Skip to main content

Women in Security Magazine Issue31

Page 1


I’ve made a point, it was ignored, and then someone else repeats it and receives credit

I would like to negotiate for a leadership role

Inclusion beyond headcount Addressing microaggressions

FROM THE PUBLISHER

Istill remember the conversations that led to the launch of the Australian Women in Security Awards. They were not easy conversations. They were not polished. They were not the kind of conversations people have when everything is going well.

They were conversations about workplace bullying, sexual harassment, equality in roles, women being overlooked, sisterhood gangs, conference etiquette, awards going to the same types of people, often men, while women doing incredible work stood quietly in the background.

You name it, I had heard it from at least one person.

Then, I sat down with my dear friend JL and found she had been hearing the same things: different names, different workplaces, same stories.

That conversation became a turning point.

From there, the Australian Women in Security Awards and Conference were born. That was eight years ago.

And, if I am honest, it was a scary time for me. It was scary to voice my own opinion so publicly. Scary to stand beside the women who had trusted me with their stories. Scary to say “no, this is not good enough anymore.”

But I did. Because I decided we were no longer going to let these women stay in the background. No longer under cover. No longer doing the work, carrying the load, leading the change and receiving no recognition or celebration for it.

Since then, I have had many more courageous conversations. Some have been about my own story. Many more have come from others: conversations shared quietly after events, in messages, over coffee, in moments where someone finally feels safe enough to say, “This happened to me,” or “I don’t know what to do,” or “I can’t speak out.”

And I hear you. I really do.

Having these conversations in this industry can be a double-edged sword. Speak up and you worry about being labelled difficult. Stay silent and you carry something that was never yours to carry alone.

So, when someone says, “I can’t speak out,” I understand where that comes from.

But I also want to say this clearly: we are all in this together.

Whatever your conversation may be, there are people in this industry who will stand beside you. There are people who will listen. There are people who know

exactly what it costs to be honest when the room would rather you stay polite.

This issue of Women in Security Magazine is about those conversations: the ones that make us uncomfortable; the ones that challenge old systems; the ones that ask why career ceilings still exist, why equity is still treated as an optional extra, why belonging is still not a given, and why building influence in traditionally closed spaces can still feel like pushing against a locked door.

Courageous conversations are not always loud. Sometimes they are quiet. Sometimes they happen in a meeting when one person says, “Can we look at this differently?” Sometimes they happen when a woman asks for the promotion, the pay rise, the opportunity or the respect she should have received years ago.

Sometimes courage is simply telling the truth without apologising for it.

For this issue, I want us to be unapologetically honest, to shed the need to make everything neat, to bring the vulnerability and speak the real talk. Because real change does not come from pretending everything is fine.

In Issue 31 you will hear from incredible voices across the industry. Lisa Ventura writes about reclaiming the

Abigail Swabey

traits that make women exceptional in cybersecurity. Jay Hira explores the conversation that keeps happening. Karen Stephens reminds us that you do not need an executive title to affect change. Madhuri Nandi shares what courageous conversations look like through real cybersecurity leadership. Marina Azar Toailoa takes us beyond discomfort and into the hardest conversations, the ones that can save lives.

And there are many more.

Each story, each article, each reflection adds something to this bigger conversation we are having as an industry. Courageous conversations built the foundation for the Awards. They continue to shape this magazine. And they are still needed.

Maybe now more than ever. So, let’s have them.

Not perfectly. Not always comfortably. But honestly.

PUBLISHER, and CEO of Source2Create

www.linkedin.com/in/abigail-swabey-95145312

aby@source2create.com.au

COLUMN

Staying

from

You don’t need an executive title to affect change

The questions we stop asking: courageous conversations through real cybersecurity leadership 88

Why AI governance needs more honest leadership conversations

“You’re too emotional for security”: reclaiming the traits that make women exceptional in cyber security

It’s not about a salary: it’s all about reality

The conversation that keeps happening Why diversity of experience across

SPONS ORSHIP

OPPORTUNITIES

ThankYou TO OUR SUPPORTING ASSOCIATIONS

UNAPOLOGETIC CONVERSATIONS FOR WOMEN IN SECURITY: THE REAL TALK TOOLKIT

This toolkit playbook is designed for women working across the security industry: cyber, physical security, guarding, executive protection, risk, resilience, intelligence, emergency management and security leadership.

The scripts are not meant to make hard conversations feel easy. They are meant to give you something steady to hold onto when a conversation gets awkward, political or emotionally loaded.

Use the wording as a starting point. Change the language so it sounds like you. Keep the structure: name the issue, connect it to impact, ask for a concrete shift then bring the conversation back to shared standards.

HOW TO USE THESE SCRIPTS

Before using any of these scripts, decide what kind of conversation you are having.

• Influence conversation: you are trying to shift thinking, behaviour or language before it becomes a formal issue.

• Boundary conversation: you need to make clear that a pattern is not acceptable.

• Escalation conversation: you have already tried informal channels, or the behaviour is serious

enough that HR, legal, compliance or senior leadership needs to be involved.

These scripts are for influence and boundary conversations. They do not replace formal reporting, workplace safety obligations, legal advice, union advice or HR processes where those are needed.

A useful frame: “I’m raising this because I want the standard to be clear, not because I want a fight.” That line works more often than people expect.

SCRIPT 1: CHALLENGING GENDER-BIASED HIRING MYTHS

Use this when someone suggests women are less suited to certain security roles because of physical presence, technical depth, toughness, availability or ‘cultural fit’.

PREPARATION

Go in with one or two examples of what the role actually requires. Separate the job requirements from assumptions about who traditionally looks the part. If possible, bring the conversation back to capability, evidence and risk.

Ask yourself:

• What myth is being implied?

• What does the role genuinely need?

• What selection criteria would produce a fairer decision?

Avoid making the conversation about whether someone is ‘sexist’. That usually sends people into self-defence mode. Focus on the decisionmaking logic.

SCRIPT TEMPLATE

“Can I pause on that for a moment? When we say this role needs someone who can ‘hold their own’ or ‘fit the environment’, I want to make sure we are not using coded language that screens women out before we have assessed capability.

“The role needs judgement, presence, risk awareness,

communication under pressure and the ability to follow through. Those things are not gendered.

“I’d like us to tighten the criteria. Instead of asking whether someone has the ‘right personality’ for security, can we ask what evidence they have of deescalation, decision-making, technical competence, resilience and team leadership?

“That gives us a stronger hire. It also protects us from repeating the same pattern and calling it merit.”

If the response is: “We’re just being realistic,” your response should be:

“I agree that we need to be realistic. That’s why I want the criteria to be specific. Realistic should mean evidence-based, not based on who has usually been hired before.”

If the response is: “Clients expect a certain type of person,” respond with:

“Some clients may have old expectations. Our job is to meet the security needs, not reinforce a stereotype. If presence matters, let’s define what presence means in behaviour, not body type or gender.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: if the group agrees to refine selection criteria. move quickly into action. Suggest a short scorecard that assesses capability rather than ‘fit’.

• Defensive reaction: if someone insists they are not biased, acknowledge intent. Then return to the process: “I’m not questioning intent. I’m questioning whether the criteria are clear enough.”

• Dismissive reaction: if the issue is waved away as overthinking, ask for the decision to be documented against the role criteria. That often changes the level of care in the room.

This constructive resolution is a hiring process that names what success looks like and tests for it fairly.

SCRIPT 2: ADVOCATING FOR PAY TRANSPARENCY

Use this when your pay bands, promotion increases, overtime rates, loadings, allowances or leadership salary pathways are vague.

PREPARATION

Gather what you can without breaching confidentiality. Know the role levels, your responsibilities, market context if available and any expanded duties you are carrying. Be clear whether you are asking for information, adjustment or a policy change.

Decide your main ask:

• “Show me the salary band.”

• “Explain how pay decisions are made.”

• “Review my pay against scope.”

• “Create a transparent framework for the team.”

Do not over-explain. Pay conversations often get derailed when women feel they need to prove they deserve the right to ask.

SCRIPT TEMPLATE

“I’d like to talk about pay transparency for my role and the pathway from here.

“At the moment, I don’t have enough visibility over the salary band, how progression is assessed, or what criteria are used for increases. That makes it hard to plan, and it also creates room for inconsistency.

“I’m asking for three things: the current band for my role, the criteria for moving to the next level and a review of whether my pay reflects the scope of my current role.

“I want this to be a practical conversation. If there is a gap, let’s name it and agree what changes are needed, and by when.”

If the response is: “We don’t discuss pay, reply with:

“I’m not asking to discuss anyone else’s confidential information. I’m asking for transparency about the range, criteria and decision process that applies to my role.”

If the response is: “Budgets are tight,” say:

" Decide whether to address the issue in the moment or afterwards. In the moment responses work best when the behaviour is public and the correction can be brief. A follow-up works better when emotions are high or the person has more positional power. Have a short line ready. You do not need a speech."

“I understand budgets matter. I still need clarity on whether the organisation recognises the level of work I’m doing. If adjustment can’t happen immediately, I’d like a written plan and timing rather than an openended ‘not now’.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: if leadership provides the band, explains the process and agree to a review date, get confirmation in writing after the meeting.

• Avoidant reaction: if you are told it is complicated or confidential, narrow the ask. “What can you share about the criteria and range for this role?”

• Minimising reaction: if you hear that money should not be the focus. reframe calmly: “Pay is one part of how responsibility is recognised. It is appropriate to discuss it.”

This constructive resolution is not just about getting a pay rise, it is a visible pathway and a decision process you can hold people to.

SCRIPT 3: ADDRESSING MICROAGGRESSIONS IN TEAM MEETINGS

Use this when a comment, joke, interruption or repeated behaviour undermines women’s authority or belonging.

