Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Lynn Dohm, Women in CyberSecurity (WICyS)

Transcript

Thank you for tuning in to today’s TL;DR episode of the Breaking Changes podcast. I’m your host and chief evangelist for Postman, Kin Lane. With Breaking Changes, we explore topics from the world of APIs, but looking at it through the lens of business and engineering leadership. Joining me today we have Lynn Dohm, director at Women in CyberSecurity. Lynn really opened my eyes to the work they are doing to bring diverse voices into the world of cybersecurity, and highlighted some of the ways in which enterprise organizations can diversify their cybersecurity teams and have a greater impact across their operations.

Let’s dive in with the basics. Who are you and what do you do?

Well, my name is Lynn Dohm, and I’m Women in CyberSecurity executive director. We often go by our acronym, WiCyS, and we pronounce it “we sis,” like “we sisters,” because that’s exactly what we are, we are a cyber sisterhood. So our mission is to recruit, retain, and advance women in cybersecurity, and we do so by creating opportunities. So we started as a conference way back when in 2014. It’s hard to believe that prior to 2014 there wasn’t any true inclusion and diversity initiative in the cybersecurity workforce, considering that we’ve always been in a workforce shortage. But there we were. We launched as a conference, it was a proof of concept, great success, we had a wonderful wait list year after year, and we realized that because of that we needed to become a 501(c)(3) nonprofit to provide year-round benefits. So that’s where we’re at right now.

Good to hear. Definitely something that’s needed. And this may be pushing on the obvious, but I think in this industry we need it. What’s generally keeping women from robust careers in cybersecurity? What are some of the obstacles that are out there?

So there’s so many reasons. The gender balance challenges are not just specifically with cybersecurity, but tech careers in general for women. The average woman does step out of a tech career at the age of 35, and 50 percent of them, after five years of being in, are looking to leave their professions. So there are some general challenges, whether or not they be unconscious bias in the workforce, not this inclusive space where trust and happiness and growth opportunities exist, perhaps some microaggressions occur in the workplace. And then also it’s just in general hard for women to be what they cannot see. So it kind of snowballs, the impact of women entering into the cybersecurity workforce when they’re not seeing others, seeing women rising up to leadership positions in the cybersecurity workforce.

So whatever the cases may be, women have made progress in the cybersecurity workforce. So back in 2014 there were 11 percent women in cyber, and now we’re at roughly 20 to 24 percent women in cybersecurity. So progress has been made. But back in 2014 we had 1 million unfilled jobs, and now we have over tripled that, we have 3.5 million, projected close to 4.2 million by 2023. So the need and the demand for the workforce exists. And for WiCyS, we’re a community of women, men, allies, and advocates that have a strong mission and passion to build that cybersecurity workforce. We do so specifically by bringing women into the workforce, keeping them in the workforce, retaining them, and then providing advancement opportunities so they could rise.

So let’s walk through some of the details of that enablement and support that you provide. Are you reaching into university levels, K through 12, or are you targeting women who might be looking for a career transition? How does someone get made aware of the opportunities in the cybersecurity space and get plugged in with WiCyS?

So now that we’re a nonprofit, we have a member base of over 5,400 members, we have representation in over 70 countries, we have 43 professional affiliates—and professional affiliates are mini-WiCyS organizations—and they’re all throughout Africa, Australia, Canada, France, India, Pakistan, the UK, and throughout the United States. And in addition to that, we have over 150 student chapters, and they’re all throughout the world as well. So our mission is to recruit, retain, and advance women in cybersecurity. We do so at that recruitment level of bringing women into cyber, into their education, into their institutions, to learn more and to advance and to be retained on their campuses because of that, but then also into careers as well. So our initiatives and training programs are designed and developed to hit every step of the way, because the recruitment’s important, but the retention is really absolutely critical there.

We don’t want women stepping out of their cybersecurity careers. The cybersecurity workforce can’t afford that. They need the top talent, they need the diversity of thought in order to solve the problems that never previously existed before. We need genders, identities, ethnicities, backgrounds, cultures, experience, and so much more, all hands on deck. So that retention piece is really important there, and that’s by cultivating the community. And then of course providing advancement opportunities, so women aren’t bored in their careers, they know that there’s advancement, they know that there’s trust and hope, and that there’s going to be happiness in the workplace, and that they’re feeling fulfilled and really thriving in the space where they ultimately want to be, and that’s in the cybersecurity workforce. So we hit it every step of the way, whether it’s in community college, college—we even have some high school chapters—but also early careers, middle management, and then CISOs in leadership roles, executives are a part of the WiCyS community too. So you get that really interesting, critical lifecycle that’s important with building up the pipeline and keeping the workforce going strong.

