28
JANUARY • FEBRUARY 2026
W W W. W O M E N I N S E C U R I T Y M A G A Z I N E . C O M
FROM THE PUBLISHER Pivoting isn’t just a career move, it’s an act of courage.
A
s professionals we often find ourselves deeply rooted in familiar roles, confident in our expertise and secure in what we know. It took me 15 years to pivot from my job! But stepping away from that comfort
zone and taking an entirely new direction, especially in the fast-evolving world of security, can be daunting. It’s completely natural to wonder. Will I catch up? Will I ever feel truly proficient? Will people think I’m a fraud? These questions are common for anyone considering a career shift, particularly for those who come to cybersecurity later in life. The trends show you’re not alone. In 2023, 16 percent of new entrants to cybersecurity were between 50 and 59, showing that mid-life pivots aren’t just possible but increasingly common. Fifty-nine percent of hiring managers are seeing more candidates from outside traditional cyber backgrounds, and more than half are changing their hiring practices to welcome career changers. With 457,398 cybersecurity job openings in 2025 alone and a predicted 33 percent growth rate ahead, opportunity in security is abundant for those willing to embrace change. But the journey is as much about mindset as skillset. Up to 70 percent of security professionals report imposter syndrome, reminding us that learning and doubt are universal, no matter your experience level. Adapting to this reality can turn discomfort into opportunity and nervousness into confidence, fuelling personal and professional growth. As we close out the year, this final issue is packed: deep dives on risk versus reward, advice on pivoting with no experience, honest discussions about age and transition, and stories of people who have made the
2
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
Abigail Swabey
leap into both cyber and physical security. You’ll also find our trusted regular columns, the inspiring What’s Her Journey features and the Student in Security spotlight. There’s something for everyone in our community, whether you’re just starting out, in the middle of a transition or looking to upskill. And remember, anyone can contribute. If you have an experience to share, a journey, some career advice or a unique perspective on tech or the sector, reach out to us (Jane jane@source2create.com.au). We’re always open to fresh voices and stories that align with our themes. You can request submission guidelines if needed. Also, if you’re interested in advertising with us, Women in Security Magazine now reaches a global audience of over 9,000 subscribers, making it a fantastic platform to put your brand in front of engaged, passionate readers. And, finally, the whole team at Source2Create and Women in Security Magazine, wish you a safe and happy holiday season. Whether you’re pivoting into something new or continuing in your current role, stay curious, confident and resilient. Here’s to new beginnings and our shared journey in security.
Abigail Swabey PUBLISHER, and CEO of Source2Create www.linkedin.com/in/abigail-swabey-95145312
aby@source2create.com.au
I S S U E 28
WOMEN IN SECURITY MAGAZINE
3
CONTENTS GETTING INTO CYBERSECURITY WITH NO EXPERIENCE: YOUR ROADMAP FOR 2026
2
FROM THE PUBLISHER
8 WHAT’S HER JOURNEY?
COLUMN
Tara McNally
14
Krity Kharbanda
16
Nkiruka Joy Aimienoho
18
Aneesa Chothia
20
Opeyemi Olaifa
22
Fathima Mohamed Thaseen
24
Ako Otudor
26
Jaime Schrepfer
28
Fiona Martin
30
DeArne McWhirter
32
Soledad Antelada Toledano
36
Cassandra Mack
38
Prime time for cybercrime
12
Simon says “freeze”
42
The ‘pivot’ secrets you didn’t know
76
Pivot: the shift from reacting to anticipating
86
INDUSTRY PERSPECTIVES Pivot: turning pain into purpose through technology
46
Pivoting with purpose: Women redefining leadership in cybersecurity’s next era 50
131 THE LEARNING HUB 134 JOB BOARD
Social media age assurance for children under 16: what it means for Aussie parents
54
The seven pivots that define a successful cybersecurity career (and why women excel at making them) 58 Emotional intelligence in security: the shift from physical presence to psychological awareness
66
Building an inclusive cyber club playbook and pitfalls
68
AI and data: protecting what powers us
72
JANUARY • FEBRUARY 2026
CAREER PERSPECTIVES The FSD risk: accountability for the autonomous workforce 80 Getting into cybersecurity with no experience
Support the Future of the
AUSTRALIAN WOMEN IN SECURITY AWARDS
®
We need your support to continue this important initiative into its 8th year.
FOUNDER & EDITOR Abigail Swabey
ADVERTISING
82
Abigail Swabey Jane Saafi
SURFING THE NET 124
The 2026 Awards will be hosted in Melbourne. To ensure this initiative continues, we invite you to partner with us as a sponsor.
ONSORSH
I
Packages ava ilable from $6,000 to $50,000 Custom packa ges tailored to your organisa tion’s needs
PP
O
Your sponsorship will help us continue to celebrate and elevate the achievements of women in security across Australia.
SP
P
JOIN US IN MELBOURNE FOR 2026
ORT
U NIT
IE
S
M A G A Z I N E C O O R D I N ATO R Jane Saafi
JOURNALISTS Stuart Corner
118
To discuss how you can support and sponsor next year’s awards, please reach out to Aby at Aby@source2create.com.au. We look forward to partnering with you to make the 2026 Australian Women in Security Awards our best yet.
SUB-EDITOR Stuart Corner
DESIGNER Rachel Lee
STUDENT IN SECURITY SPOTLIGHT
TURN IT UP 126
Paige Haines
90
Prajoti Rane
94
Tanvi Badghare
98
Amy Koralis
102
Ashley Mathew
106
Queeneth Onyike
110
Danah Mohammed Alkhan
114
Source2Create Pty Ltd is the publisher of this magazine and its website (www.womeninsecuritymagazine.com).
©Copyright 2025 Source2Create. All rights reserved. Reproduction in whole or part in any form or medium without express written permission of Source2Create is prohibited.
OFF THE SHELF 128
ASSOCIATIONS & GROUPS SUPPORTING THE WOMEN IN SECURITY MAGAZINE
Thank You
TO OUR SUPPORTING ASSOCIATIONS
GETTING INTO CYBERSECURITY WITH NO EXPERIENCE: YOUR ROADMAP FOR 2026 by Abigail Swabey
Have you ever clicked 'send’ on a job application, heart pounding, certain you’d be rejected for lacking the right experience? In cybersecurity, this experience is more common—and more surmountable—than you think. Today, the fastest-growing field in tech isn’t just seeking codebreakers with fancy degrees; it’s searching for determined, curious problem-solvers from all walks of life.
C
ybersecurity is often portrayed as an
willingness to build new skills. Here’s how you can join
exclusive realm for tech wizards and
them, no tech degree required!
computer science graduates. Yet, the reality is far more optimistic, inclusive and practical. In 2025 the demand
for cybersecurity professionals soared, and hiring
MYTHS ABOUT BREAKING INTO CYBERSECURITY • Myth 1: you need a four-year tech degree.
managers are increasingly looking for passion,
Not true. Practical skills, hands-on learning and
aptitude and adaptability rather than just formal
industry certifications can get you an interview
qualifications or previous experience.
and often the job.
If you’re eyeing a career in cybersecurity but feel intimidated by your lack of direct experience, you’re not alone. Many successful professionals in the industry started their journey from non-technical backgrounds, armed only with curiosity and a
8
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
F E A T U R E
• Myth 2: you must start as a programmer.
The industry’s urgent demand for talent means many
Many roles do not require advanced coding;
organisations are open to hiring people for their
analytical, risk management or compliance
potential and willingness to learn, not just for their
positions seek different strengths.
current skill sets.
• Myth 3: the field is only for the young. Mid-life and late career pivoters are increasingly
BREAKING IN WITH NO TECH EXPERIENCE
common, and valued for the diversity of
Many successful cybersecurity professionals began
experience they bring.
their journeys without knowledge of networking, programming or operating systems. The most
WHY CYBERSECURITY? WHY NOW?
important first step is a mindset shift: curiosity,
Cybersecurity job openings hit a record high in 2025,
persistence and a commitment to lifelong learning are
with over 450,000 positions available globally. The
more valuable than prior expertise.
sector is projected to grow 33 percent by 2033, making it one of the fastest-expanding areas in tech.
WHERE TO BEGIN
As organisations face escalating threats to their
• Start with cybersecurity awareness training. Free
digital assets the spectrum of roles continues to
and beginner-level online programs introduce key
diversify; from technical jobs like penetration testing
concepts like phishing, password safety and data
to governance, risk management, compliance and security awareness.
protection without requiring any technical skills. • Explore free resources. Many organisations, including government agencies, offer
Moreover, there is no single path into cybersecurity.
cybersecurity foundations courses aimed at the
A recent survey found that 56 percent of
public rather than specialists. These provide
cybersecurity professionals started in roles outside
foundational knowledge and confidence to
of IT, highlighting the value of transferable skills and
learn more.
fresh perspectives. Individuals without any technical background or prior understanding of cybersecurity still have real opportunities to enter the field.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
9
• Focus on transferable skills. Problem-solving,
If you are going to try and pivot into the cybersecurity
critical thinking, communication and ethics are all
workforce and don’t have any transferable skills, these
vital in security roles and often developed in non-
are the ones you need.
technical fields. Even simple acts like being a security ambassador
THE ESSENTIAL SKILLS— AND HOW TO BUILD THEM
at your workplace, organising awareness events or
Technical skills
helping develop security policies can build relevant
While you don’t need to be a coding genius, a solid
experience.
understanding of technology fundamentals is
• Volunteer for security-related tasks.
• Find a supportive community. Online forums,
indispensable. Employers typically look for:
local meetups and women-in-security groups offer encouragement, mentorship and learning paths for absolute beginners.
• networking basics: understanding how data moves across systems and the fundamentals of TCP/IP, DNS, firewalls and VPNs.
ENTRY ROLES FOR COMPLETE BEGINNERS Some security roles are especially welcoming to those starting from zero.
• operating systems: comfort working with Linux and Windows environments. • programming and scripting: learning Python, Bash or PowerShell helps automate tasks and
• Security awareness co-ordinator: focuses on training and education, ideal for teachers or communicators. • Compliance analyst: involves policy work
understand vulnerabilities. • cloud security: familiarity with AWS, Azure, or Google Cloud is increasingly valuable as businesses move to the cloud.
and documentation more than hands-on technical tasks. • Junior risk analyst: primarily assesses business
Cybersecurity fundamentals An understanding of core security principles such
processes and helps implement security
as authentication, encryption, malware types and
best practices.
common attacks like phishing or ransomware, is crucial.
Cybersecurity is not just for ‘techies’; it is a field defined by curious minds, critical thinkers and people
Soft skills
committed to making a difference. With dedication
Employers are also looking for:
and access to learning resources anyone, regardless of their starting point, can find a place in this dynamic industry.
• problem-solving and attention to detail: the ability to spot irregularities and analyse risk. • communication skills: explaining complex issues to non-technical audiences. • curiosity and willingness to learn: the drive to keep up with rapidly evolving threats and tools.
HOW TO BREAK IN: ACTIONABLE STEPS 1. Start with online courses There is an abundance of beginner-friendly online courses and boot camps. Many are free or affordable and cover cybersecurity basics, networking, operating systems and cloud principles. Platforms like Coursera, edX and Cybrary are excellent starting points.
10
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
F E A T U R E
2. Experiment with hands-on learning Employers increasingly value proof of skills over formal education. • Set up a home lab using free or low-cost virtualisation software (e.g. VirtualBox, VMware). Experiment with operating systems, networking and open-source security tools. • Join gamified learning platforms such as Hack The Box or TryHackMe which offer experiential, challenge-based learning and virtual capture the flag (CTF) competitions. • Contribute to open-source projects on GitHub, especially those related to security.
6. Seek internships, volunteering and open roles Many organisations offer entry-level internships or apprenticeships that don’t require prior experience. Volunteering for security initiatives in your community
3. Pursue entry-level certifications
or at nonprofits can help build your resumé and
Certifications signal to employers your commitment
network while contributing meaningfully.
and baseline knowledge, even if you haven’t worked in the field.
7. Tailor your application When you’re ready to apply:
• Top entry-level certifications in 2025: CompTIA Security+, eJPT, Cisco’s CCNA Cyber Ops and SSCP. • Gaining certifications can make you up to 2.5 times more likely to land an entry-level job.
• identify entry-level job titles like security analyst, security operations centre (SOC) analyst, or risk/ compliance associate. • highlight hands-on projects, certifications and
4. Leverage transferable experience
transferable experience.
Experience in IT support, network administration,
• be prepared to discuss your self-directed learning,
risk management or compliance offers a significant
home labs or any challenge-based activities you’ve
edge. Even previous work in customer service or
completed in interviews.
project management develops transferable skills in troubleshooting, communication and process documentation that are valuable in security roles.
FINAL WORDS: YOUR CYBERSECURITY JOURNEY BEGINS NOW Breaking into cybersecurity with no experience is
5. Build your professional network
not a fantasy; it’s a reality for thousands every year.
Engage with cybersecurity communities online
The field welcomes newcomers with curiosity,
and offline.
commitment and a passion for continuous learning. Start with what you have, build core skills, connect
• Join professional organisations like ISACA, (ISC)²,
with the community and be persistent. The world
OWASP, AISA, ACS etc. and attend local meetups
of cybersecurity isn’t closed off. In fact, it needs
or conferences.
you now more than ever, whether you come from
• Seek a mentor—seasoned professionals are often willing to share advice and guidance, accelerating
IT, management, education, healthcare or any other background.
your learning and helping you navigate challenges. • Leverage platforms like LinkedIn to connect with
The only wrong move is never to start at all.
practitioners and follow career paths similar to
Your journey can begin today, one step, one course,
your interests.
one connection at a time.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
11
AMANDA-JANE TURNER Cybercrime is big business, thanks to technical advancement and interconnectivity creating more opportunities. This regular column will explore various aspects of cybercrime in an easy-to-understand manner to help everyone become more cyber safe.
C O L U M N
Prime time for cybercrime The transition from the old year to the new is prime
• Secure your devices. Only download apps from
time for cybercrime! Alliteration aside, this time of
official app stores like the Apple App Store or
year is ripe for cyber scams with increased financial
Google Play, and keep your digital devices updated
activity from holiday shopping, vacations, end of
with relevant security patches.
year bonuses, seasonal sales and reduced vigilance
• Be cautious with public Wi-Fi. Avoid accessing
resulting from a focus on holidays, or added stressors
sensitive information or making online purchases
at work as the year winds up.
over public networks. Use a VPN if public Wi-Fi is your only option.
Cyber criminals exploit this time of year to trick
• Enable multifactor authentication. This adds an
people into paying faked invoices, clicking phishing
extra layer of security to your accounts, making
links or paying for heavily discounted items that do
it harder for criminals to get in, even if they have
not exist. It is a great time for scammers thanks to
your password.
increased online activity from people booking holidays
• Stay vigilant. Be suspicious of any unsolicited
online, buying presents for others, making charitable
requests for information or texts about delayed
donations and looking for discounts. Additionally,
packages. And don’t let urgency or holiday
people can be more distracted at this time of year:
excitement override your security instincts.
they may be in holiday mood, letting their guard down and relaxing their usual vigilance. How to protect yourself from seasonal cybercrime. • Verify charities before you donate. If you want to
Stay safe everyone. www.linkedin.com/in/amandajane1
www.empressbat.com
donate to a charity, first verify it is legitimate, and go direct to the website yourself by searching for it. Confirm it is genuine and has secure payment methods. Then donate through one of these. • Shop from verified and reliable sources. Go direct to a website by typing the address or searching for it instead of clicking links in emails, texts or social media. • Think critically about discount offers. Be wary of “too good to be true” offers: they can be a way for criminals to compromise your accounts or trick you into paying for a product that you will never get.
12
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
WHAT’S HER JOURNEY?
Tara McNally Manager Cybersecurity
T
ara McNally never expected a three-hour
months before my start date I was asked to defer for
evening lecture to change the course
a year due to the early impacts of COVID-19.” Rather
of her life. Yet, as she recalls, “During
than viewing the delay as a setback, she turned it into
my undergraduate studies I spent a
an opportunity. “I decided to make the most of that
semester in Washington D.C where I
time by pursuing a master’s degree in cyber risk, an
enrolled in a Cyber Risk module, surprisingly, I found
area I’d always been interested in but hadn’t had the
myself genuinely looking forward to it each week.”
opportunity to explore in depth.” When she completed
The class ran from 5 to 8pm prime hours for college
her degree, she approached HR with a request that
fatigue but Tara found the content “engaging enough
would shape her future: “I reached out to HR to see if I
to keep me focused (no small task for a college
could join the Cybersecurity team instead. They were
student sitting in class from 5-8pm!). Despite the
supportive of the switch and that’s how my career in
odds it sparked a real interest in the field and an
cybersecurity began.”
eagerness to learn more.” That spark would eventually lead her into a career she hadn’t originally planned but
Today, as a Manager in Cybersecurity, Tara
now can’t imagine not pursuing.
recognises the complexity of working in a field that evolves faster than most industries can keep up with.
14
Her transition into cybersecurity unfolded organically.
“Staying ahead of the evolving market dynamics
Tara explains, “I had accepted a graduate offer to
and threat landscape is challenging. Attackers
join the Technology Advisory team at one of the big
are becoming increasingly sophisticated and fast
consulting firms in Ireland. However, about three
moving, while regulatory demands continue to grow in
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
“Be curious, ask lots of questions (especially when you’re unsure) and don’t be afraid to put yourself out there. You don’t need to have all the answers or the perfect skillset from the start. Showing genuine interest, being willing to learn and giving things a go is equally as valuable. If you’ve got the passion, the rest will come.”
J O U R N E Y ?
big priority for me, knowing I’ll be able to keep building my skillset and continue delivering quality work is important.” Equally essential is the freedom to choose how she works. “I genuinely enjoy being in the office but also really value the option to work from home when it suits. Being part of an organisation that trusts you to decide makes a big difference.” Her own development is front of mind, and the next milestone is a significant one. “The next certification I’m aiming for is my CISSP. It covers a huge amount of content and will take lots of study, but this comes with a lot of learning, deeper knowledge and new opportunities, which I’m really looking forward to.” Despite the challenges and demands of cybersecurity, it’s the human element that brings Tara the greatest
complexity.” Her approach is proactive: “Engaging with
fulfilment. “The collaboration and connection with
industry leaders, attending key events, and proactively
others, It’s not just about the work itself but also
staying informed are critical to remaining effective
the energy and ideas that come from being around
and resilient in such a rapidly changing environment.”
smart, motivated people.” She thrives on variety too. “Whether it’s diving into a new challenge, exploring
Despite her expertise, Tara would reassure her
a different industry or picking up new skills there’s
younger self that she didn’t need to have it all figured
always something to grow from.”
out from the start. “Be curious, ask lots of questions (especially when you’re unsure) and don’t be afraid to
Maintaining balance is non-negotiable in her life. “By
put yourself out there. You don’t need to have all the
ensuring my day isn’t solely centred around work,”
answers or the perfect skillset from the start.” What
she says. From morning gym sessions to ocean
matters most, she emphasises, is mindset. “Showing
swims and sprint training after hours, her routine
genuine interest, being willing to learn and giving
is intentionally energising. “Starting early gives me
things a go is equally as valuable. If you’ve got the
time to go to the gym, grab a coffee with a friend or
passion, the rest will come.”
go for a walk before logging on… staying active and spending time outdoors helps reduce stress and
Looking ahead, Tara sees emerging technologies
keeps things in perspective.” Having hobbies she
reshaping the threat landscape. “AI and Quantum
genuinely loves, she adds, is key to recharging.
are two areas that will continue to make security difficult and solutions more complex.” AI, she notes,
Tara’s journey is a testament to following curiosity,
is accelerating social engineering at scale, putting
embracing unexpected turns, and trusting that
everyday users at heightened risk. Quantum, while
passion and perseverance will lead the way. Her path
not an immediate danger, presents long-term
may have begun in an evening lecture in Washington
implications: “Being able to get ahead is something
D.C., but her impact on the cybersecurity landscape
organisations should be thinking about.”
continues to grow far beyond the classroom.
For Tara, career decisions extend far beyond salary
www.linkedin.com/in/taramcnally
considerations. “Opportunities to learn and grow are a
I S S U E 28
WOMEN IN SECURITY MAGAZINE
15
Krity Kharbanda Application Security Professional | Advocate of women in cybersecurity
F
rom being a biology student in India to
new city, new culture, unfamiliar surroundings. She
becoming a cybersecurity professional
quickly realised that adapting was as important
in the United States, Krity’s journey has
as studying. Learning to navigate challenges
been anything but linear. To every stage
independently became a skill that would define the
she brought something from the phase
next chapter of her life.
before a skill, a mindset or a perspective that helped her take that step with greater confidence and clarity.
Graduation brought clarity of passion, but not
She pivoted constantly, taking opportunities that
opportunity. With global layoffs on the rise and
pushed her out of her comfort zone and building on
her master’s program on hold due to COVID-19,
lessons from previous experiences. Her story offers
she kept applying for roles in cybersecurity. That
insight into what it takes to navigate change, seize
persistence eventually paid off with an internship
opportunities and grow in a field as fast-moving as
at a startup. It was soon converted into a full-time
cybersecurity. For Krity, each new role is more than
role. That year became her crash course in bridging
a career progression; it’s a new opportunity to better
theory and practice. She moved beyond academic
understand how people, technology and environments
problem-solving into real-world application, tackling
interact. She is learning every day.
both technical and business challenges. She gained exposure to social engineering exercises, cloud
Krity’s academic path took her from northern
security and compliance frameworks like NIST, ISO
India to southern India to study electronics and
and GDPR. This exposure confirmed cybersecurity
communications engineering. Beyond circuits and
as the right path and made her keen to broaden the
signals she discovered a fascination with networks,
depth and breadth of her experience.
security and databases. The transition wasn’t easy:
16
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
Krity realised that technical problems are only part of the story. The bigger challenges to meaningful progress are often reading the room, navigating team dynamics and adapting to the organisational environment. Overcoming these challenges shaped both her professional approach and personal growth.
Driven to expand her skills, Krity moved to the United
Outside of work she finds joy in reading, exploring
States to pursue a master’s in information science,
cafés, dancing and cooking. Her personal mantra
focusing on information security. Graduate school
is simple but effective: ‘React’. She allows herself
tested her in ways she hadn’t anticipated. She had to
to process and immediately release emotions, then
constantly juggle the competing priorities of multiple
steps back to reflect and plan. Setbacks are not
part-time jobs and, for the first time, independent
failures; they’re lessons that inform the next move.
living. She worked as a research assistant under a
Her story demonstrates that growth is ongoing; even
business school professor, supported the university
when you reach new milestones, there’s always more
IT help desk and contributed to the Computational
to explore, understand and master.
Biology department. She drew on lessons from her undergraduate days to adjust, persevere and make
Today, Krity works in application security, and
her own way. She turned these challenges into
volunteers to give back to the community through
growth opportunities and showed how resilience and
mentoring and working with a non-profit organisation
adaptability can transform pressure into opportunity.
the Breaking Barriers Women in CyberSecurity (BBWIC) Foundation. She is always on the hunt for
During this time she landed an internship with
opportunities to learn and grow.
ServiceNow, her first exposure to corporate America. Living in a new city and facing unfamiliar professional
Krity’s journey is defined by curiosity, adaptability and
expectations, she learned quickly. The internship
the courage to pivot when needed. Every challenge,
sharpened her technical skills, expanded her
obstacle and leap into the unknown has shaped
perspective and ultimately enabled her to transition
her into someone who continues to grow both her
into a full-time role. She tackled projects she had long
technical expertise and her understanding of how
found intimidating; from penetration testing exercises
people and environments influence outcomes. While
to identifying vulnerabilities and presenting actionable
she often says her cybersecurity journey began during
reports to stakeholders.
her undergraduate studies, she believes it truly started even earlier. Because, at its core, cybersecurity is
Krity realised that technical problems are only part
about mindset and adaptability. A strong security
of the story. The bigger challenges to meaningful
mindset goes beyond technical tools; it demonstrates
progress are often reading the room, navigating
critical thinking, anticipates human behaviour
team dynamics and adapting to the organisational
and uses psychological insights to help develop
environment. Overcoming these challenges shaped
technical strategies.
both her professional approach and personal growth. www.linkedin.com/in/krity-kharbanda-0b9bb1133
I S S U E 28
WOMEN IN SECURITY MAGAZINE
17
opportunity with the Information Systems General Manager… who listened as I painted a vivid picture
Nkiruka Joy Aimienoho Chief Information Security Officer (ScB)
of the value I wanted to create.He advised that I join a niche Cyber Security and IT GRC company. I took the advice, and my journey into Information Security advisory began.” From there, she built intentionally and relentlessly. “I diligently built competence, worked hard, and cultivated a large appetite for knowledge.” She embraced complex, uncharted projects, pursued global certifications, and strengthened both her technical depth and leadership maturity. These early
N
decisions carved the path toward the executive she has become. kiruka Joy Aimienoho’s cybersecurity journey was never a coincidence; it
Professional communities have been another
was an early calling. Long before she
cornerstone of her journey. Linked with ISACA, ISC2,
became a Chief Information Security
The BCI, EC-Council, and several women-centric
Officer, the foundation had been laid.
groups such as WiCyS, WiR, SheSecures, and
“I have always been interested in the field. I got my
SheLeadsTech, Nkiruka credits these networks for
first degree in Electrical and Electronics Engineering,
being part of her journey. “I always strived to hone
my first job was on the Information Systems Service
my craft” she says, and these organisations gave
Desk at Africa’s telecom giant, MTN Nigeria, and I
her access to global best practices, world class
was particularly fascinated by the dynamics of the
thought leadership, and supportive networks that
Information Security space after interacting with
continue to uplift women across cybersecurity and
different professionals and parts of the business
resilience. They also provided a platform for her to
from the IS service desk.” That early spark matured
mentor others, a role she sees as both responsibility
into a passion not only for solving complex
and privilege.
technical problems but for shaping enterprise resilience, influencing executive cyber strategy, and
Yet the path was not without moments of doubt.
nurturing Africa’s rapidly growing cybersecurity
As a young woman navigating male-dominated
talent landscape.
environments, she often found herself having to prove her worth repeatedly. “I was one of the few women
18
Her transition from curiosity to a distinguished career
passionate about Information Security, Cybersecurity
was fuelled by decisive, courageous steps. One
or even Business Continuity, with limited support.
pivotal moment stands out vividly to her: “seizing an
I had to read ferociously, learn on the job, and learn
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
from my mistakes.” When her capabilities were
work consistently overnight but that has changed
questioned, she met it with excellence and clarity.
significantly now.” Today, she prioritises family, faith,
“I responded by going back to the drawing board,
and health acknowledging that personal grounding is
building competence, and in scenarios this was
essential for sustainable leadership. “Balance is not
required, confidently describing my portfolio and the
accidental; it is a discipline.”
remarkable feats and experience garnered. Instead of allowing these things to discourage me, I continued
Nikiruka’s journey has been shaped by extraordinary
to give my best. With time, the questioning soon
influences, leaders, thinkers, mentors, and global
turned to admiration.” For her, competence, faith, and
voices who challenged her thinking and refined
community “my tribe” formed the backbone of her
her leadership. Mikko Hyppönen remains a major
resilience. “We rise by lifting others, and your tribe will
intellectual inspiration, admired for his clarity and
be there to spur you on in times of self-doubt.”
ability to simplify complex concepts. She also draws strength from trailblazers such as Ngozi Okonjo-
Looking ahead, she anticipates a period of profound
Iweala, Adedoyin Odunfa, Tope Aladenusi, Ope
change in the cybersecurity landscape. Increased
Onifade,Nkiru Olumide Ojo, and Dr. Nneka Abulokwe.
use of AI in both attack and defence, heightened
Industry mentors and visionary executives have
regulatory scrutiny, more automation, widespread
shaped her strategic approach and resilience. And her
adoption of zero-trust, and cyber resilience becoming
community, her enduring “tribe” remains her anchor.
a board-level priority. In her words, “cybersecurity
“It is rewarding to mentor and be mentored and
must be treated as a business issue, not just an
nurturing those relationships often progresses them
IT issue.” She warns that the greatest threats will
to sponsorship.”
emerge from AI-enabled attacks, supply-chain compromise, cloud misconfigurations, deepfakes,
Staying effective in a rapidly evolving field demands
geopolitical tensions, and the persistent neglect
what she describes as “an enormous appetite for
of basic cyber hygiene. “CISOs face tremendous
knowledge.” She continuously invests in certifications,
pressure, and without balance, organisations risk
engages with global bodies, participates in cyber
over-investing in tools while under-prioritising basic
drills, attends industry conferences, and experiments
cyber hygiene — including patch management
with emerging technologies. Guided by curiosity,
and effective use of existing threat intelligence
humility, and discipline, her advice to the next
for foresight. Left unaddressed, this significantly
generation is simple: invest in yourself. Leverage
increases the likelihood of successful cyber
the many free resources available from platforms
incidents.” For her, thriving organisations will be
and podcasts to wargaming exercises and actively
those that strengthen foundational controls while
network with those already in the roles you aspire to.
embracing next-generation defence capabilities. Nkiruka’s journey is defined by purpose, resilience, Nikiruka’s career decisions are guided by purpose,
faith, and service. Rooted in a deep appetite for
values, and cultural alignment, with a strong
learning to sharpen her expertise, and driven by an
preference for environments that treat cybersecurity
unwavering commitment to uplift others, her story
as a strategic enabler and prioritise long-
continues to inspire a new generation of cybersecurity
term resilience
leaders across Africa and beyond.
Despite the intensity of her field, balance remains non-negotiable. Earlier in her career, she navigated
www.linkedin.com/in/nkirukacyberandresilience
long nights, late client calls, and constant demands. But with experience came perspective: “There were days when clients would call at 11 p.m. or I’d
I S S U E 28
x.com/InfosecAmazon
WOMEN IN SECURITY MAGAZINE
19
Aneesa Chothia Information Security Officer
A
neesa Chothia, an Information Security
and resilience. “Working in cybersecurity is an exciting
Officer at Discovery in Sandton,
and demanding role. One of the biggest challenges
discovered her passion for cybersecurity
is navigating a male dominated environment
in a way that underscores how pivotal
finding the confidence to be heard and recognised
real world experience can be. “My
for my expertise. I’ve learned that self-awareness,
interest in cybersecurity was first sparked when my
preparation, and authenticity are key. Investing
previous organisation experienced a major breach.
in leadership and personal mastery courses has
We spent many days operating a 24/7 incident
helped me strengthen my voice and presence in the
war room alongside executives, employees, and
room,” she explains. She emphasises the importance
vendors to contain the threat. This showed me how
of collaboration and mentorship: “I also believe
cybersecurity impacts technology, people, brand, and
in the power of mentorship both being mentored
trust,” she recalls. “In the aftermath, I became actively
and mentoring others. It creates room for growth,
involved in various streams to strengthen overall
confidence, and connection especially for women
defenses. The more involved I was, the more this field
entering this space.”
fascinated me. I wanted to understand the layers of protection, the risks that emanate, the potential
Aneesa is candid about the uncertainties that arise
controls that could be implemented, the processes
when forging a career in a dynamic field. Reflecting on
and technology. My interest has evolved from incident
advice she would give her high school self, she says,
response to governance, risk, and consulting. The
“I’d tell my high school self that cybersecurity is one of
constant evolution of this field continues to inspire
the most meaningful, exciting, and rewarding careers
me to continuously grow, protect, empower myself,
to embark on. It’s not just about technology, but about
and inspire others.”
protecting people, information, and the systems that keep our digital world running. Every click,
20
Early in her career, Aneesa recognised that turning
transaction, or connection requires someone behind
interest into a professional pursuit required courage
the scenes who understands how to keep it secure.”