PREPARATION

Write down the exact words or behaviour. Be specific. “He was disrespectful” is harder to act on than “He repeated my point five minutes later and it was accepted as his idea.”

Decide whether to address the issue in the moment or afterwards. In the moment responses work best when the behaviour is public and the correction can be brief. A follow-up works better when emotions are high or the person has more positional power.

Have a short line ready. You do not need a speech.

SCRIPT TEMPLATE

In the moment:

“I want to pause that. I don’t think that comment lands well.”

Or: “I’d like to finish the point before we move on.”

Or: “That was my recommendation from earlier. I’m glad we’re picking it up. Let’s take it forward from there.”

For a follow-up:

“I want to raise something from the meeting. When I was interrupted and the discussion moved on, it made it harder for my contribution to be properly considered.

“I’m not assuming that was your intention, but the impact was that my expertise was sidelined.

“In future, I’d like you to let me finish and, if my point is picked up later, I’d appreciate it being attributed properly. That keeps the discussion cleaner and fairer.”

If the response is: “It was just a joke.”

PREPARATION

“ If there is a gap, I’d like us to define it properly and agree what opportunity will let me close it. If there isn’t a material gap, then I’d like to discuss the role, title and compensation that match the work I’m already doing.”

“I understand it may have been intended lightly. I’m talking about the impact in a professional setting. Jokes that undercut someone’s credibility still affect the room.”

If the response is: “You’re being sensitive.”

“I’m being specific. The behaviour interrupted the discussion and affected those whose expertise was heard. That is worth addressing.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction : if the person acknowledges the issue and adjusts, thank them briefly. Do not over-reward basic respect.

• Embarrassed reaction: if they apologise but become awkward, keep it simple: “Thanks. Let’s move forward.”

• Hostile reaction: if they deny, mock or retaliate, document the pattern and consider taking the issue to a manager, HR or formal channel. One conversation may not be enough.

This constructive resolution is a meeting culture where women’s contributions are heard, attributed and not quietly absorbed by louder voices.

SCRIPT 4: NEGOTIATING FOR A LEADERSHIP ROLE

Use this when you are ready for a leadership position but are being kept in a ‘trusted operator’, ‘support person’, ‘second-in-command’, or ‘safe pair of hands’ box.

List your leadership evidence. Include outcomes, not just effort. Security leaders are often assessed on confidence, authority, crisis judgement, stakeholder trust and commercial awareness. So, map your experience to those areas.

Prepare for vague feedback such as:

• “You’re not quite ready.”

• “We need someone more strategic.”

• “You need more exposure.”

• “The timing isn’t right.”

Your job is to turn vague feedback into criteria, timing and sponsorship.

SCRIPT

TEMPLATE

“I’d like to discuss my progression into a leadership role.

“I’ve been operating beyond my current title in several areas: leading incident response discussions, managing stakeholder expectations, mentoring newer team members and improving how we report risk.

“I’m not asking for a general sense of whether I’m ‘ready’. I’m asking for a clear assessment against the leadership criteria. Where do I already meet the bar, and where is there a gap?

“If there is a gap, I’d like us to define it properly and agree what opportunity will let me close it. If there isn’t a material gap, then I’d like to discuss the role, title and compensation that match the work I’m already doing.”

If the response is: “We need someone with more gravitas,” respond with:

“Can we define what gravitas means in this role? If it means executive presence, calm decision-making, stakeholder influence or commercial judgement, I’m happy to discuss evidence against each of those criteria. I don’t want us to use a criterion that feels meaningful but can’t be assessed fairly.”

If the response is: “You need more visibility,” respond with:

“I’m open to building visibility. I’d like that to be intentional, not accidental. Which meetings, projects or stakeholders do I need access to, and who will sponsor that exposure?”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: if your manager agrees to assess you against criteria and identify a pathway, ask for timelines and decision owners.

• Vague reaction: if feedback stays fuzzy, keep asking for examples: “What would you need to see that you are not seeing now?”

• Gatekeeping reaction: if leadership agrees you are valuable but will not define the path, that is information. You may need a sponsor, a transfer or an external opportunity.

This constructive resolution is a leadership pathway that is specific enough to act on. If it remains vague, the vagueness is part of the answer.

SCRIPT 5: RE-FRAMING SECURITY METRICS TO VALUE DE-ESCALATION OVER PHYSICAL FORCE

Use this when performance is being measured by visible interventions, removals, arrests, shows of force, or ‘hard’ incident response while prevention and de-escalation are treated as invisible.

PREPARATION

Identify what is currently being rewarded. Then identify what good security prevents: injuries, reputational harm, customer distress, staff trauma, liability, downtime, escalation to police, media attention and repeat incidents.

Bring examples of incidents resolved through calm communication, early detection, environmental awareness or relationship-building. If de-escalation is not recorded, it is part of the problem.

SCRIPT TEMPLATE

“I’d like to challenge how we are measuring security performance.

“At the moment, the most visible metrics are incidents, interventions, removals and response times. Those matter, but they don’t tell the whole story. They can also create a culture where force looks like effectiveness, and prevention becomes invisible.

“A strong security outcome is often the thing that didn’t happen: the conflict that was defused; the person who was redirected before a confrontation; the staff member who felt safe enough to report early; the risk that was spotted before it became a headline.

“I’d like us to add de-escalation and prevention measures to our reporting. Not as soft metrics, but as risk-control metrics.”

If the response is: “We need hard numbers,” reply with:

“Agreed. We can count prevention work too. We can record de-escalation attempts, welfare checks, early interventions, repeat-location risks, customer complaints avoided, and incidents resolved without force.”

If the response is: “That sounds too soft for security,” reply with:

“De-escalation is not soft. It is disciplined control under pressure. If we value only force, we are measuring the loudest part of security, not necessarily the most effective part.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: if leadership agrees to broaden the dashboard, suggest a pilot for one site, event, shift or reporting period.

• Sceptical reaction: if the idea is treated as nice but secondary, ask what current metrics miss and whether those blind spots create operational risk.

• Cultural resistance: if team members mock de-escalation as weakness., bring the discussion back to professionalism. “Force is sometimes necessary, but needing less of it is usually a sign of better control.”

This constructive resolution is a reporting model that values prevention, restraint, safety and judgement alongside response.

SCRIPT 6: RESPONDING WHEN YOUR EXPERTISE IS INTERRUPTED, REPEATED OR REBRANDED

Use this when you make a point, it is ignored then someone else repeats it and receives credit.

PREPARATION

Notice the pattern. Is it one person, a meeting dynamic or a culture where women are expected to contribute but not visibly lead?

Prepare a line that reclaims the point without sounding like you are asking permission. The aim is not to embarrass the other person. The aim is to correct the record.

SCRIPT TEMPLATE

In the meeting, say:

“Yes, that connects with the recommendation I made earlier. I’ll build on it with the next step.”

Or: “I want to bring us back to my original point, because the risk issue is still unresolved.”

For a private follow-up with the chair or manager:

“I want to talk about how contributions are being handled in meetings.

“Today I raised the issue of [specific issue]. It didn’t get traction until it was repeated later by someone else. That may not have been deliberate, but it affects whose expertise is seen.

“I’d like you to help correct that in the moment.

If I raise a point and it gets picked up later, I’d appreciate you saying, ‘That builds on Abigail’s earlier recommendation,’ or simply inviting me to continue.”

If the response is: “You should speak up more,” come back with:

“I did speak up. The issue is not only whether I speak. It is whether the room recognises and uses the contribution when I make it.”

If the response is: “That happens to everyone,” say:

“It may happen broadly, and I’m raising it because there is a pattern here. If we want the best risk decisions we need to track where ideas come from, and not just who says them loudest.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: the chair starts attributing points and inviting you back into the discussion.

• Deflecting reaction: if you are told to be more assertive, restate the difference between assertiveness and recognition.

• Repeated pattern: if disregard of your contributions continues, document examples and raise this as a meeting effectiveness issue, not just a personal frustration.

This constructive resolution is not about seeking applause, it is about accurate attribution and better use of expertise.

SCRIPT 7: CALLING OUT ASSIGNMENT BIAS

Use this when women are repeatedly given note taking, welfare, coordination, admin, mentoring or ‘people smoothing’ tasks while men receive visible operational or strategic opportunities.

PREPARATION

Track the pattern over a few meetings or projects. Assignment bias is easier to dismiss when it appears to be an isolated incident. It becomes harder to ignore when you can show repeated occurrences.

• Be clear on the changes you want:

• Rotation of admin tasks.

• Fair assignment of visible work.

• Tasks matched to development goals.

• No assumption that women will handle emotional labour.

SCRIPT TEMPLATE

“I want to raise how work is being allocated.

“I’ve noticed I’m often asked to take notes, coordinate follow-ups, smooth stakeholder issues or support others, while higher-visibility operational work is going elsewhere.

“Those support tasks matter. I’m not above them. But if they are repeatedly assigned to the same people, they affect development, visibility and promotion readiness.

“I’d like us to rotate the support work and be more deliberate about who gets stretch assignments. For this project, I’d like to lead [specific task or workstream].”

If the response is: “You’re good at it,” come back with:

“Thank you. I know I do it well. That’s exactly why we need to be careful it doesn’t become a default role that limits my exposure to other work.”

If the response is: “Everyone has to pitch in,” respond with:

" This constructive resolution is not about seeking applause, it is about accurate attribution and better use of expertise."

“Agreed. Pitching in should be shared. I’m asking for the pattern to be shared too.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: tasks are redistributed and stretch work becomes more visible.

• Polite but unchanged reaction: if everyone agrees in principle but nothing changes, follow up in the next allocation meeting, not weeks later.

• Resentful reaction: if someone implies you are refusing teamwork, clarify by saying: “I’m asking for fair distribution, not exemption.”

