Just like cybersecurity, diversity and inclusion is everyone’s problem to solve.

“And so it’s an imperative for us,” said Dug Song, GM and co-founder of Duo Security at Cisco, during a Cisco panel on LinkedIn Live about “Embracing Diversity and Inclusion in Cybersecurity.”

In the early days of the sector, cybersecurity was kind of a “weird, esoteric topic for organizations,” because most of them, with the exception of banks, hospitals, and governments, didn’t really face cyberthreats. That has since changed. All of our personal lives and businesses connect to the internet, and therefore everyone has a security problem, Song said, adding that IT — and attackers — have evolved so fast that security hasn’t been able to keep up.

Diversity and inclusion is another area where security has lagged, Song said, noting that historically the sector’s makeup is only about 11% female. “To be successful at securing organizations and helping protect others from harm we need to be more thoughtful about how we do that,” he said. “Our teams have to be representative of those we serve, and I think that’s one of the biggest opportunities we have in this industry.”

So how does security seize this opportunity and ensure security professionals look like the communities where they work and the people they protect? Here are five lessons learned by Duo and Cisco, which acquired Duo in 2018, about how to make cybersecurity more diverse.

Size Doesn’t Matter

When it comes to employing a diverse cybersecurity team, an organization’s size doesn’t matter. There’s no “magical number of employees” that creates a “perfect sweet spot for driving a diversity strategy or an inclusion strategy,” said Trey Boynton, Cisco’s global lead for inclusion, who also came to Cisco via the Duo acquisition.

In fact, companies can use size to their advantage. Small startups with a team of five “can make exponential gains in representation” with just a few hires, she said. On the flip side, larger companies “have tradition and history. You also have the resources, and the collective will of a whole group of folks who can leverage their collective talents and skills to drive inclusion and drive an agenda around representation,” Boynton said.

You Can’t Be What You Can’t See

“I’m tired of being the only woman in the room talking about cybersecurity,” said Leticia Gammill, Cisco security channels leader for Latin America and Canada. She’s worked in security for 15 years, and said to attract more women to the sector, we need to get rid of the stereotypical image of a guy in a hoodie behind his laptop in a dark room.

And, she added “we have to change this perception that it is a career for only technical people, because cybersecurity touches everyone in IT.” This include employees with legal backgrounds who understand compliance, and those in marketing to develop product pitches. “Look at forensics,” she added. “Look at all the analysts that can speak multiple languages … and be able to analyze all the threat traffic, so you need people in liberal arts to work in cybersecurity.”

But when it comes to breaking down barriers to access, misconceptions about who can work in security is only half of it. “You can’t be what you can’t see,” Boynton said. “How do we get into spaces and communities and show that there are women in security?” And this leads to the next lesson.

Sponsorship Trumps Mentorship

Build a culture of sponsorship, and a sponsor is not the same as a mentor. A mentor serves as more of a sounding board, Boynton said. And while providing exposure about what cybersecurity jobs actually look like and who can hold them is important, there’s a pivot that needs to happen “and that’s where mentorship starts to get active and it turns into sponsorship,” she explained.

A sponsor will leverage her clout and connections to open doors and opportunities to advance women and minorities in security. “And that’s really the game changer because it’s around putting someone’s name in the room, it’s around creating space for people before they even know that they that they are in the conversation,” Boynton said.

Only one in eight women have a sponsor, and one in 12 minorities, she added.

Education and Training Are Key

Cybersecurity professionals use education and training to improve security posture by changing behavior — think: multi-factor authentication and the need for stronger passwords. Diversity and inclusion works the same way. “This is when we do things like coaching, intervention programs, inclusive leadership training,” Boynton said. “We know security product teams want to understand how people engage with their technology to help them reduce barriers to their business.” And this reflects the synergy between security and diversity, she added.

“Security is about trying to proactively think about the potential risks and threats to people in their organizations and keeping them safe,” Boynton said. "That sounds exactly like what I’m trying to do about protecting the most vulnerable and the most disenfranchised that sit on the margins and making sure that we are on teams where inclusion is driving contribution that the vulnerable are always having a voice and a seat.”

Diversity Is Everyone’s Responsibility

In another similarity with cybersecurity: diversity and inclusion is also everyone’s job — not just that of chief diversity officers. For employers looking to recruit and hire security professionals, “go outside the box,” Gammill said. In other words, look beyond a candidate’s technical skills, consider a diverse pool of applicants including those in other IT fields, and give someone the opportunity to train for and grow in the job even if they don’t check all 20 job requirements right now.

“For the women who are applying — and I know for a fact that a lot of us, if we don’t look like we can qualify for those 20 points, we don't even apply — please do yourself a favor and try,” Gammill added.

Song said Duo’s approach to inclusion involves looking at potential employees’ “cultural contributions” in addition to their technical skills. “Because change is not based on an intent,” he added. “It’s based on specific decisions and choices. And it’s a huge strategic advantage to have all of these perspectives, experiences, skillsets, mental models, frameworks from which you can solve problems … turn that diversity perspective into creativity, versus conflict.”

Inclusion (and cybersecurity) requires a commitment from the top down, as well as a holistic approach. “There is not just one way to be secure,” Boynton said. “We’ve got to do layers upon layers and controls for in-depth security,” which is no different than diversity. “I can’t just do one thing and say, ‘we’re good at inclusion.’ Because if it were like that, we’d already been good to go and tech would look exactly like the population. So because we don’t have that, we have to do all these different methods and leverage these different opportunities to drive presentation, diversity, and inclusion, and have that intersect with collaboration.”