Trellix CEO Bryan Palma on stage at RSA Conference 2022. Photo courtesy of RSA Conference, copyright RSA Conference.

SAN FRANCISCO – There is a serious problem with the homogenized nature of cybersecurity professionals, Trellix CEO Bryan Palma said during his keynote at the RSA Conference.

An overwhelming majority of individuals in the cybersecurity field identify as straight, white, and male, according to a recent Trellix-commissioned survey conducted by a market research firm.

This clear lack of diversity is holding the industry back in two main ways. "First, we are turning away great people and doing our industry a significant disservice by failing to cultivate a more inclusive environment," Palma explained. "We are all better when we benefit from the diverse perspectives of others."

And secondly, that homogenization is bad for business. "I learned this decades ago from Indra Nooyi, the former PepsiCo CEO: we do not look like our customers. And our lack of diversity restricts our ingenuity, innovation, and ability to recruit the next generation of talent," Palma said.

"Hell, the hackers are more diverse than we are. Even they understand the importance of having a bigger tent," he added.

While the diversity issue is a beast of its own, it also feeds into cybersecurity's broader talent shortage and level of preparedness.

The industry's demand for security analysts, engineers, researchers, and consultants long ago surpassed its supply, and that gap widens with each passing day, Palma said.

"In the U.S. and many other countries, we have not made the investments required to develop a national cybersecurity talent pipeline. Meanwhile, the very nascent states attacking our private corporations, they've already made those investments," he said, highlighting the importance of issues in the context of national security.

Minding the Gap

And while Palma has seen the industry give "the talent and diversity gap lots of lip service ... we still lack any scalable programs to close that gap," he said.

A holistic solution to cybersecurity's diversity and talent shortages lies in nurturing and developing cybersecurity awareness and talent in the K-12 education system, college students, and mid-career professionals looking for a change.

"Beginning in kindergarten, we should infuse cybersecurity into students' existing curriculum as kids advance through school and would have the opportunity to take standalone classes, join clubs, attend day camps, or participate in competitions focused on cybersecurity," Palma said. This type of investment is certainly a long-term one, but promises to break down social and economic barriers, he added.

Another piece of the puzzle is nurturing college students and early career professionals and encouraging them to pursue cybersecurity by increasing scholarship funding and internship programs, Palma explained.

As part of that, the company announced a partnership with the Hispanic Alliance for Career Enhancement (HACE) to launch a comprehensive mentorship and educational program.

"By extending program participation to include more historically black universities, the large schools and community colleges, we could achieve even larger more diverse talent," he added.

Thirdly, Palma said, the industry must build easy transitions for mid-career professionals looking to move into cybersecurity by supporting certification and training courses and offering apprenticeships.

"At the end of the day, success does not depend on the degree" someone has, but their passion and drive to play a role in protecting the increasingly digital world.