This constructive resolution is a work allocation pattern that does not quietly turn women into the team’s support infrastructure.

SCRIPT 8: CHALLENGING PROMOTION GATEKEEPING AND ‘READINESS’ LANGUAGE

Use this when promotion standards shift, feedback stays subjective or men are promoted on potential while women are asked for more proof.

PREPARATION

Prepare a simple evidence table for yourself: criteria, evidence, gaps, next action. Bring examples of work that show you are already operating at the next level.

Listen closely for subjective terms:

• “Ready”

• “Polished”

• “Strategic”

• “Confident”

“ Prepare a simple evidence table for yourself: criteria, evidence, gaps, next action. Bring examples of work that show you are already operating at the next level.”

• “Executive presence”

• “Fit”

These words are not always unfair, but they need definitions.

SCRIPT TEMPLATE

“I’d like to make sure the promotion criteria are being applied consistently.

“I’ve heard that I’m ‘not quite ready’, but I need to understand what that means in observable terms. Which part of the next-level role am I not yet demonstrating?

“I’d also like to compare that with the work I’m already doing: [name two or three examples].

“If the standard is experience, let’s define the experience. If the standard is leadership behaviour, let’s name the behaviour. If the standard is visibility, let’s agree who will create that visibility and by when.”

If the response is: “You just need more time,” reply with:

“Time by itself won’t close an undefined gap. What specifically should be different three or six months from now?”

If the response is: “You need to be more confident,” reply with:

“Can you give me an example of where confidence was missing and what you would expect to see instead? I want feedback I can act on.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: feedback becomes specific, and a promotion pathway is agreed.

• Foggy reaction: if you receive language but no criteria, ask for examples in writing.

• Unfair standard becomes visible: if the bar keeps moving, name that carefully: “I’m concerned the criteria are shifting. I’d like us to document the standard we’re using.”

This constructive resolution is a promotion conversation with evidence, criteria and a decision date.

SCRIPT 9: RESPONDING TO BEING LABELLED ‘TOO AGGRESSIVE’ OR ‘NOT COLLABORATIVE’

Use this when directness, challenge or authority is being interpreted more negatively because it comes from a woman.

PREPARATION

Separate style feedback from substance. There may be useful feedback inside the comment, but vague labels are not enough. Ask for examples, impact and an alternative behaviour that still allows you to lead.

Do not apologise for having a view. If you did interrupt, dismiss or speak harshly, own that specific behaviour. But do not accept a broad personality label without examination.

SCRIPT TEMPLATE

“I want to understand the feedback properly.

“When you say I was ‘too aggressive’ or ‘not collaborative’, can you point to the specific behaviour you mean? Was it my tone, the timing, the fact that I challenged the recommendation or something else?

“I’m open to adjusting how I communicate. I’m not open to losing the ability to challenge risk decisions clearly. That is part of my role.

“What would strong, direct challenge look like to you in that situation?”

If the response is: “It’s just how you came across,” respond with:

“I hear that, but I need more than an impression if I’m expected to change something. What did I say or do that created that reaction?”

If the response is: “You made people uncomfortable,” respond with:

“Discomfort can happen when risk is challenged. I want to know whether the discomfort came from my behaviour or from the issue being raised. Those are different.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: if the feedback becomes specific and usable., agree to adjust behaviour where reasonable while keeping your authority intact.

• Gendered double standard becomes clearer: if similar behaviour from men is accepted, raise consistency: “I’d like the same standard applied across the team.”

• Label sticks without evidence: document the conversation and seek a second view from a sponsor, mentor, HR partner or trusted senior leader.

This constructive resolution is feedback that improves communication without punishing women for being clear.

SCRIPT 10: REFRAMING INCIDENT DEBRIEFS SO WOMEN ARE NOT BLAMED FOR SYSTEM FAILURES

Use this when an incident review focuses on one person’s actions while ignoring staffing, training, equipment, process, rostering, role clarity, client pressure or leadership decisions.

PREPARATION

Write down the timeline. Include decisions made before the incident, resourcing constraints, escalation points and what information was available at the time. Avoid making it personal, even if the review feels personal.

Prepare to move the conversation from blame to learning.

A useful question would be:

“What would have needed to be true for a better outcome to be more likely?”

SCRIPT TEMPLATE

“I want this debrief to be useful, so I’d like us to look beyond the final moment of the incident.

“The decision made on the floor matters, and I’m prepared to discuss it. But if we only focus there, we may miss the system conditions that shaped the outcome.

“We should also look at staffing levels, role clarity, escalation options, client instructions, training, communication channels and whether the team had enough authority to act earlier.

“My concern is that, if we frame this as an individual failure, we may think we’ve solved it without actually reducing the risk.”

If the response is: “Someone has to be accountable,” respond with:

“Accountability matters. I’m asking for complete accountability, not narrow accountability. That means looking at the person, the process and the leadership conditions around the decision.”

If the response is: “Don’t make excuses,” respond with:

“I’m not trying to remove responsibility. I’m trying to understand cause. If we confuse cause analysis with excuse-making, we will keep repeating the same issue.”

EXPECTED OUTCOMES AND NEXT STEPS

• Constructive reaction: the debrief expands to include system factors and preventive actions.

• Blame-focused reaction: if leadership pushes for a simple culprit, keep returning to risk reduction: “What change will prevent recurrence?”

• Political reaction: if people avoid naming seniorlevel decisions, document the unanswered questions and ask that they be included in the debrief record.

This constructive resolution is an incident review that improves the system, not just one that finds someone to carry the discomfort.

A CLOSING LINE FOR ALMOST ANY DIFFICULT CONVERSATION

When the room gets tense, this line can bring people back.

“I’m not raising this to make the conversation harder. I’m raising it because the current pattern is already hard, just not equally hard for everyone.”

Then pause. Silence can do some of the work.

QUICK REFERENCE: WHEN SOMEONE REACTS BADLY

Reaction

Denial

Deflection

What it may sound like A steady response

“That’s not what I meant.”

“This happens to everyone.”

Confidentiality block

Retaliatory awkwardness

“We can’t talk about that.”

False agreement

“I’m not debating intent. I’m naming the impact so we can address it.”

“It may happen broadly. I’m raising the pattern I’m seeing here.”

FINAL REMINDER

“Fine, I’ll never say anything again.”

“Sure, we’ll keep it in mind.”

“I’m not asking for private information. I’m asking for the criteria that apply to this role.”

“That’s not what I’m asking for. I’m asking for a more professional standard.”

“Thank you. What will change, and when should we review it?”

A courageous conversation does not have to be dramatic. Sometimes it is just one woman refusing to let a vague comment pass as a fair process.

The aim is not to win the room in one sentence. The aim is to move the standard.

Minimising

“You’re overthinking it.”

“I’m being specific, because the impact is practical.”

Tone-policing

“You need to say it differently.”

“I’m open to discussing delivery. I also want us to stay with the substance.”

" A courageous conversation does not have to be dramatic.

Sometimes it is just one woman refusing to let a vague comment pass as a fair process.

Budget excuse

“There’s no money.”

“Then let’s separate recognition, timing and the decision pathway.”

The aim is not to win the room in one sentence. The aim is to move the standard.”

Adjunct Lecturer School of Social Science (Cyber-Criminology)

Cybercrime is big business, thanks to technical advancement and interconnectivity creating more opportunities. This regular column will explore various aspects of cybercrime in an easy-to-understand manner to help everyone become more cyber safe.

Staying safe from cybercrime: more than not clicking links

When people think about cybersecurity awareness, the same advice tends to surface: don’t click suspicious links, watch for poorly written emails, be cautious with unexpected attachments.

It is still good advice. It is just no longer enough.

Cybercrime has evolved well beyond obvious phishing attempts. AI-generated content, convincing impersonation, and phone-based social engineering have shifted the landscape. Today, an employee can be manipulated into sharing sensitive information or authentication codes without ever seeing a suspicious email.

The risk no longer sits neatly in an inbox.

Criminal groups are refining their approach. They study behaviour, mimic legitimate interactions, and exploit moments of pressure or routine. A call that sounds like IT support. A message that appears to come from a trusted supplier. A request that feels familiar enough not to question.

The methods change. The intent does not.

This is where traditional awareness programmes can fall short. Static training modules and occasional phishing simulations still have a role, but they tend to focus on patterns that are becoming easier to spot and easier for attackers to avoid.

If awareness stops at “spot the obvious,” it leaves a gap.

Effective cyber awareness now needs to build judgement, not just recognition.

It should help people pause when something feels slightly off, even if it looks legitimate on the surface. It should give them practical ways to verify requests, especially when they arrive through less scrutinised channels like phone calls or in-person interactions.

Just as importantly, it needs to create an environment where checking is encouraged.

Employees should feel confident pausing a request and asking for validation, whether that means calling back through an official number, confirming with a colleague, or reaching out to a security team. That moment of hesitation is often the difference between a near miss and an incident.

There is no loss of credibility in verifying something. There is risk in assuming it is safe.

Awareness programmes need to reflect this shift. They should move beyond teaching people what to avoid, and instead focus on how to think, how to question, and when to slow down.

Because the most effective attacks no longer rely on obvious mistakes.

They rely on trust, familiarity, and just enough urgency to stop someone asking one more question.

And often, that is the question that matters most.

www.linkedin.com/in/amandajane1

www.empressbat.com

WHAT’S HER JOURNEY?

Rachel Choong

Cyber

Security Senior Project Manager

For Rachel Choong, cybersecurity was never part of a carefully mapped career plan. Instead, her journey unfolded through curiosity, opportunity and an unwavering commitment to delivering outcomes. Today, as a Cyber Security Senior Project Manager, she sits at the intersection of technology, leadership and security proving that some of the most impactful careers are built not by following a script, but by saying yes to challenges others avoid.

