN WOMEN IN SECURITY MAGAZINE

127


OFF THE SHELF

CYBER SAFE GIRL Author // DR.Ananth Prabhu G Cyber Safe Girl is a handbook, curated to help the netizens to browse the internet responsibly. As the whole world moving online, the need for responsible browsing is very crucial as during the pandemic, there has been a sudden spike in cases of online frauds, scams and threats.

BUY THE BOOK

STRONGER TOGETHER: WOMEN IN CYBERSECURITY Authors // David Meece, Emily Zakkak, Lynn Dohm, and Gabrielle Botbol This book throws open the doors to the world of IT and Cybersecurity, celebrating over 100 accomplished women who have carved their own paths in these dynamic fields. It's not just a chronical of their achievements, though each story delves into the unique challenges they faced, offering invaluable insights and stereotypes.

BUY THE BOOK

CYBER SECURITY SECRETS: GET THE FIRST CYBER SECURITY JOB Author // Fae Donn If you're keen on PCs and want to find a new line of work in Cyber Security, this book is most certainly for you. It gives the alternate ways and mysteries to accomplish $100,000 per year in Cyber Security. It is worked to clear up how to accomplish your objective as quickly as conceivable with as little obligation as could be expected.

BUY THE BOOK

IN SECURITY Author // Jane Frankland Women matter in cybersecurity because of the way they view and deal with risk. Typically, women are more risk averse, compliant with rules, and embracing of organisational controls and technology than men. They're also extremely intuitive and score highly when it comes to emotional and social intelligence, which enables them to remain calm during times of turbulence - a trait that's required when major security breaches and incidents occur.

BUY THE BOOK

128

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


MIND THE TECH GAP Author // Nikki Robinson IT and cybersecurity teams have had a long-standing battle between functionality and security. But why? To understand where the problem lies, this book will explore the different job functions, goals, relationships, and other factors that may impact how IT and cybersecurity teams interact.

BUY THE BOOK

THE ART OF ATTACK Author // Maxie Reynolds In The Art of Attack: Attacker Mindset for Security Professionals, experienced physical pentester and social engineer Maxie Reynolds untangles the threads of a useful, sometimes dangerous, mentality.

BUY THE BOOK

BUILDING A CYBER RISK MANAGEMENT PROGRAM: EVOLVING SECURITY FOR THE DIGITAL AGE Authors // Brian Allen, Brandon Bapst, and Terry Allan Hicks Cyber risk management is one of the most urgent issues facing enterprises today. This book presents a detailed framework for designing, developing, and implementing a cyber risk management program that addresses your company's specific needs. Ideal for corporate directors, senior executives, security risk practitioners, and auditors at many levels, this guide offers both the strategic insight and tactical guidance you're looking for.

BUY THE BOOK

CYBER PERSISTENCE THEORY: REDEFINING NATIONAL SECURITY IN CYBERSPACE Authors // Michael P. Fischerkeller, Emily O. Goldman, and Richard J. Harknett Most cyber operations and campaigns fall short of activities that states would regard as armed conflict. In Cyber Persistence Theory, Michael P. Fischerkeller, Emily O. Goldman, and Richard J. Harknett argue that a failure to understand this strategic competitive space has led many states to misapply the logic and strategies of coercion and conflict to this environment and, thus, suffer strategic loss as a result.

BUY THE BOOK

I S S U E 28

WOMEN IN SECURITY MAGAZINE

129


OFF THE SHELF

SILVER AND CYBER SECURE: A QUOTE COLLECTION FOR STAYING SAFE AND SAVVY ONLINE. Author // Alexa Blake This isn’t about mastering passwords or learning tech tricks—it’s about protecting peace of mind in a connected world. Silver and Cyber Secure blends everyday wisdom with digital mindfulness, helping readers stay informed, confident, and calm in the online age.

BUY THE BOOK

CYBER EXPLORERS: SECURITY & ARTIFICIAL INTELLIGENCE IN THE 21ST CENTURY Authors // Joby James, and Dr Diya Abraham In this book, you will discover how to:

✨ Protect your personal information like a secret treasure. ✨ Outsmart cyber-villains by using your digital superpowers. ✨ Explore the amazing world of Artificial Intelligence (AI). ✨ Be kind online and help make the internet a safe, happy place. ✨ Discover the fun side of cybersecurity and even future careers! BUY THE BOOK

THE ABC'S OF CYBER SECURITY: FUN, FACTS, AND SMART LESSONS FOR THE DIGITAL GENERATION Author // Sarah Kore Introducing the ultimate resource to teach young children the crucial basics of internet safety and cyber security! In a world where digital devices are everywhere, "The ABC's of Cyber Security" uses bright, engaging illustrations and easy-to-understand language to transform complex security concepts into fun, foundational lessons.

BUY THE BOOK

CYBER SAMMI'S SAFETY ADVENTURES Author // Brigitte Collier Discover the importance of cybersecurity for kids in our latest book! As technology advances, so do the tactics of cybercriminals targeting young internet users. Parents must stay informed about evolving threats such as AI risks, data privacy loss, cyber threats, and inappropriate content.

BUY THE BOOK 130

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


THE LEARNING HUB MANAGING CYBERSECURITY INCIDENTS AND DISASTERS Most organizations plan for routine operations, but what happens when unexpected events overtake the routine? This course examines contingency planning used to prepare for and manage non-normal operations, including cybersecurity incidents – like hacking attempts, web site defacement, denial of service attacks, information disclosures; a well as other natural and man-made cybersecurity disasters.

VISIT HERE

CYBERSECURITY TRAINING FOR IT PROFESSIONALS The no-cost curriculum includes all courses to support security-driven networking, adaptive cloud security, AI-driven security operations and zero-trust network access. Completion of these courses will help cybersecurity professionals defend their networks against the widest range of ever changing threats.

VISIT HERE

SECURE CODING 101: JAVASCRIPT In the Secure Coding 101: JavaScript Module, you will learn how to improve the security of your JavaScript code through reverse engineering advanced JavaScript obfuscation functions and identifying hard to find vulnerabilities, and learning how to patch them properly.

VISIT HERE

ANALYZING DATA In this course, you’ll learn key skills and tools for data analytics, including spreadsheets, structured query language (SQL), R programming, and Tableau. You will also understand the daily tasks of a data analyst and explore the kinds of jobs you could pursue after completing this program.

VISIT HERE

I S S U E 28

WOMEN IN SECURITY MAGAZINE

131


THE LEARNING HUB CYBERSECURITY FOR BUSINESSES THE FUNDAMENTAL EDITION Are you a small business owner who is worried about being hacked? Are you confused about where to start and how to begin? Have you been looking for a course that teaches you the information/cybersecurity basics to best protect your business in a fun, relaxed manner? If so, you are going to find that this course is absolutely perfect for you!

VISIT HERE

IT & CYBERSECURITY FOUNDATIONS Cybrary’s IT and Cybersecurity Foundations career path will equip you with a strong foundation of cybersecurity knowledge and hands-on skills. Over the course of 30 courses and hands-on virtual labs, you will learn essential IT concepts, security best practices, and the technical skills needed for entry-level IT and cybersecurity roles.

VISIT HERE

UNRAVELING FISMA - CYBERSECURITY WITH REGULATORY FRAMEWORKS The US Government introduced the Federal Information Security Modernization Act in 2002 to protect its precious data. With this Cybersecurity Regulatory Framework Course, students can examine this regulation closely, understand its implications, and learn to perform the FISMA audit.

VISIT HERE

CYBERSECURITY BASICS: TOOLS AND CYBERATTACKS Cyberattacks have surged by 71% and are predicted to continue increasing. This alarming statistic highlights the continued demand for cybersecurity professionals. Jumpstart your cybersecurity career with this introductory IBM course, which introduces you to fundamental cybersecurity concepts, threats, and preventive measures.

VISIT HERE

132

W O M E N I N S E C U R I T Y M A G A Z I N E

J A N U A RY • F E B R U A RY 2026


FEATURING FREE SECURITY TRAINING RESOURCES THAT ARE AIMED AT INCREASING SECURITY AWARENESS AND HELPING PEOPLE BUILD AND UPSKILL THEIR SECURITY SKILLS.

REAL-TIME CYBER THREAT DETECTION AND MITIGATION This course introduces real-time cyber security techniques and methods in the context of the TCP/IP protocol suites. Explanation of some basic TCP/IP security hacks is used to introduce the need for network security solutions such as stateless and stateful firewalls. Learners will be introduced to the techniques used to design and configure firewall solutions such as packet filters and proxies to protect enterprise assets.

VISIT HERE

COMPUTER FORENSICS In this course, you will learn the principles and techniques for digital forensics investigation and the spectrum of available computer forensics tools. You will learn about core forensics procedures to ensure court admissibility of evidence, as well as the legal and ethical implications.

VISIT HERE

CLOUD SECURITY BASICS This course introduces you to cybersecurity for the cloud. We'll learn and apply classic security techniques to today’s cloud security problems. We start with a deceptively simple and secure web service and address the problems arising as we improve it. We’ll analyze recent cloud security vulnerabilities using standard, systematic techniques. We’ll build our own web service case studies and construct security solutions for them. Our toolkit contains classic security concepts like Least Privilege and Separation of Duty, as well as more technical cryptographic and access control techniques.

VISIT HERE

INTRODUCTION TO CYBERCRIME Begin your journey into cybercrime with this cyber crime free course. Explore the various types of cyberattacks faced by organizations today. Understand the intricacies of cybersecurity threats and discover practical preventive measures. Whether you're new to the field or seeking to broaden your knowledge, this course provides essential insights to empower you in defending against cyber threats.