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
She encourages curiosity and persistence, noting
“For individuals in similar roles, Security+ builds a solid
that the field accommodates a range of mindsets
foundation. Certifications like CISM, CCSP, CISSP, and
and strengths: “There are vast specialisations
ISO27001 provide deeper insights into governance,
within cybersecurity from ethical hacking, forensics,
risk management, and strategic leadership. Personally,
risk management, incident response so there is
I’m particularly interested in exploring AI certifications
room for individuals with different mindsets and
to understand how to protect AI systems and assess
personal strengths.”
risks responsibly and ethically.”
Looking forward, Aneesa identifies emerging trends
Despite the demands of her profession, Aneesa
and threats in cybersecurity that professionals
prioritises balance. “Maintaining work/life balance
cannot ignore. “We will see an escalation in AI-driven
is crucial. I use meditation apps like Mindspace to
attacks, where hackers leverage AI to create more
manage stress, spend time with my daughter and
sophisticated attacks such as phishing, deep fakes,
family to create meaningful memories, and start each
and adaptive malware. Supply chain vulnerabilities are
day with prayer and walks to bring calm and gratitude.
also a growing concern, especially with reliance on
These moments keep me grounded and allow me to
third-party vendors and cloud providers. The human
show up fully, personally and professionally.”
element remains the weakest link, not from lack of awareness but because attacks exploit emotions,
Finally, Aneesa offers encouragement to those
trust, and urgency. And then there’s quantum
transitioning into cybersecurity from other fields.
computing, which poses both incredible opportunities
“Cybersecurity isn’t limited to those with technical
and risks for data security.”
backgrounds, it welcomes diverse skills like analytical thinking, problem-solving, and risk
When considering career moves, Aneesa weighs
awareness. Start somewhere, be curious, commit
factors beyond remuneration. “The culture of the
to learning, surround yourself with mentors, and join
organisation, flexibility, reporting lines, leadership
professional associations. Don’t doubt the value or
style, and brand reputation are all critical. A
skills you bring. The field needs people who combine
supportive leader will encourage growth and
technical expertise with strategic thinking, empathy,
accelerate your career,” she observes. She credits
and confidence.”
her former manager, Sachin Surajbali, as a major influence, saying, “He created a space where I could
Aneesa Chothia’s journey is a testament to how
question, challenge, and contribute, which built my
passion, resilience, and mentorship can transform
confidence and guided my thinking. His leadership
curiosity into a thriving cybersecurity career. Her story
style continues to guide how I mentor others and
continues to inspire women in the field to be bold,
show up in the cybersecurity space today.”
stay curious, and shape the future of cybersecurity with confidence.
Aneesa is also committed to continuous learning, emphasizing the value of certifications.
I S S U E 28
www.linkedin.com/in/aneesa-chothia-b4251716/
WOMEN IN SECURITY MAGAZINE
21
Opeyemi Olaifa Manager & Team Lead Cybersecurity & Compliance Advisory At Digital Encode Limited
Since that moment, her initial curiosity has evolved into a deep passion. “Over the years, my interest has shifted from just wanting to understand how attacks happen to actually helping organizations
O
prevent them, respond to incidents, meet compliance requirements, and build stronger security practices. peyemi Olaifa’s journey into
It has become more than a career switch; it is
cybersecurity began from a place of
something I genuinely enjoy and feel connected to
restlessness. “After University, I worked
every day.”
as a Project Manager in an Information Technology company for about 18
Opeyemi emphasises that the early stages of her
months. I picked up good management experience
career required dedication and courage. “The biggest
and even some programming skills, but I just wasn’t
turning point was deciding to actually do the work.
fulfilled. I have always known I am more technically
I stayed up late most nights trying to learn about
inclined, so project management alone didn’t feel like
cybersecurity, burning the midnight candle just to
the right path for me.”
catch up. I asked a lot of questions honestly; I think everyone around me eventually got tired of me
Her curiosity about cybersecurity emerged as she
because I was always asking ‘why?’ or ‘how does this
explored the rising threats in the digital world. “While
work?’ But that curiosity really pushed me forward.”
trying to figure out what to do next, I started reading
22
a lot about how online threats were becoming
She recalls taking on tasks even when uncertain of
more serious and how attackers kept changing
her abilities. “I did many things afraid, but I still did
their techniques. That really caught my attention. I
them anyway because I knew the only way to grow
became curious about how these attacks could be
was to try. All these little steps, the late nights, the
detected early and how information could be properly
constant learning, the endless questions, and the
protected. I even reached out to a friend already in
courage to take on tasks outside my comfort zone
cybersecurity, and that conversation was what finally
helped me move from simply being interested in
made everything click for me. I knew this was the
cybersecurity to actually building a career in it. It
direction I wanted to go.”
wasn’t easy, but it was worth it.”
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
Reflecting on her path, Opeyemi notes that her career
become more central as organizations continue to
unfolded organically rather than according to a rigid
rely on cloud services, remote work, and a growing
plan. “When I started my journey in cybersecurity,
number of devices. Supply chain security and
I definitely did not have a clear picture of the exact
ransomware will remain major challenges. The next
roles I wanted. I just knew I wanted something
couple of years will require adaptability, continuous
more technical and challenging. I began by learning
learning, and a proactive approach to security.”
whatever I could, taking on any task that came my way, and gradually discovering the areas I enjoyed
Mentorship and professional experiences have been
the most, like digital forensics, compliance, security
central to her growth. “The most substantial influence
assessments, and advisory work. Over time, the more
on my cybersecurity career has been a combination
I explored, the clearer the picture became.”
of my mentors, peers, and especially my bosses. Even when I doubted myself, they believed in me more than
If she could advise her younger self, Opeyemi would
I did, constantly pushing me to take on challenging
focus on curiosity, patience, and hands-on learning.
tasks and step outside my comfort zone. Each
“Start exploring early, stay curious, and don’t be afraid
challenge, success, and even mistake has shaped
to ask questions, even the ones that might annoy
the way I approach problems, make decisions, and
people. Dive into learning the basics now. Embrace
mentor others.”
hands-on learning, take certification exams, and get practical experience. It’s okay to be afraid when
Despite moments of uncertainty, persistence and
trying new things; some of the best growth happens
support guided her forward. “There were times I
when you step into tasks that feel challenging or
doubted myself, wondered if I was doing the right
uncomfortable. Follow your curiosity, trust the
thing, or felt like I wasn’t learning fast enough. What
process, and never stop pushing yourself. Even small
helped me navigate those doubts was a mix of
steps taken consistently add up to a big career.”
persistence and support. My bosses believed in me even on days when I didn’t believe in myself, and
In her current role as Manager & Team Lead for
that pushed me to keep going. Over time, small wins
Cybersecurity & Compliance Advisory at Digital
helped build my confidence, and those moments of
Encode Limited, Opeyemi finds fulfillment in both
uncertainty became part of the journey that made me
problem-solving and mentorship. “The aspect of my
more determined to grow.”
current role that brings me the most satisfaction is knowing that the work I do directly helps
For those transitioning into cybersecurity from
organisations stay secure and resilient. I enjoy
other fields, Opeyemi emphasizes curiosity and
analysing risks, identifying vulnerabilities, and finding
courage. “Embrace curiosity and be willing to
practical solutions that make a real difference. I
start from the ground up. Don’t be afraid to ask
also find fulfillment in guiding and mentoring others,
questions. Take advantage of hands-on experiences
whether it’s helping a team member understand a
and certification. Don’t let fear hold you back.
complex issue or advising clients on best practices.
With persistence, curiosity, and the willingness to
Being able to combine technical expertise with
learn, you can successfully pivot into a rewarding
advisory work gives me a sense of purpose.”
cybersecurity career.”
Looking ahead, Opeyemi anticipates rapid
Opeyemi Olaifa’s story is a testament to how curiosity,
developments in cybersecurity driven by technology
courage, and continuous learning can transform
and evolving threats. “AI will continue to change the
uncertainty into a fulfilling career in cybersecurity.
game, both in how attackers craft more sophisticated attacks and in how defenders detect and respond to
www.linkedin.com/in/opeyemi-olaifa-1b6b6114a
them. Staying ahead will mean using AI to anticipate threats rather than just react to them. Zero Trust will
I S S U E 28
WOMEN IN SECURITY MAGAZINE
23
Fathima Mohamed Thaseen Account Executive at Havas NZ
F
athima Mohamed Thaseen, an Account
immersed in cybersecurity. Each session expanded
Executive at Havas NZ, discovered her
my perspective and slowly built my confidence,
passion for cybersecurity long before she
helping me recognise that this was not just an
formally entered the field. “Growing up, I
interest, but a path I wanted to commit to.” A pivotal
was always drawn to technology; curious
decision came when she pursued a Master’s in
about how systems worked, how people interacted
Cybersecurity and Digital Forensics at Auckland
with them, and how easily they could be influenced
University of Technology, alongside professional
or manipulated,” she recalls. However, it was through
development through anti-fraud masterclasses and
her husband’s work in fraud risk management within
live training sessions in Dubai. “Each step reaffirmed
the banking sector that her curiosity transformed
my decision and strengthened my determination
into purpose. “Watching him navigate complex fraud
to build a meaningful career in cybersecurity,”
investigations, respond to emerging scams, and
she reflects.
protect customers from financial harm opened my eyes to the hidden battlegrounds of the digital world.
The journey has not been without challenges.
I saw how a single oversight could lead to significant
Balancing academic pursuits, part-time work in a new
loss, and how the right expertise could prevent it.
industry, and responsibilities at home as a mother
What started as curiosity slowly transformed into
to a three-year-old has tested her resilience. “These
motivation; I wanted to understand the mechanisms
challenges have shaped me just as much as my
behind these threats, not just observe them from
academic and professional achievements. They’ve
the sidelines.”
taught me resilience, discipline, and the importance of being intentional with my time. I approach my days
24
Fathima’s early steps into the field were deliberate
with structured planning, clear prioritisation, and a
and thoughtful. “In the beginning, I joined online
commitment to continuous learning. Instead of seeing
masterclasses, attended workshops, and surrounded
obstacles as setbacks, I view them as opportunities
myself with professionals who were already
to grow stronger, more adaptable, and more focused.”
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
Fathima candidly admits that doubt has been part
threats are identified and mitigated, making security
of her journey. “Yes, like many people transitioning
operations faster and more predictive. At the same
into a highly technical field, I faced moments where I
time, emerging technologies like quantum computing
wondered whether I could truly keep up with the pace
and advanced deepfakes will challenge existing
of change. Cybersecurity moves fast, and at times
security models, pushing organisations to rethink
that felt intimidating. But instead of letting those
authentication, encryption, and digital trust.” She also
doubts define me, I turned them into motivation.
warns that AI-driven social engineering and phishing
I leaned into continuous learning, connected
attacks will become increasingly sophisticated,
with professionals who generously shared their
and securing digital identities in IoT and cloud
insights, and immersed myself in workshops and
environments will be more complex than ever.
masterclasses. Over time, I realised that uncertainty is part of growth; and that determination matters far
Fathima stresses the importance of professional
more than having all the answers from the start.”
growth and ethical work environments. “Beyond remuneration, I prioritise opportunities that support
Her path, she explains, unfolded organically. “My early
growth and long term development. Mentorship,
exposure to fraud risk activities and learning through
strong research involvement, exposure to advanced
real-life experiences opened my eyes to the powerful
tools and casework, work-life flexibility, and ethical
link between cybersecurity and fraud prevention. As I
leadership are all key factors for me.” She attributes
learned more, I started to realise where my strengths
much of her inspiration to her husband, whose work
and passions aligned. Over time, that clarity shaped
in fraud prevention gave her a front row seat to the
my goals, guiding me toward specialisation in digital
real world impact of cybersecurity. “His experience
forensics and cyber fraud investigation; fields where I
handling high stakes investigations inspired me
felt I could create meaningful impact.”
to pursue a career where I could contribute in a meaningful way.”
When asked what advice she would give her younger self, Fathima is resolute: “I would tell my younger
For aspiring professionals entering the field from
self to nurture curiosity without hesitation; to explore
other backgrounds, Fathima has clear guidance:
technology boldly and trust in the learning process.
“Cybersecurity thrives on diversity; people enter this
Cybersecurity rewards those who are persistent,
field from countless backgrounds, and each brings
ethically grounded, and willing to solve difficult
unique strengths. Stay curious, be patient with your
problems. Every challenge is a stepping stone, and
learning, and build strong foundational knowledge.
the confidence to ask questions and try new things
Your previous experience is not a disadvantage; it’s
matters just as much as technical skill.”
an asset that can shape your perspective and enrich your contributions.”
In her current role, she finds fulfilment in applying knowledge to real-world scenarios. “The most
Fathima Mohamed Thaseen’s journey exemplifies
satisfying aspect of my work is seeing how theory
the blend of curiosity, resilience, and purpose that
comes alive through practical application. Whether
defines a modern cybersecurity professional. Her
it’s analysing digital evidence, interpreting network
story is a testament to the impact that dedication
behaviour, or uncovering traces of a cyber incident,
and continuous learning can achieve, proving that a
each task reinforces the importance of cybersecurity
meaningful career in cybersecurity is not just about
in protecting individuals and organisations.”
protecting systems, it’s about safeguarding people and making a tangible difference in the digital world.
Looking ahead, Fathima anticipates transformative developments in the field. “Artificial intelligence
www.linkedin.com/in/fathima-thaseen-b92620375
and machine learning will continue to change how
I S S U E 28
WOMEN IN SECURITY MAGAZINE
25
Ako Otudor Cybersecurity Analyst
A
ko Otudor’s cybersecurity journey started
something far more human. “The most complex
with a heartbreak, her first computer was
aspect is navigating imposter syndrome,” she
infected, ruined, files wiped like they’d
shared. Her approach has been both grounded and
never existed. “I became interested in
compassionate. To navigate, I read, ask questions,
cybersecurity after I got a virus on my
talk to my family and friends, pray and accept that it
1st ever computer,” she recalled. “I was devastated
is ok to not be perfect or not feel worthy of situations.
because my files were gone and I had to rewrite
Also, I have learnt not to feel bad about how I feel at
my university assignment paper from scratch.” The
any point in time. The goal is to keep moving even if it
frustration that came from that moment grew into
is one small step at a time.”
something far bigger. “Over time, my interest has grown from knowing about cybersecurity to helping
Her doubts weren’t limited to specific moments, they
others understand and protect themselves.”
showed up regularly along the way. “There were a lot of moments,” she said. “I got through them by
Curiosity quickly became her defining trait. Ako
talking to my family, seeking advice from mentors,
remembers the early phase of her journey as one
and praying”. She didn’t begin with a carefully plotted
powered by questions, persistence and boldness.
path, either. “My path unfolded organically. I started
“I asked a lot of questions. Nothing was too small
cybersecurity in the early days in my country so
for me to ask questions about,” she said. “I also
everyone was still trying to figure it out as a group
shadowed people. If you did something I was
and individually.”
interested in learning, I would hound you. I still do these things even now.”
If she could speak to her younger self, she knows exactly what she would say. “Read and make nerdier
26
As her career developed, she found herself wrestling
friends. Stop worrying, close your eyes and just go
not with firewalls or code libraries, but with
for it. No one is perfect.” She also believes aspiring
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
cybersecurity students need one thing above all hands-on practice. “Practicals In my country, unless you have guidance and steady access to the internet for personal study, you mostly get theory.” Looking at the future of the field, Ako doesn’t hesitate. “Quantum computing,” she said, when asked which developments will be most impactful in the next two years. As for threats, she’s watching two trends closely. “Use of AI in attacks and 3rd party attacks.”
"The most complex aspect is navigating imposter syndrome... I have learnt not to feel bad about how I feel at any point in time. The goal is to keep moving even if it is one small step at a time.”
Career progression, for her, is about more than a salary bump. “Company values, work culture, the job expectations as well as the company’s unofficial
prompt properly and it can be fun to see what I can do
reputation,” she said, are essential considerations. The
in such short periods of time.”
people who shaped her career run like a throughline across her journey. “My bosses over the years,” she
Her professional network has expanded through
reflected. “They have shown me how to manage
industry organisations. “I’m a member of ISC2, EC-
situations, people, and myself. I have learnt and I
Council and a bunch of others,” she noted. “These
am still learning how to balance all these factors in
associations have broadened my awareness of
decision making.”
current issues, given me access to training and events that have taught me so much as well as opened my
As she looks ahead, she sees leadership on the
social circle.”
horizon. “Managerial and business certifications,” she said, are next on her list. “A point comes when you
Ako has seen firsthand how the talent shortage
have to learn how to direct people to properly patch
impacts organisations. “There were projects and
the server and ensure that others understand how or
tasks that could not be done or done well because
can do the same.”
there weren’t enough skilled people,” she said. “An example was forensics.”
Despite everything she has achieved, what brings Ako the most joy is simple. “Learning something new,” she
For those transitioning into cybersecurity from other
said. “Cybersecurity is a fast paced field that always
fields, she offers reassurance rooted in experience.
has something to teach you.” To maintain balance,
“Every experience is valid. There is no such thing as
she relies on boundaries. “I have a mental start and
wasted time,” she said. “Cybersecurity is so broad and
closing time based on my work schedule.”
getting broader that there is a place for you even if others don’t see it yet.”
Staying sharp is a deliberate practice, shaped by constant input. “I subscribe to newsletters, LinkedIn
Ako Otudor’s journey is shaped by curiosity,
pages, social media pages as well as podcasts,”
persistence, humility and a deep desire to learn. Her
she explained. A typical day brings variety and
path may have started with a virus on a long lost
responsibility. “I am responsible for managing several
computer, but it has grown into something far more
platforms ranging from staff training, email security,
enduring: a career dedicated to protecting others,
cloud security as well as risk management. My
expanding knowledge and making space for the next
priority is ensuring that all tasks run smoothly.”
generation of cybersecurity professionals.
These tasks are increasingly supported by emerging
www.linkedin.com/in/ako-otudor
tools. “Right now, AI,” she said. “I am learning how to
I S S U E 28
WOMEN IN SECURITY MAGAZINE
27
continues to offer guidance and, at times, even push me beyond my comfort zone, which has led me to my current position as a CISO.” That leap into the CISO role, however, was not without hesitation. “My only uncertainty in my cybersecurity career was whether to apply for and accept the CISO position,” she admits. “I was quite content and enjoyed the position of Information Security Analyst for its technical and investigative aspects.” Ultimately, it was the encouragement of her support system that convinced her to take on the challenge. “I have
Jaime Schrepfer Chief Information Security Officer
a wonderful support system that reminded me that I have never backed down from a challenge and advised me to ‘get out of my own way’ and accept the natural progression of my professional journey.” Part of that challenge has been stepping into the business oriented responsibilities that come with
J
leadership. “My career path has primarily been technical in nature, so for me, the business aspects aime Schrepfer’s journey into cybersecurity
of my CISO role I find to be more challenging,” she
began not with a single defining moment,
explains. “Budgeting, employee performance reviews,
but with a growing fascination that
and vendor relations are areas of this job that I
blended technology and human behaviour
continue to work on and improve. Having a mentor to
in equal measure. “Cybersecurity is a
guide me through these aspects of the job has been
dynamic field of interest from both a technological
quite helpful for me.”
and psychological standpoint,” she reflects. “The
28
constant evolution of technology fuels my passion
Jaime’s path into cybersecurity was anything but
for continuous learning.” Her curiosity quickly grew
linear. She started in medical transcription before
beyond the technical, drawing her into the human
pivoting to IT, expecting a future in help desk roles.
side of cyber how people think, behave, and become
But her passion for learning pulled her deeper. “My
both targets and defenders. “I find the psychological
career has unfolded organically,” she recalls. “When
side of cyber particularly fascinating, from analysing
I pivoted away from medical transcription to IT, I
threat actor motivations and techniques to observing
envisioned a career of help desk-type roles. However,
end-user behaviours and patterns. This understanding
my passion for learning seemed to naturally progress
of the human aspect of cybersecurity enhances my
beyond help desk roles into more system and network
cyber defence skills.
administration and eventually to cybersecurity.”
Her career, however, was never the product of a
Today, she champions the importance of
rigid plan. Instead, it unfolded through opportunity,
building strong technical foundations for aspiring
guidance, and the courage to evolve. In the early
professionals. “My recommendation is to build a solid
years, she credits one person above all others for
foundation of IT knowledge. Understanding various
helping shape her trajectory. “I was fortunate to have
aspects of technology, from operating systems to
had a mentor who provided guidance as I navigated
networking concepts, is important when analysing
my early career,” she says.”To this day, my mentor
cybersecurity events or architecting security systems.”
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
She also recognises that cybersecurity is not a
I am interested in pursuing several certifications, such
one-size-fits-all industry. “This ultimately depends
as the CISA and CRISC from ISACA, which I believe
on the individual’s area of interest,” she says. “For
would be beneficial in my current role as CISO.”
example, a penetration tester needs to understand operating systems, software vulnerabilities, and
Balancing her demanding role with personal wellbeing
networking concepts, whereas a GRC analyst needs
remains an ongoing effort. “Work-life balance is
to understand regulations, human psychology, risk
indeed a challenge, particularly when balancing a
probabilities, and their associated impacts.”
full-time job with a full-time doctoral program,” she says. Her escape is found in creativity. “I try to find
As she looks ahead, Jaime is both optimistic and
time, even if just 30 minutes to an hour a day, for non-
cautionary about the future of cyber. She warns
technology activities. I grew up crafting, and counted
that organisations must finally shift from reactive
cross stitch is my favorite non technology outlet.”
to proactive defence. “Analysis of successful cyberattacks reveals that many organisations are
Professional growth also requires staying sharply
falling short in their cybersecurity fundamentals. I
informed. Jaime dedicates time every day to keeping
believe we can do better.” She also points to the rapid
up with the cyber landscape. “I have integrated
emergence of transformative technologies like AI and
research and threat intelligence into my daily work
quantum computing. “Governance of this emerging
activities. I dedicate a minimum of one hour a day
technology has been slow and has been unable to
to reading all the current news, trends, and threat
keep pace,” she notes. “Looking ahead, we must
intelligence feeds.”
anticipate the emergence of quantum computing and begin developing secure governance now, before our
She also invests heavily in her team, especially
current security mechanisms are rendered obsolete.”
in an environment where recruitment is difficult. “Staffing in local government is a challenge. Public
Quantum computing, she says, is poised to become
service typically cannot match the salary offerings
one of the most significant threats and opportunities
that private sector opportunities provide,” she
in the coming years. “This emergent technology
explains. “However, I have been fortunate to have
will bring forth significant positive advancements in
staff who have chosen public service.” To support
many areas of research, but it will also be utilized for
their development, she gets creative. “We analyze
malicious intent, as we have seen many times before.”
and discuss cybersecurity news articles as a team, random pop quizzes for certification study, and most
When evaluating new career opportunities herself,
recently, I hosted a game of Backdoors and Breaches,
Jaime looks far beyond the salary line. “I evaluate
which resulted in an immediate request for another
several factors,” she explains. “Company culture,
game session.”
work-life balance, commute time, remote work options, education reimbursement, training
For those entering cybersecurity from other careers
investments, employee turnover rates, and the
much like she once did Jaime offers reassurance
stability of the organisation.”
through her own lived experience. Her journey shows that there is no single “right path,” only the willingness
Her mentor continues to be a defining influence.
to learn, adapt, and stay curious. And above all,
“He was one of my favourite instructors during my
her story reinforces a truth she lives daily: growth
early IT education and has continued to mentor me
happens when you embrace the challenge.
over the past 13 years. In fact, we are both currently pursuing our doctorate degrees in cybersecurity
www.linkedin.com/in/jaimeschrepfer
together.” Her own professional development remains a priority. “Once my university journey is complete,
I S S U E 28
WOMEN IN SECURITY MAGAZINE
29
Fiona Martin Associate Director, Business Resilience
always encouraged to say ‘yes’ to new challenges, especially if they pushed my out of my comfort zone, which helped me to open doors and gain exposure to different aspects of the field.” She adds, “Putting yourself forward helps you build valuable connections
F
with new stakeholders. I found that building strong relationships and demonstrating a willingness iona Martin, Associate Director of
to work hard were key factors in advancing my
Business Resilience, describes her entry
career journey.”
into cybersecurity as “a happy accident.” Having started her career in finance within
Fiona candidly recalls moments of uncertainty in
the UK’s largest retail and commercial
her transition into cybersecurity. “Coming from an
bank graduate scheme, Fiona explored a variety of
operational background, I initially struggled with
operational roles before joining the Cyber Security
imposter syndrome when moving into cybersecurity.
team. “By happy accident I was introduced to the
I often felt underqualified, not technical enough, or
fascinating and complex world of cybersecurity,”
not intelligent enough for a career in this field. I also
she explains. Since then, her career has spanned
think, especially in the early days being a woman
policy, risk & controls, data, governance, engagement,
in a traditionally male-dominated environment
cloud adoption readiness, and ultimately Operational
also contributed to these doubts” Overcoming this,
Resilience. “It is within Operational Resilience that
she says, was largely thanks to mentorship. “I had
I have found my passion, bringing together the
fantastic role models and mentors, both male and
increasingly complicated worlds of technology,
female, who coached me to believe in my abilities,
security, critical third party risk and data, to build
recognize my unique skill set as a strength, and help
stronger, more reliable financial services for
me to deepen my knowledge of the field. I focused
customers,” she says.
on learning, building relationships and leveraging my strengths in strategic thinking and delivery. Over time,
30
Reflecting on the early stages of her career, Fiona
I realised that diverse experiences are an asset in
highlights the importance of actively pursuing
cybersecurity, and my passion for the subject helped
opportunities. “Once I discovered my interest in cyber
me adapt and thrive. Now, as I progress in my career, I
and resilience, I actively sought opportunities that
hope to support emerging cyber talent in finding their
would expand my knowledge and experience. I was
own confidence as they begin their journeys.”
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
Her career path has unfolded organically rather
and that’s okay. Learning is a journey that never stops
than following a pre-set plan. “When I started my
and pushing yourself to be uncomfortable is how you
career in cybersecurity, I didn’t have a clear vision of
grow and develop.”
exactly where it would take me and I still don’t! As new technologies like AI, quantum computing, IoT,
Maintaining balance and wellbeing is also important
and extended reality continue to reshape the digital
to Fiona. “My happy place is outdoors, and when I’m
landscape, the nature of cybersecurity and the roles
not at work I spend as much time as possible in the
within it are constantly evolving. Many of the most
fresh air! I am a keen runner, having completed three
important cybersecurity jobs of the future probably
marathons this year, including my first ultra, and find
don’t even exist yet. That’s one of the most exciting
this a huge stress reliever and balancer in my life. I
things about this career path, you never quite know
also keep boundaries between life and work, ensuring
what opportunities or challenges will come next!”
my time is my time and making sure I get outside before work, during my lunch breaks, and when I’ve
Fiona acknowledges the significant influence of her
finished to help shut off from the day.”
mentors, particularly her previous Chief Security and Information Officer, Sharon Barber. “Her presence was
Fiona’s advice for those transitioning into
remarkable; she was strong, passionate, and highly
cybersecurity from other backgrounds is rooted in
knowledgeable, yet always kind and genuinely people
adaptability and curiosity. “Embrace adaptability and
focused. As a strong female leader in a predominantly
a mindset of continuous learning. Leverage your
male environment, she stood out and inspired many,
transferable skills, whether technical or interpersonal,
including myself. She played a pivotal role in shaping
and seek out mentorship and networking
my career, offering guidance and advice, and I
opportunities. Don’t be afraid to challenge yourself
continually aspire to emulate her leadership. On top
and the status quo; curiosity and resilience are
of her professional achievements, she also won an FA
essential. Diverse experiences enrich the field and
Cup Final!”
drive innovation.”
Discussing the challenges of her current role, Fiona
For Fiona, cybersecurity is not just a career it’s a
reflects on her recent relocation from the UK to
journey of continuous learning, resilience, and impact.
Australia and her transition from the financial sector
Her path demonstrates that success in the field is
to consultancy. “One of the harder elements of
built not only on technical knowledge but on curiosity,
changing industry is learning how to operate in a new
strategic thinking, and the courage to step into
environment, with new people, new goals, new ways
the unknown.
of working, in a new industry and new regulations. A lot of new! One thing I always try to do is embrace the chaos, remind myself I don’t know all the answers
www.linkedin.com/in/fionamartin2023
" Over time, I realised that diverse experiences are an asset in cybersecurity, and my passion for the subject helped me adapt and thrive. Now, as I progress in my career, I hope to support emerging cyber talent in finding their own confidence as they begin their journeys.”
I S S U E 28
WOMEN IN SECURITY MAGAZINE
31
DeArne McWhirter Associate Director KPMG
D
eArne McWhirter’s journey into
Her current work in the banking and financial services
cybersecurity did not begin with a single
sector brings complexity at scale. “Integrating GRC
defining moment, but rather through a
adherence across multiple risk domains and uplifting
series of roles across technology and
enterprise reporting has been complex,” she says.
software enterprises, financial services,
Her approach is grounded in strategic planning,
and banking sectors where M&A transformation,
stakeholder engagement, and the continuous
risk and compliance were always close at hand.
embedding of governance and risk transformation.
“My interest was sparked through early roles in
These challenges strengthened the toolkit she now
financial services, where technology partnering
uses to guide organisations through regulatory and
with business strategy, risk and compliance were
operational pressures.
central,” she reflects. “Over time, this evolved into a deep specialisation in Financial Services Regulation
Despite a career built on expertise and continuous
and Licensing, outsourcing services, Fintech/
growth, DeArne acknowledges that uncertainty
Regtech, cybersecurity, regulatory engagement and
has been part of the journey. “Transitions between
operational resilience across finance, government and
sectors, such as from consulting to government or
consulting sectors.”
fintech, were challenging,” she shares. “I navigated these by upskilling, adapting to regulatory changes,
As her career gained momentum, DeArne made
and aligning my work with emerging cybersecurity
intentional choices to transform that early curiosity
needs.” Those shifts delivered both resilience and
into a clear professional path. “I pursued formal
perspective, shaping a career that grew organically
education and certifications in GRC, Technology,
but always with an underpinning of leadership
information management and cybersecurity” she
and GRC focus. “By joining industry and volunteer
explains, crediting her progression through financial
membership that collaborates in specific research
services and consulting roles with exposing her
and development I have found instrumental support
to M&A transformations, global standards and
in my journey.”
regulations, and digital transformation programs.
32
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
Reflecting on what she might tell her high school self, DeArne emphasises the value of starting early. “Start with foundational IT and risk knowledge, pursue certifications, and seek roles that offer exposure to both technical and regulatory aspects of cybersecurity,” she says. She highlights the joy of constant learning: “There is always something new to review and take into account in the cybersecurity landscape and how the environment is required
“By joining industry and volunteer membership that collaborates in specific research and development I have found instrumental support in my journey.”
to adapt.” Her perspective on education remains grounded
challenges signal growth: “Problems and challenges
in multidisciplinarity. “Always focus on the key
provide us with opportunities to investigate, improve
technology building blocks and top up on specialised
and advise.”
areas you have the most interest in or see the emerging industry need,” she advises. For her, the
Her professional influences span global banking and
combination of risk and compliance frameworks, data
consulting. “Roles in these sectors exposed me to
analytics, tooling, regulatory compliance, and risk
large-scale transformation, executive engagement,
management has proven essential.
and regulatory frameworks,” she explains. She credits exceptional leaders with shaping her strategic
Looking ahead, DeArne anticipates seismic shifts
approach: “I have been very fortunate to work with
across the cybersecurity landscape. “The integration
some incredible founders and forward-thinking CROs
of AI-driven risk management tools will become
that have been mentors of mine.”
increasingly mainstream, enabling faster threat detection and response but also introducing new
Her own development continues, guided by a
complexities in governance and oversight.” She
blend of academic and professional ambition.
also points to quantum computing’s economic and
“I’m continuing my academic journey with a Juris
security implications, noting that regulators must
Doctor and a Bachelor of IT specialising in AI
“find new ways to stress test systems and anticipate
and ICT,” she shares. Earlier studies, including
vulnerabilities in real time.”
an MBA with concentrations in Six Sigma Black Belt, Innovation, and Entrepreneurship, laid the
With acceleration comes risk. “AI-enabled attacks,
foundation. Certifications like CPRM, CRISC, and
particularly those leveraging generative models, will
CCSP have fortified her expertise. Her advice: “Formal
become more sophisticated and harder to detect,”
qualifications provide foundational knowledge, while
she warns. She sees supply chain vulnerabilities
targeted certifications offer agility and relevance in a
and regulatory lag as additional pressure points.
fast-evolving landscape.”