Rachel entered cybersecurity through project management, bringing with her a talent for delivering complex technology programs. It was a skillset that naturally aligned with an industry increasingly tasked with protecting the very systems organisations rely upon.

“I came into cybersecurity through project management; I was good at delivering complex technology programs and that naturally led me to the intersection of what organisations were building and what they needed to protect.”

More than a decade later, her passion for cyber remains as strong as ever. Rather than specialising narrowly, Rachel has intentionally sought out diverse experiences across different cyber streams, technologies and products.

“What has kept me interested over more than 10 years in cyber is deliberately taking on different cyber streams and products. I try to not stay in one stream of work within cyber. Each new stream brought a different set of technologies and stakeholders and that variety kept the work engaging. As the threat landscape itself keeps evolving, there is always something new to learn and something important to defend.”

Her transition into cybersecurity was far from conventional. After building strong project management credentials including PMP, Certified Scrum Master, PRINCE2 and Scaled Agile certifications an unexpected opportunity emerged.

“My transition from digital into cyber security was not something I planned. It happened because I speak several languages and a global cyber security program needed a project manager who could work effectively with Asian teams. That language and cultural capability opened a door that pure technical skills would not be sufficient.”

Thrown into complex cyber programs involving data centres, identity access management and forensic solutions, Rachel had no formal cybersecurity background. What she did possess, however, was curiosity, determination and a willingness to learn.

“I spent long hours at work learning and delivering at the same time; they were genuinely interesting hours. That curiosity, that willingness to push myself into something unfamiliar, learning and support from the global team, was what carried me through.”

Her commitment to lifelong learning has remained a defining feature of her career. Studies in Leadership Principles at Harvard Business School, AI in Healthcare at Stanford, and AI Security Specialist training reflect a philosophy she continues to live by.

“I believe in staying relevant. That mindset of proactive learning has been one of the most consistent decisions of my career, even when managing my projects day to day.”

While cybersecurity is often viewed as a technical profession, Rachel believes its greatest challenges are deeply human. Across complex, high-pressure environments, she has learned that success is less about technology and more about people.

“Technical problems have solutions. Most of the security architects I worked with were experts in solutioning. Human complexity is different.”

Her leadership philosophy centres on trust, belonging and psychological safety principles she believes separate high-performing teams from average ones.

“What I have learned and what I genuinely believe separates great teams from average ones, is that performance is more than just about competency. It is about the environment. You can hire the most technically brilliant people in the room and still have an underperforming team if the environment does not support them.”

Throughout her career, Rachel has repeatedly transformed struggling teams into thriving ones by placing people first.

“I treat people like they matter, because they do. When people feel disrespected, they disengage. When they feel valued, acknowledged, and seen, even something as simple as communicating if they perform a job well, their motivation changes completely.”

For Rachel, leadership is not about perfection but about unlocking potential.

“There is no such thing as a perfect team. There will always be problems. But if you align people to a shared goal, look for the strengths each person brings, stay optimistic, and work as one team, you can bring out things in people they did not know they had.”

Like many entering cybersecurity, Rachel experienced moments of uncertainty. Without a formal cyber background, the steep learning curve could easily have become a barrier. Instead, she chose to see it as an opportunity.

“When I first entered cybersecurity, I had no formal background in it, the projects were complex, the learning curve was steep, and there was uncertainty if I could deliver. What carried me through was choosing to see things differently. I embraced a growth mindset and saw the difficult projects as opportunities to shape my future.”

She views cybersecurity not merely as a profession, but as a responsibility.

“I see being in cybersecurity as a kind of good fortune, like a guardian protecting organisations and the communities from threats. I have strong self-awareness that the work is hard, but my work is shaping a better future.”

Rachel’s career has continued to evolve organically, driven by delivery and trust rather than predetermined titles. One recent achievement involved establishing a hybrid SOC team and implementing a new SIEM platform under significant time pressure, earning praise from senior executives.

Yet when asked what advice she would offer the next generation, her focus shifts firmly away from technical capability.

“My advice to my high school self and to any young person entering cyber security today, starts with something that does not appear in any curriculum: develop your emotional intelligence and your soft skills.”

She believes human skills are increasingly becoming cybersecurity’s greatest differentiator.

“Your technical skills will get you a job. Your human skills will keep you there.”

As a people leader, Rachel sees communication and stakeholder management as critical skills for future cyber professionals.

“The most common gap I see in cyber security professionals is not technical. It is the ability to translate complex risk into language that a board, an executive team, or a non-technical colleague can understand and act on.”

She also advocates strongly for project management skills and emerging knowledge areas such as AI governance.

“The professionals who stay ahead are the ones who built the habit of learning continuously.”

Looking ahead, Rachel sees artificial intelligence as the defining force shaping cybersecurity.

“AI is the biggest shift since the industrial revolution. The question for every professional, every organisation, every leader right now is not whether to engage with it. It is whether you are going to ignore it or make something good out of it.”

She believes AI presents both unprecedented opportunities and risks.

“AI is both the greatest defensive tool we have, and the most powerful weapon threat actors have ever been given. That duality is what makes this moment so critical.”

From sophisticated phishing campaigns to deepfakes and voice cloning, Rachel believes organisations must rapidly adapt their security awareness strategies.

“Voice cloning means that hearing someone’s voice is no longer verification of their identity.”

Beyond cybersecurity itself, one of Rachel’s proudest achievements has been interviewing 54 senior leaders for her book, 54 Inspired Leaders . What began as an act of giving back became an extraordinary learning experience.

“The 54 leaders I interviewed for my book shaped me more than I expected. The book was purely an act of giving back and using my strengths which is listening.”

The experience reinforced her belief that leadership and cybersecurity are inseparable.

“I was not brought into the CISO’s most critical programs because I was the most technical person in the department. I was brought in because I deliver, which means I can lead people, manage complexity, navigate stakeholders, and get things done under pressure. That is leadership applied to cyber security.”

At the heart of Rachel’s career lies a strong sense of purpose.

“I make no money from the book. And I find genuine joy in the work. That is my higher purpose. Achieving something meaningful and having fun along the way. If I can help uplift even one person out there to become a better leader, I declare that a victory.”

That same philosophy extends to the way she approaches work-life balance. Through meditation, small habits and deliberate recovery, she prioritises sustainability in an industry known for its intensity.

“The same philosophy applies to burnout prevention. Do not wait until you are depleted to rest. Build recovery into the routine. Sustainability is a strategy, not a luxury.”

For Rachel Choong, cybersecurity has never been solely about technology. It is about people, leadership and creating environments where others can thrive. Her journey demonstrates that while technical expertise may open doors, it is empathy, resilience and purpose that create lasting impact.

And perhaps her most powerful message is the simplest: come as you are, keep learning, and use your strengths to lift others along the way.

www.linkedin.com/in/rachel-choong-80160014b

I S N O W A I S A ' S N E W I S N O W A I S A ' S N E W

P U B L I S H I N G P A R T N E R P U B L I S H I N G P A R T N E R H N A

Click here to read the newest edition of Cyber Today

Wendy Ngcongo

Cybersecurity Architect | Data | Cloud | AI

Wendy Ngcongo’s path into cybersecurity was never linear, but it was always deliberate.

“My journey into cybersecurity has not been a straight line, but it has been deeply intentional,” she says.

Born in Izingolweni, a small and underprivileged community in KwaZulu-Natal, South Africa, Wendy spent her early years there before later being raised in Durban, where her journey began to expand through education, exposure, and mentorship.”

“She instilled in me the importance of education, discipline, and learning a skill,” Ngcongo reflects. “She taught me that growth requires effort, and that education can open doors far beyond the environment you come from.”

That sense of possibility first showed up as curiosity. Not a grand career plan. Just questions.

“I was always curious about how things worked, and that curiosity introduced me to computers,” Wendy says. “I remember being fascinated by the simple ability of a computer to type a document, save it, and retrieve it later. Coming from an underprivileged background, that felt powerful to me.”

That moment was simple on the surface. It was enough to pull her further in.

Ngcongo began working with computer and cellphone repairs. It was hands-on, sometimes messy, and exactly what she needed.

“That practical exposure revealed something important about me: I was drawn to how systems connect,” she explains.

That realisation led her into networking, where the bigger picture started to form.

“Networking helped me understand how devices communicate, how data moves, and how infrastructure supports the digital services people rely on every day.”

From there, the transition into cybersecurity felt less like a pivot and more like a continuation.

“Once you understand how systems connect, you also begin to understand where they can be exposed, misconfigured, attacked, or protected,” she says. “Networking became the bridge between my early technical curiosity and the cybersecurity work I do today.”

Along the way, mentorship played a quiet but important role. A lecturer from the Durban University of Technology offered guidance that sharpened her focus and discipline.

“That mentorship exposed me to the value of guidance, discipline, and learning from people who had already walked ahead of me.”

Wendy continued to build on that foundation through formal studies and ongoing certifications, expanding her scope beyond technical execution into cloud, data, and governance. Each layer added context. Each step made her thinking broader, not just deeper.

“One of the most important lessons I have carried from networking into cybersecurity is that security is shaped long before an incident occurs,” she says. “The way systems connect, the way traffic moves, the way access is granted, and the way environments are monitored all influence how resilient an organisation becomes.”

It’s a perspective that now defines her work as a cybersecurity architect. Security, for her, isn’t reactive. It’s designed.

“Cybersecurity is not only a technical function, but an architectural and operational responsibility.”

Consulting has become a natural extension of that mindset. She works closely with organisations to translate technical complexity into something more usable, something that informs real decisions.

“I enjoy helping organisations understand technical risk in a practical way, especially where security decisions influence operations, resilience, and longterm business confidence.”

“Many people think they need to know everything before they begin. My experience has taught me the opposite. You grow by building strong foundations, asking questions, practising consistently, and allowing your path to unfold with discipline and patience.”

