As the race to recruit female talent in STEM continues moving ahead with steady progress, stunning statistics still wrack the cybersecurity sector: Women working in cybersecurity currently account forless than one quarter of the overall workforce.
Megan Rapinoe. Sister Rosetta Tharpe. Shirley Chisholm. Donning jeans and a Ukrainian flag t-shirt, the director of the nation's lead cybersecurity agency ticked through PowerPoint slides of women "who took a sledgehammer to the glass ceiling."
"I need your help," said Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, on Friday to an audience of 1,700 female cybersecurity professionals assembled for a three-day technical conference in Cleveland. "We need to get to 50% of cybersecurity by the year 2030. Think we can do it?" Someone whistled. ACDC pulsed through the speakers. "Come on!" Easterly rallied.
After exiting the stage, Easterly told CBS News she has become accustomed to setting "unreasonable" goals. "That's been sort of my [modus operandi] my entire life," she quipped. "And I honestly believe if you set a super ambitious goal, and you as a leader inspire and empower people, and look at that goal as something that may be challenging, highly ambitious, but is in fact achievable, you can get there."
Pressed on how close America's cyber defense agency is to "getting there," Easterly responded down to the decimal. "Right now, we're at 36.4% women at CISA's workforce, but I think we can get to 50% before 2030." She paused before adding, "Actually, I'm hoping we can get there before 2025."
Easterly says she hopes colleagues across the federal workforce including FBI, NSA, U.S. Secret Service make similar pledges. The Army veteran-turned-corporate leader came close to "getting there" in her previous stint as head of Firm Resilience at Morgan Stanley, where she oversaw a team that was roughly 48% women.
Currently, there's just one woman serving as chief information security officer, or "CISO," among the top 10 largest companies nationwide: Chandra McMahon, CISO of CVS Health. The former executive at Verizon and Lockheed Martin can remember what it was like to be the only woman in the room.
"Cybersecurity is not well understood as a career or as an opportunity," McMahon said during an interview with CBS News on Friday. "What most people don't realize is that there's a spectrum of roles and careers that you can have." McMahon rattled them off: "Penetration testers, ethical hackers, the cyber security engineers and architects."
But the gender gap marks just one of the cybersecurity workforce's persistent challenges. Hispanic, African American, Asian and American Indian/Native Alaskan workers made up just 4%, 9%, 8% and 1% respectively of the cyber security workforce, according to the Aspen Institute.
An estimated 3.7 million cybersecurity jobs are available but unfilled, according to the latest (ISC) Cybersecurity Workforce Study, with 377,000 of those vacancies located in the United States. By that measure, the global cybersecurity workforce will need to grow 65% in 2022 to effectively defend organizations' critical assets.
Last week, Microsoft called recruitment of women "mission-critical" to filling the worldwide cyber vacancies. A survey commissioned by Microsoft Security found that only 44% of female respondents felt sufficiently represented in their industry.
Not all "black hoodies" and "dungeons"
Part of the federal government's cyber strategy is just showing up. Easterly, who ditched plans to appear via video at Friday's Women in Cybersecurity Conference only to instead dance onto stage to the tune of ACDC, recounted the thrill of manning CISA's booth at the conference.
"At the end of the day, if people can see me as the director of America's Cyber Defense Agency, then there are women out there who can say I can be her," she told CBS News.
A decade ago, that lack of visibility in a security field known for operating behind the scenes served as the inspiration for the group behind Friday's conference, Women in Cybersecurity, or "WiCyS."
"I think people have to understand that even though cybersecurity works best when it's invisible, there are so many people behind it," said WiCyS founder Dr. Ambareen Siraj.
"There's this stereotypical notion about cybersecurity that it's all about fighting. And we're all working in some sort of dungeon in black hoodies. But it is really not the case," Siraj said.
Unclogging the cyber talent pipeline will require more than just breaking a stereotype though, with experts advocating for more outreach to non-traditional candidates.
"Some of the best talent we have in cyber did not come from a background in cybersecurity," McMahon said.
Just 38% of women came from an IT background, compared to half of men in today's cybersecurity workforce. According to the (ISC) report, women also have higher rates of entry from self-learning (20%) compared to male counterparts (14%).
"We're now seeing an opening in the market for cyber skills. It's not so siloed in that you must have a cybersecurity degree," McMahon added.
Mind the gap: reshaping the federal workforce
Just 25.2% of the full-time federal cyber workforce is female, compared to 43.6% of government workers nationwide, according to the non-profit Partnership for Public Service, which assesses data from the U.S. Office of Personnel Management and U.S. Census Bureau.
The federal cybersecurity workforce is also decades older than the U.S. labor force. The percent of full-time cyber employees under the age of 30 steadily increased from 4.1% to 6.3% between September 2014 and September 2021. But it still lags behind the almost 20% of the employed U.S. labor force in 2021 that is under age 30. In the federal IT workforce, there are 15 times more employees over the age of 50 than under age 30.
"I think the most fundamental problem in the federal workforce is the lack of generational diversity," said Max Stier, head of the Partnership for Public Service. "There are very, very few young people in the federal technology and cyber workforce. And it becomes this self-fulfilling prophecy: the absence of young talent makes it harder for new young talent to want to come in or stay."