VISIT HERE

I S S U E 28

WOMEN IN SECURITY MAGAZINE

133


J O B B OA R D CD-CYBER SECURITY- CRISIS & RESILIENCE-SENIOR ASSOCIATE | PWC ACCELERATION CENTER INDIA FULL TIME

INDIA

potential threats to an organisation's security, as well as managing vulnerabilities to prevent cyber attacks. You will play a crucial role in safeguarding sensitive information and enabling the resilience of

ABOUT THE JOB

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to digital infrastructure. identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. In threat intelligence and vulnerability management APPLY HERE at PwC, you will focus on identifying and analysing

EXPERIENCED - CYBER DATA PROTECTION | DELOITTE FULL TIME

ITALY

• Face and solve customer challenges in innovative and effective way The Experienced resource will be integrated into a work • Engage with internal and external stakeholders team and responsible for: to strengthen business relations and create • Manage data protection activities within wider business opportunities projects, identifying, evaluating, and designing best in class data protection solutions, demonstrating operational excellence, vision and strategic thinking APPLY HERE • Execute complex project activities, coordinate part of the team while supporting your more senior colleagues in managing client relations and expectations YOUR ROLE

DIRECTOR OF SECURITY | REMOTE FULL TIME

SOUTH AFRICA

KEY RESPONSIBILITIES • Define, implement, communicate and maintain security strategy, policies, goals and requirements aligned with business strategy, and manage security resources, to support the company’s objectives • Work with the Security Council and Remote’s senior leadership in developing Remote’s Information Security vision, strategy and road-map of Remote’s Security function • Recruit and nurture individual growth to build an autonomous and high performing Security team

134

W O M E N I N S E C U R I T Y M A G A Z I N E

• Be an advocate of information security best practices and proactively looking to improve and drive Remote’s security posture, driving efforts to improve Security Awareness across company • Drive Remote’s security risk management program, by partnering with Legal, Data Protection and Finance in developing and managing our enterprise risk management framework(s), and collaborating with senior leaders in reducing Information Security risks

APPLY HERE

J A N U A RY • F E B R U A RY 2026


SENIOR CYBERSECURITY RISK ANALYST | DRAPER FULL TIME

UNITED STATES OF AMERICA

JOB DESCRIPTION: • Serve as a subject matter expert for cybersecurity risk management and compliance frameworks including NIST SP 800-171/53, DAAPM, CMMC, RMF • Develop and implement consistent, high quality System Security Plans (SSPs), Risk Assessment Reports (RARs), Plans of Actions & Milestones (POA&Ms) and Standard Operating Procedures (SOPs) across the enterprise classified IT portfolio • Perform Security Control Assessments for enterprise classified systems, oversee implementation

of corrective actions and provide remediation strategies where relevant • Work closely with the Office of Threat Management (OTM) to conduct vulnerability assessments and threat analysis of the IT portfolio. Furthermore, monitor, evaluate and report on cybersecurity risk, incident response actions, and compliance gaps

APPLY HERE

L2 SOC ANALYST | CISOMETRIC FULL TIME

INDONESIA

RESPONSIBILITIES : • Investigate and validate escalated alerts from L1. • Perform deep-dive analysis using SIEM, EDR, firewall, and cloud security tools. • Correlate logs to identify IOCs, attack chains, and help L1 to define true/false positives. • Execute containment actions (host isolation, account lock, block IP/domain). • Escalate major incidents to L3/IR teams when required. • Conduct proactive threat hunting based on intel or nomalies.

• Reporting & Documentation: Maintain accurate tickets, timelines, and incident reports aligned with SLAs. • SIEM Tuning & Optimization: Reduce noise, refine detection rules, propose new use cases. • Mentor L1 analysts and support process improvements.

APPLY HERE

ASSOCIATE ADVISOR - CYBER RESILIENCE CONSULTING | SAEPIO INFORMATION SECURITY FULL TIME

UNITED KINGDOM

WHAT YOU WILL BE DOING As an Associate Advisor, your responsibilities will typically include: • Assessment and Advisory Delivery • Conduct cyber assessments through Saepio’s digital platform • Review client systems, policies, and controls to identify strengths and gaps

I S S U E 28

• Support the creation of tailored reports and security improvement roadmaps • Present findings to clients, providing clear and practical recommendations • Client Engagement

APPLY HERE

WOMEN IN SECURITY MAGAZINE

135


J O B B OA R D SENIOR CONSULTANT OR MANAGER, DIGITAL FORENSICS & INCIDENT RESPONSE - CYBERSECURITY | BDO CANADA FULL TIME

CANADA

As a Senior Consultant or Manager, in Digital Forensics & Incident Response on BDO’s Cyber Threat Management & Response team, your responsibilities will include: • Leading complex incident investigations and forensic engagements: endpoint, network, cloud-native environments, memory, disk, and log analysis. • Performing digital forensic examinations across multiple operating systems and devices using industry-standard tools (e.g., EDR/EDR-forensics, EnCase, Rekall, Wireshark, etc.).