“The intersection of quantum computing, AI, and regulatory complexity will demand a proactive,
The greatest fulfilment in her role comes from
resilient approach, one that prioritises adaptability,
working at the intersection of technology, law, and
collaboration, and continuous learning.”
leadership. “I’m actively involved in research and implementation of emerging technologies particularly
When considering future opportunities, she
AI and quantum computing and their implications
looks beyond salary alone. “I would consider the
for cybersecurity, regulatory compliance, and ethical
organisation’s GRC maturity, leadership support,
governance,” she says. Shaping enterprise-wide GRC
scope for strategic influence, and alignment with
frameworks and influencing board-level governance
regulatory and innovation goals.” For DeArne,
are among her most rewarding responsibilities.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
33
Balancing such a demanding career requires
For those transitioning into cybersecurity, DeArne’s
grounding. “I maintain balance through physical
guidance is encouraging and pragmatic. “Start by
activity and community involvement, such as surf
identifying and leveraging your transferable skills,
lifesaving and competitive ocean paddling,” she says.
particularly in governance, risk management,
Off the water, she is an avid AFL fan. “Having grown
legal compliance and strategic communication.”
up in a non-AFL state and supporting the Sydney
Certifications and short-form courses can help
Swans since 1982, I’ve gone to most games, including
build credibility, and understanding frameworks like
seven grand finals.”
Cybersecurity Risk Institute (KPMG Strategic Partner), NIST and ISO 27001 is essential. “Cybersecurity is
Her days are structured around strategic
no longer just a technical function, it’s a board-level
engagement and risk alignment. “A typical day
priority,” she says. “The most successful transitions
involves coordinating with internal and external
happen when individuals combine their domain
stakeholders, reviewing and refining enterprise-
expertise with a commitment to continuous learning,
wide GRC frameworks, and translating regulatory
collaboration, and ethical leadership.”
developments into actionable practices,” she explains. She stays current through academic research,
DeArne’s journey is a testament to adaptability, vision,
emerging technology insights, and participation in
and the power of weaving together multidisciplinary
industry forums.
expertise. Her career path may have unfolded organically, but her purpose has remained clear: to
Technology remains central to her effectiveness.
strengthen resilience, elevate governance, and guide
“GRC platforms, SIEM tools, data analytics
organisations through the evolving complexities of
technologies, and compliance systems aligned
cybersecurity with integrity and insight.
with standards and regulations (global and local) are pivotal,” she says. She also continues to draw value from professional networks and associations.
www.linkedin.com/in/dearne-m-91903817a
“I gain access to thought leadership, training, and regulatory updates.”
34
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
Want to get matched with Lead Gen experts but dont know where to start?
Our solution experts can help you find the right supplier, Looking to streamline your B2B lead generation process?
Want to use multiple suppliers but dont have time to coordinate? Need a consistent stream of leads coming into the sales team? Looking to tap into new markets? Need end-to-end lead nurture programs?
LET US HELP YOU OVERCOME YOUR LEAD GEN CHALLENGES REACH OUT TODAY FOR AN INSTANT QUOTE. The team at Source2Create has all the necessary skills to get the job done for you, so your time can be reserved to focus on other things.
With:
aby@source2create.com.au charlie@source2create.com.au source2create.com.au
Soledad Antelada Toledano Security Advisor, Office of the CISO, Google Cloud
F
or Soledad Antelada Toledano, Security
“I quit my job, packed my bags, and bought a ticket
Advisor in Google Cloud’s Office of the
to San Francisco in 2010 after enrolling in a Network
CISO, cybersecurity wasn’t a career
Security degree from CCSF,” she recalls. “I invested all
she selected, it was a destination she
my savings into a future I couldn’t even see yet.”
arrived at by relentlessly following her
own curiosity. “I didn’t plan to enter cybersecurity, it
Arriving in the United States stripped her back to the
happened because I kept asking questions no one
essentials. She was learning English and hacking
around me could answer,” she reflects. What began as
simultaneously, translating concepts as fast as she
an instinctive need to understand how systems work
was absorbing them. “I wasn’t just learning how to
and how they fail eventually became the backbone
execute a buffer overflow; I was learning how to say
of her professional purpose. Over more than two
‘buffer overflow’ in English.” The hands-on nature of
decades, she has moved through technical, strategic,
the program was exactly what she craved breaking
and leadership roles, shaping security practices that
things, experimenting, understanding through doing.
are transparent, collaborative, and designed to scale
That intensity paid off when a professor recognised
safely in an increasingly complex world.
her drive and recommended her for an internship at Lawrence Berkeley National Laboratory (LBNL).
The turning point in her career came with a leap that
“I went from learning about networks to defending a
most would have considered impossible. After nearly
network used by Nobel Prize winners,” she says. She
ten years as a software developer in Spain, she felt
became the first woman in the lab’s cybersecurity
boxed in, staring at a career that was comfortable
department, an intimidating milestone that taught her
yet uninspiring. The hacker culture she saw in films
a value she carries today: “Audacity is a security skill.
sparked something deeper, a fascination with the
You have to be willing to ask questions and admit what
unknown world beneath the surface of technology.
you don’t know so you can fix it.”
But access to that world didn’t exist where she was.
36
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
Her journey, however, was not without uncertainty, just not in the way many expect. “There were many challenges along the way but I decided to stop trying to be the ‘smartest’ person in the room and decided to be the most persistent,” she says. That
J O U R N E Y ?
“ Audacity is a security skill. You have to be willing to ask questions and admit what you don’t know so you can fix it.”
persistence became her anchor. Navigating unfamiliar environments, working alongside scientists exploring the origins of the universe, and securing data of global importance required humility and grit. “The
Tomorrow’s cyber leaders will be interdisciplinary
moment I accepted that ‘I don’t know, but I will find
by necessity.
out’ is a perfectly acceptable answer, it helped a lot.” It also reinforced a truth of cybersecurity: nobody
Despite the scale of her work and the high-pressure
knows everything, but everyone must be willing to
environments she has operated in, what fulfills her
keep learning.
most is profoundly grounded. “The most profound source of satisfaction for me is the undeniable impact
Her career path unfolded not through rigid planning
that comes with securing the public sector,” she
but through following her intellectual instincts. “If I
says. “We are safeguarding the critical infrastructure,
had stuck to a rigid plan, I would have limited myself,”
the power grids, water systems, and transportation
she says. What emerged instead was a web of
networks that underpin civil society.” Knowing
roles spanning ethical hacking, penetration testing,
her work helps keep communities safe gives her
vulnerability management, security operations, and
a sense of purpose that transcends job titles or
leading a High-Performance Computing security
technical achievements.
team. She has managed hundreds of incident responses, implemented device security programs,
But sustaining that impact requires balance,
and even led security for a U.S. presidential political
something she had to learn deliberately after years
campaign, an unexpected pivot that demanded both
of high-intensity incident response. “Taking care of
technical depth and strategic resilience. With most
yourself should be a part of the job description for
of her career dedicated to serving or supporting the
every security role,” she insists. Chronic, unspoken
public sector, she remains committed to that mission.
stress is a quiet hazard in the industry. She learned to rest before burnout, to step away without guilt,
Looking ahead, Soledad is clear-eyed about the
and to trust her team through intentional delegation.
forces reshaping cybersecurity. The rapid evolution
“Delegating doesn’t just save you; it empowers
of agentic AI, capable of autonomous reasoning
greater impact.”
and action, will fundamentally transform the speed of defence. Attacks on critical infrastructure water
Soledad’s journey is defined by courage, the courage
systems, power grids, transportation networks will
to uproot her life, to enter rooms where she was the
escalate, pushing governments toward stricter
only woman, to admit what she didn’t know, and to
resilience mandates. And with quantum-resistant
follow curiosity over certainty. Her career stands
cryptography on the horizon, organizations must
as a testament to what happens when persistence
urgently catalogue and protect their cryptographic
becomes a discipline and audacity becomes a tool
assets before adversaries exploit the window of
for change.
vulnerability. These shifts, she believes, demand professionals who understand not just networks but code, policy, human behavior, AI, and data science.
I S S U E 28
www.linkedin.com/in/soledad-antelada-toledano
WOMEN IN SECURITY MAGAZINE
37
Cassandra Mack Chief Information Security Officer (CISO), TensorWave
I
n the world of cybersecurity leadership, few stories
and they tell me a similar story. We’re all working to
capture resilience, reinvention, and unapologetic
get past our imposter syndrome and make a dent in
determination quite like that of Cassandra Mack,
the work we need to do.”
Chief Information Security Officer at TensorWave. Her journey did not begin with firewalls, threat
Transforming this interest into a real career required
hunting, or penetration testing. Instead, she started
grit. Cassandra spent years studying for what she
in risk management and compliance at a time when
describes as the “gold standard” certification failing
“cybersecurity” wasn’t yet a household term.
it four times. Many would have stopped there; Cassandra did not. “I finally figured out that the
Cassandra recalls a defining moment early in her
journey of a thousand miles was the thing I needed
career, when self doubt nearly convinced her that
to get enough confidence to go for my first CISO job,”
transitioning from project management into security
she says. Ironically, once she landed the job, she
was beyond her reach until a mentor pulled her aside.
realised the certification itself wasn’t the key. “I didn’t
“She told me, ‘you’re better than this!’” Cassandra
need the cert. I just needed to realise I had what it
says. “It took me a while to take her words to heart, but I eventually made my way over and haven’t looked back since.” Her early curiosity transformed into something deeper as the field evolved. “I find it more fascinating now that it’s moving and evolving so fast,” she says. And even as a seasoned CISO, she’s quick to acknowledge a universal truth among peers: “Sometimes I think I’m
“ I finally figured out that the journey of a thousand miles was the thing I needed to get enough confidence to go for my first CISO job.”
getting way behind, and then I talk with another CISO
38
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
W H A T ’ S
H E R
J O U R N E Y ?
“ I truly believe the hands-on real-world experience I got made all the difference. Technical expertise helps you speak the language of engineers. There’s a certain level of respect that comes when you can speak their language.”
took to get started and build on my knowledge over
world experience I got made all the difference,”
time. Perseverance is what made the difference.”
she says. “Look for programs with professors who actually work in the field. Technical expertise helps
Like many in the field, Cassandra faced periods
you speak the language of engineers. There’s a certain
of uncertainty none more challenging than the
level of respect that comes when you can speak
moment the calls simply stopped coming. “For the
their language.”
first time, I genuinely doubted if I was still worthy of the ‘CISO’ title,” she says. To support her family, she
Looking ahead, Cassandra sees seismic shifts
took on multiple smaller jobs at once and revived
on the horizon. “AI is going to severely speed up
her consultancy. “It was a grind,” she admits. “But I
implementation, analysis, and actioning of alerts,”
compressed four or five years of experience into two.”
she predicts. “It’s going to make enterprise-level tools affordable for small businesses. But it’s also speeding
That difficult chapter brought an unexpected reward:
up the abilities of the bad guys.” She also warns that
community. “I started getting invited to boards and
quantum computing is nearing the ability to crack
councils, and I eventually became a host for the
modern encryption: “We’re a few years at most away
National and Virtual Cyber Breakfast Clubs,” she
from breaking RSA.”
explains. The experience rebuilt her confidence and expanded her influence. “Sometimes, you have to take
When asked about emerging threats, she points again
a step back to sprint forward.”
to AI-powered attackers. “The bad guys now have more power to do stupid things really fast,” she says.
Her ambition to become a CISO had always been
She also highlights the need for stronger vulnerability
clear even before she knew how to get there. “I’ve
management and the rising importance of cyber
always had my eye on the C-suite,” she says. “I
risk quantification. “It’s a matter of prioritisation and
meandered my way there over time, with a lot of
understanding how to use tools to identify what is
guidance and a lot of monkey-see, monkey-do.”
most important. CRQ will help direct spending where
Training, conferences, and hands-on consulting roles
it’s needed most.”
steadily shaped her into the leader she is today. For CISOs evaluating new roles, she urges caution If she could speak to her high-school self, Cassandra
beyond salary. “You want to look at whether you’re
knows exactly what she’d say: “Your outright belief in
covered under D&O insurance,” she says, pointing to
yourself paid off. It took longer for you to climb the
real-world cases that have devastated executives.
ladder, but that broad skillset helps you every day. I
She’s equally candid about mental health. “Burnout in
have no regrets. I appreciate what it took to get here.”
cyber is real. I developed a bit of a drinking problem myself and successfully sought treatment. My biggest
Education played a major role in that development.
advice: develop healthy coping mechanisms, and seek
Her time at DeVry and Keller Graduate School stands
help if you need it.”
out as formative. “I truly believe the hands-on real-
I S S U E 28
WOMEN IN SECURITY MAGAZINE
39
“ Sometimes you have to take a step back to sprint forward.”
Her typical day spans contracts, questionnaires, tool analysis, vendor conversations, audits, security events, and team development. Strategy and planning remain weekly priorities. “Revisiting budgets is important to gain and keep the top-down support I
Her greatest career influence is her mentor, Dasha
need,” she says.
Davies. “She believed I was better than what I was doing,” Cassandra says. “She encouraged me through
Her most valued tools are those that offer an
failed CISSP attempts, difficult projects, and set a
aggregated organisational view, automate compliance
great example of what an expert should strive to be:
work, or support risk quantification. “Justifying
resilient, always learning, excellent, and humble.”
spending based on real-world scenarios is crucial,” she explains.
Cassandra holds several ISACA certifications, with CISM standing out as the most impactful.
Cassandra stays deeply involved in the industry
In her current role, she finds joy in teamwork and
through ISACA, The Cyber Breakfast Club, The CISO
meaningful progress. “I especially enjoy putting tools
Society, Carnegie Mellon’s Executive CISO Group,
and processes in place that work for the business, not
and ISSA.
just for compliance. And I love when someone brings a security concern to me that means our hard work to
When it comes to the skills shortage, she points to
educate is actually working.”
infrastructure security architects with DevSecOps knowledge as particularly hard to find as well as
To stay balanced, she prioritises reading, friendships,
professionals who can say “yes, and” instead of being
sobriety, time with her children, and travel. “Getting
the classic “Doctor No.”
away and seeing new things really inspires me to do better,” she says.
To career changers, she offers firm but encouraging guidance: “Don’t be scared. Commit and go. You
Professionally, she stays informed through peer
absolutely can do it, but don’t expect it overnight.
Slack groups, industry bulletins, white papers, and
You need a few years, potentially a degree or
an unexpected resource. “Admittedly, I use Google
certifications. You’re not going to transition with a
Gemini on a daily basis,” she says. “It helps me
weekend bootcamp.” She also advocates for strategic
understand how things work and put explanations
mobility: “Keep moving every 18 months if you aren’t
into simple terms.”
getting challenged. It’s ok to move when you’re growing just remember that at senior leadership levels, we want to see staying power.” Cassandra’s journey is a testament to persistence, courage, and the power of taking the long way around. As she says herself, “Sometimes you have to take a step back to sprint forward.” And in her case, every step forward or back has led her exactly where she was always meant to be. www.linkedin.com/in/cassandramack-lasvegas
40
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
EXCLUSIVE
ADVERTISING PACKAGE For the past four years, Source2Create has proudly delivered Women in Security Magazine to the industry free of charge, championing diversity, inclusion, and the incredible contributions of women in cybersecurity. As we continue to grow, we now need partners to help us sustain and expand this vital platform. By supporting this package, you’re not just backing us—you’re investing in the magazine, its community, and the future of women in security. To ensure we can keep delivering this high-value publication, we’re introducing a nominal fee for $900 Ex GST, an exceptional package that provides extensive coverage and visibility.
WHAT'S INCLUDED? OFFICIAL PARTNER RECOGNITION Your logo will be prominently displayed at the beginning of the magazine in our “Partner of the Issue” panel.
GLOBAL AUDIENCE REACH Your brand will be seen by 5,000+ global subscribers through our free, bi-monthly digital publication, dedicated to supporting and showcasing women in security.
2 FULL-PAGE ADVERTS Feature your brand in two issues of your choice between March and December.
2 JOB POSTINGS Advertise up to two job opportunities in the magazine and across our social media platforms, reaching a highly engaged cybersecurity audience.
ONLINE BANNER ROTATION on WomenInSecurityMagazine.com
This high-value package ensures maximum visibility for your brand while directly supporting the continuation of Women in Security Magazine.
Join us in making an impact—partner with us today!
EMAIL JANE@SOURCE2CREATE.COM.AU
CRAIG FORD Craig is an experienced cyber security professional with various qualifications including two master’s degrees. He is the Head Unicorn (co-founder and director) of Cyber Unicorns, in which he acts as a vCISO to clients such as Baidam Solutions, Wesley Mission, PCYC, Hungry Jacks and Ipswich City Council. He was CTO (Chief Technology Officer) for Baidam Solutions between January 2022 to June 2023, where he led the technical services team, helping to build out the internal services capability for Baidam. Craig was QLD chair for AISA for two years until he was appointed to the national board of directors in December 2022.
Simon says “freeze” I am not sure if you all know this game. Many moons
Now, close your eyes and try to imagine a common
ago, when I was in primary school here in Australia,
scenario in the cybersecurity industry.
we would play the game Simon Says. In the game you have someone who is ‘Simon’ who directs all other
You are a new graduate or career changer. You have
players to do things. For example: “Simon says touch
spent years, or maybe, if you have been lucky, just
your nose,” or “Simon says stand on one leg.”
months preparing for your change. You score that elusive position. It could be in GRC, red teaming or
Simon would try to trick people by saying, for example
SOC. You get your foot in the door.
“Touch your toes” without preceding this instruction with “Simon says.” Those who followed such an
Now, Simon says “freeze,” and you do not move
instruction would be kicked out of the game, and
a muscle.
the game would continue in this way until only one person remained.
You have made it, you are in, and it’s very common for people to freeze at this point. They will not change
You are all probably reading this, thinking: “Craig,
path. They will not pivot to another area for 5-10
have you lost your marbles? What has Simon Says
years. They pigeonhole themselves. They will commit,
got to do with cybersecurity or the theme of this
even if they hate the first position they have gained.
edition, Pivot?” I get the reservation. I get the instinct to become that Well, honestly, nothing (shoulder shrug emoji).
statue, I really do. I have been there myself. You get the opportunity you have been working so hard to get,
But, like my article in which I connected cybersecurity
one you have put so much investment into gaining.
to the story of the three little pigs, just because there
You don’t want to do anything to jeopardise your
is no direct link, doesn’t mean I can’t be a little creative
success in any way.
and pull us all in for some entertainment and a bit of nostalgia.
Now, I am going to give you some advice, which you can take or leave. If you get that first job and you don’t
Okay, so my link to Simon Says: I want to draw your
love it, don’t quit. That isn’t the best thing to do. What
attention to one common command or request in
I suggest is: make the most of your opportunity. You
Simon Says, and that is “Simon Says Freeze.” Given
are now on the inside. Things can get easier from this
this command, everyone would have to freeze in the
point. What you need to do in this situation is to make
exact, current, position . (Definitely easier said than
sure you do not pass up opportunities to step outside
done, I can tell you from experience. Especially if you
your lane in the organisation you have joined. Allow
are at a strange angle and you have a few directions
yourself to be seen as someone who will step up to
to trick you without the Simon Says).
the plate and give things a go, to put everything you have into it and learn fast.
42
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
Craig is a published author with three different book series – ‘A Hacker I Am’ cyber education series, ‘Foresight’ is his Cyberpunk/hacker fantasy novel series and then there is ‘The Shadow World’, a co-authored kids cyber education book. He is a freelance cyber security journalist and is a regular columnist with the Women in Security Magazine, as well as a freelance contributor for Cyber Today, Top Cyber News, SecureGov, Careers with STEM and Cyber Australia magazines.
C O L U M N
Then, keep doing that, over and over again. You will
Maybe you do not wear as many hats as I, but do you
gain new skills. You will discover other roles in which
get where I am going with this? Be open to pivoting.
you excel, and can explore to see if pivoting in the
Be open to opportunities as they arise, and don’t be
industry is something you want to do.
afraid to say you don’t like something. Adapt, change your path and keep moving forward.
Being open to pivoting instead of being frozen as in Simon Says, or in the game of Statues (another you
Simon (Craig) says “Go and be amazing. You all have
may have played as a child). You can be flexible and
it in you to break through, to succeed. So go do it.”
find your happy place. I know you might be sitting there thinking: “Craig, that
www.cyberunicorns.com.au
is easier said than done.” Yes, it is. Look at my career. Look at the different things I have done, and still do. I
www.linkedin.com/in/craig-ford-cybersecurity
write. I teach. I have done pentesting and SOC work. I am a CISO. I talk on the stage almost every week. I
www.facebook.com/CyberUnicorns
love the variety and the difference I can make through these diverse activities.
I S S U E 28
www.instagram.com/cyberunicorns.com.au
WOMEN IN SECURITY MAGAZINE
43
INDUSTRY PERSPECTIVES
ADRIANA JONES
PIVOT: TURNING PAIN INTO PURPOSE THROUGH TECHNOLOGY by Adriana Jones, engineer, cybersecurity advocate and founder of The Innocent Souls Project (TISP)
There are moments in life that split you in two: the
This was the turning point that transformed my story
person you were before and the person you become
into a mission to protect children.
after. For me, that moment was created as a result of reality I never chose, but one that set the path I would
FROM ENGINEERING TO CYBERSECURITY: A JOURNEY OF REINVENTION
take for the rest of my life.
My journey began in Guatemala, where in 2016 I
surviving child sexual abuse many years prior. It’s a
became the first woman in my intake to graduate with
46
For years, I wrestled with silence. Then one day, I
a degree in civil engineering. At the time, my focus
decided silence wouldn’t protect me, but speaking up
was on infrastructure; how to design and build safer
might protect someone else. That decision became
environments in the physical world. I didn’t know that
my pivot, the turning point where pain met purpose,
one day I’d be designing systems of a different kind;
and purpose found its voice in technology.
ones that would protect children in the digital world.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
After moving to Australia, I found myself navigating both a new country and a new chapter in my life. I continued to learn and grow, completing advanced diplomas in leadership and ministry (2017–2019) and in project management (2022). These studies helped me build not just technical skills, but resilience, empathy and vision; qualities that would later shape my approach to technology and leadership. In 2024 a major opportunity arrived. I was selected as one of just 34 women across Australia to receive a national cybersecurity scholarship from the Institute of Applied Technology (IAT), an incredible initiative empowering woman to enter and excel in cybersecurity. That scholarship became the doorway to further micro credentials in security management leadership, human aspects of cybersecurity and other fields that aligned perfectly with my growing mission:
What began as a personal mission quickly evolved
to protect children through education, awareness
into a professional ecosystem. I realised that, while
and innovation.
the digital world offers many benefits to humanity, it also exposes the most vulnerable, children, to dangers
I’m now completing my master’s in cybersecurity,
that many adults aren’t equipped to recognise
deepening my expertise and sharpening my ability
or avoid. These range from online grooming,
to lead ethical, practical and people-focused
cyberbullying and exposure to harmful content to
safety technology projects. Each qualification and
cybersecurity threats, data misuse and the growing
scholarship has been a stepping stone, not just in my
issue of AI-generated child sexual material.
career, but in my calling.
BUILDING SAFETY THROUGH EDUCATION AND TECHNOLOGY
THE BIRTH OF THE INNOCENT SOULS PROJECT (TISP)
Under TISP, I developed Cybersafety, a cybersecurity
In 2025, I founded The Innocent Souls Project (TISP),
awareness program tailored specifically for childcare
an initiative born from conviction, innovation and
professionals, educators and parents. Unlike generic
courage. TISP is more than an organisation; it’s a
online safety training, Cybersafety connects three
movement designed to bridge the gap between the
essential pillars: cybersecurity, eSafety and physical
online world and the physical world.
safety, showing how digital threats can quickly translate into real-world risks.
Our mission is simple yet profound: to equip parents, childcare providers, educators and carers with the knowledge and tools to keep children safe in the digital age.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
47
Pro te ct in g O
n re ild ch
nl
in
e
an
do
f fli n
e
WE HAVE ESTABLISHED A NEW STANDARD FOR CHILD PROTECTION THAT INTEGRATES CYBERSECURITY, ESAFETY, AND PHYSICAL SAFETY TRAINING. Contact Us www.theinnocentsoulsproject.com.au
I N D U S T R Y
P E R S P E C T I V E S
The content is concise, practical and continuously
This approach has allowed TISP to engage with
updated to reflect emerging cyber threats and eSafety
students, professionals and government officials,
challenges. Most importantly, it’s accessible We’ve
sparking powerful discussions about how technology,
partnered with a leading cybersecurity awareness
creativity and ethics intersect in child protection. It
platform to make the program compliant, scalable
has also shown that innovation doesn’t have to be
and easy to use across the childcare industry.
cold or corporate; it can be human and heart driven.
In parallel, I began creating free digital books for
THE RIPPLE EFFECT OF PURPOSE
children, written in a way that makes learning about
Since founding TISP I’ve witnessed how one story,
safety approachable and engaging. Every child
when told with authenticity, can inspire many others.
deserves to understand how to protect themselves
I’ve seen survivors find strength in knowing their
online, no matter their background or resources.
voices matter. I’ve seen educators and parents realise
Through storytelling, I’m ensuring no child is left
that cybersecurity isn’t just an IT issue, it’s a child
behind in learning how to stay safe.
safety issue.
LEADING WITH INNOVATION, EMPATHY AND VISION
And I’ve seen professionals from across sectors unite
My leadership philosophy is rooted in one belief:
for good.
around one shared belief: technology can be a force
technology must serve humanity. My call to action is this: let’s continue building a world At TISP our technology strategy is built on three
where technology protects, not harms.
key pillars. Let’s design systems that reflect our values, not only 1.
2. 3.
Protection: ensuring every initiative actively
our capabilities. Let’s ensure that every child grows
safeguards children and empowers adults to
up in a digital world that is safer, smarter and kinder,
become effective first line protectors.
because we made it so. For me, protecting children
Accessibility: making education and awareness
isn’t just a profession, it’s a purpose and the pivot that
tools simple, inclusive, and widely available.
changed my life forever.
Innovation: applying creativity and forwardthinking technology to prevent harm.
These pillars guide every project and partnership we undertake. Whether we’re designing new safety modules or consulting with cybersecurity leaders, our focus is always the same: protect children, empower
au.linkedin.com/company/tisp-the-innocent-souls-project
www.instagram.com/tisp_project
theinnocentsoulsproject.com.au
carers with the right tools, and drive cultural change.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
49
JO STEWART-RATTRAY
PIVOTING WITH PURPOSE: WOMEN REDEFINING LEADERSHIP IN CYBERSECURITY’S NEXT ERA by Jo Stewart-Rattray, Oceania Ambassador, ISACA A pivot isn’t a U-turn. It’s defined as a deliberate
bias (and still do), managed limited representation
realignment to stay balanced while things change
(and still do) and juggled competing demands (and
around you. Over three decades working in technology
still do), all while continuing to advance, advocate
and security, I’ve watched the industry pivot over
for and mentor one another. In the face of these
and over again. We’ve gone from cleaning up after
challenges our ability to adapt became one of our
a virus strike to hunting threats before they appear;
greatest strengths, especially for those of us on the
from defending the perimeter with simple firewalls
frontline during the pandemic, which produced lasting
to questioning every user and device in a zero-
changes to how we work.
trust world. ISACA’s 2025 Tech Workplace and Culture Study
50
Meanwhile, threats have grown more sophisticated.
shows how far we’ve come and how far there is to go.
What began as simple mischief has evolved into
More than a quarter of women surveyed (27 percent)
targeted ransomware and supply chain attacks that
said they faced gender or diversity bias when entering
can bring an organisation to its knees. And, where
the tech industry, compared with just four percent of
defence was once manual and rules-based, we
men. More than one in three women say they have
now use AI-based toolsets to detect anomalies and
experienced gender discrimination at work, a rate four
respond in real time.
times higher than for their male peers.
HOW WOMEN HAVE ALWAYS PIVOTED
These numbers paint a picture that many of us
For women in cybersecurity, the act of pivoting is
already know firsthand. For years, women were
nothing new. Many of us have forged careers in an
discouraged or excluded from STEM pathways,
industry that wasn’t built with us in mind. We’ve faced
denied access to the same resources as men, and
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
left without visible role models in leadership. Even
more accurately and bring broader perspectives to
today, women in tech are more likely to feel isolated,
newer technologies like AI and quantum computing.
to question whether they belong, and to struggle with
Companies that understand these benefits of diverse
re-entry after taking time out of the workforce to raise
teams are tying inclusion to leadership accountability.
the next generation. Pay gaps, long hours and a lack
In my opinion, this has the potential to create long-
of flexibility still drive many talented women to leave
lasting change.
the workforce.
FROM COMPLIANCE TO INFLUENCE A PIVOT IS UNDERWAY
One of the most important pivots we’re seeing in
However, the industry is pivoting, slowly.
the industry is the slow shift from compliance to
Educational institutions now offer more programs for
influence. Boards still ask, “Are we compliant?” and
women and girls in STEM, companies are introducing
rightly so, but the conversation is beginning to
mentorships and leadership pathways, and more
broaden. Increasingly, they’re also asking, “Are we
women are stepping into governance, privacy and risk
resilient?” and “What is the risk of...?”
roles where they can influence policy and culture. The more progressive boards are starting to ISACA’s 2025 Tech Workplace and Culture Study
recognise that resilience requires decisions to be
validates this. It shows 41 percent of employers now
made well before a crisis hits. For example, whether
have programs to hire more women into technology
to pay or not to pay a ransom is a governance
roles, and almost half have initiatives to promote
question that must be settled long before an
women into leadership roles.
attack occurs. Yet, in many organisations, those conversations still haven’t happened. Real leadership
The barriers women face in technology did not
in this space means developing a clear risk appetite,
form overnight, and they won’t disappear without
defining where responsibility sits and ensuring boards
sustained effort. I applaud organisations that realise
understand the implications of their choices before
diverse teams make better decisions, anticipate risk
the pressure is on.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
51
ISACA’s focus on digital trust reflects this
women’s contributions while building pathways for
transformation. It recognises that cybersecurity
the generations to follow. The program connects
cannot be siloed from ethics, privacy, risk
women through mentoring, networking and leadership
and sustainability.
development, equipping women at every stage of their career with confidence and skills.
Pivoting from compliance to influence means translating technical issues into language business
PIVOTING TOWARD PURPOSE
leaders understand. It’s about showing not just how
When I think about my own career, and the many
to manage risk, but why it matters to customers,
women I’ve had the privilege to mentor, the pivots that
investors and the wider community.
mattered most were never just about technology, they were about people and purpose. After decades in this
TECHNOLOGY PIVOTS
field I’ve learnt that the most resilient professionals
AI has been the most profound pivot point of the past
are those who stay true to their values while pursuing
few years. ISACA’s 2025 AI Pulse Poll found that,
their professional goals.
while 81 percent of professionals report AI is already being used in their workplace, only 28 percent of
For women in security, pivoting with purpose means
organisations have a formal AI policy. The speed of
embracing change as an opportunity to shape what
adoption has outpaced the frameworks designed to
comes next, whether that’s by leading, influencing or
keep it safe.
ensuring trust sits at the centre of technology.
This is where the ability to learn quickly becomes a mark of real leadership. ISACA’s Advanced in AI
ABOUT THE AUTHOR
Security Management (AAISM) credential is one
Jo has over 25 years’ experience in the security
way our profession is formalising how we govern AI.
sector. She consults in risk and technology issues
It’s equipping leaders to handle AI-related security
with a particular emphasis on governance and
risk, ensure transparency and make sound ethical
cybersecurity as a director with BRM Advisory.
decisions. For women looking to broaden their
Jo is the Oceania Ambassador for global IT
influence, becoming well versed in AI governance and
professional association, ISACA, and an ISACA
AI-centric security management represents a natural
Hall of Fame inductee. Jo is the former Vice
pathway to do so.
President, Communities of the Australian Computer Society and Ambassador of the
The next pivot will arrive with quantum computing.
National Rural Women’s Coalition. She regularly
The encryption methods that protect our data today
provides strategic advice and consulting to the
may be obsolete tomorrow. Forward-thinking leaders
banking and finance, utilities, healthcare, tertiary
are already scenario-planning for that disruption.
education, retail and government sectors.
PIVOTING THE PIPELINE The industry’s future depends on our ability to pivot
www.linkedin.com/in/jo-stewart-rattray-gaicd-4991a12
the pipeline itself. To attract, retain and uplift a more diverse generation of professionals. Mentoring programs, scholarships and rural outreach initiatives are part of that effort, but so is visibility. When young women see leaders who look like them at the helm of security teams and boards and committees, they see possibility. At ISACA, initiatives such as SheLeadsTech continue to spotlight
52
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
UNLEASHed
? us in jo to y ad re . 26 20 . ne ur bo Mel Step into the spotlight as a champion of Australia’s vibrant, diverse, and resilient security sector. By joining the Australian Women in Security Awards as a sponsor, you’ll be recognised as a leader driving innovation and inclusion—while supporting the remarkable trailblazers shaping cyber, IT, and protective security. Help foster a future where everyone can thrive.
Become a sponsor. Register your interest today! Contact Aby at aby@source2create.com.au womeninsecurityawards.com.au
JOANNE COOPER
SOCIAL MEDIA AGE ASSURANCE FOR CHILDREN UNDER 16: WHAT IT MEANS FOR AUSSIE PARENTS By Joanne Cooper, Founder - ID Exchange
In today’s hyperconnected world children are growing
The trial is being led by the Australian eSafety
up with smartphones in their pockets and social
Commissioner, Julie Inman Grant, and is focused on:
media accounts before they can legally drive. While the internet offers incredible opportunities to learn,
• keeping children safe from online harm.
connect and play it also presents serious risks for
• limiting access to adult or inappropriate content.
our children and teens, especially from online data
• reducing exposure to advertising and profiling.
collection, surveillance and manipulation of young
• ensuring social media platforms comply with
forming minds.
online safety laws.
That’s why the Australian Government’s Age
This is a starting point. More measures need to be
Assurance Technology Trial (AATT) to introduce a
considered to develop powerful, legally recognised
social media ban for children under 16 is a vital step
data rights mechanisms to control how a child’s
forward, and why parents need simple, enforceable
personal data is shared, sold or used in both online
tools to stay in control and protect their children from
and offline systems.
harmful online situations. My firm, ID Exchange, has been working since 2015
WHAT IS THE AUSTRALIAN AGE ASSURANCE TECHNOLOGY TRIAL?
to design and implement simple privacy controls
The Australian Age Assurance Technology Trial is
participating in the AATT to help parents prevent the
part of a world leading national initiative to explore
oversharing of personally identifiable information on
technologies and frameworks to block users below
themselves and their children and enable them to opt
16 years of age from certain online services without
out of unwanted online communications.
and consent mechanisms for parents. We are now
compromising their privacy.
54
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
THE REAL RISK: YOUR CHILD’S DATA
PARENTAL CONSENT: WHAT THE LAW SAYS
Age assurance is about more than limiting access to
Under the Online Safety Act (2021) and upcoming
content; it’s about controlling who can collect data on
reforms to the Australian Privacy Act, organisations
your child, where it goes and how it’s used.
will have stricter obligations to:
I often reflect on attending a primary school
• obtain parental consent before collecting data
cybersecurity session to inform parents on how to protect their children. When the police officer addressing the session asked parents to raise their hand if their child had a personal computer in their bedroom, less than 10 percent did so. This request
from children under 16. • allow for easy opt out from marketing, tracking and data sales features. • provide clearer explanations of what data is being collected and why.
was followed by “raise your hand if your child has a mobile phone.” Now, around 70 percent of parents
But, as a parent, you will need practical tools to make
raised a hand, and the officer said: “If your child
these rights work.
takes that mobile into their bedroom, they have a computer in their safe space bedroom, and a world
That’s why, at ID Exchange, we are in the process
of predators can reach them without your knowledge
of building under 16 child eSafety apps that offer
or awareness.”
the child and the parent automated services with a biometrically verified mechanism that is under
Right now, most platforms:
parental control. We don’t like facial images or other personal information such as the child’s address
• ask for age but don’t verify it.
being used to verify their age. Our aim is to do the
• allow easy opt in for tracking but make opting out
legal and compliance heavy lifting to make this a
very difficult. • profile children’s behaviour to feed them targeted ads.
simpler, auditable and reuseable service for parents and place them in greater, more transparent and use case appropriate control.
• share, or sell, children’s data with third-party advertisers or data brokers. • have gaps in security that predators or bad actors take advantage of.
HOW PARENTAL CONTROLS HELP WITH AGE ASSURANCE Verified parental consent uses the latest in digital identity technologies, including:
Even well-meaning platform operators often fail to provide parental control mechanisms that are verified, easy to use or aligned with Australia’s privacy and safety laws.
• self-governed and private tools to allow you to action and confirm parental or guardian roles. • verifiable credentials to prove your relationship to the minor. • biometric test approaches to validate the age of a child in real-time. • tokenised consent receipts that record your decisions in real time. • Alias linkages for online pseudonyms your child can use. The tools enable you to act with authority, digitally and legally, to control who has access to your child’s
I S S U E 28
WOMEN IN SECURITY MAGAZINE
55
data even when that data is collected in seemingly
Here’s what you can do:
anonymous ways. They also give you the ability to opt out easily with confidence.
• read about eSafety initiatives in your home country to be informed about the changes occurring.
Imagine this scenario: your child signs up for a new
• hold discussions with your children about what
gaming app. You want to ensure their location, usage
they access, what they like and dislike about
habits and chat logs are not being shared or profiled
online services and who/what they regularly
by the company behind the app, or being sold to
interact with.
third parties.
• ask about mental health impacts, issues with sleeping or concentration or online bullying
With better parental controls you can:
at school. • start to monitor and audit your child’s consent
• act as the verified parent or guardian to deactivate the service for the child. • link the child’s account (even if it uses
actions to remove harms. • learn the signs of your child’s behaviour being impacted by their connection to the digital world.
a pseudonym). • send a legal opt out instrument to the platform to block access. • receive proof that the opt out was sent and recorded. • follow up if the platform fails to comply.
YOUR CHILD’S DIGITAL FUTURE STARTS WITH YOU The Australian Age Assurance Technology Trial is gaining pace. However, real protection comes from empowered parents using tools built for the digital age.
These are not preference settings, they are legally mandated options supported by Australian and many
It’s not all bad news. Online connectivity opens a
international privacy laws.
plethora of learning pathways, peer connections and amazing digital experiences. However, taking
PART OF A GLOBAL MOVEMENT
advantage of these requires taking the guesswork out
Australia is not alone in facing these challenges.
of online safety and turning legal rights into simple,
Countries like:
meaningful actions backed by leading partners and technologies.
• the UK with the Age-Appropriate Design Code, • the EU, with the GDPR and Digital Services Act,
SPREAD THE WORD
• the US, through COPPA and the California Privacy
Let’s make the internet safer, smarter and
Rights Act,
fairer together.
are also advancing the protection of children online
If you’re part of a school, youth organisation or
while preserving digital rights.
parenting group, share this article to help other parents take control of their children’s data and
ID Exchange is actively working with regulators, civil
privacy online.
society and technology partners to ensure Australia leads the way in human-centric, family-first digital consent solutions.
www.idexchange.me
WHAT PARENTS CAN DO NOW
www.linkedin.com/in/joanne-cooper-50369734
If you’re a parent or guardian of a child under 16, it’s time to prepare for the shift.
56
W O M E N I N S E C U R I T Y M A G A Z I N E
x.com/idexchange_me
J A N U A RY • F E B R U A RY 2026
LISA VENTURA
THE SEVEN PIVOTS THAT DEFINE A SUCCESSFUL CYBERSECURITY CAREER (AND WHY WOMEN EXCEL AT MAKING THEM) by Lisa Ventura MBE FCIIS, Chief Executive and Founder, Unity Group Solutions Limited/AI and Cyber Security Association
When I look back at my journey into cybersecurity,
I’ve noticed that women often excel at making these
I can’t help but laugh at how unconventional it’s been.
pivots, perhaps because we’re used to navigating
From working in entertainment with Chris Tarrant, the
complex situations and adapting to environments that
first host of Who Wants to be a Millionaire in the UK,
weren’t originally designed for us.
to founding the UK Cyber Security Association/Cyber Security Unity and more recently founding the AI and
In this article I want to share the seven critical
Cyber Security Association and Unity Group Solutions
pivots that define successful cybersecurity careers.
Limited, to receiving an MBE for services to the
These are lessons learnt from my own journey,
industry and being made a Fellow of the Chartered
from the incredible women I’ve met over my years
Institute of Information Security, my career has been
in the cybersecurity industry, and from countless
anything but linear, and I have pivoted so many times.
conversations I’ve had.
And you know what? That’s exactly what makes it valuable.
THE EDUCATION PIVOT: FORMAL VERSUS INFORMAL LEARNING
The truth is, a successful career in cybersecurity isn’t
Let’s start with a truth the industry doesn’t talk about
about following a straight path. It’s about knowing
enough: you don’t need a degree to have a brilliant
when to pivot, how to adapt, and having the courage
career in cybersecurity. I know this because I have
to change direction when needed: something I have
lived it.
had to do on more than one occasion. Over the years
58
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
My original career choice was journalism, and I was
classroom and group settings where I could make
all set to embark on a degree pathway, but for various
notes and do things my own way. Neurodivergent
reasons I was unable to take that path because I
individuals often thrive in informal learning
could not move away from home. Instead, I stayed
environments, so don’t let anyone tell you there’s only
in my hometown and studied for a higher national
one ‘right’ way to learn.
diploma in business and finance. It was equivalent to a first degree, but it wasn’t the education or career pathway I had planned for myself.
THE SPECIALISATION PIVOT: CHOOSING YOUR NICHE Cybersecurity is vast. You’ve got penetration
The education pivot isn’t about choosing between
testing, security architecture, governance, incident
formal and informal learning; it’s about recognising
response, threat intelligence, security operations,
that both have value and knowing when to leverage
cloud security, application security and dozens of
each of them. Formal education provides foundational
other specialisations. When you’re starting out,
knowledge and industry recognition. Certifications
cybersecurity can feel overwhelming.
like CISSP or CISM open doors and demonstrate commitment, but informal learning is where the
The specialisation pivot is about finding your niche
magic happens.
without boxing yourself in permanently. Early in your career, I recommend being a generalist. Learn
It’s the blog posts you read at midnight because
a bit about everything. This foundation is invaluable,
you’re fascinated by a new attack vector. It’s the
because cybersecurity doesn’t happen in silos.
YouTube tutorials, the conversations at security meetups, the hands-on experimentation in your
But, at some point, you need to choose a direction.
home lab. Women often excel at this pivot because
This is where women often hesitate. We’re taught to
we’re used to being self-directed learners. Many of
keep our options open, to be flexible. We worry that
us have had to teach ourselves twice as much to be
specialising will close doors. But here’s the truth:
considered half as competent.
specialisation opens doors. It makes you the go-to person for specific problems. It builds your reputation.
My advice? Start where you are. Don’t let the lack of a specific degree stop you from entering this field. I’ve seen people without degrees excel in the industry and those with degrees in subjects such as psychology, English literature and varied backgrounds become exceptional cybersecurity professionals. What matters is that you never stop learning. The threat landscape evolves daily. Embrace informal learning as a core part of your professional identity. Follow thought leaders, read security blogs, join communities like the Australian Women in Security Network, and attend webinars amongst other things. And always, always stay curious. As someone diagnosed with autism, ADHD, dyspraxia and dyscalculia, I can tell you that traditional classroom settings aren’t always designed for how my brain works best. I always learnt better away from
I S S U E 28
WOMEN IN SECURITY MAGAZINE
59
How do you choose your specialisation? Follow your
Imposter syndrome often strikes hardest when you’re
energy. What aspects of security make you lose track
about to do something important: when you’re being
of time? What problems do you find yourself thinking
considered for a promotion, asked to speak at a
about even when you’re not at work?
conference or offered an exciting opportunity. Your brain, trying to protect you from failure, starts listing
For me, it became clear my strength was in
all the reasons you’re not qualified.
cyberpsychology and the human aspects of cybersecurity, in building communities and in
The confidence pivot happens when you recognise
cybersecurity awareness training, communications
those thoughts for what they are and do the thing
and bringing people together. That specialisation
anyway. Women excel at this pivot because we’ve
led me to found the UK Cyber Security Association/
had practice. We’ve spent our entire careers proving
Cyber Security Unity and, recently, the AI and Cyber
ourselves in spaces that weren’t designed for us.
Security Association and Unity Group Solutions. Eventually, it led me to receive an MBE from King
Here’s my practical advice.
Charles III in 2023 for services to cybersecurity and to diversity, equity, inclusion and belonging (DEIB), and
First, collect evidence. Keep a folder of positive
to being made a Fellow of the Chartered Institute of
feedback and accomplishments. When imposter
Information Security.
syndrome strikes, review this evidence. It’s hard to argue with facts.
Here’s the beautiful thing: a pivot is not permanent. You can pivot again. Maybe you start in penetration
Second, talk about it. Silence gives it power. When we
testing, move into security architecture and
share our doubts, we discover that everyone feels this
eventually into leadership. The skills you develop
way. I’ve had CEOs tell me they feel like impostors.
in one specialisation often transfer to others in surprising ways.
Third, reframe your inner dialogue. Instead of “I don’t know enough to deserve this opportunity,” try “I don’t
Women excel at these pivots, because we tend to
know everything yet, but I’m capable of learning.”
think holistically. We see connections others miss. We understand that technical skills alone aren’t enough.
Fourth, act as if. Sometimes you need to fake
These qualities make us adaptable specialists who
confidence until you feel it. Take that speaking
can pivot when the industry or our interests change.
engagement. Apply for the promotion. Action creates confidence, not the other way around.
THE CONFIDENCE PIVOT: OVERCOMING IMPOSTER SYNDROME
Being openly neurodivergent has taught me
If I had a dollar for every time I’ve felt like an
something important: there’s no single ‘right’ way to
impostor in this industry, I’d be rich enough to retire.
be confident. Confidence doesn’t have to look like
Imposter syndrome is so prevalent among women in
what you see on television. It just has to be authentic
cybersecurity that I co-founded International Imposter
to you.
Syndrome Awareness Day with Nat Schooler and Kim Adele in 2021.
The confidence pivot also means becoming comfortable with not knowing everything. In
The confidence pivot isn’t about eliminating
cybersecurity this is crucial, because none of us can
self-doubt. Instead, it’s about transforming your
know everything. Real confidence includes saying
relationship with imposter syndrome from something
“I don’t know, but I’ll find out,” without feeling like
that paralyses you into something that propels
a failure.
you forward.
60
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
THE LEADERSHIP PIVOT: TECHNICAL TO STRATEGIC
From being technical to being strategic: can be
This pivot is where many brilliant technical
validation. Leadership is messier. Success is harder to
professionals get stuck. They’re exceptional at the
measure. The feedback loop is longer.
challenging because technical skills provide concrete
hands-on work but hesitate when opportunities arise to move into leadership.
But the cybersecurity industry desperately needs more women in leadership. We need diverse
The leadership pivot isn’t about abandoning your
perspectives at the decision-making table. We
technical skills. It’s about leveraging them in service of
need leaders who understand that security is about
bigger goals. It’s about moving from solving problems
protecting people, not just systems.
yourself to empowering others to solve problems. If you’re considering this pivot, start small. Mentor Coming from a non-technical background, I couldn’t
someone. Lead a project. Volunteer to present to
rely on deep technical expertise alone. I had to
senior leadership. Each experience builds your
develop strategic thinking, communication skills and
leadership muscles.
the ability to bring people together. In some ways, not being the most technical person in the room forced me to develop leadership skills earlier.
THE ADVOCACY PIVOT: INDIVIDUAL SUCCESS TO COMMUNITY BUILDING There’s a moment in many a successful career when
Women often excel at this pivot because many of the
you realise your own success is no longer sufficient.
skills required for effective leadership are skills we’ve
This is when the advocacy pivot happens.
been developing our entire lives. Active listening, empathy, seeing multiple perspectives, building
The advocacy pivot is about leveraging your
consensus, creating psychological safety. These
platform and experience to lift others up. It’s about
aren’t ‘soft’ skills, they’re essential leadership skills.
moving from “How do I succeed?” to “How do we all succeed?”
The technical-to-strategic pivot requires several shifts. From individual contributor to team enabler: your success is measured by what your team achieves. From operational focus to strategic vision: instead of “How do we fix this specific vulnerability?” you ask “How do we build a security culture that prevents vulnerabilities?” From technical communication to business communication: you translate security concerns into business language, talking about business risk rather than CVE scores. From knowing all the answers to asking the right questions: leadership is about creating an environment where smart people can do their best work.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
61
The advocacy pivot requires vulnerability. You must share your struggles, not just your successes. You must risk criticism from those who don’t understand why advocacy is necessary. But here’s what I’ve learned: advocacy is one of the most fulfilling pivots you can make. When someone tells you that your story inspired them to enter cybersecurity, when you see a mentee achieve something they didn’t think possible, that impact outlives any individual achievement. Advocacy also keeps you connected to the human side of this industry. We’re not just protecting systems, we’re protecting people, communities and ways of life.
THE RESILIENCE PIVOT: SETBACKS TO COMEBACKS If there’s one pivot I understand deeply, it’s this one. In 2012 and 2013 I experienced some of the darkest I made this pivot when I rebranded the UK Cyber
periods of my life. My marriage ended suddenly in
Security Association as Cyber Security Unity. I’d
2012, and that meant leaving behind the cybersecurity
achieved things I never thought possible, but I kept
software development company my ex-wife and I
seeing the same problems: lack of diversity, women
worked in together. I remarried in April 2012, but I
leaving the industry, talented people being overlooked.
lost my only son, Francesco, who was stillborn at 33
I realised I could either complain or do something
weeks. I had to rebuild my career from scratch. There
about them.
were days when getting out of bed felt impossible.
Women excel at this pivot because we understand
The resilience pivot is about transforming setbacks
what barriers look like. We’ve experienced being the
into comebacks. It’s about finding the strength to
only woman in the room, being interrupted, having our
continue when everything in you wants to give up.
ideas attributed to men. Women often excel at this pivot because we’ve Advocacy takes many forms. It might mean
had to develop resilience just to exist in this
starting or joining organisations like the
industry. We face microaggressions, unconscious
Australian Women in Security Network, speaking
bias and, sometimes, outright discrimination.
publicly about our experiences, mentoring and
These experiences build resilience that gives us
sponsoring others, creating content that amplifies
competitive advantage.
underrepresented voices, or advocating for policy changes organisations.
But resilience isn’t about being invulnerable. The resilience pivot happens when you acknowledge the
When I decided to be openly neurodivergent in a
pain, learn from the experience and choose to move
professional context, it wasn’t easy. But I knew
forward anyway.
visibility mattered. Every time someone like me
62
succeeds and talks about it, it makes the path slightly
Resilience in practice means accepting that failure
easier for the next person.
is part of growth. The best penetration testers fail
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
hundreds of times before finding the vulnerability. It
The legacy pivot requires shifting from short-term to
means building a support network, because I couldn’t
long-term thinking. It means making decisions that
have survived my darkest periods alone. It means
might not benefit you directly but will benefit others in
finding meaning in suffering. I channelled my grief
the future.
into creating Frankie’s Legacy, supporting parents who’ve experienced pregnancy loss.
For me, this pivot meant focusing on diversity, inclusion, and supporting neurodivergent people
It means taking care of your mental health. As a
in cybersecurity. When I’m no longer active in the
qualified mental health first aider, I’m passionate
industry, I want to know I helped make it more
about normalising mental health support in
accessible and welcoming.
cybersecurity. Burnout is endemic in this field. Resilience means recognising when you need help,
The legacy pivot also changes how you measure
and seeking it without shame.
success. Instead of “What did I achieve?” you ask “What did I enable others to achieve?” This doesn’t
It means maintaining perspective. When you’re in the
mean you stop caring about your own career
middle of a crisis, you feel the world is ending. The
development, but it adds a dimension that makes
resilience pivot helps you see this as one chapter in a
your career more meaningful.
longer story. The cybersecurity industry needs resilient
WHY WOMEN EXCEL AT MAKING THESE PIVOTS
professionals because the work is hard. You’re
We excel not because we’re inherently better at
constantly fighting adversaries, dealing with high-
adapting, but because we’ve had to be. Every woman
stress situations and tight deadlines. But every
in cybersecurity has had to navigate an industry that
time you make this pivot, your sense of self, your
wasn’t designed with us in mind.
values and your commitment to your purpose become stronger.
These challenges have made us exceptionally good at pivoting. We’re used to reading situations, adapting
THE LEGACY PIVOT: CAREER TO LASTING IMPACT
our approach and finding creative solutions. We’re
The final pivot is when you start thinking beyond
had role models. We’re used to building communities
your own career and asking: what impact will I
because we’ve often felt isolated.
used to learning on the job because we haven’t always
leave behind? But these skills aren’t just valuable for our own Legacy in cybersecurity takes many forms. It might
careers; they’re exactly what the cybersecurity
be the people you’ve mentored who become leaders
industry needs. We need professionals who can pivot
themselves. It might be the organisations you’ve
quickly as the threat landscape evolves. We need
founded that continue serving the community. It
leaders who can adapt their communication. We
might be the policies you’ve implemented, the content
need advocates who understand that diversity makes
you’ve created or the culture you’ve helped shape.
us stronger.
Women excel at this pivot because we often think
Women don’t excel at these pivots despite the
in terms of relationships and impact rather than
challenges we face. We excel at them because of the
just individual achievement. We understand that
challenges we face.
real success is about the difference we make in people’s lives.
MAKING YOUR OWN PIVOTS If you’re wondering where you are in your own pivot journey, here’s my advice.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
63
First, recognise that pivots are normal. A successful
LISA ON SOCIAL MEDIA
career isn’t a straight line. Don’t judge yourself for pivoting. Celebrate it as evidence that you’re growing.
www.lisaventura.co.uk
Second, give yourself permission to pivot. Your
@cybergeekgirl
career belongs to you. www.linkedin.com/in/lisasventura/
Third, seek support. Every pivot is easier with people who believe in you. Join communities like
www.facebook.com/lisasventurauk
the Australian Women in Security Network or Cyber Security Unity.
www.instagram.com/lsventurauk
Fourth, be patient with yourself. Pivots take time.
bsky.app/profile/cybergeekgirl.bsky.social
Trust the process. You can find examples of the talks she done Fifth, remember why you’re here. Reconnect with
previously and of interviews, panel discussions and
that purpose when pivots feel difficult.
moderating/chairing events on her YouTube channel here https://www.youtube.com/@CyberSecurityLisa/
THE JOURNEY CONTINUES I’m still making pivots in my own career. The difference now is that I recognise pivots for what they
ABOUT LISA VENTURA MBE FCIIS
are. They are not signs of failure or indecision, but
Lisa Ventura MBE FCIIS is an award-winning
evidence of a dynamic, evolving career. Every pivot
cybersecurity specialist, published writer/author,
I’ve made has added something valuable to who I
journalist and keynote speaker. She is the chief
am and what I can offer. Your pivots will do the same
executive and founder of Unity Group Solutions
for you.
Limited and of the AI and Cyber Security Association, a membership body and trade
The cybersecurity industry needs you. It needs your
association set up as the global voice of AI and
unique perspective, your skills, your resilience and
cybersecurity and to promote the safe, secure,
your ability to pivot and adapt. Don’t let anyone tell
responsible and ethical use of AI. In addition,
you your unconventional path is a weakness. It’s your
she is the founder of Cyber Security Unity, Neuro
greatest strength.
Unity and AI Unity.
What I want to leave you with is this: make the pivots.
As a consultant Lisa also provides cybersecurity
Take the risks. Change direction when needed. Build
awareness and culture change training along
your career on your own terms. And when you’ve
with neurodiversity in the workplace training,
made your pivots and found your success, reach
and works with cybersecurity leadership teams
back and help the next woman make hers. That’s how
to help them collaborate more effectively. She
we change this industry: one pivot, one person, one
has specialist knowledge in the intersection
success at a time.
of AI and cybersecurity, the human factors of cybersecurity/social engineering, cyber
64
The journey is long, but you don’t have to take it alone.
psychology, neurodiversity and in diversity, equity,
We’re building this future together and I, for one, can’t
belonging and inclusion (DEIB). More information
wait to see where your pivots take you.
about Lisa can be found on www.lisaventura.co.uk.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
MARINA TOAILOA
EMOTIONAL INTELLIGENCE IN SECURITY: THE SHIFT FROM PHYSICAL PRESENCE TO PSYCHOLOGICAL AWARENESS By Marina Toailoa, Founder- Mummy Safety Security Project Security incidents are rarely just physical. They
to assess emotional cues, maintain composure and
are human events driven by stress, fear, anger
communicate empathy under pressure. The most
and confusion. Whether it’s an altercation, a
successful responders are trained not only to act fast
medical emergency or an act of aggression, how
but to have emotional awareness of the event.
a responder reads and manages emotions can determine the difference between de-escalation and
Emotional intelligence is the ability to recognise,
disaster. If responders focus only on procedures and
understand and manage one’s own emotions while
not people they risk missing critical emotional cues
influencing the emotions of others.
that could indicate an imminent escalation of the situation. Emotional intelligence allows responders to recognise those cues and adjust their approach. For instance, lowering their tone, giving space or showing empathy to help calm and stabilise others. In the past, the focus was on command presence: appearing to be in control, assertive and ready to act. While that remains important, today’s environment demands something deeper: the ability
66
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
IN PHYSICAL SECURITY, EMOTIONAL INTELLIGENCE TRANSLATES INTO FIVE ESSENTIAL COMPETENCIES.
In essence, emotional intelligence doesn’t replace
1.
Self-awareness: recognising one’s emotional
Emotional intelligence enhances a responder’s ability
triggers and physiological responses
to listen actively, speak clearly and build rapport
under stress.
quickly, even in tense moments.
2.
4.
in an incident often matters as much as what is said.
Self-regulation: maintaining control over one’s Motivation: remaining mission-focused even in
TRAINING FOR THE MIND AS WELL AS THE MUSCLE
emotionally charged environments.
To embed emotional intelligence in physical security
Empathy: understanding the perspectives and
operations, organisations must invest in developing it
emotions of others, including victims, aggressors
intentionally. This means:
impulses to avoid escalating a tense situation. 3.
tactical ability, it amplifies it. How something is said
and bystanders. 5.
Social skills: communicating clearly, calmly and respectfully to de-escalate tension.
• integrating emotional intelligence into incident response training, not just soft-skills workshops. • using scenario-based learning to simulate high-
Each of these skills contributes directly to operational
stress emotional environments.
outcomes. A guard who can detect fear or confusion
• encouraging reflection and feedback after every
early can tailor their approach, reducing the likelihood
incident - not just on what happened, but on how
of physical confrontation. A supervisor who models
people felt.
calm emotional control helps set the tone for an entire
• recognising and rewarding calm, empathetic
team’s response. Empathy doesn’t make a responder
responses as much as quick or forceful ones.
weak; it makes them effective. It creates cooperation instead of resistance.
The future of security training isn’t about replacing toughness: it’s about redefining it. True strength lies in
THE REAL-WORLD IMPACT OF EMOTIONALLY INTELLIGENT RESPONSES
composure, understanding, connection and the ability to turn chaos into calm.
Consider two security officers responding to an agitated individual in a lobby. The first relies on
Emotional intelligence represents the evolution
physical authority, using a raised voice and physical
of physical security from reactive enforcement to
posturing to assert control. The second takes
proactive, human-centred protection. In a world where
a moment to assess the situation, noticing the
every incident involves emotion the smartest and
individual’s shaking hands and rapid breathing. They
safest responders are those who can manage their
speak slowly, maintain distance and acknowledge the
own emotions while understanding others, and those
person’s distress. The result? The first scenario risks
who do not take things personally.
escalation. The second opens the door to rapport building, de-escalation and resolution.
Because, at the end of the day, security isn’t just about keeping people safe; it’s about keeping people whole,
EMOTIONALLY INTELLIGENT RESPONDERS CAN:
emotionally, physically and psychologically. In short, embrace your human side as a strength.
• de-escalate volatile situations faster and with fewer physical interventions. • build trust with the public and with stakeholders.
www.linkedin.com/in/mia-azar-toailoa-66259511a
• reduce legal and reputational risk to their organisation.
www.instagram.com/mummysafetysecurityproject
• improve team cohesion and morale through emotional modelling.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
67
RYAN FOX
BUILDING AN INCLUSIVE CYBER CLUB PLAYBOOK AND PITFALLS By Ryan Fox, Security Engineer When I arrived at university I imagined the campus
to make friends and build essential industry skills
would be loud, collaborative and curious. In reality, it
in cybersecurity.
felt quiet and fragmented. I loved cybersecurity, but
68
the spaces around me didn’t feel designed for learning
THE HARD NUMBERS
out loud, or for making friends. So, I started the
Our Discord group launched in October 2024 with
Deakin University Cybersecurity Association (DUCA)
10 members and grew month by month, reaching
to build the community I wished I’d found: a place
750+ by November 13, 2025 (see graph below).
where people could be themselves, learn together
That’s an average of ~60 new members per month.
and belong. My one line mission today is simple:
We’re now formalising a retention baseline, tracking
give people the supportive environment they need
30/60/90 day engagement and trimester renewals so
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
we can publish a clear renewal percentage after our
judgement space where new students step out,
December cycle. Early signals are strong: members
learn, and feel supported in the environment we
are coming back for second and third events,
wished we had and building it has been incredible.”
and many are transitioning from being members
• Sham: “DUCA exists so belonging isn’t accidental:
to being on the committee, some even taking on
we design events and communication to remove
leadership tasks.
friction so people can connect and grow; that intentionality powers the community, and seeing
WHO BELONGS, AND HOW WE INCLUDE
people realise they belong keeps me going.”