Still, the journey hasn’t been without doubt. There were moments where stepping into certain rooms felt uncertain.

“There were moments where I questioned whether I was ready for certain spaces,” she admits. “Those moments taught me that confidence is built through preparation, exposure, and the willingness to keep growing.”

It’s a sentiment that sits in contrast to the common assumption that people need to “arrive” before they begin.

“Many people think they need to know everything before they begin. My experience has taught me the opposite. You grow by building strong foundations, asking questions, practising consistently, and allowing your path to unfold with discipline and patience.”

Today, Wendy sees cybersecurity as one of the defining fields of this era, shaped by rapid digital transformation and shifting risk landscapes.

“Organisations are becoming more digital, cloud adoption is increasing, AI is changing how businesses operate, and cyber threats are becoming more sophisticated,” she says. “Security professionals must think beyond tools and understand how risk, architecture, and people influence security outcomes.”

Looking ahead, she is clear about where the pressure points will sit.

“Cybersecurity will be heavily shaped by AI-driven threats, cloud security, identity protection, data privacy, and operational resilience,” she says. “Attackers are becoming faster, more automated, and more creative.”

But with that complexity comes a shift in responsibility.

“This is where cybersecurity becomes more than a technical career. It becomes a leadership responsibility.”

For Wendy, the most meaningful part of her work isn’t just solving problems. It’s helping reshape how organisations think.

“I find purpose in helping security become clearer, more practical, and more connected to business decisions.”

And when it comes to those considering the field, especially women, her advice is steady and grounded.

“Build the foundation first. Learn networking, understand how systems connect, and do not rush to look advanced before you understand the basics.”

“There is no single path into this field. Some people enter through IT support, networking, software development, audit, risk, governance, cloud, or data. What matters is not where you start, but how intentionally you build.”

She’s also quick to challenge the idea of a single entry point.

“There is no single path into this field. Some people enter through IT support, networking, software development, audit, risk, governance, cloud, or data. What matters is not where you start, but how intentionally you build.”

For women stepping into cybersecurity, she keeps it simple.

“Stay curious, build the foundation, and allow your voice to grow with your journey.”

Her own journey is still unfolding, shaped by each decision, each lesson, each stretch into something new.

“My journey is still unfolding, but I am grateful for every step,” she says. “Cybersecurity has challenged me, stretched me, and given me opportunities to contribute to something bigger than myself.”

At its core, that’s what continues to drive her.

“At the heart of my journey is a desire to help build safer digital environments and to inspire others to believe that they too can grow into meaningful, impactful roles in this industry.”

www.linkedin.com/in/wendy-ngcongo-455035155

ADVERTISING PACKAGE EXCLUSIVE

For the past four years , Source2Create has proudly delivered Women in Security Magazine to the industry free of charge , championing diversity, inclusion, and the incredible contributions of women in cybersecurity. As we continue to grow, we now need partners to help us sustain and expand this vital platform.

By supporting this package, you’re not just backing us—you’re investing in the magazine, its community, and the future of women in security. To ensure we can keep delivering this high-value publication, we’re introducing a nominal fee for $900 Ex GST, an exceptional package that provides extensive coverage and visibility.

Samantha Finan

Independent CISO

Cybersecurity was never part of Samantha Finan’s master plan. In fact, as she reflects on her career today as an Independent CISO with more than two decades of experience, she is the first to admit that the industry found her rather than the other way around.

“Honestly, I completely fell into it and I mean that in the best possible way,” she says. “When I emigrated back to the UK from Canada, I needed to find my footing in a new job market, and cybersecurity found me more than I found it.”

What began as an unexpected career move quickly evolved into a lifelong passion. For Samantha, the dynamic nature of cybersecurity became impossible to resist. The ever-changing threat landscape, emerging technologies and shifting regulations ensured there was always something new to learn.

“There is genuinely never a dull moment,” she explains. “The field is constantly evolving, the

threat landscape shifts, the technology changes, the regulatory environment moves and you have to move with it.”

Over the years, Samantha’s own perspective evolved alongside the profession itself. What was once considered a backoffice IT function has transformed into a board-level priority, placing security leaders at the centre of business strategy.

“What started as a happy accident has become something I’m deeply passionate about,” she says. “My own interest mirrors that journey: from the technical and operational nuts and bolts early on, to now thinking about how security enables business strategy and how you quantify and communicate risk at the highest levels of an organisation.”

Early in her career, Samantha embraced opportunities before feeling entirely ready. Working in Access Control at SBC Warburg and later expanding her expertise at Dresdner and Standard Chartered, she built her knowledge through hands-on experience while investing in professional development.

“I didn’t wait to feel completely ready before stepping into bigger roles,” she says. “I also invested in my credentials early.I first achieved my CISSP back in 2002, which at the time was a real marker of seriousness in the field.”

That blend of practical experience and formal certification became a powerful foundation. Yet Samantha believes curiosity has been equally important.

“There came a point where I became more intentional about the kind of leader I wanted to be and the culture and standards I wanted to set. That intentionality around leadership has become just as central to who I am professionally.”

“Cybersecurity rewards people who ask ‘but why?’ and ‘what if?’ constantly,” she says.

Like many leaders in the industry, Samantha’s journey has not been without moments of self-doubt. Without a traditional computer science background, she sometimes questioned whether she belonged in the field.

“There were absolutely moments of imposter syndrome particularly when stepping into more senior roles or presenting to increasingly senior audiences,” she says.

Rather than focusing on what she lacked, Samantha leaned into the strengths she brought to the profession.

“What helped me was focusing on what I did bring: strong communication skills, an ability to see the bigger picture, genuine curiosity, and a real commitment to understanding the business context of security, not just the technical side.”

She also found strength in the cybersecurity community itself.

“People in this field tend to be generous with their knowledge and time,” she says. “Leaning into that community rather than trying to go it alone made a huge difference.”

Her path to leadership unfolded organically rather than through rigid career planning.

“I had no five-year plan that involved becoming a CISO,” Samantha says. “For a long time I was focused on doing the current job really well rather than plotting the next three moves.”

Instead, she followed challenging problems wherever they emerged, particularly in identity and access management long before identity security became a boardroom issue.

“I think there’s real value in being genuinely engaged with the work in front of you, rather than always looking over your shoulder at the career ladder,” she reflects.

As her career progressed into Managing Director roles, her focus shifted beyond technical excellence to leadership and culture.

“There came a point where I became more intentional about the kind of leader I wanted to be and the culture and standards I wanted to set,” she says. “That intentionality around leadership has become just as central to who I am professionally.”

Today, one of the most complex challenges

Samantha tackles is the safe adoption of artificial intelligence. In her current work, she has been developing security frameworks and guardrails for AI and generative AI technologies.

“The technology is moving so fast that the risk landscape is shifting almost in real time,” she explains. “You’re trying to enable innovation while managing real data protection, access and model risks.”

Her approach is rooted in collaboration rather than restriction.

“If you just say ‘no’ to everything, you lose credibility and people go around you,” she says. “Understand

the tools deeply, engage with the business on what they’re actually trying to achieve, and build practical guardrails that protect without paralysing them.”

Looking ahead, Samantha sees AI reshaping cybersecurity on both sides of the equation.

“Both cybercriminals and cybersecurity teams are racing to leverage AI, and the arms race is intensifying rapidly,” she says. “AI-powered detection and response will become genuinely transformative, but the risks are real and growing.”

Among the emerging threats that concern her most are AI-enabled attacks, identity-based threats and growing geopolitical tensions.

“None of these are entirely new,” she says, “but their scale, sophistication and speed are escalating in ways that demand constant vigilance.”

When reflecting on the people who shaped her career, one name stands above all others: Wendy Nather.

“Without question, Wendy Nather took a chance on me early in my career, and I genuinely haven’t looked back since,” Samantha says. “The fact that she saw potential in me and gave me an opportunity when I was finding my feet shaped not just my career trajectory but also the kind of leader I’ve tried to become.”

“Cybersecurity needs people who can think critically, communicate clearly, understand human behaviour and navigate organisations.”

That influence continues through Samantha’s own commitment to mentorship. Five of the people she has mentored have gone on to become CISOs themselves, a legacy she values deeply.

“I hope I gave them some fraction of what Wendy gave me,” she says.

For the next generation considering a cybersecurity career, Samantha’s advice is simple but powerful.

“Don’t wait until you feel ready,” she says. “Cybersecurity needs people who can think critically, communicate clearly, understand human behaviour and navigate organisations.”

Her own journey proves exactly that. From an accidental introduction to cybersecurity to becoming a trusted boardroom advisor and Independent CISO, Samantha Finan’s career demonstrates that there is no single path into the profession. Curiosity, courage, community and continuous learning can open doors that no carefully constructed plan could ever predict.

And perhaps her greatest lesson is one that resonates far beyond cybersecurity itself: success is rarely achieved alone.

“Find your people early,” she says. “The mentors, the colleagues, the community. This is not a field where you succeed alone, and the relationships you build will shape your career in ways you can’t predict.”

www.linkedin.com/in/samantha-finan

Nagammai Shanmugham

CISO Standard Chartered

Nagammai Shanmugham, was never simply about protecting systems. It was about transforming the way organisations think about security itself.

Today, Nagammai serves as Vice President, Identity & Access Management SME in the CISO Organisation for Group Functions at Standard Chartered, where she leads strategic initiatives that enhance identity security, enable business resilience, and foster trust in an evolving digital landscape.

She started her career working closely with enterprise systems and production environments, gaining firsthand insight into the realities of business operations. It was during these formative years that she observed a challenge that would ultimately define her professional mission.

“I witnessed several situations where information security was perceived as a blocker to business productivity rather than a strategic enabler,” Nagammai recalls. “One particular real-world incident deeply influenced my thinking. I saw how

delayed security integration created operational friction, increased risk exposure and impacted business confidence.”