Yeah, I’m guessing it’s pretty critical for women to see themselves at all those levels throughout their career, right? See women in positions of leadership, in policy-making, throughout this, so that they can picture themselves being in that role at a later part of their career, and that helps with that happiness and retention.

Yeah, absolutely. Part of one of the WiCyS initiatives is also providing speaking and media opportunities, and that’s so that we’re a collective voice of women in cyber, we could be what others can see, and that’s the cybersecurity professionals that we are. And in addition to that, when you’re in that leadership and executive role, paying it forward to others—we often say, together we thrive, and as one woman rises, she’s reaching her hand out and bringing another woman with her. So our mentor-mentee program was designed and developed to really hone in on those mentors that are ready to pay it forward and have that shared experience and provide that shared experience with others, so that we can make progress.

So as a startup or an enterprise organization that is realizing the growing need for investment in our cybersecurity efforts and programs, where do we get started in supporting WiCyS and helping make our operations more diverse, so that we have more voices and more eyes and more people on the problem?

So the best place to start is just dive right into the WiCyS organization. Women, men, allies, and advocates, everyone is welcome. And just like folks are navigating through their cybersecurity careers, everyone is navigating through WiCyS membership and what areas resonate with you and where do you find alignment. Within our member portal we have special interest groups like neurodiversity and cybersecurity, data privacy, cybersecurity law, Latinas and cybersecurity. So it’s all about finding that community and where you resonate and what areas your needs are in, and scoping out what those needs are and fulfilling them.

True. How can I try to influence leadership when it comes to cybersecurity and investment in this area? And I find we get a lot of lip service: yes, it’s a priority, yes, it’s a problem, but we’re still seeing—and this is hypothetical, I’m not saying this is the company I work at—we still see corners being cut in to be efficient, to create productivity, and maybe I’m not feeling like security is enough of a priority that it really should be. How do I convince leadership regarding the urgency?

It is a challenge that a lot of companies have, so you’re not the only one that’s witnessing this. In your experience here and there, it is definitely just boiling back and peeling back the layers and continuing to work with the leadership on the educational piece of it all, and bringing awareness to it, and having those crucial conversations, effectively communicate what the needs are and where that needs to be started to fill that void, and just continue to move forward in that direction. There are, just like many areas, there are challenges with cybersecurity and bringing leadership on board to the exact prioritized immediate needs. Sometimes it has significant challenges and significant consequences. But never giving up, and always knowing that educating is part of the process of being a cybersecurity leader.

How do you—because it seems like this is a lot. I approach a lot of organizations dealing with legacy code, legacy infrastructure, modernizing things, and there’s a lot of fear that decomposing the monolith into a smaller system is going to open up more security holes. There’s a lot of concerns around legacy tech. But I feel like there’s also a lot of legacy business and cultural aspects that contribute. So how are you equipping women specifically to have an equal voice, equal footing, when it comes to joining some of these teams that may historically not have the legacy gender makeup, the diversity that’s needed? How are you equipping women to jump into these teams and add value?

So well, first of all, employers are coming to us because they want to make a difference, and they’re reaching out, identifying that the gender diversity and gender balance on their teams isn’t what it should be and isn’t up to par. So the first thing is acknowledging to them that, kudos, they’re paying attention. I was at an event in Ohio last October, and they did a presentation, and afterwards I was sitting next to a CISO, and we were just having a general conversation. He said he was proud that he had 35 percent women on a cybersecurity team. I said, wow, that’s great, that’s above the industry average. And he said that he’s not going to stop until he’s at 50 percent. So it’s like, what are you doing that’s different? He said, I’m paying attention. And so he’s not accepting “there are no women for the workforce,” there’s not an answer to him. He’s not accepting general recruiting practices when they say, here are all your applicants. He’ll say, that’s not good enough, and he’ll challenge the status quo.

So there’s so many systemic, embedded ways that certain businesses do business, but it takes one champion to really just challenge that and build the team that they want to secure the business and defend the company that they’re working for. And that takes really championing and taking a very active role in the hiring practices, and not accepting no, and investing your money in organizations like WiCyS. We just had a conference last week in Cleveland, Ohio, we had 1,700 women in cybersecurity. So we challenge that question of “there are no women in cyber,” and we say, here we are, we exist, and we all get together at a technical conference and learn and grow from each other’s experiences. So it’s about that, it’s about reducing the barriers, bringing up the soft skills, on-the-job tracks, not doing things the old way just because it’s the old way and that’s the way it’s always been done. It’s thinking outside of the box, thinking of cybersecurity, building your team as those folks coming into an apprenticeship, thinking about the soft skills that are needed for women and men, for allies and advocates, to be in this space, to create an inclusive culture.