Diversity is a series of design choices. Thirty three
• Paige: “Partnerships, diverse panels, empowering
percent of our members identify as women or non-
women-presenting committee members, and
binary, and approximately 60 percent are international
ongoing care across learning, collaboration,
students. Because not everyone can attend in
and support—via education, mentorship, and
person—Deakin has students across multiple
CTFs—drive our diversity and build an inclusive,
campuses and countries—we record or pre-record
representative club where everyone feels valued
learning content so no one has to miss out. We also
and grows.”
make our session materials available in advance,
• Kat: “Empowering diverse voices, DUCA
add captions to recordings and keep Q&A logs so
shapes cybersecurity’s future and values
quieter voices are heard. We track opt-in identity
every perspective; that first step opens doors,
data and simple post-event feedback to make our
confidence to speak helps us grow, and its
events increasingly welcoming. Policies reflect our
inclusive, transformative support shows every
inclusiveness with a zero tolerance for any anti-
voice matters.”
social behaviour online or in-person. All these design
• Chloe: “As someone outside cybersecurity, I’ve
choices shape an environment where students from
never felt out of place at DUCA; openness and
diverse backgrounds feel comfortable, and we act
support let you show up as you are and grow
when they give us feedback.
academically and personally, and diversity isn’t a checkbox—you feel it in how people welcome,
THE FEMALE MAJORITY EXECUTIVE TEAM
include, and lift each other.”
I’m grateful to lead alongside Chloe Fok, Sham with their consent). Roles adjust as we grow, but this
WHAT WORKED: FIVE REPEATABLE PROGRAMS
leadership core sets the tone: empathetic, organised
1.
Polavarapu, Paige Haines and Kat Ho (named here
Rotating roster (what/why/how). We run a four-
and unafraid to experiment. Short quotes from the
week cycle: pentesting lab, cyber theory, industry
team we’ll confirm before publication:
guest, beginner-friendly CTF. All these were made by students, for students. This cycle serves
• Ashley: “DUCA is more than cybersecurity it’s
mixed skill levels and avoids fatigue. A shared
community, connection, and growth: a no-
template (agenda, assets, comms copy) makes
I S S U E 28
WOMEN IN SECURITY MAGAZINE
69
2.
it easy to rinse and repeat. If you’d like a copy of
cochair was a surprise and a responsibility. ACUCyS
our materials, feel free to reach out.
connects 15+ universities, giving us a platform to
Majority interactive sessions. Our rule of thumb
share playbooks, cohost CTFs and lift inclusion
is one third talk, two thirds doing. A session
standards across campuses.
could be a live Q&A with a guest, a step-by-step micro challenge. Interactivity raises confidence
A 90-DAY PLAYBOOK YOU CAN RUN ANYWHERE
and retention.
1.
exploit walkthrough, or pairing up to solve a
3.
coffee chats with students from outside your
vary speakers, backgrounds, roles and journeys
immediate circle. Define two or three personas
so students meet many versions of “what
you’re serving (eg, absolute beginner, switcher,
success looks like.” We keep a rotating shortlist and an outreach script so we don’t over invite the 4.
deep diver). 2.
Ship a starter series (Weeks 3-6). Four
same voices.
events: pentest lab, theory talk, industry AMA,
Celebrations that close the loop. End of
beginner CTF. Publish the slides, code and recap
trimester socials, tiny awards and highlight posts give the community a sense of momentum.
5.
Listen (Weeks 1-2). Short survey plus three
Industry invitations with equity. We intentionally
each week. 3.
Make it interactive by default (Weeks 3-12).
Celebrating effort (not just results) keeps
Add a ‘do together’ segment to every session and
volunteers energised.
a take home artifact (a tiny writeup, a report or
Food and beverages. It sounds simple, but shared meals change the room. We budget per
a checklist). 4.
Recruit and support (Weeks 4-10). Fill explicit
head, label dietary options and use “structured
roles, events, ops, comms, partnerships. Use
mingle” prompts so people leave with at least
one shared task board and a 20 minute weekly
three new names.
standup to keep momentum. 5.
Celebrate and iterate (Weeks 11-12). Close
PITFALLS, AND HOW WE COURSE CORRECTED
the loop with a social, thanks to speakers and
• Burnout. Passionate students often overcommit
sponsors, tiny awards and a public post that
or get placed away from their strengths. We
invites the next cohort.
added role-fit check-ins, capped concurrent responsibilities and created mandatory rest
LET’S CONNECT
windows around exams. The goal: protect
If you believe DUCA can help you, or if you’d simply
people first.
like to chat, we’d love to hear from you. We care
• Rejecting rather than adopting ideas. Early on,
deeply about this community. We’re happy to
we were quick to say “No” to rough ideas. Now we
help however we can: sharing resources, running
say, “Yes, if…” and codesign small pilots. Treating
a workshop, connecting mentors or co-hosting
ideas as drafts has unlocked more ownership and
something fun. And if you have opportunities,
better programs.
speaking spots, sponsorships, internships or joint
• Under-management. With too few executives, subcommittees stalled. We introduced clear
events, we’re excited to collaborate. Let’s build the bridge together.
scopes, sub-team leads and a weekly 20 minute standup to unblock quickly. Lightweight structure
ryanfox0005@gmail.com
beats heroic effort. www.linkedin.com/in/ryanrfox-cybersecurity
PARTNERSHIPS AND BRIDGES Joining the Australian Council of University Cyber
duca.au
www.instagram.com/deakincyber
Societies (ACUCyS) was a dream. Being elected
70
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
INTERESTED IN WORKING TOGETHER? Contact Aby Aby@source2create.com.au www.source2create.com.au
MEDIA
CONTENT
EVENTS
ADVERTISING
CUSTOM AS-A-SERVICE
JAY HIRA
SHRUTI KAMATH
ERIN CARROLL
AI AND DATA: PROTECTING WHAT POWERS US by Jay Hira, Cyber Director – Financial Services, KPMG Shruti Kamath, Consultant, Business Resilience, KPMG Erin Carroll, Consultant, Business Resilience and Cyber Risk, KPMG
There’s a special kind of energy at the start of a
and opportunities to innovate. But with speed comes
journey. We all remember standing on a platform
risk. The value of AI is dependent on the quality and
at dawn, the city still quiet, watching the first train
security of the data underpinning it.
of the day glide into the station. Around us, people gather, some eager, some anxious, all with their own
We have seen what happens when governance is
destinations in mind. As the train doors open, we step
overlooked. Data breaches, regulatory penalties and
aboard together, trusting the tracks ahead to carry
reputational damage are no longer distant threats.
us safely.
They become real, and they can derail us in moments. The lesson is clear: we must build our foundations
In many ways, this is precisely how we find ourselves
with care.
with AI and data. The technology is undeniably
72
powerful, and the possibilities vast. We’re all building
We often hear data called ‘the new oil’. But data is
those modern data lakes, brimming with potential,
more like passengers in high-speed trains: volumes
and the excitement is real. Yet, as we prepare to set
are growing, and movement is at an astonishing
off, we must pause and consider whether the tracks
speed. AI amplifies both the benefits and the dangers
beneath are ready to carry us at speed. If they are
of ever increasing data volumes. Yes, high quality
misaligned, neglected or left unsecured, the train will
data helps us understand our customers, improve our
not reach its destination safely. In our world, those
services and drive growth, but, on the flip side, low-
tracks are data governance.
quality data exposes us to risk.
AI is the engine driving us forward, and we are
Data is both an asset and a liability. It powers our
accelerating. We see opportunities everywhere.
businesses, but it also brings risk. Protecting it is not
Data lakes offer us new insights, better decisions
just a technical challenge, it is a shared responsibility.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
We would never leave the train doors open nor allow anyone to tamper with the tracks. We must safeguard our data with the same care.
BUILDING THE TRACKS: THREE PILLARS OF DATA GOVERNANCE Good governance is like a well-designed rail network. It ensures that every part of our organisation receives
" Data is both an asset and a liability. It powers our businesses, but it also brings risk. Protecting it is not just a technical challenge, it is a shared responsibility."
what it needs, safely and reliably, as we move together toward our destination. Our governance framework rests on three strong pillars; just as a
2. Quality and integrity
train relies on its engine, tracks and crew to keep the
Reliable data forms the foundation of sound
journey smooth and secure.
decisions, and clean data ensures fewer errors and smoother processes. It helps us build trust with
1. Ownership and accountability
our stakeholders and unlocks the full potential
When we know who is responsible for each data
of analytics and AI.
asset we act with confidence. Clear roles reduce confusion and prevent mistakes. Accountability builds
3. Security and compliance
trust with our customers, those inside and outside
Security is our digital lock and alarm, protecting our
our organisation. When responsibilities are mapped,
valuable assets with access controls, encryption
everyone knows where they fit, allowing all to move in
and monitoring. Compliance is not optional; it is the
the same direction. This collective clarity enables us
framework that guides us to manage data responsibly
to achieve collective wins.
and that protects us from unnecessary fines. We must regularly review and improve our compliance practices, because technology and regulations constantly change.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
73
• Clear policies for data access and use. It’s critical
" By making governance the train that unites our efforts, we move from ambiguity to clarity, ensuring our AI journey is effective, responsible and tailored to our needs."
to know who can access what, and why. • Controls for prompts and outputs. These prevent misuse and allow for monitoring of results. • Continuous monitoring and review. AI is in no way a set-and-forget solution, and monitoring is thus non-negotiable. • Transparency and explainability. We must ensure decisions are auditable and understandable, although not necessarily in that order. Keeping these guardrails in mind, we acknowledge that true success isn’t measured solely by our arrival
FACING THE CHALLENGES: THE GOVERNANCE GAP
at the destination, but by the care, integrity and
Many organisations focus on the AI engine and
Our stations along our journey include:
vigilance we demonstrate throughout the journey.
overlook the train itself: the governance that carries everything forward. Without clear governance as
• Accurate, consistent and complete data.
our foundation, AI models can easily veer off track,
• Compliance with laws and standards, with neither
delivering unsafe or unintended outcomes. Just as a
penalties nor breaches.
train needs sturdy rails to stay on course, we require
• Effective risk management and mitigation.
robust measures for data quality, input prompts,
• Trust from stakeholders, built on transparency
output controls and ongoing monitoring. Risk
and ethics.
management is not just the job of a single team; it’s a
• Streamlined processes and reduced inefficiencies.
shared responsibility for everyone on board.
• Authorised access to the right data at the right time.
We’ve all witnessed the consequences when policies and procedures are unclear. Having rules is not sufficient; the entire crew must know them, understand them and follow them. By making governance the train that unites our efforts, we move from ambiguity to clarity, ensuring our AI journey is effective, responsible and tailored to our needs.
STAYING ON TRACK: GUARDRAILS FOR SUCCESS Just as a train relies on sturdy rails to travel safely so must we establish practical safeguards to ensure our progress remains steady and secure. These safeguards include: • Standards for data quality: well defined and enforced. After all, low-quality data leads to low-quality outcomes.
74
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
I N D U S T R Y
P E R S P E C T I V E S
• Governance that supports our strategic goals.
the weight of our ambitions. We have set clear
• Regular reviews and improvements.
guardrails to keep us on course, empowered our
• Clear metrics and reporting on performance.
teams to act with integrity and fostered a culture where ethics and accountability are as important as
If our safeguards are our guardrails and our measures
performance. Each checkpoint station—ownership,
of success the stations, then governance is the
quality, security and transparency—has ensured we
train that carries us forward, uniting our customs,
do not just move quickly, but move wisely.
accountability and leadership as we journey together toward responsible and resilient AI. Governance is
But the journey does not end at the first destination.
more than just a set of technical controls, it is the
The landscape ahead will continue to shift, with
culture that shapes how we travel together. True
new technologies, regulations and risks emerging
progress relies on accountability and leadership
on the horizon. To remain resilient we must commit
at every level, empowering our teams to question,
to ongoing maintenance, regularly reviewing our
challenge and continuously improve our practices.
practices, learning from each experience and adapting
By fostering an environment where ethics and
our governance to meet tomorrow’s challenges. This
integrity are valued as highly as performance we
means investing in our people, strengthening our
ensure our journey remains not only efficient but also
processes and keeping our values at the heart of
principled and resilient.
every decision.
REACHING THE DESTINATION: A RESPONSIBLE AND RESILIENT AI FOR THE FUTURE
Ultimately, the true measure of success is not
As our train slows and we approach the end of this
our customers and our communities. By making
journey it’s worth reflecting on what has brought us
governance the train that carries us, we ensure our
here safely. Every successful arrival is the result of
AI journey is not only fast and innovative, but also
careful planning, shared vigilance and a steadfast
responsible, ethical and repeatable.
how well we achieve our goals but the confidence and trust we build along the way; with our teams,
commitment to doing things right. The speed and innovation of AI may be our engine, but it is governance—the train itself—that carries us forward,
www.linkedin.com/in/jayhira
keeping us aligned, secure and resilient.
www.linkedin.com/in/shruti-kamath
Throughout our journey we have relied on strong
www.linkedin.com/in/erinlouisecarroll
tracks—our data governance framework—to support
" To remain resilient we must commit to ongoing maintenance, regularly reviewing our practices, learning from each experience and adapting our governance to meet tomorrow’s challenges. This means investing in our people, strengthening our processes and keeping our values at the heart of every decision."
I S S U E 28
WOMEN IN SECURITY MAGAZINE
75
KAREN STEPHENS Karen Stephens is the co-founder and CEO of BCyber. After more than 25 years in financial services, Karen moved into SME cybersecurity risk management. She works with SMEs to protect and grow their businesses by demystifying the technical aspects of cybersecurity and helping them to identify and address cybersecurity and governance risk gaps. She was recently named inaugural Female Cyber Leader of the Year at the 2023 CyberSecurity Connect Awards in Canberra.
C O L U M N
The ‘pivot’ secrets you didn’t know Well. My Spidey senses must be working overtime,
KNOCK IMPOSTOR SYNDROME ON ITS HEAD.
because my last article touched on how important
Don’t underestimate the value of your background.
change has been for our company, and now I find
My former career focused on risk management,
myself once again revisiting my career pivot.
compliance and business development for small and medium enterprises. Cybersecurity intersects with all
I first wrote about my move from financial services
these fields, yet it often gets pushed aside. Hint: good
into cybersecurity in this very magazine way back in
cyber resilience isn’t just about the ‘tech’; it’s about
2021. The experiences of Covid lockdown and home
business risk as a whole.
schooling were still too fresh a memory to laugh about, and we were a fledgling company. My, how the
ZERO TRUST.
pivot has been pivoting.
We need to blame my financial services GRC background for this one. We all know what zero
Before launching into my learnings, I need you to keep
trust means in the tech sense, but in cyber risk
in mind one overarching theme: that the pivot itself
management you should “go beyond the tech” and
is not a linear process, it is more a wild ‘three steps
expand the usual definition to incorporate evidence
forward two steps back followed by a twirl around’
of what is really in place. Don’t trust something is in
process. But, that is why we pivot. You can say many
place, being actioned or configured, have evidence to
things about my pivot into cyber risk management
substantiate it. Hint: just saying something is in place
work, but that it is boring is not one of them.
doesn’t always make it so. A ‘snapshot’ as evidence is a start, but nothing beats regular ongoing monitoring
So, what are my key learnings all these years later?
and supervision.
BE THE TRANSLATOR.
GOD IS IN THE DETAILS.
It doesn’t sound like a biggie, but, trust me, it is.
The movies would have us believe that cyber risk
I came from financial services where terms are
management is all about hunting down bad guys
standardised (sometimes even dictated by law), and I
from darkened rooms while surviving on chips and
found this not to be the case in cyber. For example, in
energy drinks. Perhaps, for a few, it is. While flashy
finance, an assessment and an audit are significantly
ransomware breaches may grab attention, it’s the
different, but in my new world, these terms are used
basics that truly matter. Think of them as your ticket
interchangeably. They shouldn’t be. This was a bit
to playing the game of cyber resilience. Hint: the
of a shock. My suggestion: have your stakeholders
basics aren’t sexy, but they are the proverbial ‘pay to
describe what they want to achieve when scoping
play’ in cyber resilience, eg good password hygiene (for
work rather than, for example, assuming terms are
everyone), patching (for everything), cyber education
being used in their purest sense. Hint: the ‘tech’ and
(for all) and MFA (where possible). These are a good
the ‘business’ people may use the same terms, but
start, but not an end game on the cyber resilience road.
they may not carry identical meanings.
76
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
BAD NEWS BEAR.
promotion). I’ve found everyone I’ve encountered to
And, yes, I have been called that. Sometimes in cyber
be incredibly generous with their insights and time.
risk management you have to deliver news that is bad
The challenge often lies in having the courage to ask
or unpalatable. Once again, blame it on my financial
for help.
services GRC background, but I hold a firm belief that, if you know about a gap or vulnerability you need to
So, go and be bold. Give cyber a whirl!
raise it ASAP. After all, when an ‘unknown’ becomes ‘known’ a business can actively choose to either
And may 2026 bring you and yours only peace, joy
address it, mitigate it or accept it. If you don’t raise it,
and happiness.
you take away their agency to make a decision. Hint: it’s the hidden surprises—the unknown unknowns—that can truly catch you off guard and ‘bite you on the butt’.
www.linkedin.com/in/karen-stephens-bcyber
Transitioning into cyber risk management is daunting
www.bcyber.com.au
x.com/bcyber2
karen@bcyber.com.au
youtube.bcyber.com.au/2mux
but having a mentor and joining supportive groups like the AWSN, Insurtech Australia, the RegTech Association, ISACA and the like has made a world of difference for me (and note this is not a paid
I S S U E 28
WOMEN IN SECURITY MAGAZINE
77
CAREER PERSPECTIVES
RAJANI ARJULA
JAY HIRA
THE FSD RISK: ACCOUNTABILITY FOR THE AUTONOMOUS WORKFORCE by Rajani Arjula, Director, Cyber Delivery at Anchoram Jay Hira, Cyber Director – Financial Services, KPMG
There is a rhythm to the early morning. I find it
technical question; it is about trust, responsibility
grounding to step outside as the city stirs, watching
and leadership.
the first cars on the road. The streetlights are still on. The air is fresh. I often pause to take in the
THE PARADOX OF DIGITAL IDENTITY
predictability of human action. For decades there was
Our old security playbooks were built for a world
comfort in knowing a human was at the wheel on
of static roles and human pace. They assumed a
those cars, adhering to a clear set of rules. We trusted
predictable human user. With agentic AI, the ‘user’ is a
that driver.
machine. The gap in accountability is wide.
Now, that predictability is changing; on the road and
• Actions happen at machine speed. No human can
in the digital world. On the road we have full selfdriving (FSD) and, in the digital world, its equivalent:
keep up. • The ‘confused deputy hazard’ is real. Imagine
Agentic AI. These systems plan, decide and act on
an agent needing to access a simple database.
their own. and, like self-driving cars, learn and improve
If the backend system is configured with broad
with every journey. They deliver faster services
privileges the agent can do far more than
and smarter operations in banking, healthcare and
intended; not by design, but because the trust
government. The transformation is real.
boundaries were never clear.
But, as we hand over more control, a question sits
When things go wrong, the accountability lands on us.
with every leader: if the car is driving itself, how
Even if an autonomous agent took the action, it is our
do we guarantee control, and who is accountable
name on the line.
when the route goes wrong? This is not just a
80
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
C A R E E R
P E R S P E C T I V E S
THE UNSEEN COST OF LOST CONTROL
2. The principle of least privilege
We are seeing more AI project failures. Often, the
Agents must be given only the minimum access
cause is not poor technology, but poor governance.
needed for the task: no master keys for routine jobs.
The cost of a single flawed decision from an unaccountable agent is not just a technical glitch, it is
3. Dynamic trust, earned not assumed
a direct threat to our revenue and reputation.
Trust must be earned, not given. Future systems should incorporate trust scores that reflect policy
When an autonomous system encounters a blind
adherence. Permissions must be dynamic. If an agent
spot it exposes sensitive data or triggers cascading
acts out of character, its access must be restricted
failures in seconds. This erodes the very trust we
immediately.
have worked so hard to build with our customers and stakeholders. The risk is material, and the cost
4. Continuous oversight and response
of remediation far outweighs the investment in
Periodic audits are not sufficient. Oversight must
proactive governance.
be continuous and at machine speed. We need rapid response systems ready to revoke access or
BUILDING TRUST BY DESIGN
shut down an agent within seconds if its behaviour
We cannot treat identity as an afterthought. We
is unexpected.
must build it in from the start. Trust by design means establishing human accountability and turning risk
THE JOURNEY IS OURS TO SHAPE
into a strategic advantage. Here is how we earn trust
Agentic AI offers immense benefits. But every gain
in a machine-dominant world.
comes with the need for greater control. This is a strategic and cultural shift. It demands collaboration
1. Unique identity and ownership
across teams. If we are proactive and embed a
Every AI agent must have a unique digital identity
security model rooted in accountability and dynamic
similar to every car having a licence plate. This
control, our AI agents can become the most trusted
ensures traceability. A human owner must be
members of our digital workforce.
responsible for the agent’s behaviour and lifecycle. When I finish my walk, the city is fully awake. The roads are busy. The flow of traffic depends on shared vigilance and clear road rules. Our digital infrastructure is no different. The future is autonomous, but leadership is not. We must be the captains of trust, defining the rules and ensuring every autonomous action can be traced back to human responsibility. The future is autonomous. But trust still depends on access, identity and unwavering human accountability. www.linkedin.com/in/rajani-arjula
www.linkedin.com/in/jayhira
I S S U E 28
WOMEN IN SECURITY MAGAZINE
81
POOJA SHIMPI
GETTING INTO CYBERSECURITY WITH NO EXPERIENCE by Pooja Shimpi, Cybersecurity GRC Lead | AI Governance | Global Council for Responsible AI Ambassador for Australia
If there’s one question I hear more than any other,
Cybersecurity is not reserved for a chosen few. It
it’s this: “How can I get into cybersecurity if I have no
is accessible, learnable and full of opportunities for
experience?” And every time, my answer is the same:
beginners. Here’s what I’ve learnt from coaching
experience isn’t where you start, curiosity is.
people who successfully broke into the field without experience, and here’s what you can learn from
Cybersecurity has a reputation for being intimidating:
their journeys.
a field full of technical geniuses, complex tools, cryptic jargon and job descriptions that seem to have
YOU DON’T NEED TO BE TECHNICAL TO START
been written for superheroes. But, if you look closely
The biggest misconception is that cybersecurity
at the people working in this industry today, you’ll
requires deep technical skills from day one. It doesn’t.
notice a very different reality.
Cybersecurity is an ecosystem with 30+ career paths, and many don’t require you to code, configure
Many of them did not start in cybersecurity. Some
firewalls or analyse malware.
began in IT or operations, some in customer service, some in law, HR, finance, accounting or marketing.
Some of the most beginner-friendly areas include:
Some were career changers. Some felt completely lost in the beginning, yet they made it.
• governance, risk and compliance (GRC). • privacy.
82
I’ve personally mentored and guided several people
• cyber awareness and training.
who had no security background yet who, today, are
• security policy and documentation.
thriving security professionals. Not because they
• vendor risk management.
knew everything, but because they were willing to
• project security coordination.
learn, ask questions and take the next step.
• controls assurance and audit.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
C A R E E R
P E R S P E C T I V E S
These roles rely more on communication, logical
Once you understand the why, the how
thinking, curiosity, documentation, understanding
becomes easier. Cybersecurity isn’t about memorising
processes and analysing scenarios than on
tools, it’s about understanding behaviour, patterns
technical skills. You can build technical depth later,
and risk.
but these do not have to be your starting point. Your background isn’t an obstacle. It’s often your
One mentee described her breakthrough perfectly:
competitive advantage.
“I spent months trying to memorise technical details, getting more confused daily. Then I started reading
UNDERSTANDING CONCEPTS MATTERS MORE THAN TOOLS
about actual breaches: what happened, why it
When people start learning cybersecurity they often
everything connected.”
mattered, how it could have been prevented. Suddenly
think they need to master every tool, every framework, every attack type. But the truth is much simpler: you need only a solid conceptual foundation. When I mentor beginners, the first things I ask them to understand are: • what cyber risk actually means. • why organisations are targeted. • how breaches happen. • what security controls do. • the basics of frameworks like ISO 27001 or NIST CSF. • that the difference between threats, vulnerabilities, and risks matters. • essential concepts like encryption, authentication
" The biggest misconception is that cybersecurity requires deep technical skills from day one. It doesn’t. Cybersecurity is an ecosystem with 30+ career paths, and many don’t require you to code, configure firewalls or analyse malware."
and access control is more valuable.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
83
THE SKILLS YOU ALREADY HAVE ARE MORE VALUABLE THAN YOU THINK
given you something cybersecurity will always need:
One of the most powerful moments in mentoring is
background is relevant; it’s whether you can articulate
when someone realises their past experience isn’t
how it translates to security work.
transferable skills. The question isn’t whether your
irrelevant, it’s valuable. I’ve seen this repeatedly and I have guided:
START SMALL: BUILD MICRO-SKILLS AND MICRO-WINS I tell every mentee: “Start where you are. Use what
• a project manager who moved into governance, risk and compliance (GRC) because stakeholder
you have. Learn one thing at a time.” Small wins build confidence, and confidence builds momentum.
communication, documentation and structured thinking were already part of his daily routine.
Here are practical, beginner-friendly steps:
• a business analyst who shifted into security governance because she had experience mapping processes, identifying gaps and translating technical issues into business language. • a software tester (non-security) who transitioned
or blogs. • complete a beginner course on security fundamentals.
into application security because testing, breaking
• write a short summary of what you learnt.
things and thinking like an adversary were already
• practice conducting a cyber risk assessment for a
natural strengths. • an accountant who moved to assurance because controls, audits, checklists and compliance were already familiar concepts.
84
• learn basic cyber concepts through short videos
fictional small business. • try one hands-on lab from learning platforms like TryHackMe. • document your practice in a simple portfolio.
Cybersecurity is not only about technology, it’s
These ’micro-wins’ might feel small but employers
fundamentally about people, behaviour, risk,
notice initiative. They prove your mindset, not just
processes and decision-making. Your past career has
your skillset.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
C A R E E R
P E R S P E C T I V E S
more prepared than you think. Don’t wait for 100
" Small wins build confidence, and confidence builds momentum."
percent readiness. Many ‘required’ skills are actually preferences. Employers often value candidates with the right attitude and potential over those that check every box.
THE HUMAN SIDE OF STARTING FROM ZERO One mentee spent three months documenting in
Every mentee I’ve supported felt uncertain at the
simple blog posts everything he had learnt, never
beginning, until one small moment when something
expecting anyone to read them. When he started
finally clicked: a concept made sense, a vulnerability
applying for jobs those posts became tangible proof
scan became clearer, a framework felt logical, or a
of his seriousness and ability to explain complex
security interview went better than expected.
topics clearly. Multiple interviewers specifically mentioned his blog as a deciding factor in hiring him.
That moment changes everything. It’s the point where “I don’t know where to start” becomes “I can actually
NETWORKING OPENS MORE DOORS THAN CERTIFICATIONS
do this.” And if they could reach that moment, so can anyone reading this.
Certifications are helpful, but they are not the first ticket into cybersecurity, social skills are.
YES, YOU CAN START WITH ZERO EXPERIENCE
Every mentee I’ve worked with who transitioned
If you’re starting with no experience, remember:
successfully had these things in common. They connected with the cybersecurity community.
• you do not need a technical background.
They attended meetups.
• you do not need every certification.
They asked questions.
• you do not need permission.
They reached out to professionals.
• you do not need to know everything.
They joined discussions. They showed curiosity.
What you do need is:
In return, they received tips, referrals, guidance,
• curiosity.
confidence, opportunities and job leads. Cybersecurity
• consistency.
is a welcoming space because everyone remembers
• community.
what it felt like to start.
• confidence in your transferable skills. • willingness to learn.
When beginners take the initiative to show up, they get more support than they expect.
Cybersecurity has space for you: not ‘someday’, not when you’re ‘ready’, but starting today. The path won’t
YOU DON’T NEED PERMISSION TO BEGIN
be perfectly linear and you’ll encounter discomfort
Many aspiring professionals wait for ‘the perfect
along the way. But thousands of people before you
moment’ or ‘the perfect role or ‘the perfect skillset’
have walked this exact path and succeeded.
before applying for their first job. But the reality is that no one enters cybersecurity fully prepared. Not
Start learning. Start connecting. Start applying. The
even experienced professionals. The field evolves too
cybersecurity community is waiting for you, and your
quickly for anyone to feel ‘complete’.
unique perspective is exactly what the field needs.
If you understand the basics, have curiosity and
www.linkedin.com/in/poojashimpi
can communicate your strengths you are already
I S S U E 28
WOMEN IN SECURITY MAGAZINE
85
MADHURI NANDI Madhuri Nandi, Head of Security at Nuvei, AWSN Board Chair, Author of Cyber Smart book Madhuri is a cybersecurity leader with nearly 20 years of experience in cybersecurity across strategy, governance, risk, compliance, product and engineering. She holds a master’s degree in cybersecurity and serves as head of security at Nuvei and as chair of the AWSN Board. Madhuri is the author of the Cyber Smart book and creator of a cybersecurity awareness framework. She is known for her strong voice on inclusive leadership, mentorship and community building.
C O L U M N
Pivot: the shift from reacting to anticipating There’s a moment in every career when you realise
knew them. What it taught me was people. Clients
you’re no longer just ‘doing work’. You are carrying the
would talk for 30 minutes about a problem and only
weight of decisions. People look at you before you
at minute 31 tell me the thing that actually mattered.
even say anything. And sometimes, if you are honest,
I learnt to listen to the silences, to the politics, to the
you feel as if you are still catching up to the version of
way decisions really get made.
you everyone else sees. One client asked me, “Your report is great. But what My own pivot wasn’t a single lightning moment. It was
I actually need is for my CEO to understand the
a slow accumulation of discomforts, small wins and
human impact. Can you do that?” It was the first
those conversations that stay with you long after the
time I realised cyber is 50 percent controls and 50
meeting ends.
percent conversation.
WHEN YOUR SKILLS NO LONGER MATCH YOUR AMBITION
THE NEXT PIVOT: ENGINEERING AND PRODUCT
I started out hands-on, very hands-on; the kind of
Engineering taught me patience: that ‘fixing’ things
work where your day ends when logs stop shouting
is easy. Aligning teams? That’s a different world.
at you and alerts calm down. I loved that world: the
Product management taught me to think like the
clarity, the rush, the technical puzzles, the feeling that
business, not the security team. When you manage
I had ‘fixed’ something.
a product, you can’t hide behind ‘best practice’. You have to justify decisions with dollars, time, customer
Then something subtle started happening. People
impact and trade-offs.
stopped asking me how the attack happened. They started asking me questions like: “What does this
I remember sitting in a room with architects, arguing
mean for us?” “How do we stop this from happening
passionately for the control we absolutely needed.
again?” “Can you brief the CIO in 10 minutes?” It felt
One of them said, “Can you tell me what the business
as if I was being quietly pushed from the engine
case is in one sentence?” I froze, not because I
room onto the command deck. And I wasn’t ready. Or,
didn’t know the answer, but because I wasn’t used
maybe, I didn’t think I was.
to summarising information in such a way. That day changed the way I communicate. I stopped talking
86
THE FIRST MINI PIVOT: CONSULTING
about controls. I began discussing risk appetite, trust
Consulting didn’t teach me frameworks. I already
and growth.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
THE LEADERSHIP PIVOT: WHEN REACTING ISN’T ENOUGH
WHAT I WISH I KNEW EARLIER Here’s some truths no one told me.
Leadership comes gradually, then suddenly. You go from being the one doing the work to the one
1.
You don’t pivot once. You pivot constantly. Every
unblocking others, to the one people look to during a
new role, new program, new crisis and new team
crisis expecting calm, clarity and confidence. No one
is a pivot.
prepares you for that moment. Especially when you’re
2.
thinking, “I’m worried too.” I learnt that leaders don’t remove fear; they help the room breathe through it.
The higher you go, the fewer answers matter and the more alignment matters.
3.
Your technical confidence gets you into the room; your emotional intelligence keeps
And this is where anticipation enters. Leadership isn’t
you there.
“We fixed today’s problem.” It’s “What could tomorrow
4.
Strategy is not a document; it’s a way of thinking.
look like?” “How do I prepare my team emotionally,
5.