That experience ignited a passion to change the narrative.

“I wanted to contribute toward building security practices that support sustainable production environments while enabling business growth and innovation,” she says.

Over time, her interests expanded far beyond infrastructure and operational security into areas including Governance, Risk and Compliance (GRC), Identity and Access Management (IAM), Cloud Security, Security Operations Centre (SOC) functions and Application Security.

Today, her philosophy is clear.

“I view cybersecurity not as a control function alone, but as a business enabler that builds trust, resilience and long-term organisational value.”

Her rise into cybersecurity leadership was driven by deliberate and continuous learning. Recognising the multidisciplinary nature of the profession, Nagammai invested heavily in building both technical and governance expertise. Alongside certifications such as CISSP, Certified CISO, ISO 27001 Lead Auditor and Implementor, SCJP and CCNP Route & Switch, she pursued a Post Graduate Diploma in Cyber Law and Cyber Forensics.

Her learning journey continues even today as she undertakes a Master’s program in Artificial Intelligence and Machine Learning with MLOps as an elective.

“I strongly believe cybersecurity professionals must evolve alongside emerging technologies,” she says.

Beyond formal qualifications, practical experimentation became an essential part of her growth.

“I consistently worked on personal design and development initiatives to sharpen my practical skills and stay relevant in a rapidly evolving industry.”

Leading cybersecurity in the banking and financial services sector brings unique challenges. The rapid pace of cloud adoption, AI integration, automation and digital transformation means security leaders must constantly balance competing priorities.

“One of the most challenging aspects of leadership in cybersecurity within the BFSI sector is balancing security, compliance, innovation and business agility simultaneously,” Nagammai explains.

Yet for her, the challenge extends beyond technology.

“The challenge is not only technical, it is also cultural and strategic. Security leaders must communicate risk in a language business stakeholders understand and ensure that security becomes part of decision-making from the beginning rather than an afterthought.”

Her approach to overcoming complexity centres on collaboration, trust and mentorship.

“I strongly believe in enabling teams rather than operating through fear-based security models,” she says. “Building trust with stakeholders and demonstrating how cybersecurity contributes to resilience and business continuity has helped me navigate complex environments successfully.”

Like many professionals, Nagammai has faced moments of uncertainty throughout her career. Cybersecurity is a field that demands constant adaptation, and periods of transition can challenge even the most experienced practitioners.

“Cybersecurity is a demanding field that requires constant adaptation, and there were moments where the path ahead seemed unclear,” she reflects.

What kept her moving forward was a commitment to growth and a refusal to let setbacks define her future.

“Most importantly, I would remind myself that authenticity matters. There is no single perfect path into cybersecurity.”

“I consciously chose not to allow temporary setbacks to divert me from my long-term vision. Instead, I focused on strengthening my technical capabilities, leadership skills and industry knowledge.”

Communities also played a vital role in her development. Through mentorship and involvement in professional networks, she found both support and purpose. In particular, Toastmasters became a transformative experience.

“Public speaking and mentoring others allowed me to reflect on my own journey and recognise the impact I could create beyond technical contributions alone.”

If she could speak to her younger self, her advice would extend beyond technology.

“I would tell my younger self that cybersecurity is not just about technology it is about people, trust, communication, resilience and continuous learning.”

She also emphasises the value of leadership and authenticity.

“Technical expertise is important, but the ability to influence, collaborate and inspire others is what truly accelerates long-term success,” she says. “Most importantly, I would remind myself that authenticity matters. There is no single perfect path into cybersecurity.”

Looking to the future, Nagammai believes artificial intelligence will reshape the cybersecurity landscape in profound ways. AI-powered threat detection, predictive analytics and adaptive security

architectures will become increasingly central to enterprise security strategies.

“At the same time, the convergence of AI, cloud computing, identity security and zero trust frameworks will redefine enterprise security models,” she explains.

She also believes cybersecurity’s place in the boardroom will continue to strengthen.

“Cybersecurity is no longer viewed purely as an IT responsibility; it is becoming a business-critical leadership function.”

However, emerging threats continue to evolve just as rapidly. Nagammai points to AI-powered attacks, sophisticated social engineering, deepfakes and AIgenerated phishing campaigns as some of the most pressing risks organizations will face.

“The challenge will not only be technological but also related to governance, visibility and skilled talent availability,” she warns.

Among the greatest influences on her journey have been professional communities and a lifelong commitment to learning. Her involvement with cybersecurity organisations and Toastmasters has helped shape her into the leader she is today.

“Toastmasters helped me transform from a technical professional into someone capable of articulating

EDITORIAL THEMING & DEADLINES

For Stephanie Uzama, cybersecurity was never part of a grand career plan. Instead, it began with something far simpler than curiosity.

Coming from a healthcare background, Stephanie was already familiar with environments where precision, trust and accountability mattered deeply. Yet as she observed the increasingly digital world around her, she became fascinated by a question that sits at the heart of cybersecurity: how can systems we rely on every day fail or be manipulated without obvious signs?

That curiosity slowly evolved into purpose.

“Over time, I stopped seeing cybersecurity as just technical security work and started understanding it as a governance and risk discipline,” Stephanie explains.

Today, as a GRC Analyst and Consultant, Stephanie has carved out a path that blends structured thinking, risk management and business alignment proving that cybersecurity careers rarely follow a straight line.

Her transition into the field was driven by intentionality. Rather than consuming information broadly, she focused on building practical capability in areas that directly translated to real-world impact.

“The turning point for me was deciding to move from passive learning to structured building,” she says. “I stopped consuming information randomly and started focusing on areas that would actually translate into professional capability.”

That shift led Stephanie to develop tangible projects such as risk assessments, compliance documentation and governance frameworks that mirrored the realities organizations face every day. She deliberately aligned her learning, writing and portfolio with the type of work she wanted to pursue.

“Clarity made a huge difference,” she reflects. “I began aligning my learning and projects to reflect the kind of roles I actually wanted, instead of staying broad.”

Like many professionals entering cybersecurity, Stephanie experienced moments of uncertainty. The field can appear vast, highly technical and difficult to navigate, especially for those transitioning from another industry.

“There’s always that internal question asking whether you are catching up fast enough or if you are heading in the right direction,” she says.

Rather than measuring herself against others, Stephanie chose a different perspective.

“What helped me was focusing on direction rather than speed. I kept building, kept learning, and allowed progress to show itself over time.”

Her journey into GRC itself was also an evolution rather than a fixed destination. Initially drawn to the technical side of cybersecurity, she eventually discovered governance, risk and compliance and immediately recognised something familiar.

“I realised GRC aligns with how I naturally think,” she says.

That alignment continues to shape her approach today. One of the greatest challenges in cybersecurity, she believes, is bridging the gap between frameworks on paper and the complexity of real organisations.

“In cybersecurity, frameworks are clear on paper, but real environments are messy,” Stephanie explains. “Systems are layered, priorities compete and decisions are rarely black and white.”

As a result, she has learned to think less about perfection and more about context.

“Instead of trying to find perfect answers, I focus on risk-based reasoning: what matters most, what the impact looks like and what is realistically implementable.”

Her work with startups has further reinforced this mindset. Through freelancing engagements, Stephanie spends much of her time helping earlystage companies understand and manage security risks in practical, actionable ways.

“A lot of my work involves helping teams understand their risk posture in practical terms, not overly complex frameworks, but clear direction they can act on.”

What she finds most rewarding is the opportunity to bring structure to complexity.

“There is something satisfying about connecting the dots between risk, controls and outcomes,” she says. “Taking something complex and unstructured and translating it into something clear and actionable makes me feel fulfilled.”

Looking ahead, Stephanie believes artificial intelligence will significantly reshape the cybersecurity landscape in the coming years, creating new governance and security challenges as organizations increasingly rely on AI-driven systems.

At the same time, she sees third-party and supply chain risk as one of the most pressing threats organizations face.

“As organisations become more interconnected, vulnerabilities don’t just come from internal systems but from partners and external dependencies,” she notes.

Professional growth remains central to Stephanie’s journey. She views certifications such as ISO 27001, CRISC and CISSP not simply as credentials, but as opportunities to deepen practical understanding.

“For me, the focus is not just collecting certifications, but choosing ones that deepen practical understanding of how security is implemented and governed in real organisations.”

Among the many influences on her career, Stephanie credits both her healthcare background and the guidance of her mentor, Chineye Udechukwu, for shaping her professional outlook.

“Having someone who consistently reinforces clarity in direction has helped me approach my growth more intentionally rather than randomly exploring different paths,” she says.

If she could speak to her younger self, Stephanie’s advice would be simple yet powerful: focus on consistency.

“Cybersecurity can look overwhelming at the beginning because of how broad it is,” she says. “But clarity comes with time and repetition.”

Her message is one that resonates far beyond cybersecurity.

“Progress in this field is not linear, so it is better to stay consistent than to try to rush competence.”

In a profession often defined by rapid change and emerging threats, Stephanie Uzama’s journey is a reminder that success is not built overnight. It is built through curiosity, intentional growth and the courage to follow a path that evolves along the way.

www.linkedin.com/in/stephanie-uzama-40619a273

Sandra Estok

Sandra Estok was eleven years old when life narrowed quickly.

“I was eleven years old when my mom and I were evicted,” Sandra says. “The only place she could afford to rent was a small shack. There was no running water. No bathroom. Just enough space for the two of us.”

At that age, she didn’t have the language to describe what she was living through. No talk of resilience. No framing of adversity. Just observation.

“I only knew that my mother woke up every day and kept going, and so did I.”

That pattern didn’t let up. The instability continued, and eventually, even that small space was gone. By sixteen, Estok had graduated high school and moved in with relatives, choosing a one-year secretarial program with a clear goal in mind.