Data on the federal government's cybersecurity workforce vacancies remains scarce, but Stier estimates a "minimum of tens of thousands of jobs" is needed to bolster U.S. cyber defenses.
A 47-page audit by the Senate Homeland Security Committee last year found federal agencies responsible for safeguarding the security and personal data of millions of Americans earned a C- report card in talent recruiting.
Since 2014, the Department of Homeland Security has received a whopping $76 million to create a new cyber talent recruiting system, which launched with 150 job postings, last November. DHS received 650 applications in its first 48 hours of operation but has not released further progress reports on hiring. There are currently five positions posted on the Cyber Talent Management System's dashboard.
Easterly says CISA, an agency of approximately 5,000 full and part time employees, plans to hire between 500-1000 more in the next few years.
In an effort to reach young talent, the agency has also formed partnership programs with the Girl Scouts, Cyber Corps, and Historically Black Colleges and Universities.
But among career leaders in the government's Senior Executive Service (SES), just 28% of STEM leaders are female, and only 19% are people of color.
"It's not just women, but it's all types of diversity. Whether that's neuro diversity, diversity of gender identity, of sexual orientation of race, of national origin," Easterly said.
Leaders from across the federal government and private sector have likened diversity initiatives to a national security imperative.
"What we would like to see is a strong, adequate cybersecurity workforce that has people of all kinds, different racial backgrounds, ethnicity, gender," said Siraj. "When we have diverse people working in cyber, which is an extremely complex place, then it is more likely that we are going to bring the different perspectives and skills necessary to solve complex problems."
No room for "vigilance fatigue" amid Ukraine-Russia crisis
As information warfare plays out in the shadows of the Ukraine-Russia crisis, Easterly worries about "vigilance fatigue."
"It is hard to maintain a very high tempo of extreme preparedness," she conceded. "But we are not even a month into this unjust illegal, unprovoked invasion of a democracy and we need to continue to keep our shields up," Easterly told CBS News.
CISA and the FBI have released two alerts this week alone, including a joint bulletin to satellite communication (SATCOM) networks just days after the hack of telecommunications firm Viasat by unidentified actors disrupted broadband satellite internet access at the start of the Russian invasion.
That fatigue is further punctuated by a cybersecurity workforce shortage that sees more than just the federal government working overtime to monitor potential threats.
CISA and FBI "have not identified cyber activity in the US Homeland attributable to Russian state actors since the invasion commenced," an NYPD intelligence bulletin obtained by CBS News and published last week indicated.
But since November, the Department of Homeland Security has overseen more than 80 briefings, table exercises and informational sessions with the private sector designed to bolster U.S. cyber defenses in the event of Russian malicious cyber activity.
Through its Joint Cyber Defense Collaborative, CISA administers a Slack channel dedicated to information sharing with tech and cybersecurity giants, including Cloudflare, CrowdStrike, Mandiant, Microsoft, Verizon, Google, and Amazon Web Services, along with the NSA, the FBI, and US Cyber Command.
Still, cybersecurity advocates worry that a lack of investment in cybersecurity extends to the larger workforce, with compromises a few clicks away from unwitting employees scanning through email inboxes. "You actually need the broader workforce familiar and capable of addressing these cyber challenges in the context of their normal, daily jobs," Stier said. "Consider the classic phishing incident."
"We are putting out more and more information so that the public understands the nature of the threat environment," Easterly said, Friday. "We have said consistently, that every business large and small remains at risk and is vulnerable to Russian malicious cyber activity. That's why we need to continue to keep our shields up to be prepared to be vigilant, to keep our thresholds low for sharing information about anomalous activity, and to ensure that we are working together for the collective cyber defense of the nation."
Catherine Herridge contributed to this report.
Trending News
CBS News reporter covering homeland security and justice.