You can be decisive and still human. You can be
not just technically?” “How do we build resilience, not
strong and still vulnerable.
just maturity?”
WHY ANTICIPATION MATTERS NOW One of the most defining lessons for me was realising
Cybersecurity is moving faster than ever, but
that emotional intelligence is not a ‘soft’ skill but a
leadership hasn’t always kept pace. We don’t need
strategic skill: the kind that turns a team from reactive
more heroes running into fires. We need leaders
to proactive.
building cities that don’t ignite so easily.
THE REAL PIVOT: ANTICIPATION AS A MUSCLE
The future of cyber isn’t just tools and frameworks.
When you’ve lived in SOCs, consulting rooms,
It’s leaders who understand people, culture,
engineering floors and boardrooms, you start seeing
psychology and trust; leaders who can sense the
patterns. You anticipate tension before it escalates.
shift’; leaders who can pivot again and again. Maybe
You anticipate a breach pattern before the attacker
that’s the secret. Every pivot we make moves us
shifts. You anticipate burnout before your team
slightly closer to who we’re meant to become.
burns out. www.linkedin.com/in/madhurinandi
Anticipation isn’t fortune-telling. It’s experience plus empathy plus pattern recognition. It’s saying, “I’ve seen this movie before, but this time, I’m not just reacting to the plot twist.”
I S S U E 28
WOMEN IN SECURITY MAGAZINE
87
STUDENT IN SECURITY SPOTLIGHT
Given my background, and my passion for people, my ideal role would be a leadership position in the threat intelligence space. A role wherein I will be PAIGE HAINES
able to proactively identify and analyse potential threats before they impact our society. I’m especially motivated by my desire to protect vulnerable
Paige Haines is currently pursuing a Bachelor of Cyber Security at Deakin University. Bachelor of Cyber Security student at Deakin University.
members of our society, who often face the biggest risk from threat actors. In addition, I am someone who thrives on strategy, and pursuing a leadership role allows me to guide decisions and help shape effective mitigation strategies, further protecting my community.
In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest? When speaking to those who are not within the field,
When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?
I often take an anecdote based approach, where I
My decision to pursue cyber security didn’t come
discuss how threats in the field relate to threats that
from a single moment, but was rather shaped by a
the person may experience in their day to day life,
series of different experiences that slowly connected
such as the decision to drive somewhere and take
over time. I grew up surrounded by computers and
the risk of an accident, or going to the grocery store
90s game consoles as my parents loved collecting
at the end of the day and taking the risk that they
retro technology from their childhood. Being around
may have run out of roast chickens.
tech always felt very natural to me. After graduating high school in 2018, I spent a few years working
Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?
full-time while trying to figure out what I truly
When I was first entering the industry, one of the
entire identity stolen after falling victim to a phishing
biggest misconceptions I thought was that cyber
attack. I remember watching her bank accounts get
security had to be an incredibly technical field and I
drained, as she frantically spent hours on the phone
was ready to hone my skills in a specialised area. It
with multiple companies trying to recover anything
came as a surprise when I realised that it was still
she could. It was honestly heartbreaking that
very human-centric, and I could transfer a lot of the
something like this could happen to someone that I
skills I developed in my marketing career into cyber
worked with, someone who I was close with.
cared about. During this time, a close colleague of mine had her
security. I attribute a lot of my success to leaning into this aspect of cyber security and it has led to some
Not long after, I took a role at a technology company
fantastic industry connections.
in their marketing department. I was an avid gamer, and so this role was a lovely mixture of my love for
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?
90
W O M E N I N S E C U R I T Y M A G A Z I N E
gaming and new technologies, as well as my love for writing. When I was later made redundant from this role, I suddenly found a space to pause and
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
think deeply about my future. In these four months,
and the potential of future use of AI in risk
I reflected on all those moments, and I constantly
management”. This was an incredible experience as
returned to technology, and my desire to help people.
it aligned perfectly with a goal I had set for myself.
Cyber security felt like such a natural fit for me. It was this moment that I decided to take a leap of
At the start of 2025, I promised myself that I would
faith and apply to the Bachelor of Cyber Security at
complete a speaking engagement before graduating
Deakin University as a mature-age student, finally
in 2026. Being able to achieve this goal at the end of
ready to pursue the field that brought all of the above
2025, a full 12 months ahead of schedule, made this
experiences together.
moment so significant to me. I was able to speak on a topic I am very passionate about, and accomplish a
Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations.
career goal much earlier than anticipated.
network for all the opportunities I have been afforded
Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?
in my time as a student and as a professional in the
As part of my degree, I am currently undertaking
field. From my first trimester, I was determined to
an internship as a Cyber Security Analyst at
grow into the person I had always wanted to be, and
CAPA Intelligence. I work closely with the critical
carve out my own space in a new industry. Through
infrastructure sector, specifically in electricity. In
social anxiety and imposter syndrome, I had a feeling
this role, I have learned so much relating to industry
that this new chapter was made for me, and I was
tools, and domain knowledge that is an extension of
resolute in trying out a different approach.
my course.
I made a commitment to put myself out there at
Security Australia (WiCyS). It is within these spaces
The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?
that I have met so many incredibly driven individuals,
I have pursued many certifications, as these are
where I have formed friendships and connections
offered to high-achieving students in my degree. So
that have continued to support me both personally
far, I have obtained the Certified Secure Computer
and professionally. In my goal to embrace every
User (C|SCU) from EC-Council, and the
opportunity to connect with others, I attribute
Certified in Cyber Security (CC)
much of my success to the constant support and
from ISC2, which is one I
generosity of these individuals.
pursued personally, outside
I could never fully express how thankful I am to my
as many events as possible. I actively engaged in communities such as the Australian Women in Security Network (AWSN), and Women in Cyber
of study. Given my interest
Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.
in threat intelligence, I was
Thus far, the most memorable event I have been
Forensic Investigator (C|HFI)
involved in was my recent contribution to the IEEE
from EC-Council which was a
Conference on Engineering Informatics. I was invited
certificate I was committed to
to join a panel discussing “Cyber risk quantification
obtaining. I am currently studying
I S S U E 28
able to have the opportunity to obtain the Computer Hacking
WOMEN IN SECURITY MAGAZINE
91
PAIGE HAINES
in your field of interest, and it is for this reason that
Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?
I have decided to pursue threat intelligence and
For me, the most challenging aspect of my own
forensic investigations-related certifications.
cyber security journey is balancing my current casual
for this certification, with an intended completion date of February 2026. I am a firm believer in choosing certifications that will open opportunities
role with my full-time studies as time management
What aspect of your cybersecurity studies excites you the most, and why?
can become quite complicated. To manage this,
The hands-on labs are the most memorable part of
sleep, as I found this has an extreme impact on
the course, and there are plenty of units that offer the
my ability to take on work and my productivity.
opportunity to develop skills in industry-related tools
By prioritising my overall health, I was then able
and investigation techniques which mirror real-world
to tackle both commitments without jeopardising
techniques closely. As I move into my third year of
my wellbeing.
I ensured that I was getting enough exercise, and
study, the units are becoming much more aligned with specialised cyber skills including malware analysis, and ethical hacking.
Conversely, which aspect of your studies do you find least interesting or useful, and how do you navigate through it?
Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus? There are so many fantastic niches within the cyber security industry, and I would love to see
I am not much of a coder, so many of the coding-
more people-centric units that go beyond simple
based units, particularly those involving C(++, #).
governance. In the future, I would love to see an
I really enjoyed utilising Python for my machine
entire governance, risk, and compliance unit, as I
learning units, as I found the language a bit more
have found I do quite a lot of compliance work in
intuitive and more aligned with my style of work!
my current role, and feel that I could have benefitted from a structured unit exploring these topics.
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why? Communication is such an integral part of any job role, and given most IT and cyber security students are largely introverted, I do genuinely believe they could benefit drastically from a unit that dives into management, and interpersonal skills between employees of all different levels. Developing skills in translating more complex reports into a format that highlights business value over content is something that I think could benefit a lot of specialised cyber employees in the future.
92
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
What is your preferred source for staying informed about cybersecurity trends and general information?
S P O T L I G H T
with random companies if it is not needed. These proactive actions have allowed me to remain aware of new threats.
In my field, staying up to date is absolutely essential,
great for getting quick insights into threats that are
Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider?
actively unfolding in the wild. Because I work within
I would not make any changes to my trajectory,
the operational technology space, I also make a point
as I am incredibly proud of the things I have
of checking blogs from companies like Forescout
achieved thus far. I believe that I have achieved
and Dragos. Their updates help me stay connected
a lot despite only having just finished my second
to what’s happening in the OT world and ensure I’m
year of university, and I am eager to maintain this
always learning something new.
momentum even when I finish my degree. The
so I lean on a mix of reliable sources to keep my knowledge sharp. I regularly read the TLDR newsletter and follow the ACSC data feed. They’re
connections and knowledge that I have gained
Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.
throughout these last two years has been nothing short of life changing. instagram.com/bit.blondie
My experience in cyber security has been largely driven by my own enthusiasm and curiosity and I have found that the community, for the most part,
www.linkedin.com/in/paigehai
has been incredibly welcoming and supportive of newcomers and my peers. While there will always be occasional moments wherein my knowledge or dedication is underestimated, I try not to let these moments define what my journey looks like. Over time, I have realised that my consistent effort and passion speaks very loudly, and they have opened doors for me to collaborate within the community. I prefer to let my work, and the results of my dedication, speak for themselves.
What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? I have set up biometric authentication on almost every device and account I have to better my security posture. From my previous experiences, I have also learnt the importance of having conversations about cyber security with my family and friends to ensure they are taking it seriously as well. In addition, I often minimise the amount of personal data I share
I S S U E 28
WOMEN IN SECURITY MAGAZINE
93
PRAJOTI RANE
Prajoti Rane, a determined and inquisitive Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI) Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI)
When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? Initially, my parents were very concerned. Their understanding of cybersecurity came from movies and social media, where hackers were portrayed negatively, so they thought what I was doing might be illegal. To change that perception, I started writing blogs that explained cybersecurity concepts in the simplest way possible. They didn’t read all of them, but over time, they realised that my work was about protecting cyberspace, not breaking it. Today, they
Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?
actively educate friends and family about online
My interest in cybersecurity started in a very real and my father’s credit card was hacked. Fortunately,
Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.
multi-factor authentication saved him from what
One of the most memorable moments was attending
could have been a serious financial loss but that
a regional CTF hackathon alone. Everyone else was
moment lit a spark in me. I became determined to
in groups, and I felt intimidated and almost cried.
understand how these attacks happened and how
But I pushed through, competed solo, and finished
people could protect themselves.
strong. That experience taught me resilience and
unexpected way during the COVID lockdown, when
safety and are extremely vigilant, something that makes me proud.
self-belief qualities that continue to guide me in For the next six months, I threw myself into learning
this field.
everything I could. I even found myself pretending
hacker,” but I was naive and still building my skills.
Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?
Even so, every small breakthrough felt huge and
I have had the privilege of completing three
pushed me to keep going.
internships, each of which was a turning point in my
to be male in online forums because, as a woman, I wasn’t taken seriously and was often dismissed or mocked. At the time, I had this dream of being a “cool
career. These experiences taught me things I couldn’t
94
Now, after several internships and plenty of hands-
learn academically, such as working with SIEM tools
on experience, my mindset has changed completely.
and approaching problems calmly and strategically.
I’m no longer drawn to hacking out of curiosity; I’m
Most importantly, they improved my communication
focused on defending, protecting, and helping others
skills. For example, during my time at Agropur, an
stay safe. Looking back, I’m genuinely proud of how
elderly employee struggled with MFA and visited
far I’ve come and how much I’ve grown since those
my desk daily to complain. One day, I explained
early days.
MFA using a simple door analogy, and he finally
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
understood. After that, he never came back with
To overcome this, I created a structured approach: I
complaints. That moment reinforced how critical
dedicate specific blocks of time for labs and projects,
clear communication is in cybersecurity.
and then allocate separate time for certification prep. For example, I built a home lab using VirtualBox and
The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?
Kali Linux to practice penetration testing and network
One of the biggest challenges I face is balancing
you can do; certifications show what you know. Both
hands-on projects with certifications. In
matter, but hands-on experience has taught me to
cybersecurity, there’s no single roadmap; some
think critically and troubleshoot under pressure skills
people swear by certifications, while others
that no exam can fully replicate.
monitoring. These projects gave me confidence to explain concepts during interviews, which I believe is more impactful than just listing certifications. My philosophy is simple: projects demonstrate what
emphasize practical experience. Early on, I felt torn preparing for exams like Security+, CEH, or CISSP.
What aspect of your cybersecurity studies excites you the most, and why?
Certifications are important because they validate
What excites me most is the problem-solving aspect.
your knowledge and help you stand out in the job
Cybersecurity often feels like working through a
market, but they don’t always reflect real-world
complex puzzle every vulnerability is a clue, and
problem-solving skills.
every solution strengthens the system. I enjoy the
between spending time building home labs and
I S S U E 28
WOMEN IN SECURITY MAGAZINE
95
PRAJOTI RANE
challenge of thinking critically and creatively to stay
application vulnerabilities and how they handled
ahead of threats. It’s rewarding to know that the
them. Listening to their real-world stories gave me a
work I do has a real impact on protecting people and
perspective I could never get from a textbook.
organisations, which makes every solved problem feel meaningful.
I also take part in Capture the Flag (CTF) competitions and online communities. I’ll admit, I
Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus?
was pretty intimidated at first, but pushing through
My coursework is heavily focused on web security,
discovered on my own.
that fear really paid off. These experiences have sharpened my problem solving skills and introduced me to so many tools and techniques I wouldn’t have
which is important, but I believe network security deserves more emphasis. While some consider
But beyond the technical side, being part of this
networking old-fashioned, the reality is that nearly
community has boosted my confidence. It’s
75% of cyberattacks still occur through network
incredibly inspiring to meet people who share the
vulnerabilities. Networking is foundational; it’s the
same passion and to learn from their journeys. Some
backbone of cybersecurity. You can’t truly secure
of these connections even turned into mentorship
systems without understanding how networks
opportunities, which helped me make better career
operate. Because of this gap, I’ve had to pivot toward
decisions and focus on what truly excites me
certifications and hands-on projects to strengthen
in cybersecurity.
my networking knowledge.
Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience? Yes, I love being involved in the
Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences. Absolutely, and unfortunately, it’s been a recurring theme. In group projects, I’ve often been overlooked
cybersecurity community. I try to
by professors directing technical questions to my
attend as many meetups and
male teammates while ignoring me, even when I
conferences as I can,
contributed significantly. One memorable instance
especially around
was during a presentation where the professor asked
Boston, where
my male teammates a question about our project.
the tech scene
They struggled to answer, and I had to step in and
is incredibly lively
explain the solution. That moment was bittersweet; it
and welcoming.
proved my competence but also highlighted the bias.
These events have
96
helped me grow in
Early in my journey, I faced even harsher challenges
ways I never expected.
online. During CTF competitions, once participants
I still remember attending
discovered I was a woman, I became a target for
a local OWASP chapter
ridicule. It affected my confidence so much that I
meeting where experts
pretended to be male for six months just to learn
broke down real web
in peace. Looking back, that was a survival tactic,
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
but it also fueled my determination. Today, I’ve built
by revisiting core concepts like network security,
enough skills and confidence to demand respect
incident response, and cloud security, and practicing
for my work. My response to discrimination has
hands-on scenarios in my home lab.
always been to outperform expectations. I believe representation matters, and I want to be part of the
I’ve also learned that interviews aren’t just about
change that makes cybersecurity more inclusive.
technical skills, they test your ability to think under pressure and communicate clearly. For example,
What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape?
one interviewer asked me to explain MFA to a
I take my personal cybersecurity very seriously; it’s
That experience taught me that cybersecurity
second nature now. I never share live updates or my
professionals must bridge the gap between
location on social media; if I post, it’s after I’ve left the
technical complexity and user understanding. While
place. This habit started after a frightening incident
I’m nervous about the upcoming job search, I’m
in high school when a stalker tracked me through
confident that my mix of technical skills, practical
an Instagram post and followed me home. That
experience, and communication ability will help me
experience taught me how dangerous oversharing
stand out.
non-technical person, which reminded me of the elderly employee I helped during my internship.
can be. Today, I use multi-factor authentication (MFA) on
www.linkedin.com/in/prajoti-rane
every account that supports it, strong and unique passwords managed through a secure password manager, and I regularly monitor my digital footprint. I also avoid connecting to public Wi-Fi without a VPN and keep my devices encrypted. Beyond protecting myself, I educate friends and family about these practices because cybersecurity awareness is often the weakest link. For me, security isn’t just professional, it’s personal.
Have you actively sought employment opportunities in the cybersecurity field, and if so, what has been your experience with the application and interview process? Currently, I’m interning, but I’ll soon start applying for full-time roles. Honestly, the job market is daunting. Cybersecurity is competitive, and while demand is high, employers often seek candidates with years of experience. My past internship interviews were mostly situational focused on problem-solving and communication, but full-time roles demand deeper technical expertise. I’m preparing for that
I S S U E 28
WOMEN IN SECURITY MAGAZINE
97
learning, constantly adapting, constantly solving new mysteries. So when I talk about cybersecurity casually, I frame it as the modern-day version of TANVI BADGHARE
both a detective’s work and an architect’s vision: you investigate, you design, and you protect. And for me, that combination makes it one of the most exciting careers anyone can step into.
Tanvi Badghare is in her final year of a B. Tech in Computer Science and Engineering, specialising in Cyber Security and Digital Forensics at VIT Bhopal University, India. B. Tech in Computer Science and Engineering student at VIT Bhopal University, India.
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice? Upon graduation, I hope to work in a research driven role in cybersecurity, with a strong focus on theoretical cryptography. I’ve always enjoyed exploring new ideas and uncovering patterns, and research gives me the freedom to follow that
In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?
curiosity in a meaningful way.
When someone who isn’t from this field asks why
Every concept opens a new door. I genuinely find it
cybersecurity excites me so much, I tell them that
intriguing and fun, almost like solving a puzzle that
it feels like working at the intersection of puzzles,
could one day protect millions of people.
Cryptography, in particular, caught my eye because it feels like a place where discovery never stops.
protection, and possibility. We live in a world where nearly everything our conversations, our finances,
As a woman pursuing research in such a
our memories exist as data. Cybersecurity is the
mathematically intense and traditionally male-
invisible force that keeps that world trustworthy.
dominated area, I’m motivated by more than just the science. I’m motivated by the idea of taking up space
For me, the most thrilling part is that it’s not just
in rooms where women are still underrepresented,
about stopping attacks; it’s about outsmarting them
and contributing to knowledge that shapes the future
before they even exist. Especially in cryptography,
of secure communication.
which is my passion, there’s this beautiful blend of mathematics and creativity. You’re building systems
It’s a path that excites me both intellectually and
that allow people to prove things without revealing
personally, one where I can explore, innovate, and
them, or compute securely without ever exposing
help redefine what the next generation of women in
the underlying data. It feels almost magical, but
cybersecurity research looks like.
it’s grounded in real science that impacts billions
technical field, it’s a deeply human one. Every
Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?
solution we build protects someone’s privacy, dignity,
The most influential factor in my cybersecurity
and safety. And because threats evolve so fast, the
journey has been discovering theoretical
field never becomes repetitive. You’re constantly
cryptography and especially the work of Shafi
of lives. I love explaining that cybersecurity isn’t just a
98
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
Goldwasser. I actually entered the field through
multiple branches of
zero-knowledge proofs, long before I knew how
cybersecurity AI-driven
deep and fascinating the landscape truly was. But
threat detection, STIX/
when I encountered Goldwasser’s work, it drew me
TAXII-based intelligence
in with a sense of possibility. It wasn’t the technical
sharing, and zero-
side that drew me in first , it was the feeling that
knowledge protocols. It’s still
this field had room for imagination, curiosity, and a
evolving, but taking the lead
kind of intellectual courage. Her contributions made
has allowed me not only to
cryptography feel less like a distant, rigid discipline
shape the technical direction,
and more like a world of ideas that could be explored,
but also to grow into the kind
questioned, and expanded. And the fact that this
of researcher and collaborator I want to become.
world was shaped so profoundly by a woman made it feel much more accessible to me.
For me, these experiences are more than stepping stones; they’re the beginning of a path I’m carving for
It made me realise that theoretical cryptography
myself as a woman in cybersecurity who hopes to
wasn’t just something I enjoyed in isolation, it was
contribute meaningfully to theoretical cryptography.
a place where I could build a future. And in many
Each project and opportunity helps me deepen my
ways, I’m still at the very beginning of that journey.
curiosity, strengthen my skills, and move one step
I’m constantly looking for opportunities to deepen
closer to the research future I envision.
my understanding, whether through research, of ideas that first drew me in. I hope to keep growing,
What aspect of your cybersecurity studies excites you the most, and why?
learning, and gradually shaping my own place in
The part of cybersecurity that excites me the most
this field.
is cryptography, especially zero-knowledge proofs
collaborations, or any chance to engage with the kind
and multi-party computation. For me, it feels less
Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?
like a subject and more like a place where all the
Beyond my academic studies, my practical
drawn to ideas that require patience and imagination,
experience has been a blend of industry exposure
and cryptography gives me that feeling every single
and self-driven exploration. I may still be at the early
time that sense of unlocking a concept that once
stages of my journey in cryptography, but I’ve already
felt impossible.
things I’ve loved since childhood finally converge: mathematics, theory, patterns, and the quiet joy of understanding something deeply. I’ve always been
worked as a Cyber Risk & Compliance Intern, where I spent a month understanding how organisations
Zero-knowledge proofs were my first doorway into
handle real-world security challenges. Even though
this world, and I still remember the moment they
it wasn’t directly cryptographic, it grounded my view
“clicked” for me. It felt almost poetic the idea that you
of the field and reinforced my desire to move toward
could prove something without revealing the thing
more research-oriented work.
itself. As I explored multi-party computation, that feeling only grew stronger. These fields have a kind
At the same time, I’ve been actively building my
of elegance and purpose that genuinely moves me.
experience through projects that push me closer
They show how pure theory can shape the real world
to the theoretical space I hope to contribute to. I’m
in profound ways, from privacy to trust to security
currently leading a team project that brings together
at scale.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
99
TANVI BADGHARE
The more I study cryptography, the more I realise
hand-holding; it’s about having someone there to
that this is where I see my future. It’s why I’m
nudge you forward at the right moments while letting
preparing to pursue my master’s in Fall 2026. I want
you explore independently.
the chance to go deeper, to contribute to research, and to be part of the community of people who are
Starting out can still feel daunting, but I’ve learned
quietly building the foundations of tomorrow’s secure
that I don’t need to change who I am to find my place
systems. For me, cryptography isn’t just the most
in cybersecurity. I just need to build my path in a
exciting part of cybersecurity; it’s the part where I feel
way that feels authentic to me guided by curiosity,
most at home challenged, inspired, and completely
small steps, and the occasional helping hand when it
certain that this is where I’m meant to be.
truly matters.
Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges? One of the hardest parts of my cybersecurity journey
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?
hasn’t been the concepts themselves, it’s been
Yes, definitely. I’ve come to realise that thriving
figuring out where to start, who to turn to, and how
in cybersecurity especially as a woman in a still-
to find guidance beyond the classroom. As someone
growing community takes more than just technical
who leans naturally toward introversion, stepping into
know how. Interpersonal skills, confidence, and the
wider technical communities can feel intimidating,
ability to connect with others are just as important,
and sometimes taking that first step seems tougher
because in a smaller community, every interaction
than anything that comes afterward.
counts. Networking isn’t just about creating opportunities; it’s also about finding your place and
What’s helped me is learning to take small,
feeling like you belong.
intentional steps. I often start quietly reading research papers, following work that inspires me,
I haven’t yet had the chance to meet the leading
or joining online spaces where conversations feel
researchers whose work inspires me, but that’s
meaningful rather than overwhelming. Along the
something I hope to change in the coming years. I
way, I’ve been lucky to have a mentor who
want to attend conferences, engage with the wider
offered guidance when I really needed
research community, and, with guidance from the
it. Even occasional check-ins showed
right mentors, one day present my own papers.
me that seeking help doesn’t require
Those spaces are where ideas grow, collaborations
being extroverted, it just means being
spark, and young researchers find their voice.
honest about where you are and where you want to go.
Building non technical skills like communication and leadership is a big part of that journey. Leading
Over time, these small
team projects, explaining complex ideas clearly, and
approaches have made it
forming meaningful connections all help amplify the
easier to ask questions, reach
impact of your technical work. For women in tech,
out, and build confidence
these skills also make it possible to claim space,
at my own pace. I’ve also realized that mentorship
share perspectives, and contribute confidently to shaping the future of cybersecurity.
isn’t about constant
100
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
So while my heart is in the theoretical and technical
distance ahead, but we can see plenty there that
side of cybersecurity, I’ve learned that the non-
needs to be done.” To me, that perfectly captures my
technical skills are just as crucial for the kind of
journey in cybersecurity.
researcher and the kind of professional I aspire to become.
Looking back, there are a few things I wish I had done differently, mainly starting earlier and engaging more
Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience?
actively with the cybersecurity community. If I could,
Yes, I’m actively involved in the broader cybersecurity
how important community engagement is not
and cryptography community, and I’m intentionally
just for opportunities, but for exposure to ideas,
working on expanding that involvement. So far,
collaborations, and mentorship.
I would have attended conferences, participated in workshops, and reached out to professionals sooner. Being naturally introverted, I underestimated
I’ve been part of my university’s WiCyS (Women in Cyber Security) Student Chapter, which has been
I now realise that building connections early
a fantastic way to get early exposure to peer-led
whether through forums, conferences, or university
discussions, workshops, and collaborative learning
chapters can accelerate learning and open doors
environments. I also follow and engage with the IACR
to research possibilities. I also wish I had explored
Cryptology e-Print archive to keep up with cutting-
research sooner, gaining hands-on experience and
edge research in cryptography, especially in areas
perhaps even contributing to papers before my
I’m passionate about, like zero-knowledge proofs and
later semesters.
homomorphic encryption. That said, these reflections have shaped my path While I’m still at the early stages of my community
moving forward. I’m now much more intentional
involvement, I’m gradually broadening it. Engaging
about expanding my network, joining global
with these communities has already enriched my
communities, seeking out conferences, and taking
learning, exposed me to diverse perspectives, and
initiative in research-focused work. Rather than
helped me stay in tune with industry trends. As I
seeing these earlier gaps as regrets, I view them as
grow, I hope to take a more active role attending
guidance that helps me move forward with clarity,
conferences, contributing to discussions, and
confidence, and purpose.
eventually presenting my own work with the guidance of mentors.
I’m also deeply grateful to Abigail Swabey and the team for creating spaces like this, where women in
For me, being part of the community isn’t just about
cybersecurity can share their journeys. These spaces
networking; it’s about growing as a researcher,
truly make a difference.
building confidence, and finding spaces where I can learn, contribute, and feel represented as a
For anyone who resonates with my journey or works
woman cybersecurity.
in cryptography, zero-knowledge proofs, multi-party computation, or theoretical cybersecurity research
Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider? As Alan Turing said, “We can only see a short
I S S U E 28
I’d love to connect on LinkedIn or by email. I’m always excited to learn, collaborate, and grow within this community. www.linkedin.com/in/tanvi-i
WOMEN IN SECURITY MAGAZINE
101
I had no prior IT experience or studies in school so cybersecurity was completely new to me. When I first considered studying cybersecurity, my preconceived idea was that it would be almost entirely technical AMY KORALIS
coding, networks and systems which honestly made me nervous about how I would progress. But that uncertainty is what pushed me to keep learning and
Amy Koralis is a dual-degree student at Macquarie University, currently pursuing a Bachelor of Cyber Security and a Bachelor of Laws. Bachelor of Cyber Security and a Bachelor of Laws student at Macquarie University.
embrace the challenge and as I progressed I quickly realised how much broader and diverse the field truly is. Alongside the technical foundations, I have been able to study areas like cybersecurity management, privacy, digital forensics, governance and the human factors that influence security decisions. What surprised me the most is how naturally cybersecurity has aligned with my legal studies and the intersections between regulation and digital systems has made my experience far richer than I expected.
In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?
I get genuinely excited when speaking to people
Once I graduate I would like to build a career as a
who aren’t familiar with cybersecurity because I get
cyber lawyer in advisory and litigation, supporting
to explain to them how it’s this dynamic blend of
organisations as they prepare and respond to
problem solving, creativity and real world impact.
cybersecurity incidents. I feel there is a growing
As someone studying the unique combination of
demand for lawyers who understand both the
cybersecurity and law, I often highlight that the field
legal and technical dimensions of cybersecurity
is far broader than traditional programming roles,
to guide organisations through every stage of
it opens doors to careers at the intersection of
incident response and confidently navigate complex
technology, governance, policy, ethics, investigations
technical matters. What motivates me the most
and human behaviour.
is the opportunity to bridge the gap between law and technology. Cybersecurity is not just about
What I love most is the ever-evolving nature of the
technology, it is about understanding people,
work; things change fast and the constant shift
organisations, behaviour, policy and risk.
creates challenges that push you to keep learning and thinking critically. Cybersecurity welcomes people from all kinds of academic and professional backgrounds, each bringing strengths that are technical, analytical or strategic. That diversity is what makes the field so exciting and accessible.
When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? When I was in Year 11 exploring different degree
Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?
102
W O M E N I N S E C U R I T Y M A G A Z I N E
options to combine with law, I knew I wanted something that used my strengths in maths and science as well. My dad works in the IT sector, so we had a lot of conversations about what that path
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
could look like, but IT felt too broad and technical
digital literacy and ensuring everyone has the skills
for what I wanted. It wasn’t until cybersecurity came
to stay safe online. Seeing how our work could
up in conversations with my dad and later with my
empower schools and give teachers and students
tutors that I realised it could be the right path for me.
foundational cybersecurity awareness made the
At the time, Macquarie University had just introduced
experience truly meaningful. That real world impact
a Cybersecurity degree, one of the only universities
is what has stayed with me the most.
offering it. The opportunity to combine law and
incredibly supportive, even though the degree was
Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?
new and none of us knew exactly where it would
I do feel that Macquarie University has made a
lead. Looking back five years later, cybersecurity
strong effort to keep pace with the rapid evolution
has exploded across every industry and specialised
of cybersecurity. From my very first unit, lecturers
cyber law roles are now in high demand. It’s
emphasised that there would be no traditional
incredibly rewarding to see how my decision to study
textbooks for this field because the landscape
cybersecurity has set me up for a strong future in the
changes too quickly. Most of our learning comes
field and I am genuinely excited about the learning
from analysing current articles, case studies and real
ahead and the career I am building.
world incidents which keeps the content relevant
cybersecurity and study in a field that blended governance, policy and technology really appealed to me. My family, peers and career advisors were all
and grounded in practice. Earlier in my degree, there
Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.
was definitely a heavier weighting toward technical
The most memorable moment in my cybersecurity
units introduced that focus on communication,
journey so far was completing my placement project
people skills and management, recognising that
through Macquarie University, where I led a team
cybersecurity professionals need to translate
that developed cybersecurity training materials for
technical concepts to diverse audiences not just
teachers and hands-on activities for students. Our
work behind the scenes. It is important that the
project was so well received that we were invited to
degree continues to evolve alongside industry
deliver our activities to primary school students as
developments so it remains professionally relevant
part of Macquarie University’s outreach program.
and continues to prepare students for the realities of
What made this project so impactful was realising
cybersecurity work.
units but the balance has improved over time. I have noticed a shift in the curriculum, with more
that cybersecurity isn’t just about protecting big organisations or responding to high-profile incidents, it is also about sharing knowledge, closing gaps in
What aspect of your cybersecurity studies excites you the most, and why? The aspect of cyber security that excites me the most is exploring the intersection between technology, policy and human behaviour. I love understanding not just how incidents happen technically, but why they happen, what organisational decisions, governance gaps or behavioural factors contributed. I get excited by the constant problem solving cybersecurity demands and that there is never one approach to resolving problems.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
103
AMY KORALIS
Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?
