Women in IT Security, Security Strategy, Plan, Budget, Leadership, Training, Security Operations, SOC

Women’s History Month: Build cyber resilience by welcoming diversity

Modern banner with artistic illustrations of women in various professions, set against a gradient background with motivational quotes for International

COMMENTARY: Every March we celebrate Women’s History Month, an ideal time to reflect on how far women have come in cybersecurity.

Despite making up only 22% of the cybersecurity workforce, women have had an outsized influence on the field. We’ve protected privacy at a national scale, taught computers to compile code, and even helped win wars.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The world’s “first computer programmer” was a woman. These pioneers were outsiders in a male-dominated industry, but their contributions changed the world. Now, we have a chance to change the world by embracing another group of outsiders: our non-technical staff members.

Protecting digital assets isn’t just about computer skills anymore. Today, we live in a world in which malicious AI can compromise entire organizations with a few plain-English prompts. If we want to build resilience against modern cyberthreats, we need to look at cybersecurity from a holistic perspective. We need our IT personnel and security pros, but we also need our artists, designers, analysts, salespeople, communications experts, and customer service reps. We also need leaders who champion their diverse skill sets.

Just as listening to female perspectives changed cybersecurity history, listening to our colleagues today can define the field’s future.

A holistic approach

Up until recently, cybersecurity was entirely in the hands of mostly male IT teams. Employees worked in physical offices with computers and servers that basically never moved. Teams could fight off most cyberthreats with a firewall and an antivirus suite. All anyone else on staff needed to do to contribute to cyberdefense was keep strong passwords.

Now, all bets are off. Employees work from desktops, laptops, tablets, and smartphones. They work in offices, at home, or just about anywhere with an internet connection, often with limited security. Every device has different configurations, and every worker has different cybersecurity habits. Phishing, malware, and unpatched vulnerabilities are more common than ever, especially now that AIs can exploit them.

Even the best IT team can’t deal with every possible threat. That’s why we need a broader, more inclusive approach. Companies need communications people who know the difference between a real email and a phishing lure. We also need artists, who can spot a deepfake photo in seconds. Companies need the social media experts, who protect the audience from spam and scams. We need people who can think differently. The more diverse perspectives we bring to the table, the stronger and more creative our solutions become.

In today's digital world, resilience isn't just about withstanding threats. It's about recovering quickly and using every challenge as a lesson. But true resilience also means supporting each other and fostering environments where everyone can thrive, regardless of background.

 Inclusive leaders, empowered staff

At many organizations, “what IT knows” and “what everyone else knows” are in (at least) two different silos. If we want every skill set to contribute to our cybersecurity framework, change has to start from the top. Leaders need to make things easier for people, meeting them where they are, and embodying balance. If our leaders value diverse perspectives, the rest of the staff will have a good example to follow.

In fact, our leaders might have more in common with the general staff than they do with the IT department. According to the Splunk CISO Report 2026, 85% of CISOs say that their fellow executives have “low cybersecurity fluency.” This isn’t necessarily bad, since it means leaders, IT personnel, and non-technical staff have a lot to learn from each other. Having frank, honest conversations about what we know and what we don’t can lead to unexpected “aha!” moments.

There’s also a practical reason that leaders should encourage their non-technical staff to get involved in cybersecurity: skill gaps. Just about every organization has specialized tasks they need done and not enough skilled workers to do them. But based on the Splunk CISO Report, no more than 1% of organizations think technology investments can fix skill gaps. Only 28% of CISOs prioritize finding new full-time staffers, and only 6% see hiring contractors as the ideal solution.

Instead, two-thirds of CISOs want to fill skill gaps by upskilling the current workforce. We can teach technical skills, especially to anyone who has a basic knowledge of computer systems. But we can’t teach curiosity, adaptability, and problem-solving. When we ask our staffs to apply their skills in new and unexpected ways, a lot of them will jump at the chance.

 Diversity of thought

Cybersecurity has become much more than just a technical role. We need all kinds of people and all kinds of skill sets. Talk to the staff, and it’s possible all these type of people exist within the organization, many of whom are ready and willing to learn new skills.

Cybercriminals have better tools than ever, so we need a resilient framework more than ever. But resilience does not just mean how much threat intelligence we can gather or how many malicious URLs we can block. Resilience gets built in small, daily acts of listening and learning.

By championing each other and celebrating resilience — both individual and organizational — we can build a more secure, innovative, and inclusive future for everyone.

Jothi Dugar, President, The Chaos Guru; Kirsty Paine, Field CTO, Splunk

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds