The recently introduced Diverse Cybersecurity Workforce Act aims to address the need for a diverse and skilled workforce. The act would require the Cybersecurity and Infrastructure Security Agency (CISA) to establish a program focused on cybersecurity workforce opportunity outreach to underprivileged communities.
M. K. Palmore, director of the office of the CISO at Google Cloud, explained the impact of this act and the importance of building a diverse cybersecurity workforce.
SDxCentral: The Aspen Institute estimates that 9% of cybersecurity workers are Black, 4% are Hispanic, 1% are Native American, and 24% are women. How does this lack of diversity in cybersecurity affect the security posture of organizations and national security?
Palmore: Throughout my career in both the public and private sectors, I've been struck by how much the security sector is a monoculture in appearance and sometimes in thinking. Security teams are constantly tasked to solve complex problems that often don’t have a clear solution and yet many teams are built up of people who share the same backgrounds and think the same way – missing out on a crucial aspect of problem solving: diversity of thought.
The cybersecurity field needs new, fresh perspectives to meet our greatest challenges. I have experienced firsthand how diverse perspectives build teams with better creative outcomes. A team that lacks differing perspectives is likely to fall into the same security traps time after time, weakening security posture for both organizations and national security at scale.
SDxCentral: How do you see the Diverse Cybersecurity Workforce Act improving the situation and helping to build a more diverse cybersecurity workforce?
Palmore: The Diverse Cybersecurity Workforce Act has the potential to uplift the importance of the critical issue of the cyber[security] workforce gap and ensure a more resilient and adaptable landscape for the future. By addressing systemic challenges that have existed for years – like cybersecurity education, burnout, hiring, and reskilling security talent – this initiative will help dismantle barriers that have previously prevented underrepresented and disadvantaged communities from seeing the cybersecurity industry as a career pathway.
SDxCentral: How can the private sector work with the public sector in achieving the goals set out by the Diverse Cybersecurity Workforce Act?
Palmore: The biggest way that the private sector can aid the public sector as they modernize their organization to achieve the goals laid out by the Diverse Cybersecurity Workforce Act is through information sharing. Offering government agencies insight into what has worked and what has not is crucial as the public sector looks to diversify its cyber[security] talent pool. Sharing resources such as training programs and certificates that have helped to gain and retain talent can assist in the development of the public sector’s hiring process and mission to promote retention. Additionally, the private sector can offer training programs and internships to help invest in talent in the industry overall.
SDxCentral: What are some challenges you anticipate in the implementation of this program at CISA to promote the cybersecurity field to underrepresented and disadvantaged communities, and how can they be addressed effectively?
Palmore: One of the biggest challenges that the public sector faces is pay parity, particularly when every industry is facing a cybersecurity talent shortage and competition for top talent. Candidates are often aware that they could be making more elsewhere, so reinforcing that the public sector is a viable option for breaking into cybersecurity, with numerous training and development opportunities, is essential.
Many also assume that a career in the public sector means staying there forever. The reality is that public sector roles can be a pathway to a successful cyber[security] career in government and beyond. Based on my own public sector experience, cybersecurity professionals who start in government can gain significant experience within a short period, allowing them to build and potentially leverage those skills in a different sector down the line.
SDxCentral: Can you discuss the benefits you have observed from having teams with diverse backgrounds and perspectives within cybersecurity at Google Cloud or other organizations and agencies?
Palmore: Cybersecurity is a team sport, and addressing emerging cybersecurity threats must be an all-hands-on-deck effort. At Google Cloud we are always trying to solve global challenges, and when we problem solve we aim to find solutions at a global scale, not only prioritizing how we can solve for an individual instance but addressing how we can solve this challenge for the planet. Our teams ensure we’re successfully building and investing in solutions that apply to and support the greater good.
SDxCentral: What leadership advice would you offer to other technology companies looking to foster a more diverse and inclusive work environment?
Palmore: Tech leaders looking to build a more diverse and inclusive workforce can focus on five key areas.
- Revamp recruitment: When looking for new talent, go beyond traditional qualifications and focus on core skills potential overall. This often allows for a wider pool of talent who can bring new perspectives.
- Invest in learning and development: Prioritize ongoing training programs for current employees and aspiring cybersecurity professionals.
- Drive industry awareness: Challenge stereotypes and engage with potential candidates to showcase diverse career paths in cybersecurity. This can include participating in career fairs, offering internships, and highlighting non-technical aspects of the field.
- Prioritize mentorship and retention efforts: Foster knowledge sharing and career growth through mentorship programs and examine your organization’s ability to retain talent.
- Encourage networking: Support employees in building strong professional networks through online platforms and relevant communities.
- Representation matters: Make an effort to showcase your organization’s success in this realm by promoting the presence of women and representatives from underrepresented communities across all levels of your organization. People need to see a pathway for themselves.
Comments