• Collecting, analyzing, and maintaining critical data sources including system logs, network traffic captures, EDR telemetry, threat intelligence feeds in order to support investigations and remediation. • Interpreting forensic artifacts, identify Indicators of Compromise (IoCs) and adversary Techniques, Tactics & Procedures (TTPs), and producing actionable intelligence.

APPLY HERE

THREAT INTELLIGENCE & CYBERSECURITY MANAGING CONSULTANT, STRATEGY & TRANSFORMATION – ADVISORS | MASTERCARD FULL TIME

BRAZIL

ROLES AND RESPONSIBILITIES • Delivery of client projects and solutions for assessing and improving threat intelligence programs, assess risk exposure, identify threat landscape, protect against attacks, and orchestrate continual improvements of cybersecurity and threat intelligence programs. • Assist with sales and product management activities such as technical pre-sales support and creation of products bundles.

• Led definition and development of deliverables to solve client problems, address and communicate difficult client situations, and produce actionable recommendations. • Create positive team environment and support collaboration across multiple teams to produce outstanding deliverables.

APPLY HERE

DIRECTOR CYBER SECURITY | FINDR FULL TIME

GERMANY

This is a senior role reporting directly to the CTO. You’ll lead a talented Cyber Security team, drive the security roadmap, and play a key part in shaping how a regulated financial business protects its most critical systems. IF YOU WANT TO: • Define and deliver security strategy in a highly regulated, tech-driven environment • Lead and develop a strong cyber team while staying hands-on when needed

136

W O M E N I N S E C U R I T Y M A G A Z I N E

• Work with cutting-edge technology in the digital asset and trading space • Collaborate directly with engineering, risk and compliance teams • Influence decisions at board level • …then this is a great opportunity to make an impact at scale.

APPLY HERE

J A N U A RY • F E B R U A RY 2026


DEVOPS / CLOUD PLATFORM ENGINEER | ONEREG FULL TIME

NEW ZEALAND

WHAT YOU’LL BE RESPONSIBLE FOR • Designing and maintaining cloud infrastructure • Improving CI/CD pipelines and deployment processes • Monitoring, alerting, and incident response • Ensuring security, reliability, and scalability

• Supporting engineers with tooling and best practices

APPLY HERE

FIELD CHIEF INFORMATION SECURITY OFFICER | LENSA FULL TIME

UNITED STATES OF AMERICA

ROLE DESCRIPTION • Develop and implement an information security strategy that aligns with the organization's goals and objectives to ensure comprehensive protection of information assets. • Oversee the development and enforcement of security policies to ensure that all security policies, procedures, and protocols are up-to-date and effectively implemented across the organization. • Lead risk management efforts by identifying, assessing, and mitigating information security risks

to protect the organization from potential threats and vulnerabilities. • Manage incident response and recovery by developing and overseeing the execution of incident response plans to address security breaches and ensure timely recovery.

APPLY HERE

IT SECURITY ARCHITECT | THERMO FISHER SCIENTIFIC FULL TIME

HUNGARY

KEY RESPONSIBILITIES: • Design and implement secure remote access solutions, including VPNs, VDI, and other remote access technologies. • Develop and enforce remote access security policies and procedures. • Conduct regular security assessments and audits to identify vulnerabilities and ensure compliance with security standards.

• Collaborate with IT and business teams to integrate security measures seamlessly into remote access systems. • Monitor security information and event management (SIEM) systems to detect and respond to security incidents. • Investigate and mitigate security incidents related to remote access.

APPLY HERE

I S S U E 28

WOMEN IN SECURITY MAGAZINE

137


Support the Future of the

AUSTRALIAN WOMEN IN SECURITY AWARDS

®

We need your support to continue this important initiative into its 8th year.

The 2026 Awards will be hosted in Melbourne. To ensure this initiative continues, we invite you to partner with us as a sponsor.

NSORSH

I

Packages ava ilable from $6,000 to $50,000 Custom pack ages tailored to your organisa tion’s needs

PP

O

Your sponsorship will help us continue to celebrate and elevate the achievements of women in security across Australia.

O SP

P

JOIN US IN MELBOURNE FOR 2026

ORT

IE U NIT

S

To discuss how you can support and sponsor next year’s awards, please reach out to Aby at Aby@source2create.com.au. We look forward to partnering with you to make the 2026 Australian Women in Security Awards our best yet.


Turn static files into dynamic content formats.

Create a flipbook