“I wanted to help support my family. I was practical. Dreams felt expensive.”

Her first step into the working world came through an internship at Heinz in Venezuela. She was still a teenager, working as an administrative assistant, learning structure, responsibility, and rhythm. Then one ordinary task shifted something in her.

“One morning, Gisela, the administrator I supported, called me over and handed me an envelope,” Sandra recalls. “She said, ‘Sandra, please take this package to a hotel.’”

The errand felt simple. The destination did not.

“I looked up and realised it was the Hotel Pipo International, a five-star hotel,” she says. “As I walked inside, I felt like I had stepped into another world.”

Sandra remembers the details. The kind that stays with you.

“The marble floors reflected the light overhead. A stunning chandelier hung from the high ceiling, and elegant flower arrangements decorated the space in a way that felt effortless and intentional.”

After delivering the envelope, something unexpected happened.

“He looked at me and said, ‘Sandra, have a seat. Order breakfast and charge it to my room.’ Then he walked away.”

She hesitated. Then she sat.

“It was a buffet. And to me, that was extraordinary,” she says. “There were more options than I knew what to do with.”

But it wasn’t the food that stayed with her.

“As I sat eating, people started arriving for breakfast. Some wore business suits and carried briefcases. At one table, a woman opened what looked to me like a tiny computer.”

She watched. Quietly.

“Not because I wanted luxury. Not because I wanted the hotel. But because I realised something that had never occurred to me before: people lived like this. People worked like this. People traveled. People created an impact.”

And then, something shifted.

“My mind started visualising. I could see myself wearing a suit. Carrying a briefcase. Traveling. Learning. Making an impact.”

It was subtle, but decisive.

“And quietly, I made a decision. I am going to become a businesswoman. I do not know exactly how yet. But education will be my path.”

“For the first time in my life, I realised there were possibilities beyond the world I had experienced.”

She thought about her family. What they needed. What she could become.

“And quietly, I made a decision. I am going to become a businesswoman. I do not know exactly how yet. But education will be my path.”

She still comes back to that moment.

“That breakfast changed my life.”

From there, the path was built piece by piece. Work during the day. Study at night. Eventually, a qualification in systems engineering and a growing career in technology. It was a movement. Not always smooth, but forward.

Years later, in 2005, that trajectory carried her across continents. Her employer relocated her and her husband from Venezuela to Milwaukee, Wisconsin.

“I still remember my first winter there, snow rising to my knees, the cold shocking my body and my imagination,” Sandra says. “I had built a life that once felt impossible.”

And then, without warning, everything shifted again.

After a trip to South America to visit family, Estok boarded a flight expecting to return home. Instead, she was pulled aside.

“Two Homeland Security officers boarded the plane. I handed over my passport,” she says. “Suddenly, I was the only passenger escorted off the plane.”

What followed was confusion, then fear.

“Hours passed. Questions. Silence,” she recalls. “Eventually, they returned my passport. Stamped in red: REVOKED.”

The reason would take time to surface.

“A criminal in China had stolen my identity and was using my information to smuggle women into the United States.”

The next six years were defined by something most people never imagine needing to prove.

“For six years, I had to prove I was myself. Again. And again. And again.”

It took a toll.

“That experience nearly broke my marriage, my career, and my mental wellbeing.”

But it also forced a deeper question to the surface. One that would quietly redirect everything.

“What does it mean to protect what matters?”

That question became the turning point into cybersecurity. Not out of fear, but clarity.

“I realised cybersecurity was never only about systems, networks, or devices,” Estok says. “It was about people. Identity. Trust. Safety. Human lives.”

From there, Sandra’s work expanded with intention. She founded Way2Protect®, created the Happily Ever Cyber® book series, developed cyber literacy resources for children, and began shaping conversations around digital wellbeing in a way that feels accessible, not abstract.

She doesn’t frame her story around the most dramatic chapter, though.

“But if you ask me what changed my life, I would not say identity theft. I would not say moving countries. I would not say entrepreneurship,” Sandra says.

Instead, she returns to something much quieter.

“I would say it was breakfast. A single moment when possibility entered the room and sat across from me.”

The identity theft taught her something different. Something harder.

“Identity cannot be built only on achievement, titles, or documents. It must be rooted deeper.”

Now, as technology accelerates and the boundaries between physical and digital lives continue to blur, her perspective remains steady.

“Artificial intelligence is reshaping work. Cybersecurity has become part of everyday life,” Sandra says. “Yet my advice remains simple: do not wait for certainty before imagining a different future.”

Sandra is careful about how she frames challenge and identity.

“Your circumstances are not your identity. Your challenges are not your ending.”

And she leaves space for what stories can become when they are used with intention.

“Our stories are not meant to hold us back,” Sandra says. “When we use them with intention, they become our superpower.”

Then, almost as a quiet signature on everything she’s built:

“We all deserve to live Happily Ever Cyber®.”

www.linkedin.com/in/way2protect

For Isabella Schulz, technology was never something distant or unfamiliar.

Growing up in a household where both of her parents worked in IT, conversations about technology were simply part of everyday life. Those early experiences planted the seed for what would eventually become a career in cybersecurity, although at the time she could never have imagined just how diverse and rewarding the profession would prove to be.

“My interest in cybersecurity started when I was young since both of my parents work in IT, so technology was always part of conversations growing up. From an early age, I developed an appreciation for how much modern life depends on technology and the importance of protecting the systems people rely on every day.”

What captivated Isabella most was not simply the technology itself, but the pace at which cybersecurity evolves. In a world where new threats emerge daily, she saw a profession that would continually challenge her to grow.

“What initially attracted me to cybersecurity was how dynamic the field is. Unlike many areas of technology that follow more predictable development cycles, cybersecurity constantly evolves alongside the threat landscape, whereby new risks, technologies and challenges emerge every day, which means there is always something new to learn and a new problem to solve.”

Today, as a Graduate Consultant at KPMG, that fascination has only deepened. Working across a wide variety of clients and industries has shown her that cybersecurity extends far beyond technical controls and security tools. Every engagement offers a new perspective, a fresh challenge and another opportunity to learn.

“Since joining KPMG, my understanding of cybersecurity has expanded significantly. I’ve had the opportunity to work across multiple different clients, industries and engagements, which has given me a much deeper appreciation of how broad the profession is. The combination of technical learning, problem solving and working with experienced

" I still regularly question whether I am technical enough, and I think that is something many people in cybersecurity experience regardless of their level of experience because fundamentally, cybersecurity is a field where there is always more to learn. New technologies, threats and approaches emerge constantly, so it is impossible to know everything. Over time, I have learned that feeling challenged is often a sign that you are growing.”

professionals has reinforced that this is a field I am genuinely passionate about.”

Like many graduates entering the profession, Isabella quickly realised that cybersecurity can feel overwhelming at times. The breadth of knowledge required, coupled with the rapid pace of technological change and the emergence of artificial intelligence, means there is always something new to understand. Rather than allowing that to become intimidating, she has learned to embrace the challenge.

“One of the most challenging aspects of starting a career in cybersecurity is adapting to the breadth of the field. Understanding that there is always more to learn, and as a graduate it can sometimes feel overwhelming trying to understand complex concepts whilst keeping pace with a rapidly changing industry, especially since the adoption of AI has increased so rapidly.”

One project in particular transformed the way she viewed difficult problems. Asked to work on Monte Carlo simulations to model cyber risk outcomes, Isabella initially questioned whether she was capable of contributing to such advanced work. Instead of stepping back, she leaned into the discomfort.

“A project that stands out to me involved using Monte Carlo simulations to model potential cyber risk outcomes for organisations. Initially, I felt completely out of my depth because it combined advanced quantitative analysis with cybersecurity concepts.

Rather than avoiding the challenge, I took the time to understand the mathematics behind the model and how it connected to cyber risk frameworks. Once I understood the foundations, it became one of the most interesting and rewarding pieces of work I have ever been involved in.”

That experience fundamentally changed her outlook.

“That experience reinforced an important lesson for me: many challenges become opportunities when you are willing to stay curious and invest time in learning.”

Even with those successes, Isabella is refreshingly honest about the self-doubt that can accompany a career in cybersecurity. She believes imposter syndrome is something many professionals experience, regardless of where they are in their careers.

“Absolutely. I still regularly question whether I am technical enough, and I think that is something many people in cybersecurity experience regardless of their level of experience because fundamentally, cybersecurity is a field where there is always more to learn. New technologies, threats and approaches emerge constantly, so it is impossible to know everything. Over time, I have learned that feeling challenged is often a sign that you are growing.”

She credits much of her confidence to the people around her, particularly the supportive culture she has found at KPMG and the guidance of one mentor who has played a significant role in her development.

“What helped me navigate those doubts was the support of mentors and colleagues. I have been fortunate to work alongside incredibly talented people at KPMG who are so generous with their time and knowledge. In particular, one of my mentors, Mina Zaki, has had a significant impact on my development. She consistently encouraged curiosity, provided guidance at any time and helped me build my confidence as I learned. Having people who so positively support your growth by encouraging learning makes a tremendous difference when you are starting your career.”

Interestingly, Isabella’s journey into cybersecurity wasn’t mapped out from the beginning. While she always knew she wanted to work with technology, the exact destination only became clear through experience.

“My path unfolded quite organically. In high school, I was interested in technology and knew I wanted to work in IT in some capacity, but I did not have a clear picture of what that career would look like. At university, I gravitated towards data analytics because I enjoyed working with information, identifying patterns, solving complex problems, and turning data into meaningful insights.”

Her time at KPMG ultimately confirmed she had found the right career.

“While I joined KPMG with an interest in cybersecurity, it was only through hands-on experience that I realised how passionate I was about the field, and the more exposure I gained, the more I appreciated the diversity of the challenges and opportunities available within cybersecurity.”