Infosecurity Magazine, Cyber Daily, iT News, and
One of the areas I have found most challenging
threats. Social platforms like LinkedIn and GitHub
in my cybersecurity studies has been the more
are great for joining conversations, learning from
technical components. I enjoy the analytical
professionals, and seeing what’s happening in the
thinking and problem solving involved, but the
field right now.
CyberCX. I also keep an eye on reports from organisations such as ACSC and major cybersecurity firms to stay informed about the latest trends and
depth of programming and command line work can sometimes be more complex to grasp, especially
Beyond reading, I really enjoy attending seminars
without an IT background. There are moments I have
and university events. At Macquarie, the Computing
felt overwhelmed but I have learnt this is part of the
Society regularly hosts industry talks, which have
learning curve in cybersecurity. To work through a
been an incredible opportunity to hear directly
challenge, I focus on breaking down problems into
from cybersecurity professionals and see how the
smaller pieces and practicing regularly. I have also
concepts I learn in class come to life in real-world
found that collaborating with peers and working
situations. These experiences make my studies feel
through problems together has been invaluable and
more connected to the industry and inspire me to
has helped me see solutions I wouldn’t have found
keep growing.
on my own.
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?
www.linkedin.com/in/amy-koralis-1848b122a
Yes, absolutely. Cybersecurity roles today require more than just technical skills and I have become increasingly aware of the importance of interpersonal communication, management and leadership skills. Whether you are presenting a risk assessment, explaining technical issues to non technical audiences or just supporting an organisation through a cyber incident, your ability to communicate clearly can make all the difference. For someone like me who aims to work at the intersection of cybersecurity and law, these skills are even more important.
What is your preferred source for staying informed about cybersecurity trends and general information? As a student, I make it a point to stay connected with the cybersecurity world by following trusted publications and subscribing to newsletters like
104
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
Join Us in Empowering
Future Leaders
! d e t n a W y it r u c e S in Students Are you a student passionate about shaping the future of security? Do you have innovative ideas and insights to share with a global audience? Join us in contributing to the Women in Security Magazine and become a voice for the next generation of security leaders!
Why contribute?
Gain valuable exposure: Reach over 11000 subscribers globally and showcase your expertise to industry professionals.
How to get involved
Make an impact: Share your experiences, challenges, and aspirations to inspire others and shape the future of security.
Let us know you are interested. We will send you a series of questions of which you can choose which ones you would like to answer. Submit those back to us in an email. We will then edit to be a concise and flowing edited Q&A.
Don't miss this opportunity to be part of a vibrant community of students driving change in the security industry. Contact us today to learn more about how you can contribute to the Women in Security Magazine!
Contact: jane@source2create.com.au
ASHLEY MATHEW
Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare? When I first became interested in cybersecurity, I imagined it was all penetration testing, hacking
Ashley Mathew is currently pursuing a Bachelor of Cybersecurity at Deakin University in Melbourne. Bachelor of Cybersecurity student at Deakin University in Melbourne.
challenges, and constant coding. I think that’s the picture a lot of us start with when we hear the word “cybersecurity.” But once I actually stepped into the field, I realised how different and much broader it really is. There’s a huge amount of thoughtful analysis, documentation, and structured decision-making behind every technical move. Sometimes, simply
In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?
paying close attention and understanding the bigger
When I explain why cybersecurity is exciting, I usually
One of the biggest mindset shifts for me was
start with something everyone understands. Our
discovering that not every cyber role requires heavy
whole world runs on technology now. For example,
coding. In fact, some barely touch it. You can build an
thinking about hospital records that were once
incredible career in areas like digital forensics, GRC,
handwritten are all sitting in electronic systems
policy development, threat intelligence, or auditing
today. Every bit of your personal information, from
with only basic Python knowledge. Cybersecurity has
your address to your emergency contacts, is just a
so many paths and that’s what makes it exciting.
picture matters just as much as (or even more than) the hands-on technical work.
click away.
gets a hand on it. One malicious person inside
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?
that system and having full control over it. Your
I am aiming for a SOC analyst role, and my
details, your identity, everything that matters to
connection to it started in an unexpected way. While
you, suddenly at someone else’s leisure. That’s how
preparing a presentation on What is SOC for the
critical cybersecurity is in the world we live in. The
Deakin University Cybersecurity Association (DUCA),
world now thrives online, If you don’t know how to
I realised just how much the role resonated with me.
protect yourself or the people you care about, you are
Talking about it to others made me see the fast pace,
exposed without even realising it
the constant problem solving, and the responsibility
Now imagine someone with the wrong intentions
of monitoring and defending systems in real time in a
106
And that’s where cybersecurity becomes fascinating.
different light. Since then, I have been learning more
You get to understand what actually happens behind
about the role and developing personal skills to better
the scenes, the impact, the cause, the prevention, the
fit it. I am always eager to connect with anyone who
recovery and once you see how much of the world
can share advice or insights, as every conversation
depends on it, the importance and the excitement
sparks new ideas and motivates me to keep
speak for themselves.
improving. What excites me most is the combination
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
of technical work and analytical thinking. In this role,
few in the near future. Certifications are a great way
your actions have immediate impact, and you are
to bridge theory into practical knowledge. They help
constantly adapting and learning. At the same time,
you test yourself, keep your skills sharp, and build
I am open to exploring other areas if something
confidence. While they are especially useful later
sparks my interest more, but for now, SOC feels like
in your career to stay on your toes, they are also a
the perfect fit for me.
strong starting point. I believe in the current market you can pursue cybersecurity roles without a degree
Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?
if you have the certifications and the knowledge
Multiple people have shaped my journey in
so far (ISC)² SSCP for operational security.
to back them up. For my goal of becoming a SOC analyst, some certifications I am considering include CompTIA Security+ for foundational knowledge and
cybersecurity so far. My family has been incredibly influential, giving me the freedom to pursue what I am passionate about, supporting my decisions unconditionally, and going above and beyond for my dreams.
Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape? Cybersecurity evolves at an incredible pace, and
The amazing cybersecurity community I have found
while my academic program provides a solid
through my university, particularly through creating
foundation in theory, principles, and best practices,
and being part of the Deakin University Cybersecurity
it cannot always keep up with the latest threats
Association (DUCA), has been a huge influence.
and tools in real time. The program does, however,
Being in an environment where we uplift each other,
challenge you, teach time management, and
learn together, and grow together has shown me
introduce concepts that encourage you to explore,
first-hand how the people you surround yourself with
learn, and discover solutions for yourself.
truly shape your path. Supplementing my studies with hands-on practice, Finally, the tutors and professionals I have met at
involvement in university clubs like the Deakin
conferences and events have been invaluable. Their
University Cybersecurity Association (DUCA),
guidance, advice, and quiet support have helped
attending industry events, and engaging with the
me navigate challenges and stay motivated. It has
wider cybersecurity community has been essential.
been an incredible journey so far, and I am genuinely
These experiences allow me to see the current
excited for what comes next.
threat landscape, explore new technologies, and stay up to date in ways that go beyond the classroom.
The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?
I S S U E 28
Ultimately, combining academic grounding with active engagement outside the classroom builds both confidence and adaptability, equipping me to handle the evolving challenges of the cybersecurity field
I have not completed any
What aspect of your cybersecurity studies excites you the most, and why?
cybersecurity certifications yet,
The aspect of my cybersecurity studies that excites
but I am planning to pursue a
me most is the practical, investigative nature of
WOMEN IN SECURITY MAGAZINE
107
ASHLEY MATHEW
the work. Working directly with tools like Kali Linux,
overwhelming. I make it a point to try and complete
Nmap, Metasploit, Wireshark, and SQL injection
all the higher tasks, and during break, I reflect on any
testing environments and being able to see how
missed work or areas where I could have improved.
vulnerabilities are exploited, how attacks unfold, and
Discussing my approach with high-achieving
how systems can be misconfigured or manipulated
peers has been particularly enlightening, seeing
has been incredibly engaging. Our assignments have
how they present their submissions and approach
taken this even further. I have worked on uncovering
problems has shifted my perspective and helped me
hidden data within images, analysing compromised
understand that sometimes the smallest details can
systems, tracing digital artefacts, and identifying
make a significant difference.
weaknesses before designing the fixes to prevent
combination of hands-on investigation, technical
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?
depth, and real-world problem-solving is what keeps
Absolutely. The truth is that cybersecurity is rarely a
the field constantly interesting for me.
one-person job; it is part of a much bigger system in
those issues from recurring. Understanding not only how to detect and solve a problem but also how to build long-term prevention strategies has been one of the most rewarding parts of the course. This
which multiple departments collaborate to protect
Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges?
networks, systems, and data. You must be able
Some aspects of my cybersecurity studies,
effectively during incidents or projects.
to communicate coherently with colleagues from different roles, explain intricate security concerns to non-technical stakeholders, and collaborate
particularly practical labs, can be quite challenging. When I encounter difficulties, I first try to work
I’ve been actively honing these skills working with the
through the problem on my own, often revisiting it
Deakin University Cybersecurity Association (DUCA),
multiple times or taking a break and returning with
volunteering at events, participating in hackathons,
a fresh perspective. If I am still stuck, I reach out
coffee catchups and more. These experiences taught
to peers or tutors for guidance, using their hints
me how to collaborate in groups and learn from other
and insights to work through the
people’s perspectives.
problem collaboratively. I am not someone who can just give up on something, even if an assignment is past its due date or feels
Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience? Yes, I am actively engaged in the broader cybersecurity community through my involvement with the Deakin University Cybersecurity Association (DUCA). I was initially recruited by the club president over a year ago, and since then, my journey within DUCA has been incredibly enriching. I began as a Content Coordinator, creating blog posts, social media content, and promotional
108
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
a passionate community. Over time, I have taken on
Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.
more leadership responsibilities, serving as Social
Gratefully, I have not personally experienced
Media Co-Executive and now Secretary, where I
discrimination in cybersecurity. However, I have
lead DUCA’s social media strategy, coordinate with
noticed occasions, such as in lectures, where
research and content teams, and represent the club
I am often the only female student, which can
at events. Additionally, I have presented at events on
sometimes feel a bit intimidating. What has made
cybersecurity topics, sharing insights with peers and
a huge difference is having supportive lecturers
helping spark interest in the field. Being part of DUCA
and being part of communities like the Deakin
has enriched my experience in multiple ways. It has
University Cybersecurity Association (DUCA), AWSN,
allowed me to develop leadership, communication,
and WiCyS. These networks provide constant
and organisational skills while connecting with peers
encouragement and mentorship, showing that there
and industry professionals. Most importantly, it has
is nothing women cannot achieve in cybersecurity. I
shown me how surrounding yourself with passionate,
am extremely grateful for these experiences and the
motivated people can shape your growth, inspire
amazing people who continue to demonstrate that
curiosity, and push you to continuously learn and
gender is never a barrier in this field.
materials to raise awareness about cybersecurity. I actively participated in events, workshops, and O-Week stalls, helping engage students and foster
explore the field of cybersecurity.
What is your preferred source for staying informed about cybersecurity trends and general information?
What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? To maintain strong personal cybersecurity in today’s
I stay informed about cybersecurity trends and
digital landscape, I take a considered approach. I
general information through a combination
use strong, unique passwords managed through
of resources and active engagement with the
a secure password manager, enable multi-factor
community. I am subscribed to newsletters like
authentication on important accounts, and ensure
TDLRs, which provide concise updates on a wide
my devices and software are updated, carefully
range of the latest developments in the field. I also
evaluating the new updates before installation, not
regularly listen to cybersecurity podcasts, including
every new update is immediately the best one.
Lost in Cyberia, CyberWire Daily, and Darknet Diaries, which offer insights into real-world threats, emerging
In addition to technical measures, I remain vigilant
technologies, and industry perspectives.
in daily digital interactions. I carefully manage my privacy settings and exercise caution against
Additionally, I use LinkedIn to follow thought leaders
potential scams or suspicious activity. I approach
and analyse perspectives from other professionals
personal cybersecurity with a mindset of awareness,
and like-minded peers. I am an avid reader of blogs,
caution, and continuous learning, adapting to new
especially on new systems, tools and techniques.
challenges as they arise.
I also attend webinars or virtual events whenever possible to gain deeper insights depending on the company and topic. This combination of resources
www.instagram.com/deakincyber
helps me stay up to date, broaden my understanding, and continuously learn about both the technical and
www.linkedin.com/in/ashleyymathew
practical aspects of cybersecurity.
I S S U E 28
WOMEN IN SECURITY MAGAZINE
109
traditional path of getting accounting certifications and building experience in that field (and to be fair, I am still working toward those too). When I QUEENETH ONYIKE
mentioned cybersecurity, the reaction wasn’t exactly enthusiastic. To them, it sounded like a field “meant for men,” and the idea of me entering it without an
Queeneth Onyike studying Accountancy at the University of Nigeria, Nsukka. Accountancy student at the University of Nigeria, Nsukka.
IT background felt unrealistic. I won’t lie there were moments when their doubts made me question my own choices. It felt like I was trying to build a whole new career from scratch. But I’m very active on LinkedIn, so I started looking for people with backgrounds like mine finance and accounting who were thriving in cybersecurity. And I found them: Associates and Managers in the Big
In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?
4, CISOs and CTOs across major African banks and
This comes up all the time. The moment I mention
viable, and sustainable path for me.
fintechs. Seeing their success gave me the evidence I needed, not just to reassure myself, but also to convince my parents that cybersecurity is a real,
cybersecurity, most people instantly picture a hacker. build a career in cybersecurity if they’re curious and
What aspect of your cybersecurity studies excites you the most, and why?
willing to keep learning. ”You’re never starting from
I honestly find myself torn between OSINT and
zero so many of the skills you already have can be
Compliance because both speak to different sides
transferred and shaped into something valuable in
of me. I’ve always been someone who pays close
the security space. And because cybersecurity is
attention to detail, and that skill fits perfectly in
always changing, there’s always something new to
either path.
I usually smile and tell them, “Honestly, anyone can
learn. It takes consistent effort to keep your skills sharp and your knowledge up to date, but it’s worth
With OSINT, I love the idea of gathering and analysing
it. It may sound like a lot at first, but trust me: it’s a
information from public sources, social media, news
deeply rewarding field, both financially and in terms
sites, online databases and turning it into something
of impact. Cybersecurity isn’t going anywhere, and
meaningful. It’s fascinating to see how much you can
the value of those who work in it will only continue
uncover from what people share online, even when
to grow.
they think they’re invisible.
When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?
Compliance, on the other hand, feels almost like
At first, there was definitely some skepticism,
standards and policies just feels like something that
especially from my parents and friends. Since I’m
comes naturally to me.
home. I’ve held leadership roles since high school and university, and as the oldest child, I naturally grew up making sure rules were followed and things ran smoothly. Helping people stay aligned with
studying accounting, everyone assumed I’d follow the
110
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
S P O T L I G H T
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?
Cyblack Cybersecurity Bootcamp. I received the
I want to land a role in IT Audit or GRC. These
say it changed the trajectory of my journey from
roles leverage my existing knowledge and skills in
a place of anxiety to confidence. The application
accounting. Additionally, it would be more ideal when
process required a video submission which initially
applying for jobs in the Big 4 or financial institutions.
discouraged me, but I had to remind myself to
I want to be that bridge in IT and Finance securing
maximize every opportunity to grow in this space.
financial data. In my region, finance scams are very
The next three months was a wholesome experience
popular, whether it’s a data breach, social engineering
from mentorship sessions by seasoned experts, to
or phishing. A lot of people do not understand
beginner-friendly classes and guided learning. Due
what it means to be cyber safe, especially in their
to the Bootcamp, I wrote the ISC2 CC exam which
finances and I need to fill in that gap, through
was a confidence booster passing an entry level
public awareness about risks, cyber education, and
Cybersecurity exam despite coming from a non IT
implementing robust safety measures especially in
background. Since then, I have taken more courses
financial institutions.
especially in GRC, actively journaling my learning
acceptance email on 1st May (my birth month) and it was that confirmation I was seeking. I’d
journey in public, and networking with seasoned
Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.
professionals for guidance.
The most significant event in my Cybersecurity journey to date was getting accepted into the
I S S U E 28
WOMEN IN SECURITY MAGAZINE
111
QUEENETH ONYIKE
The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice? I currently hold the ISC2 CC certification, and I recently started Google’s Cybersecurity Professional Certificate this November. It’s been a great way to build momentum, especially as I prepare to take the Security+ next year. I’m also eyeing the CGRC from ISC2 because it’s such a strong certification for anyone interested in GRC so I’m keeping that on my radar.
I’m building, how long they’ll take me to complete,
What is your preferred source for staying informed about cybersecurity trends and general information?
and what skills or knowledge I’ll walk away with. And
I’m active on LinkedIn and X (formerly Twitter), so a
of course, cost definitely plays a role when planning
lot of my sources are Cybersecurity professionals
out these exams. Overall, I’m choosing certifications
and experts I follow. I’m subscribed to a few weekly
that make sense for my goals and help me grow
newsletters via email that cover news, trends and
steadily and confidently in the field.
recent developments in Cybersecurity.
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?.
Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider?
Absolutely. There’s always a demand for non-
it’s releasing all the fear and doubt that made me
technical (soft) skills in Cybersecurity. You can’t
question if Cybersecurity was right for me. The
expect top-level decision makers or even the
occasional bouts of anxiety stalled my learning
average person to understand IT jargon. Directors
journey a lot. I’d also network with professionals,
may undermine or dismiss existent risks in the
asking for help, guidance and learning resources
organisation because of the inability of a GRC
from those who’ve successfully walked the path,
Analyst to clearly break down and explain the degree/
not trying to figure out everything on your own with
level of risk, consequences of non-compliance etc.
Google and ChatGPT.
When I choose certifications, I try to be really intentional. I look at how relevant they are to the path
Cybersecurity is a collective effort, just a breach from one computer can shut down the organisation’s entire system, thus interpersonal communication skills cannot be neglected.
112
W O M E N I N S E C U R I T Y M A G A Z I N E
If I would make any changes to my career trajectory,
www.linkedin.com/in/queeneth-onyike x.com/nnennabuilds
J A N U A RY • F E B R U A RY 2026
DANAH MOHAMMED ALKHAN
Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice? I aspire to work as a penetration tester or cybersecurity analyst. These roles really appeal to me because they involve both technical and
Danah Mohammed Alkhan is currently pursuing a Bachelor’s degree in Cybersecurity at the University of Bahrain. Cybersecurity student at the University of Bahrain.
analytical thinking. I enjoy identifying vulnerabilities, understanding how attackers operate, and building stronger defenses. It’s like solving puzzles while helping organizations stay safe, which combines both my curiosity and sense of responsibility.
When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest?
When I decided to study cybersecurity, my parents
When I talk about cybersecurity, I usually describe
were surprised at first since cybersecurity is still
it as being on the frontlines of the digital world like
a growing field, especially for women, but that
protecting an entire universe that exists online.
only motivated me more. I felt proud to take a
Every day, new challenges appear, and it’s our job
path that’s both challenging and meaningful, and
to stay one step ahead of attackers. It’s not just
their encouragement gave me confidence to keep
about coding or systems; it’s about solving real-
pushing forward.
and friends were thrilled and very supportive. They knew how much I’ve always loved technology, so they saw it as a perfect fit for me. Some people
world problems and protecting people’s privacy. The excitement comes from knowing that what you do genuinely makes an impact in keeping others safe.
Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?
114
Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations? The biggest influence on my journey has been my curiosity and love for technology. I’ve always been fascinated by what happens behind the
At first, I thought cybersecurity was mainly about
scenes in digital systems, which led me to explore
hacking and coding. But as I progressed through
cybersecurity deeply. My professors, classmates,
my studies, I discovered it’s much broader, involving
and family have all played a major role in supporting
strategy, analysis, digital forensics, and even risk
and motivating me. Their encouragement reminds
management. The field is much more dynamic
me that I can excel and make a real impact in this
than I imagined. It requires continuous learning
field, strengthening my goal of becoming a skilled
and adapting, which makes it even more exciting
penetration tester who helps make cyberspace safer
and rewarding.
for everyone.
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression.
S P O T L I G H T
One of the most memorable moments in my
Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?
cybersecurity journey was during my first ethical
I completed an internship at Daresni Company,
hacking lab, where I worked on solving the Natas
where I worked as an Administrative Executive.
wargames challenges. Each level pushed me to think
While it wasn’t purely a cybersecurity role, it gave
differently, from exploring hidden directories to using
me insight into managing information securely and
tools like Burp Suite and analyzing cookies to bypass
understanding data protection from an organizational
login restrictions. It was the first time I truly felt like
perspective. Additionally, I’ve worked on several
a problem-solver in a real hacking environment.
university projects related to cybersecurity,
Later, another defining experience came from a web
which helped me apply classroom knowledge to
security testing project where my team and I used
practical scenarios.
SQLMap to uncover vulnerabilities and deploy a PHP
yet responsible, cybersecurity work can be. Those
The cybersecurity industry offers various certifications from different organisations. Have you pursued, or do you plan to pursue any of these certifications? If so, which ones, and what factors influenced your choice?
experiences confirmed that I’m on the right path
Yes, I’ve earned the AWS Cloud Practitioner
and made me even more eager to keep learning and
certification, and I’m currently working through
improving my technical skills.
Google’s Cybersecurity Professional Certificate. My
web shell for privilege escalation. The moment our script successfully executed and revealed admin access was incredibly exciting. It showed me how theory and practice come together and how powerful,
I S S U E 28
WOMEN IN SECURITY MAGAZINE
115
DANAH MOHAMMED ALKHAN
next goal is to pursue CompTIA Security+. I chose
memorization and not much hands-on work. When
these certifications because they give me practical,
that happens, I try to tie the concepts back to real-
hands-on knowledge that builds on what I’m learning
world examples or small projects of my own. Making
at university, and I appreciate that they’re widely
those connections helps me stay motivated, and it
recognised in the cybersecurity industry. For me, it’s
reminds me that even the driest theory has value
exciting to see how each one adds a new layer of
once you see how it plays out in real situations.
understanding and confidence as I grow in this field.
Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?
Are there specific aspects of your cybersecurity studies that you find particularly challenging? If so, what are they, and how do you approach overcoming these challenges? At times, balancing technical complexity with time
My university does a good job at keeping up with
management can be challenging. Some topics
modern cybersecurity trends, but I also believe
require a lot of practice. I overcome this by setting
there’s always more to learn beyond the classroom.
small, manageable goals, practicing consistently, and
The field evolves so fast that staying updated
seeking help from professors or online communities
requires self-learning and exploration. I make it a
when needed.
point to read articles, attend workshops, and follow cybersecurity communities to stay current with new threats and defense techniques.
What aspect of your cybersecurity studies excites you the most, and why?
I think more emphasis could be placed on hands-on
I’m most excited about learning how to protect
learning, labs, and penetration testing environments.
systems and networks from attacks. It’s fascinating
These practical experiences make the concepts more
to understand both sides how attackers think and
meaningful. Some overly repetitive theory based
how to counter their strategies. I love the idea of
courses could be condensed to make room for that
defending privacy and digital integrity,
practical exposure. Additionally, some university
especially as technology becomes
electives could be replaced with more practical,
more central to everyday life.
Conversely, which aspect of your studies do you find least interesting or useful, and how do you navigate through it?
116
Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus?
hands-on courses.
Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why? Yes, definitely. I believe that technical skills alone aren’t enough to succeed in cybersecurity.
Sometimes I struggle
Communication, teamwork, and problem-solving are
with the more repetitive
just as important. In many situations, cybersecurity
or overly theoretical parts
professionals have to explain complex issues to
of cybersecurity especially
people who don’t have a technical background. Being
when it feels like it’s all
able to do that clearly and confidently helps build
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
S T U D E N T
I N
S E C U R I T Y
trust and ensures that security becomes a shared responsibility across an organisation.
S P O T L I G H T
changes to your career trajectory? If yes, what adjustments would you consider? I’m genuinely happy with the path I’ve chosen.
Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience?
If anything, I would have started exploring
I try to join cybersecurity workshops, seminars,
digital safety.
cybersecurity earlier. It’s a field full of opportunities, and every step has taught me something new about technology, resilience, and the importance of
and conferences whenever I can. Even though I
professionals, hear about real challenges in the
Have you actively sought employment opportunities in the cybersecurity field, and if so, what has been your experience with the application and interview process?
field, and connect with people who share the same
Yes, I’ve started exploring internship and job
passion. Being part of those conversations makes
opportunities in cybersecurity. The process has been
me feel like I’m slowly finding my place in the wider
both exciting and educational.
haven’t taken part in formal clubs or competitions yet, these events have been incredibly valuable. They give me the chance to learn directly from
cybersecurity community.
Have you ever encountered situations where being a woman in cybersecurity made you feel disadvantaged or discriminated against? If so, please share your experiences.
www.linkedin.com/in/danah-mohammed-alkhan
Personally, I haven’t faced direct discrimination, but I am aware that women in cybersecurity often have to prove their expertise more than others. I see it as motivation to keep learning, performing, and showing that gender doesn’t define capability. I’ve also met many inspiring women in the field who remind me that representation matters.
What measures do you have in place to enhance your personal cybersecurity in today’s digital landscape? I make sure to use strong, unique passwords and enable multi-factor authentication on all my accounts. I also keep my devices updated and avoid sharing personal information carelessly. Cybersecurity starts with personal habits, and I try to apply everything I learn academically to my daily online life.
Reflecting on your journey thus far, would you, with the benefit of hindsight, make any
I S S U E 28
WOMEN IN SECURITY MAGAZINE
117
LISA ROTHFIELD-KIRSCHNER Author of How We Got Cyber Smart | Amazon Bestseller
Olivia and Jack chat about the new social media rules OLIVIA – 6:12pm Mum just sent that MASSIVE email about the new social media rules. You read it yet? JACK – 6:13pm Yeah Had to scroll for, like, three hours. Wait. So are we literally getting kicked off Snapchat and YouTube?
😑
OLIVIA – 6:14pm Not kicked off right now. But it sounds like, by 2026, we’re probs gonna have to prove our age or get Mum + Dad to say yes. And we’re both still under 16 then. JACK – 6:15pm So annoying. Like I’m 14, not 4. I use Snapchat to keep in touch with my friends. I’m not starting a revolution. OLIVIA – 6:16pm Yep. I use YouTube to learn a lot of interesting stuff about the world. I like watching cool basketball and bike tricks and cooking tips. But I kinda get the “people who aren’t who they say they are” bit. Remember that weird guy who DMed you last year?
OLIVIA – 6:18pm IDK. I guess it’s not about us personally. Mum said they’ve seen heaps of nasty stuff happening to kids our age. Also, the part about “no more typing in a random birth year and getting through” made me feel personally attacked.
😂
JACK – 6:19pm Look, 2000 is a great birth year, OK? Super realistic. Can’t believe they’re ruining my acting career as a 25-year-old. OLIVIA – 6:20pm RIP your fake adult life. But lowkey, if the apps actually verify ages properly, that might mean less 40 year olds pretending to be 15 in group chats. JACK – 6:21pm True. And less 10-year-olds on TikTok doing ‘what I eat in a day’ videos. That stuff is so boring. OLIVIA – 6:22pm I know. And the ‘pressure to look a certain way’ bit Mum mentioned. That’s real. That one girl in your class who edits all her pics so much she looks like an AI filter.
JACK – 6:17pm Yeah… OK true. That was creepy. Still, it feels like the government’s putting us all in the ‘too little, too dumb’ box.
118
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
JACK – 6:23pm Yeah. She literally cries when a post doesn’t hit 200 likes. I don’t want you to end up like that. So I do get why they’re trying to slow it down till people are a bit older. OLIVIA – 6:24pm It still sucks that we need ‘parent permission’ for everything though. Feels babyish. JACK – 6:25pm Mmm. But at least Mum’s not like “delete it all, play in the streets forever”. She said we can figure out together what makes sense. Maybe I can keep Snapchat if they can see it’s just me chatting to my friends. OLIVIA – 6:26pm She also said “it’s not about whether we trust you”. I actually believe her. They let me keep Discord after that whole convo about blocking people. JACK – 6:27pm Yeah. And remember when I showed Dad that hate comment I got? He didn’t freak out or delete my account. Just helped me report and block. So maybe this new rule is them getting backup from the law. OLIVIA – 6:28pm Backup parents “Now with added government support”
😂
JACK – 6:29pm LoL Shut up. What I’m still confused about: if I’m under 16 in 2026, can they just like pause my account? What happens to my photos??
I S S U E 28
OLIVIA – 6:30pm From what Mum said, accounts might need to be “paused or adjusted”. So maybe: • We can keep them if Mum and Dad approve. • Or they’re locked till we’re 16. • Or we get kicked but can download our stuff. We should ask. I don’t want my Grade 6 last day at school pics being lost in the void. JACK – 6:31pm Same. Also, she said they’ll use Apple Screen Time and Google Family Link. Are we getting fully stalked now? OLIVIA – 6:32pm She said, “keep an eye… without being intrusive.” I think it’s more like: • time limits. • to downloading dodgy apps. • seeing if some dodgy rando is spamming us. Not reading every single DM where you complain about me. Probably. JACK – 6:33pm Chill. I complain about you out loud. No DMs needed. But actually, it might be good for me. Sometimes I doomscroll for no reason and then feel anxious and find it hard to fall asleep OLIVIA – 6:34pm Yeah, same. Maybe if the app kicks me off after an hour, I’ll actually finish my homework on time or get to sleep quicker.
WOMEN IN SECURITY MAGAZINE
119
JACK – 6:35pm You? Finish homework? Ok now YOU sound like government propaganda. OLIVIA – 6:36pm “Sponsored by the eSafety Commissioner.” Speaking of…Mum said we can check out esafety.gov.au if we want more info. Wanna look later? Curious what the actual rules are versus what TikTok rumours are saying. JACK – 6:37pm Yeah, let’s. Everyone at school is already saying “they’re deleting ALL our accounts tomorrow,” which is obviously fake news. Would be nice to know the real deal. OLIVIA – 6:38pm Same. Also, she mentioned “shared accounts”. JACK – 6:39pm Depends. Would you ever do a shared TikTok with me or is that too crazy? OLIVIA – 6:40pm If you promise no Fortnite dances and no burping into the mic, maybe. Could be a ‘chaotic twin’ account. Baking fails, dog videos, that kind of thing. JACK – 6:41pm Deal. ‘Approved by Mum & Dad.’ Actually that might be kinda fun. So… we hate the rule, but also kind of understand it? Like: annoying now, maybe helpful later?
OLIVIA – 6:42pm Yeah. I’d rather be slightly annoyed than seriously messed up by some random online. And it’s not forever. Once we hit 16, we get to choose. JACK – 6:43pm Ok, let’s talk to them at dinner. Questions list. 1. What happens to our current accounts? 2. Can we keep some apps with their permission? 3. How much are they actually going to ‘watch’? 4. Can we set the limits together, not just them deciding? OLIVIA – 6:44pm Good list. Add 5. Can we make a shared sibling YouTube so I become famous for my amazing baking skills? JACK – 6:45pm Already added. Title: “Olivia makes the best chocolate fountain, and spills it all over herself.” OLIVIA – 6:46pm You’re the worst. Thanks for talking this through though. I felt heaps more panicked before. JACK – 6:47pm Same. At least we’re in the same boat till we hit 16. Now come help set the table for dinner before Mum makes a rule about that too.
www.linkedin.com/in/lisarothfield-kirschner
howwegotcybersmart.com
120
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
How We Got Cyber Smart addresses cyber safety, cyber bullying and online safety for elementary school-aged children. Lisa has partnered with Cool.Org, and her content is found on the Department of Education website.