When you have inclusion, diversity expands. Everyone wants to focus on diversity first, it’s a metric of success, it’s very easy to be a part of that, looking at diversity as a metric. But inclusion is much harder, because it’s only felt, and it’s felt when you’re excluded. When you’re part of an inclusive space, you don’t know when anyone else is feeling excluded, because you’re included. It really does stem from the leadership down, when the leadership takes an active, contributing role of being an advocate, being the voice for women in cyber, being the voice for building a great team with a powerful diversity of thought, of taking those steps and putting their time and contributions in, and what it would take for them to build the teams that they want to have. That’s what makes the difference.

Yeah, that’s powerful. It’s really about us internalizing, seeing the change that we want to see, understanding the value and making the space and making the investment, not just in the technical, in the team growth, but in being present at conferences, being part of the community, and changing the culture of how security’s approached. But it’s difficult, because everything with security is one of those things you don’t really see until things are really bad and have gone south. So it is one of those things that we have to start doing in good times, and have this conversation and invest and keep pushing for that type of diversity and inclusion across the team, so that when, if something does happen, it’s seen, it’s called out, and it’s brought to our attention, and we minimize the damage that’s done. Because this type of long-term investment planning is hard to do when you’re in the moment and you’re trying to move really fast.

And so, the last conference was in person. Is coming to the conference the best way to open our team’s eyes? What’s your best recommendations as far as pushing us over that edge and to change?

So thank you, Vince—and it really brings everyone a part of the community, but it’s one of many different ways. We are a member-based—our membership, and just like navigating through cybersecurity careers, navigating through your membership and what areas really resonate with you all and what areas do you really want to focus your attention on, because there’s so many different initiatives, including our mentor-mentee program. We designed and developed a curriculum to upskill and uplevel women, no matter where they’re at in their careers, preparing them for their next level of advancement. So we have men, women, CISOs, executives, and C-suite leaders in there that are part of this program, obtaining the resources that we provided in the curriculum, holding these conversations, but now being able to carry themselves forward with a stronger sense about them. Champion our own community. We provide that opportunity for allyship, for advocacy, for learning. Our leadership series is Speak, Listen, Community, and it’s all about those that are a part of WiCyS in a leadership capacity—we have over 500 leaders that are volunteers within the organization—but what does allyship, what does advocacy, what does inclusiveness mean to others, and how could we embrace it as a community and all collectively rise up because of it?

For me, as a technology expert, I get into certain silos. I was originally a database administrator, so very much internal databases within the enterprise, and you have all these protections on it, these things that you do within the enterprise to protect that data, that center of value for your company. But for me, APIs and then open source—I run our open source technologies program—there’s a lot of value in externalizing, being part of a community. And a big part of APIs is that externalization of our operations, where we’re letting partners in, we’re partnering with folks, we’re co-collaborating on content, so we’re being exposed to ideas. So what I hear you saying is, it’s not just, oh, I have women and diverse voices on my internal team and this is how we operate internally. This is much wider than just my org. This is a community thing we invest in, we learn, we all grow together, we strengthen together, and then that feeds my team and makes my team stronger, and then ultimately my cybersecurity program better.

Oh my gosh, you just summed it up beautifully. Let’s take that and have that repeat over and over again out to others. That is beautiful, because when you create the space of inclusion, diversity expands, and all benefit from it. So that was well said.

Well, I thank you all for your work, and it’s something now that WiCyS is on my radar, I’ll be getting more involved, more in tune, tuned into the newsletter. We’ll have this podcast coming out showcasing the great work you all are doing. And I think when it comes to API security, it’s a regular theme that I’m going to keep bringing up in the show, and I’ll keep referring folks your way and see who else we can—and see what other opportunities there are for us to partner together, because this is pretty top priority for Postman, and just the API space in general. Security—APIs are kind of the poster child for potential security vulnerabilities, and I think we need a lot more discussion and a lot more people paying attention to what’s happening. So I thank you for your work.

Yeah, thank you. Thank you for having me here to be able to share some information. I appreciate it.

Thanks again to Lynn for stopping by. You can find more about WiCyS at wicys.org, and you can find Lynn on LinkedIn. You can subscribe to the Breaking Changes podcast at postman.com/events/breaking-changes. I’m your host, Kin Lane, and until next time, cheers.