Recent findings from ISC2 and Women in Cybersecurity (WiCyS) shed light on the pay disparity by ethnicity and gender and the inclusion challenges and causes in the cybersecurity industry.

ISC2 surveyed 15,000 U.S.-based cybersecurity professionals for its recent Global Workforce Study and found the cybersecurity profession seems to enjoy more pay parity compared to the broader U.S. labor market. The average reported salary is $147,138, with entry-level positions averaging $86,000 annually to C-suite executives at $215,000, compared to the median U.S. wage of $59,428.

However, ISC2's research showed pay disparities by both ethnicity and gender.

Most (80%) of the respondents in this survey are White, followed by Black or African American (8%), Hispanic or Latinx (7%), East Asian or Southeast Asian (7%), South Asian (4%), and American Indian or Alaska Native (2%).

Cybersecurity professionals of South Asian descent top the salary charts at $155,000, whereas Hispanics/Latinx and Blacks/African Americans earn at the lower end, averaging $136,000 and $132,000, respectively.

Pay gap between genders

The study also found “a significant disparity between genders,” which underlines the continued existence of the gender pay gap in the cybersecurity industry.

  • Non-managerial, mid-advanced women cybersecurity professionals earn $131,000 on average, $7000 less compared to what men in the same roles earn ($138,000).
  • Female managers earn $138,000, $12,000 less than what men in the same roles earn ($150,000).
  • Women at the manager and executive levels reported higher average annual salaries than men in the same roles. The pay gap at the director and middle manager level is $2,000, with women earning $177,000 in annual salary compared to men earning $175,000.
  • Women at the C-suite and executive levels earn an average salary of $220,000, which is $8000 more than the average salary for men in the same roles.

“While salary has historically not been a top motivator for people to pursue a cybersecurity career, our research suggests that organizations that focus on addressing pay disparities have more engaged cybersecurity teams and are more effective at minimizing the impact of workforce gaps,” ISC2 researcher wrote in the study.

Dissecting the gender gap and inclusion in cybersecurity

The WiCyS State of Inclusion Benchmark in Cybersecurity further complicates the narrative by delving into the experiences of women in the field.

“Previous studies have illustrated that the representation of women in cybersecurity is much lower than it should be, but can’t explain why or how we can improve matters,” the report wrote.

WiCys, partnered with diversity, equity and inclusion (DEI) tech company Aleria, collected data from more than 1,000 cybersecurity professionals including about 35% men and 65% women, from more than 20 different organizations for the assessment.

The report revealed workplace experiences of women are dramatically worse than men across virtually every category. For example, women are excluded on average at twice the rate of men across various categories such as respect, career growth, access and participation and recognition.

This exclusion is magnified for women are about five times more likely than men to cite their direct managers and peers as sources of experiences that interfere with their satisfaction and their ability to perform at their peak.

The study identifies recurring themes of exclusion, including gender bias, tokenism, lack of feedback, underutilized skills, glass ceiling, menial tasks, being passed over for promotions, and inadequate compensation and recognition.

Aleria's interactive calculator estimates significant financial losses due to productivity drops and unwanted attrition “simply because it is treating women and people of color differently than white men.”