READ NOW
WOMEN IN SECURITY MAGAZINE CONTRIBUTORS 01
02
1. AMANDA-JANE TURNER
Author of the Demystifying Cybercrime series and Women in Tech books. Conference Speaker and Cybercrime specialist
2. TARA MCNALLY
Manager Cybersecurity
03
04
3. KRITY KHARBANDA
Application Security Professional | Advocate of women in cybersecurity
4. NKIRUKA JOY AIMIENOHO
Chief Information Security Officer (ScB)
05
06
5. ANEESA CHOTHIA
Information Security Officer
6. OPEYEMI OLAIFA
Manager & Team Lead Cybersecurity & Compliance Advisory At Digital Encode Limited
07
08
7. FATHIMA MOHAMED THASEEN
Account Executive at Havas NZ
8. AKO OTUDOR
Cybersecurity Analyst
09
10
9. JAIME SCHREPFER
Chief Information Security Officer
10. FIONA MARTIN
Associate Director, Business Resilience
11. DEARNE MCWHIRTER
11
12
Associate Director KPMG
12. SOLEDAD ANTELADA TOLEDANO
Security Advisor, Office of the CISO, Google Cloud
13. CASSANDRA MACK
Chief Information Security Officer (CISO), TensorWave
13
14
14. CRAIG FORD
Head Unicorn – Cofounder and Executive Director, Cyber Unicorns. Australian Best Selling Author of A Hacker I Am, Foresight and The Shadow World book series. vCISO – Hungry Jacks, Wesley Mission, PCYC and Baidam Solutions
15
16
15. ADRIANA JONES
Engineer, cybersecurity advocate and founder of The Innocent Souls Project (TISP)
16. JO STEWART-RATTRAY
Oceania Ambassador, ISACA
17
18
17. JOANNE COOPER
Founder - ID Exchange
18. LISA VENTURA MBE FCIIS
Chief Executive and Founder, Unity Group Solutions Limited/AI and Cyber Security Association
122
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
19
20
19. MARINA TOAILOA
Founder- Mummy Safety Security Project
20. RYAN FOX
Security Engineer
21
22
21. JAY HIRA
Cyber Director – Financial Services, KPMG
22. SHRUTI KAMATH
Consultant, Business Resilience, KPMG
23. ERIN CARROLL
23
24
Consultant, Business Resilience and Cyber Risk, KPMG
24. KAREN STEPHENS
CEO and co-founder of BCyber
25. RAJANI ARJULA
Director, Cyber Delivery at Anchoram
25
26
26. POOJA SHIMPI
Cybersecurity GRC Lead | AI Governance | Global Council for Responsible AI Ambassador for Australia
27. MADHURI NANDI
27
28
Madhuri Nandi, Head of security at Nuvei, AWSN Board Chair, author of Cyber Smart
28. PAIGE HAINES
Bachelor of Cyber Security student at Deakin University
29. PRAJOTI RANE
29
30
Master’s student in Cybersecurity at Worcester Polytechnic Institute (WPI)
30. TANVI BADGHARE
B. Tech in Computer Science and Engineering student at VIT Bhopal University, India
31
32
31. AMY KORALIS
Bachelor of Cyber Security and a Bachelor of Laws student at Macquarie University
32. ASHLEY MATHEW
Bachelor of Cybersecurity student at Deakin University in Melbourne.
33
34
33. QUEENETH ONYIKE
Accountancy student at the University of Nigeria, Nsukka
34. DANAH MOHAMMED ALKHAN
Cybersecurity student at the University of Bahrain
35. LISA ROTHFIELD-KIRSCHNER
35
I S S U E 28
Author of How We Got Cyber Smart | Amazon Bestseller
WOMEN IN SECURITY MAGAZINE
123
SURFING THE NET
BREAKING BARRIERS IN CYBER: AN IMPACTFUL JOURNEY WITH WCS2 By Women cyber security Society Meet Attracta, an aspiring cybersecurity professional from Calgary, Alberta. Not long ago, Attracta was looking to pivot into the cybersecurity field but wasn’t sure how to break in. When she came across a post on LinkedIn about the Women CyberSecurity Society (WCS2) Scholarship Program, she felt a spark of hope.
READ BLOG
WHO OWNS THE CYBERSECURITY OF SPACE? By Maryam Shoraka As a cybersecurity professional, I have spent decades watching humanity build digital castles without moats. We did it with the internet, with artificial intelligence and with critical infrastructure. Now, we are doing it again, this time in orbit. We are racing to commercialize space to connect the unconnected and monetize orbit, yet we are ignoring the most important question: Who owns the cybersecurity of space?
READ BLOG 124
W O M E N I N S E C U R I T Y M A G A Z I N E
CYBERSECURITY IN THE DIGITAL AGE: THE ROLE OF WOMEN IN SHAPING TOMORROW'S SECURITY By Lisa Kearney In the spring of 2018, after more than 20 years in cybersecurity, I found myself questioning my place in the field. I wondered if I truly belonged, whether I should pursue something else, and why the journey felt so difficult and isolating.
CYBERSECURITY IN 2026: AI-DRIVEN ATTACKS, DEEPFAKES & MORE By CyberPedia (Satarupa Dutta) Hi Readers! The future of cybersecurity in 2026 is changing fast and frankly speaking, it is getting out of control. The digital world of humans is changing with AI-generated attacks that travel at a higher speed than humans can react to deepfakes that seem incredibly authentic. This is what the new threat age will appear like.
READ BLOG
READ BLOG
SOCIAL ENGINEERING TACTICS: HOW TO SPOT AND STOP THEM
FROM NETWORKING TO ETHICAL HACKING: THE BEST CAREER PATH TO CYBER SECURITY
By Ford Leadership & Cyber Resilience In the complex world of cybersecurity, the greatest vulnerability isn’t a piece of code; it’s human psychology. Social engineering is the art of manipulating people into divulging confidential information or performing actions that compromise security. These attacks bypass technical defenses by targeting the natural human tendencies to trust, help, and respond to urgency.
READ BLOG
By Network Bulls With increasing data breaches, ransomware attacks, and digital espionage – cybersecurity has become one of the most critical and rapidly growing career fields. Companies all over the world are hiring skilled professionals who can secure networks, mitigate threats, and outsmart cybercriminals.
READ BLOG J A N U A RY • F E B R U A RY 2026
THE INCREDIBLE SHRINKING SHELF LIFE OF IT SKILLS By CIO (Mary K. Pratt) The accelerating pace of technical innovation is driving rapid turnover in the skills necessary for organizational success, leaving IT leaders and individual professionals uncertain about where to place their upskilling bets.
READ BLOG
LOST IN THE CLOUD: WHAT HOME ALONE 2 TEACHES US ABOUT CLOUD SECURITY By (Red Canary) Laura Brosnan The festive season is in full swing, which means the Home Alone series is likely top of mind for many of us. It got me thinking about how Kevin McCallister really is a quintessential figure head of proactive defense. As I argued in my original blog, the pint-sized defender is masterful at analyzing his environment and preparing for the inevitable. Such wisdom can also apply to the cloud. So, I’m doubling down and leveling up. Think of this as his sequel adventure.
READ BLOG I S S U E 28
THE WIRED GUIDE TO DIGITAL OPSEC FOR TEENS By WIRED (Lily Hay Newman) Teenagers have always been formidable hackers. In fact, in recent years, some of the most high-profile and brazen digital attacks around the world have been carried out by teens. But even if you're not a hacker, you’re probably still a prolific user of digital tools and social platforms.
READ BLOG
MALWARE, ZERODAYS & NATIONSTATE INTRUSIONS By Openvpn ( Heather Walters) Cybersecurity has been especially active over the last 7 days. From new backdoors to critical zero-day patches and new ransomware trends — the threats keep coming. Here are the top stories you should know about.
READ BLOG
IT SECURITY IN TWO EASY STEPS
AI: LACKING GUARDRAILS, TALENT, AND RESOURCES?
By Acronym Solutions Inc.(Jeff Farley)
By Forta (Gina Cardelli)
It’s not just the frequency of attacks that’s escalating; it’s also the complexity and impact. According to Security Intelligence, we’re seeing more double extortion and even triple extortion strategies to ensure the success of a ransomware attack. These attacks first steal a copy of your data, such that not only are your systems and data held ransom, but your entire backup set and those who would not want to see it published are targeted.
AI adoption is accelerating faster than governance maturity can keep pace. Many companies are still integrating responsible AI practices rather than treating them as a standard operating discipline. Deloitte reported that nearly twothirds of entities have adopted generative AI without establishing proper governance controls. That ultimately means a growing field of more blind spots: unmonitored or unsanctioned usage, insufficient oversight, and compliance risks that surface only after the fact.
READ BLOG
READ BLOG WOMEN IN SECURITY MAGAZINE
125
TURN IT UP
INSIDE THE CYBER GUILD: HOW DEBBIE SALLIS EMPOWERS CYBER LEADERS With IMPACT Podcast Series In this episode of IMPACT: Women in Leadership, host Mary Ann Brown continues her conversation with Debbie Sallis, Founding Executive Director of The Cyber Guild Foundation, to explore how mentorship, leadership, and community are reshaping the future of cybersecurity.
With CLICK HERE PODCAST Recorded Future News’ awardwinning Click Here podcast tells stories about the people making and breaking our digital world. Hosted by former NPR Investigations correspondent Dina Temple-Raston, we introduce listeners to the shadowy characters behind ransomware attacks, disinformation campaigns, and hacks to the people trying to stop them.
CLICK TO LISTEN
CLICK TO LISTEN
MOLLIE BREEN: ACCELERATING OT SECURITY, RELIABILITY AND EFFICIENCY
WHY BUSINESSALIGNED SECURITY WINS
With The PrOTect OT Cybersecurity Podcast In a recent episode of PrOTect OT, Mollie Breen, the dynamic founder and CEO of Perygee, sat down to discuss her journey into the realm of OT (Operational Technology) security.
CLICK TO LISTEN 126
MIC DROP: A FORMER NORTH KOREAN HACKER SPEAKS OUT
W O M E N I N S E C U R I T Y M A G A Z I N E
With Be Fearless Podcast Coleen Coolidge, ex-CISO of Segment and Twilio and startup advisor, didn't start in cybersecurity - she was a new project manager who got thrown into the deep end, but that discomfort launched an 18-year career that would see her build security teams from scratch at companies like Segment and Twilio
CLICK TO LISTEN
POST-THANKSGIVING LEFTOVERS: A SMORGASBORD OF RANDOM TOPICS WITH LAURA AND KEVIN With That Tech Pod This week’s post-Thanksgiving episode is a full smorgasbord of random stories, internet rabbit holes, and tech-adjacent tangents. Laura and Kevin skip the usual guest and run through a pile of listener-requested topics.
CLICK TO LISTEN
CYBERSECURITY HAS LOST THE PLOT With Down the Security Rabbithole Podcast This week's pod features your favorite hosts reflecting on how security has lost its way. When everything is a catastrophe, nothing is. When every breach is world-ending, none of them matter. Have we completely lost the plot? Prepare to have a good think.
CLICK TO LISTEN J A N U A RY • F E B R U A RY 2026
AI-FIRST VULNERABILITY MANAGEMENT: SHOULD CISOS BUILD OR BUY? With Cloud Security Podcast Thinking of building your own AI security tool? In this episode, Santiago Castiñeira, CTO of Maze, breaks down the realities of the "Build vs. Buy" debate for AI-first vulnerability management.
CLICK TO LISTEN
BUILDING TRUST AND COMPLIANCE: GUIDING A CLIENT TO CMMC LEVEL 2 CERTIFICATION With SEISO podcast In this episode, we take you behind the scenes of how our team helped a client successfully achieve CMMC Level 2 certification. From assessing gaps and aligning controls to overcoming legacy system challenges and navigating the audit process, we break down each step of the journey. You’ll hear how collaboration, governance, and a clear security roadmap turned a complex compliance goal into a milestone achievement.
CLICK TO LISTEN I S S U E 28
WHEN CYBER CAMPAIGNS CROSS A LINE With Risky Business podcast Tom Uren and Patrick Gray discuss a new report proposing a framework for deciding when cyber operations raise red flags. It suggests seven red flags and could help clarify thinking about how to respond to different operations.
THE CYBERSECURITY DEFENDERS PODCAST With The Cybersecurity Defenders Podcast A podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe to the show wherever you listen to podcasts!
CLICK TO LISTEN
CLICK TO LISTEN
FROM FBI TO CYBERSECURITY LEADER: M.K. PALMORE'S CAREER JOURNEY | BREAKING INTO CYBERSECURITY
MEET THE INCIDENT RESPONSE CHAMPIONS
With Breaking Into Cybersecurity In this episode of Breaking Into Cybersecurity, M.K. Palmore, a cybersecurity leader and former FBI special agent, shares his journey from serving in the Marines and the FBI to leading his own consulting firm, Apogee Global RMS.
CLICK TO LISTEN
With Australian Cyber Voices: The Official AISA Podcast In this episode of Cyber Voices, David Willett chats with former participants of the Australian Women in Security Network (AWSN) and Retrospect Labs Incident Response Competition. The panelists, including competition winners and runnersup, share their transformative experiences in this hands-on, teamwork-based event.
CLICK TO LISTEN WOMEN IN SECURITY MAGAZINE
127
OFF THE SHELF
CYBER SAFE GIRL Author // DR.Ananth Prabhu G Cyber Safe Girl is a handbook, curated to help the netizens to browse the internet responsibly. As the whole world moving online, the need for responsible browsing is very crucial as during the pandemic, there has been a sudden spike in cases of online frauds, scams and threats.
BUY THE BOOK
STRONGER TOGETHER: WOMEN IN CYBERSECURITY Authors // David Meece, Emily Zakkak, Lynn Dohm, and Gabrielle Botbol This book throws open the doors to the world of IT and Cybersecurity, celebrating over 100 accomplished women who have carved their own paths in these dynamic fields. It's not just a chronical of their achievements, though each story delves into the unique challenges they faced, offering invaluable insights and stereotypes.
BUY THE BOOK
CYBER SECURITY SECRETS: GET THE FIRST CYBER SECURITY JOB Author // Fae Donn If you're keen on PCs and want to find a new line of work in Cyber Security, this book is most certainly for you. It gives the alternate ways and mysteries to accomplish $100,000 per year in Cyber Security. It is worked to clear up how to accomplish your objective as quickly as conceivable with as little obligation as could be expected.
BUY THE BOOK
IN SECURITY Author // Jane Frankland Women matter in cybersecurity because of the way they view and deal with risk. Typically, women are more risk averse, compliant with rules, and embracing of organisational controls and technology than men. They're also extremely intuitive and score highly when it comes to emotional and social intelligence, which enables them to remain calm during times of turbulence - a trait that's required when major security breaches and incidents occur.
BUY THE BOOK
128
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
MIND THE TECH GAP Author // Nikki Robinson IT and cybersecurity teams have had a long-standing battle between functionality and security. But why? To understand where the problem lies, this book will explore the different job functions, goals, relationships, and other factors that may impact how IT and cybersecurity teams interact.
BUY THE BOOK
THE ART OF ATTACK Author // Maxie Reynolds In The Art of Attack: Attacker Mindset for Security Professionals, experienced physical pentester and social engineer Maxie Reynolds untangles the threads of a useful, sometimes dangerous, mentality.
BUY THE BOOK
BUILDING A CYBER RISK MANAGEMENT PROGRAM: EVOLVING SECURITY FOR THE DIGITAL AGE Authors // Brian Allen, Brandon Bapst, and Terry Allan Hicks Cyber risk management is one of the most urgent issues facing enterprises today. This book presents a detailed framework for designing, developing, and implementing a cyber risk management program that addresses your company's specific needs. Ideal for corporate directors, senior executives, security risk practitioners, and auditors at many levels, this guide offers both the strategic insight and tactical guidance you're looking for.
BUY THE BOOK
CYBER PERSISTENCE THEORY: REDEFINING NATIONAL SECURITY IN CYBERSPACE Authors // Michael P. Fischerkeller, Emily O. Goldman, and Richard J. Harknett Most cyber operations and campaigns fall short of activities that states would regard as armed conflict. In Cyber Persistence Theory, Michael P. Fischerkeller, Emily O. Goldman, and Richard J. Harknett argue that a failure to understand this strategic competitive space has led many states to misapply the logic and strategies of coercion and conflict to this environment and, thus, suffer strategic loss as a result.
BUY THE BOOK
I S S U E 28
WOMEN IN SECURITY MAGAZINE
129
OFF THE SHELF
SILVER AND CYBER SECURE: A QUOTE COLLECTION FOR STAYING SAFE AND SAVVY ONLINE. Author // Alexa Blake This isn’t about mastering passwords or learning tech tricks—it’s about protecting peace of mind in a connected world. Silver and Cyber Secure blends everyday wisdom with digital mindfulness, helping readers stay informed, confident, and calm in the online age.
BUY THE BOOK
CYBER EXPLORERS: SECURITY & ARTIFICIAL INTELLIGENCE IN THE 21ST CENTURY Authors // Joby James, and Dr Diya Abraham In this book, you will discover how to:
✨ Protect your personal information like a secret treasure. ✨ Outsmart cyber-villains by using your digital superpowers. ✨ Explore the amazing world of Artificial Intelligence (AI). ✨ Be kind online and help make the internet a safe, happy place. ✨ Discover the fun side of cybersecurity and even future careers! BUY THE BOOK
THE ABC'S OF CYBER SECURITY: FUN, FACTS, AND SMART LESSONS FOR THE DIGITAL GENERATION Author // Sarah Kore Introducing the ultimate resource to teach young children the crucial basics of internet safety and cyber security! In a world where digital devices are everywhere, "The ABC's of Cyber Security" uses bright, engaging illustrations and easy-to-understand language to transform complex security concepts into fun, foundational lessons.
BUY THE BOOK
CYBER SAMMI'S SAFETY ADVENTURES Author // Brigitte Collier Discover the importance of cybersecurity for kids in our latest book! As technology advances, so do the tactics of cybercriminals targeting young internet users. Parents must stay informed about evolving threats such as AI risks, data privacy loss, cyber threats, and inappropriate content.
BUY THE BOOK 130
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
THE LEARNING HUB MANAGING CYBERSECURITY INCIDENTS AND DISASTERS Most organizations plan for routine operations, but what happens when unexpected events overtake the routine? This course examines contingency planning used to prepare for and manage non-normal operations, including cybersecurity incidents – like hacking attempts, web site defacement, denial of service attacks, information disclosures; a well as other natural and man-made cybersecurity disasters.
VISIT HERE
CYBERSECURITY TRAINING FOR IT PROFESSIONALS The no-cost curriculum includes all courses to support security-driven networking, adaptive cloud security, AI-driven security operations and zero-trust network access. Completion of these courses will help cybersecurity professionals defend their networks against the widest range of ever changing threats.
VISIT HERE
SECURE CODING 101: JAVASCRIPT In the Secure Coding 101: JavaScript Module, you will learn how to improve the security of your JavaScript code through reverse engineering advanced JavaScript obfuscation functions and identifying hard to find vulnerabilities, and learning how to patch them properly.
VISIT HERE
ANALYZING DATA In this course, you’ll learn key skills and tools for data analytics, including spreadsheets, structured query language (SQL), R programming, and Tableau. You will also understand the daily tasks of a data analyst and explore the kinds of jobs you could pursue after completing this program.
VISIT HERE
I S S U E 28
WOMEN IN SECURITY MAGAZINE
131
THE LEARNING HUB CYBERSECURITY FOR BUSINESSES THE FUNDAMENTAL EDITION Are you a small business owner who is worried about being hacked? Are you confused about where to start and how to begin? Have you been looking for a course that teaches you the information/cybersecurity basics to best protect your business in a fun, relaxed manner? If so, you are going to find that this course is absolutely perfect for you!
VISIT HERE
IT & CYBERSECURITY FOUNDATIONS Cybrary’s IT and Cybersecurity Foundations career path will equip you with a strong foundation of cybersecurity knowledge and hands-on skills. Over the course of 30 courses and hands-on virtual labs, you will learn essential IT concepts, security best practices, and the technical skills needed for entry-level IT and cybersecurity roles.
VISIT HERE
UNRAVELING FISMA - CYBERSECURITY WITH REGULATORY FRAMEWORKS The US Government introduced the Federal Information Security Modernization Act in 2002 to protect its precious data. With this Cybersecurity Regulatory Framework Course, students can examine this regulation closely, understand its implications, and learn to perform the FISMA audit.
VISIT HERE
CYBERSECURITY BASICS: TOOLS AND CYBERATTACKS Cyberattacks have surged by 71% and are predicted to continue increasing. This alarming statistic highlights the continued demand for cybersecurity professionals. Jumpstart your cybersecurity career with this introductory IBM course, which introduces you to fundamental cybersecurity concepts, threats, and preventive measures.
VISIT HERE
132
W O M E N I N S E C U R I T Y M A G A Z I N E
J A N U A RY • F E B R U A RY 2026
FEATURING FREE SECURITY TRAINING RESOURCES THAT ARE AIMED AT INCREASING SECURITY AWARENESS AND HELPING PEOPLE BUILD AND UPSKILL THEIR SECURITY SKILLS.
REAL-TIME CYBER THREAT DETECTION AND MITIGATION This course introduces real-time cyber security techniques and methods in the context of the TCP/IP protocol suites. Explanation of some basic TCP/IP security hacks is used to introduce the need for network security solutions such as stateless and stateful firewalls. Learners will be introduced to the techniques used to design and configure firewall solutions such as packet filters and proxies to protect enterprise assets.
VISIT HERE
COMPUTER FORENSICS In this course, you will learn the principles and techniques for digital forensics investigation and the spectrum of available computer forensics tools. You will learn about core forensics procedures to ensure court admissibility of evidence, as well as the legal and ethical implications.
VISIT HERE
CLOUD SECURITY BASICS This course introduces you to cybersecurity for the cloud. We'll learn and apply classic security techniques to today’s cloud security problems. We start with a deceptively simple and secure web service and address the problems arising as we improve it. We’ll analyze recent cloud security vulnerabilities using standard, systematic techniques. We’ll build our own web service case studies and construct security solutions for them. Our toolkit contains classic security concepts like Least Privilege and Separation of Duty, as well as more technical cryptographic and access control techniques.
VISIT HERE
INTRODUCTION TO CYBERCRIME Begin your journey into cybercrime with this cyber crime free course. Explore the various types of cyberattacks faced by organizations today. Understand the intricacies of cybersecurity threats and discover practical preventive measures. Whether you're new to the field or seeking to broaden your knowledge, this course provides essential insights to empower you in defending against cyber threats.
VISIT HERE
I S S U E 28
WOMEN IN SECURITY MAGAZINE
133
J O B B OA R D CD-CYBER SECURITY- CRISIS & RESILIENCE-SENIOR ASSOCIATE | PWC ACCELERATION CENTER INDIA FULL TIME
INDIA
potential threats to an organisation's security, as well as managing vulnerabilities to prevent cyber attacks. You will play a crucial role in safeguarding sensitive information and enabling the resilience of
ABOUT THE JOB
At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to digital infrastructure. identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. In threat intelligence and vulnerability management APPLY HERE at PwC, you will focus on identifying and analysing
EXPERIENCED - CYBER DATA PROTECTION | DELOITTE FULL TIME
ITALY
• Face and solve customer challenges in innovative and effective way The Experienced resource will be integrated into a work • Engage with internal and external stakeholders team and responsible for: to strengthen business relations and create • Manage data protection activities within wider business opportunities projects, identifying, evaluating, and designing best in class data protection solutions, demonstrating operational excellence, vision and strategic thinking APPLY HERE • Execute complex project activities, coordinate part of the team while supporting your more senior colleagues in managing client relations and expectations YOUR ROLE
DIRECTOR OF SECURITY | REMOTE FULL TIME
SOUTH AFRICA
KEY RESPONSIBILITIES • Define, implement, communicate and maintain security strategy, policies, goals and requirements aligned with business strategy, and manage security resources, to support the company’s objectives • Work with the Security Council and Remote’s senior leadership in developing Remote’s Information Security vision, strategy and road-map of Remote’s Security function • Recruit and nurture individual growth to build an autonomous and high performing Security team
134
W O M E N I N S E C U R I T Y M A G A Z I N E
• Be an advocate of information security best practices and proactively looking to improve and drive Remote’s security posture, driving efforts to improve Security Awareness across company • Drive Remote’s security risk management program, by partnering with Legal, Data Protection and Finance in developing and managing our enterprise risk management framework(s), and collaborating with senior leaders in reducing Information Security risks
APPLY HERE
J A N U A RY • F E B R U A RY 2026
SENIOR CYBERSECURITY RISK ANALYST | DRAPER FULL TIME
UNITED STATES OF AMERICA
JOB DESCRIPTION: • Serve as a subject matter expert for cybersecurity risk management and compliance frameworks including NIST SP 800-171/53, DAAPM, CMMC, RMF • Develop and implement consistent, high quality System Security Plans (SSPs), Risk Assessment Reports (RARs), Plans of Actions & Milestones (POA&Ms) and Standard Operating Procedures (SOPs) across the enterprise classified IT portfolio • Perform Security Control Assessments for enterprise classified systems, oversee implementation
of corrective actions and provide remediation strategies where relevant • Work closely with the Office of Threat Management (OTM) to conduct vulnerability assessments and threat analysis of the IT portfolio. Furthermore, monitor, evaluate and report on cybersecurity risk, incident response actions, and compliance gaps
APPLY HERE
L2 SOC ANALYST | CISOMETRIC FULL TIME
INDONESIA
RESPONSIBILITIES : • Investigate and validate escalated alerts from L1. • Perform deep-dive analysis using SIEM, EDR, firewall, and cloud security tools. • Correlate logs to identify IOCs, attack chains, and help L1 to define true/false positives. • Execute containment actions (host isolation, account lock, block IP/domain). • Escalate major incidents to L3/IR teams when required. • Conduct proactive threat hunting based on intel or nomalies.
• Reporting & Documentation: Maintain accurate tickets, timelines, and incident reports aligned with SLAs. • SIEM Tuning & Optimization: Reduce noise, refine detection rules, propose new use cases. • Mentor L1 analysts and support process improvements.
APPLY HERE
ASSOCIATE ADVISOR - CYBER RESILIENCE CONSULTING | SAEPIO INFORMATION SECURITY FULL TIME
UNITED KINGDOM
WHAT YOU WILL BE DOING As an Associate Advisor, your responsibilities will typically include: • Assessment and Advisory Delivery • Conduct cyber assessments through Saepio’s digital platform • Review client systems, policies, and controls to identify strengths and gaps
I S S U E 28
• Support the creation of tailored reports and security improvement roadmaps • Present findings to clients, providing clear and practical recommendations • Client Engagement
APPLY HERE
WOMEN IN SECURITY MAGAZINE
135
J O B B OA R D SENIOR CONSULTANT OR MANAGER, DIGITAL FORENSICS & INCIDENT RESPONSE - CYBERSECURITY | BDO CANADA FULL TIME
CANADA
As a Senior Consultant or Manager, in Digital Forensics & Incident Response on BDO’s Cyber Threat Management & Response team, your responsibilities will include: • Leading complex incident investigations and forensic engagements: endpoint, network, cloud-native environments, memory, disk, and log analysis. • Performing digital forensic examinations across multiple operating systems and devices using industry-standard tools (e.g., EDR/EDR-forensics, EnCase, Rekall, Wireshark, etc.).
• Collecting, analyzing, and maintaining critical data sources including system logs, network traffic captures, EDR telemetry, threat intelligence feeds in order to support investigations and remediation. • Interpreting forensic artifacts, identify Indicators of Compromise (IoCs) and adversary Techniques, Tactics & Procedures (TTPs), and producing actionable intelligence.
APPLY HERE
THREAT INTELLIGENCE & CYBERSECURITY MANAGING CONSULTANT, STRATEGY & TRANSFORMATION – ADVISORS | MASTERCARD FULL TIME
BRAZIL
ROLES AND RESPONSIBILITIES • Delivery of client projects and solutions for assessing and improving threat intelligence programs, assess risk exposure, identify threat landscape, protect against attacks, and orchestrate continual improvements of cybersecurity and threat intelligence programs. • Assist with sales and product management activities such as technical pre-sales support and creation of products bundles.
• Led definition and development of deliverables to solve client problems, address and communicate difficult client situations, and produce actionable recommendations. • Create positive team environment and support collaboration across multiple teams to produce outstanding deliverables.
APPLY HERE
DIRECTOR CYBER SECURITY | FINDR FULL TIME
GERMANY
This is a senior role reporting directly to the CTO. You’ll lead a talented Cyber Security team, drive the security roadmap, and play a key part in shaping how a regulated financial business protects its most critical systems. IF YOU WANT TO: • Define and deliver security strategy in a highly regulated, tech-driven environment • Lead and develop a strong cyber team while staying hands-on when needed
136
W O M E N I N S E C U R I T Y M A G A Z I N E
• Work with cutting-edge technology in the digital asset and trading space • Collaborate directly with engineering, risk and compliance teams • Influence decisions at board level • …then this is a great opportunity to make an impact at scale.
APPLY HERE
J A N U A RY • F E B R U A RY 2026
DEVOPS / CLOUD PLATFORM ENGINEER | ONEREG FULL TIME
NEW ZEALAND
WHAT YOU’LL BE RESPONSIBLE FOR • Designing and maintaining cloud infrastructure • Improving CI/CD pipelines and deployment processes • Monitoring, alerting, and incident response • Ensuring security, reliability, and scalability
• Supporting engineers with tooling and best practices
APPLY HERE
FIELD CHIEF INFORMATION SECURITY OFFICER | LENSA FULL TIME
UNITED STATES OF AMERICA
ROLE DESCRIPTION • Develop and implement an information security strategy that aligns with the organization's goals and objectives to ensure comprehensive protection of information assets. • Oversee the development and enforcement of security policies to ensure that all security policies, procedures, and protocols are up-to-date and effectively implemented across the organization. • Lead risk management efforts by identifying, assessing, and mitigating information security risks
to protect the organization from potential threats and vulnerabilities. • Manage incident response and recovery by developing and overseeing the execution of incident response plans to address security breaches and ensure timely recovery.
APPLY HERE
IT SECURITY ARCHITECT | THERMO FISHER SCIENTIFIC FULL TIME
HUNGARY
KEY RESPONSIBILITIES: • Design and implement secure remote access solutions, including VPNs, VDI, and other remote access technologies. • Develop and enforce remote access security policies and procedures. • Conduct regular security assessments and audits to identify vulnerabilities and ensure compliance with security standards.
• Collaborate with IT and business teams to integrate security measures seamlessly into remote access systems. • Monitor security information and event management (SIEM) systems to detect and respond to security incidents. • Investigate and mitigate security incidents related to remote access.
APPLY HERE
I S S U E 28
WOMEN IN SECURITY MAGAZINE
137
Support the Future of the
AUSTRALIAN WOMEN IN SECURITY AWARDS
®
We need your support to continue this important initiative into its 8th year.
The 2026 Awards will be hosted in Melbourne. To ensure this initiative continues, we invite you to partner with us as a sponsor.
NSORSH
I
Packages ava ilable from $6,000 to $50,000 Custom pack ages tailored to your organisa tion’s needs
PP
O
Your sponsorship will help us continue to celebrate and elevate the achievements of women in security across Australia.
O SP
P
JOIN US IN MELBOURNE FOR 2026
ORT
IE U NIT
S
To discuss how you can support and sponsor next year’s awards, please reach out to Aby at Aby@source2create.com.au. We look forward to partnering with you to make the 2026 Australian Women in Security Awards our best yet.