See more here:
Women make up just 24% of the cyber workforce. CISA wants to fix that. - CBS News
- Google researchers have cracked a key internet security tool - Recode [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Letter: Internet security is in jeopardy - INFORUM [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- New internet security device launched to safeguard schools against child abuse - Phys.Org [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Everything You Need to Know About Cloudbleed, the Latest Internet Security Disaster - Gizmodo [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Data from internet-connected teddy bears held ransom, security expert says - Fox News [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Emsisoft Internet Security 2017.2.0.7219 - TechCentral.ie [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- What you need to know about 'Cloudbleed,' the latest internet security bug - Globalnews.ca [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Google cracks longtime pillar of internet security - MarketWatch [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- BullGuard | Internet Security and Antivirus protection ... [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet Storm Center - SANS Internet Storm Center [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet-connected 'smart' devices are dunces about security - ABC News [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Derry internet security expert warns that advanced internet technology 'a risk to us all' - Derry Now [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Firewall Test, Web Tools and Free Internet Security Audit ... [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security in the spotlight: How is the internet safer today than it was 20 years ago? - Mobile Business Insights (blog) [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Jim Mullen: Unsocial internet security | Columnists | auburnpub.com - Auburn Citizen [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security company launches a perfume line to promote cybersecurity - Mashable [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Internet security - Wikipedia [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Are you undermining your web security by checking on it with the wrong tools? - The Register [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Bruce Schneier on New Security Threats from the Internet of Things - Linux.com (blog) [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Carpe Diem: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Motivation Monday: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Medical records of 26m patients at risk because of GP surgeries' failing internet security - The Sun [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Free Internet Security | Why Comodo Internet Security Suite ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Internet Security Software | Trend Micro USA [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Fix crap Internet of Things security, booms Internet daddy Cerf - The Register [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Internet of Things security: What happens when every device is smart and you don't even know it? - ZDNet [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- CUJO is cuter than Wall-E, and it's the only internet security device you'll ever need - Yahoo News [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- The Senate just voted to undo landmark rules covering your Internet privacy - Washington Post [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- What the Cloudbleed disaster says about the state of internet security - Information Age [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Google Has Declared Symantec Harmful To Internet Security - UPROXX [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Internet Security Analysts: North Korea Is Planning a Global Bank Heist - Breitbart News [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Internet Security Firm Confirms WikiLeaks 'Vault 7' At Least 40 Cyberattacks Tied to the CIA - The Ring of Fire Network [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Homeland Security warns of 'BrickerBot' malware that destroys unsecured internet-connected devices - ZDNet [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security ... - Business Wire (press release) [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- Mucheru urges private sector to boost investment in internet security - The Standard (press release) [Last Updated On: April 25th, 2017] [Originally Added On: April 25th, 2017]
- Cloudflare debuts a security solution for IoT - TechCrunch [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Russian-controlled telecom hijacks financial services' Internet traffic - Ars Technica [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Avira Internet Security Suite v15.0.26 - TechCentral.ie [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- NSA To Limit Some Collection Of Internet Communication - NPR [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Report Indicates '10 Concerts' Facebook Trend Could Compromise Your Internet Security - Complex [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- "Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree - Huffington Post [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Don't Fall For This Tech Support Scam Targeting PC Users - KTLA [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Yikes! Antivirus Software Fails Basic Security Tests - Tom's Guide [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Watch Hackers Sabotage an Industrial Robot Arm - WIRED [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Decoding Internet Security: Spear phishing - Washington Post [Last Updated On: May 5th, 2017] [Originally Added On: May 5th, 2017]
- From the Desk of Jay Fallis: To internet vote, or not to internet vote - BarrieToday [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- Crippling cyberattack continues to spread around the world - Los Angeles Times [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Cyber Security Experts: Russia Disproportionately Targeted by Malware - Voice of America [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- The Latest: 29000 Chinese institutions hit by cyberattack - ABC News [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- Cyberattack Aftershock Feared as US Warns of Its Complexity - New York Times [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- This week's poll: Priorities for improving internet security - The Engineer [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Akamai Releases First Quarter 2017 State of the Internet / Security Report - PR Newswire (press release) [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Do Macs get viruses? - PC Advisor [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Massive Ransomware Attack Underscores Threats To Internet Security - Benzinga [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- Security News This Week: Hoo-Boy, Mar-a-Lago's Internet Is Insecure - WIRED [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Internet security firm calls for law to compel information sharing to ... - The Star, Kenya [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Check It Out: No need to unplug after reading books on internet security - The Columbian [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- How to beat security threats to 'internet of things' - BBC News - BBC News [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Best Mac antivirus 2017 - Macworld UK [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Avira, Kaspersky Top Windows 10 Antivirus Tests - Tom's Guide [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Paranoid about internet security? Here are the most secure OS options - The American Genius [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Blockchain Offers Hope for the Broken Internet - Fortune [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- New uses for RFID and security for the internet of things - Phys.Org [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Security Best Practices for the Internet of Things - Web Host Industry Review [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Internet infrastructure security guidelines for Africa unveiled - Premium Times [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- In addressing internet security issues, make sure to provide solutions - Minneapolis Star Tribune [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Whistic Partners with the Center for Internet Security to Extend the ... - PR Web (press release) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet Security Alliance: NIST framework metrics should focus on threats - Inside Cybersecurity (subscription) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China cyber-security law will keep citizens' data within the Great Firewall - The Register [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Cyber security: Africa gets Internet security guidelines - TheNewsGuru [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China to Implement Its First Law on Internet Security After Ransomware Attack - Sputnik International [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Decoding Internet Security: Ransomware - Washington Post [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet security upgrade on course - Business Daily (press release) (blog) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- What's the Safest Laptop For Internet Security? - HuffPost [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Every Day Is Internet Security Day - The Chief-Leader [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- 5 Reasons why internet security is crucial in 2017 - Techworm [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Are Pop-Ups An Internet Security Threat? - Good Herald [Last Updated On: June 4th, 2017] [Originally Added On: June 4th, 2017]
- 3 Ways Software Programs Can Help With Internet Security in 2017 - Geek Snack [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Inside Social Security: Make every day your internet security day - Santa Ynez Valley News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- SOCIAL SECURITY: Every day is internet security day - Palm Beach Post [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]