Boosting Diversity in Cybersecurity with WiCyS’s Lynn Dohm
Lynn Dohm talks about accessibility and inclusivity challenges within today’s cybersecurity landscape; the importance of leveraging diverse mindsets, skill sets and perspectives; and how to meaningfully improve the recruitment, retention and advancement of women in cybersecurity.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Techstrong tv.
Our next guest is Lynn Dome. Lynn is the executive director of an organization called We sis. We're gonna learn all about it, but first we're gonna learn a little bit about Lynn.
Lynn, welcome to Techstrong tv. It's great to have you here. Thanks so much for having me, Alan.
So I mentioned Wi Sis, but we'll jump into that in a second. Let's hear a little bit about you. Sure, sure.
So, um, you know, I'm executive director of the WIS organization. I've had a long history with women in cybersecurity. We often go by our acronym, W-I-C-Y-S, pronouncing it.
We sit just like you did 'cause we're a global cyber sisterhood. But my journey into cybersecurity workforce initiatives really started about 15, 16 years ago now when I started working on a government grant in cybersecurity. So it was my first introduction to cybersecurity in general, and it was fascinating to me.
I was instantly just hooked on it because everyone that was working on these different type of training programs and skill development training programs, upskilling and reskilling, you know, individuals to go into cybersecurity, they were so tuned in and tapped into the good work that they were doing when they were working into the, into the many different cybersecurity initiatives. There was such a, a hyperfocused, it was ever evolving. It was so completely changing.
Um, and everyone was just had this heightened level of excitement around the workforce and the work that they were doing. And so I really resonated with the workforce initiatives within cybersecurity, and that's how I just navigated throughout my career. I started at, in Chicago based office where the national cyber for systems security and information assurance.
And I went to many different nonprofits for-profits and government grants working on why is there a workforce shortage, why wouldn't anyone wanna be in cybersecurity? And what is the big barrier and challenge to get women and underrepresented individuals into the cybersecurity workforce? And that's my niche area where I just stayed throughout my career.
And around 2015, I started working in a support capacity for wiis. And it wasn't until 2018 that I attended my first WIIS conference. You know, WIIS started as a conference, now we're a nonprofit.
But I attended my first conference in 2018, and it was really truly life changing. It was the first time in my career where I had camaraderie, where I had a network, a community was formed, and my career advanced very significantly throughout that year. And, um, in August of 2019, the founder sent me a message asking me if I would consider applying for executive director roles.
So it was the first time in my life that I had this opportunity where I could merge my passion and my career into one. And that's how I became executive director October of 2019. And it's been going strong ever since.
Five years. Five years later. Huh.
Good for you. What a great story. You know, so Lynn, I've been in security a long time, right?
I, I started in insecurity 1990, late nineties. And back then, I will tell you, you wanna know the truth. Back then you saw an occasional woman, Right?
But everybody in security was weird. The men, the women, whether they identified as men or women or whatever, it was a lot of weird people in security. For whatever reason, we, and maybe that's why I was attracted to it, but we attracted a lot of like alternative alt people and people who had different outlooks on life.
And then security sort of went mainstream in the early two thousands, right? It became a thing. And, um, you know, we didn't call it cyber that was InfoSec or just security.
And all of a sudden I think people started noticing there's not a lot of women here. There's like a, a sausage factory, there's all guys here. And and then when women did start coming, a lot of these, let me back up.
My wife's a social worker. Mm-Hmm. When I first started taking her to RSA and security shows, remember on the way home one year, she said, you realize most of your friends are on the spectrum.
I said, what do you mean? She said, yeah, no, they're, they're functional, highly functional people, but you know, most of these guys are. And I said, all right, I guess I am too.
Right? And, and I think a lot of the guys had trouble were not trouble, but they didn't interact well with women and, and not only not interacting well, but there became this undercurrent of, of harassment. And I think some of them weren't doing it with the intention of harassing.
They just didn't know how to speak to women. You know, not that you need to speak special to women, but you don't have to be an, I don't want to use bad words, but you don't have to be an idiot. Right.
Just because someone you're talking to isn't a man. Mm-Hmm. And, and there was a lot of that.
And, and I started hearing stories from some of my friends in the cyber industry who were women about being harassed, people not taking no for an answer, being diminished because they weren't a man. And, and these kinds of things. At the same time, you'd go to these security shows and they would be Booth babes and those would be the only, the predominant women on the show floor were women dressed, you know, provocatively or as Booth babes or because they weren't smart enough.
They were as smart as everyone else. But, so there was that period that I think gave rise to conferences like Wiis and Women Who Code. And you know, a lot of my friends who, who I, I, I think my friend Chen Wang and, and Jennifer Manila and, and Aaron, uh, s Sec Barbie and, and a lot of these women who were icons, I think in security back then, but how to work five times as hard to get half as high Mm-Hmm.
As, as their male counterparts. So it does my heart good that today I feel like we really made a lot of, and I'm sorry for going on this whole tangent, but I, I does my heart good that we've made the progress we've made Mm-Hmm. I'm not saying the job is done.
I'm not saying all is beautiful in the world, but we're a lot better now about it than we were, let's say 10 years ago. Right? And, but we still have issues.
And by the way, it's not just women. There's, there's a lot of underrepresented communities Mm-Hmm. In, in, in this cybersecurity world.
So I got that off my chest, chest. But now going forward, what do we have to do to continue the progress that's made and, and kind of get to where we need to be? Yeah.
So, uh, I mean, to your point, 10 years, 10 years is a, a long amount of time as a decade. And when we started as just a conference, a cybersecurity conference in 2014, we started because women represented 11% of the cybersecurity workforce at that time. Yep.
Now, our founder, Dr. Amber Raj, who is at Tennessee Tech University at that time, she reached out for the first grant for the WIIS conference to start because she wasn't even seeing the mere 11% within her circles of industry, academia, and government. And so her idea was, if women in cybersecurity exist, let's bring them together for a technical conference so we could learn and grow together.
And so the community was formed and that technical conference continued to move forward after the grant funding was done, then a lot of big companies that really enjoyed it and saw the value in it continued to invest into it. But in 2018, ISC two reported that women still represented that mere dark gray, 11% of the workforce. So although we were seeing the traction and the progress within our community gathering together and growing, we weren't seeing it in the workforce in general.
And that's why we became a nonprofit in 2018. In 2019. Um, and beyond about for the past five years, we've staggered between that 20 to 24, 20 5% in the workforce.
So for our mission is to recruit, retain, and advance women in cybersecurity. We know we could recruit all we want, but can we retain and what does that advancement look like? And to your point about historically, cybersecurity has not been a, a, a very, uh, inclusive space, not a very, um, welcoming space for whatever reason it may be.
And so for whatever those reasons might be carried on into that workforce, they still remain. And so, because our mission is to recruit, retain, and advance, we wanted to look at that retention and the advancement piece. So we started peeling back the layers and really started looking at what is the state of inclusion for women in cybersecurity?
And how could us as a nonprofit start breaking down some of those barriers too? And also provide data so that employers have some responsibility as well, because there's no sense in putting out initiatives unless, you know, the actual, pinpoint the actual barriers. So we could talk about diversifying the workforce all we want, but inclusion is a very complicated 'cause.
Inclusion is a feeling and it's only felt when you're excluded. So we knew for us, it was hard for us to bring state of inclusion for women in cybersecurity on employers radar when the likelihood of executives, the higher that they rise in their careers, you know, the higher that individuals lives in their careers, the less experiences of exclusions they had. So therefore, how could we expect them to be aware of inclusion when they're not even experiencing exclusion anymore?
And so we thought it was extremely important to provide data metrics, measurable points. And so that's why we partnered with Ely in 2023 last year to quantify the experiences of exclusion and identify the state of inclusion for women in cybersecurity. And the report was really eye-opening, really eye-opening.
And now employers could read that report and they could put intentional initiatives in place that would help overcome those barriers and be extremely intentional. Because we know that when you have attrition on your teams, that comes outta the recruitment dollars, it reduces productivity, that it decreases creativity and innovation on those teams. And the reason why the diverse mindsets and perspectives are so important to those cybersecurity teams is in order to solve challenges that have never previously existed, you need not only all genders, but its ethnicities, cultures, backgrounds, experiences, and more.
So the value that women, for us were for women and non-binary individuals bringing to cybersecurity is very extreme. And so we, we not only wanna create accessibility for more women to enter in, but we want to also ensure that there's an inclusive space where everyone belongs and advancement and growth opportunities are there. So some key findings of that report is that the obvious findings that you likely already know is that women are twice as likely to be excluded, um, than men.
Um, but what was really interested in, in, for us that Elyria are researcher partner that they haven't seen in any other industry is that 57% of the individuals, you know, we had over a thousand, um, participants in the, in the, um, in the, um, uh, benchmark report, uh, that was produced at the beginning of this year for 2023. But, um, but what was interesting is that career growth and advancement is the second source of exclusion that they don't see in any other industry. And that also aligns that women are experiencing a glass ceiling at around six years within their career.
So you could imagine what the culprit, what those issues might actually be contributing to that likely getting passed up for promotions. I mean, we all know about potential microaggressions, unconscious bias, maybe sometimes conscious bias to your point on how, you know, how the industry once was. Um, and, but then there's things like being passed up, promotion time and time again.
Yeah. Being undervalued on the team, being, um, not utilized to the best of your capabilities to be just assumed that you're accepting status quo, uh, for others to, uh, take ownership for some of your contributions. Those are all things that, uh, you know, kind of start, uh, it's like death by a thousand paper cuts after a while.
And when you're not seeing a really clear trajectory and career and growth advancement within a particular organization, you'll start looking otherwise. And so that's Weiss now has this report and this data and this metrics for individuals and companies and leaders in this space to pay attention to. And instead of throwing initiatives out there for their companies to overcome some of the challenges, they could be now extremely intentional with the data that we're able to produce for them.
Love it. org. org.
Dot org. org? Yes.
We have it under initiatives. We have the state of inclusion. You guys are gonna be at the RSA conference?
We are, we are gonna be there. So we will be all over RSA. There's, we have some presentations, uh, that got accepted and we'll be at many different events.
We'll be hosting an event. So I'll be sending you an invite, Alan, for you to be Well, We're, we're at broadcast alley all week. I want to see you there in person and let's catch up more there.
I would love it. Alright. Right.
We'll have your people call my people and we'll make it happen. That sounds great. That Sounds alright.
Lynn, thank you so much for coming on. This was really good. Um, as I said before, look, I'm, I'm a caveman.
I've been in this business all long and I've seen, I've seen real progress, but there's so much more. We didn't even discuss pay inequity to tell you the truth. There's still lots of that out there too in this industry.
But we, you know, you could be a glass half empty or a glass half full kind of guy and progress is progress, but there's more to be made. Thank you so much for coming on and keep up the great work at recess. Yeah, thank you Ellen.
And thank you for being an ally to the organization and bring awareness to the work that we're doing, um, and to the awareness of just, uh, diversifying the workforce in general. So we appreciate you. Thank you.
All right. org. Go check out their latest report and it's a great organization again, to whole get involved with.
We're gonna take a break here on Text Drug tv and we'll be right back.