“What has kept me engaged is the fact that no two days are the same. Every client, project and problem presents a new learning opportunity, and my evolving curiosity has confirmed that I am in the right profession.”

If she could offer advice to her younger self, Isabella says she would challenge one of the biggest misconceptions about cybersecurity.

“I would tell my younger self that cybersecurity is much broader than most people think, it’s not just coding.”

“While technical skills are important, cybersecurity also relies on communication, business understanding, critical thinking and problem solving. Many of the most successful professionals in the field can efficiently and clearly bridge the gap between technical concepts and business outcomes, providing an immense amount of clarity in important moments.”

She would also encourage aspiring professionals to develop the confidence to ask questions.

“I would also encourage myself to focus on developing strong communication skills and to never underestimate the value of asking questions. Being able to clearly explain complex ideas and collaborate with different stakeholders is a skill that becomes increasingly valuable throughout your career.”

For Isabella, the people she works alongside continue to be one of the greatest influences on her career. Surrounded by experienced professionals who are generous with their knowledge, she has learned that curiosity is every bit as valuable as technical expertise.

“My mentors at KPMG and all of the individuals who I am able to ask questions to have had an incredible impact on my career and their patience and encouragement has propelled me to strive for success. As a graduate I feel the most important quality one can have is a love of learning, curiosity, and being able to dive head first into a problem and start solving it. The incredibly talented individuals at KPMG have greatly encouraged me to develop my problem solving skills, and I am incredibly fortunate to be surrounded by such amazing individuals and be able to use my skills to solve fascinating security problems every single day.”

That passion for solving problems is also what makes her role so rewarding.

“The most rewarding aspect of my role is helping organisations better understand and manage their cyber risk. I particularly enjoy working with stakeholders to understand risk at an organisational level and identify practical ways to strengthen security. There is something incredibly satisfying about contributing to work that helps an organisation make better decisions and improve its resilience.”

“Seeing recommendations implemented and knowing that your work has had a tangible impact is one of the most fulfilling parts of the profession. It’s incredibly rewarding to know that the effort you put into understanding a problem can ultimately help protect an organisation and the people who rely on it.”

For those considering a move into cybersecurity from another profession, Isabella’s advice is both practical and reassuring. She believes the industry thrives because of its diversity of backgrounds and perspectives.

“At first I assumed that you need a highly technical background to succeed in cyber, but whilst this may make things easier at first, a love of problem solving, sharp critical thinking skills, and the ability to communicate and effectively understand threats has proven to be enormously beneficial. Many people assume they need a highly technical background

“One lesson I have learned throughout my journey is that a love of learning is often more important than starting with all the answers. If you are willing to take the time to learn, ask questions and embrace challenges, there is a place for you in cybersecurity.”

to succeed in cybersecurity, but the industry benefits enormously from diverse perspectives and experiences. Skills developed in fields such as business, law, accounting, marketing or data analytics can all be incredibly valuable.”

“Cybersecurity needs people who can communicate effectively, think critically, solve problems and understand business risk. Technical skills can be learned over time, particularly when you have curiosity and a willingness to continuously develop yourself.”

Ultimately, Isabella believes there is one quality that stands above all others.

“One lesson I have learned throughout my journey is that a love of learning is often more important than starting with all the answers. If you are willing to take the time to learn, ask questions and embrace challenges, there is a place for you in cybersecurity.”

For a graduate already making her mark in the industry, that mindset of continuous learning, curiosity and resilience is not only shaping Isabella Schulz’s own career it is also a reminder that some of the most successful journeys in cybersecurity begin not with knowing everything, but with being willing to keep learning.

www.linkedin.com/in/isabella-schulz-241b31172

CRAIG FORD

Craig is an experienced cyber security professional with various qualifications including two master’s degrees. He is the Head Unicorn (co-founder and director) of Cyber Unicorns, in which he acts as a vCISO to clients such as Baidam Solutions, Wesley Mission, PCYC, Hungry Jacks and Ipswich City Council. He was CTO (Chief Technology Officer) for Baidam Solutions between January 2022 to June 2023, where he led the technical services team, helping to build out the internal services capability for Baidam. Craig was QLD chair for AISA for two years until he was appointed to the national board of directors in December 2022.

The road to success is a bumpy one

I want to be clear from the start. This is not a polished success story. It is simply how I see it. You may not agree, and that’s fine. The point is to make you think.

Because the road to success is not smooth. It is uneven, unpredictable, and at times uncomfortable. There are setbacks you don’t expect and lessons you don’t particularly want but they tend to stick.

I’ve been fortunate to build a visible career in cybersecurity, both in Australia and internationally, through public speaking and writing over the past seven or eight years. That visibility brings conversations. People share their journeys, their frustrations, their questions. I value those conversations.

Often, I hear the same thing: that I’ve had an impressive career, that I’ve achieved a lot, that I’ve been lucky.

And yes, on the surface, it looks that way. In the past year, I’ve received eight awards, five international book awards and three cybersecurity industry awards. I’ve been shortlisted for others and included in various “top” lists.

That matters. I don’t dismiss it.

But it is not the full picture.

What matters more is the twenty-plus years behind it. The part you don’t see. The missteps, the setbacks, the long stretches where nothing seemed to move forward.

I grew up in Inverell, a regional town in New South Wales. I started in IT as a trainee at a small shop at most, a team of four or five. Before that, I completed Certificates III and IV in ICT at TAFE, driven by a general curiosity about how things worked.

At the same time, I was working nights as a supermarket security guard and weekends as a bouncer. For a while, I did all three. Not because it was strategic, but because it was necessary.

Eventually, I built enough experience to move from trainee to technician, working on-site and building networks. I made mistakes. I still do. But I kept going. I stayed in that role for five years before moving to the Gold Coast to look for something bigger.

From there, my career developed gradually into support roles, security responsibilities, before they were formally labelled as “cyber,” then into a dedicated cybersecurity position with an MSP. I ran a SOC, worked on penetration testing, and explored different paths within the field.

I enjoyed pentesting, but couldn’t quite break fully into it. So I shifted direction, continued in blue team

Craig is a published author with three different book series – ‘A Hacker I Am’ cyber education series, ‘Foresight’ is his Cyberpunk/hacker fantasy novel series and then there is ‘The Shadow World’, a co-authored kids cyber education book. He is a freelance cyber security journalist and is a regular columnist with the Women in Security Magazine, as well as a freelance contributor for Cyber Today, Top Cyber News, SecureGov, Careers with STEM and Cyber Australia magazines.

COLUMN

work, and moved into senior consulting and eventually CISO-level responsibilities.

That progression might sound linear when summarised. It wasn’t.

When I tried to move into a formal cybersecurity role, I faced hundreds of rejections. Not dozens—hundreds. It was relentless.

At that point, I already had over a decade of experience in IT and security-related work. I was building secure systems, even if my job title didn’t reflect it. I held a master’s degree and was working on a second.

None of that guaranteed an opportunity.

It was frustrating. At times, it felt like there was no clear way in. And I know many people still experience that same barrier today.

But this is the point I want to make: what you see now is not the full story. It never is.

Comparing yourself to someone else’s visible success, especially the version presented online, rarely helps. It tends to distort reality more than clarify it.

A better question is simpler: Is this the field you actually want to be in?

If the answer is yes, then the next step is yours to figure out. Not mine, not anyone else’s. You can learn from other people’s paths, but you cannot follow them exactly. That approach usually leads nowhere useful.

There is also a harder truth worth stating plainly. Progress takes time. You are unlikely to step into

a senior role without experience. Occasionally, someone gets a break but most people build their way there, slowly.

That process can be uncomfortable. It can feel like you are not moving at all.

And you will have setbacks. Everyone does.

The difference is what happens next. Whether you keep going, adjust your approach, or decide to step away. All of those are valid decisions but they should be conscious ones.

If you choose to stay, then commit to it. Build your network. Support others. Pay attention to what the difficult moments are teaching you, even if it only becomes clear later.

There is no single path through this industry. There are many, and most of them are not obvious at the beginning.

So go into it with open eyes. Expect detours. Expect delays. Expect the occasional setback that forces you to rethink your direction.

And remember that everyone you meet is carrying their own version of that journey, whether you can see it or not.

Be decent to people. It matters more than you think.

www.cyberunicorns.com.au

www.linkedin.com/in/craig-ford-cybersecurity

www.facebook.com/CyberUnicorns

www.instagram.com/cyberunicorns.com.au

INDUSTRY PERSPECTIVES

WHY AI GOVERNANCE NEEDS MORE HONEST LEADERSHIP CONVERSATIONS

Artificial intelligence is already drafting reports, automating decisions, analysing data, influencing hiring and reshaping how organisations operate quickly. Adoption is accelerating. The conversations that should sit alongside it are not.

Not the technical ones. The human ones.

Who is accountable when AI systems fail? Who speaks up when governance lags behind innovation?

And who carries the quieter work of raising ethical concerns, challenging blind spots, or pushing for more inclusive decision-making often in rooms where they are still the only one?

New findings from ISACA’s 2026 AI Pulse Poll point to an industry moving quickly on adoption, but far more cautiously on governance, accountability and readiness.

Globally, 90 per cent of respondents believe employees are already using AI within their organisation. Yet only 22 per cent say AI return on investment has met or exceeded expectations. More than half were unsure how long it would take to shut down an AI system following a security incident. Thirty-nine per cent did not know whether formal shutdown processes even existed.

It is a familiar pattern. Innovation moves first. Accountability, culture and governance follow behind.

For many women and underrepresented professionals in security, that gap is not new. Raising concerns, questioning assumptions, or asking whether organisations are genuinely prepared for risk can still come at a cost.

Historically, influence in security has not always come with formal authority. Many have learned to lead through persistence, collaboration and careful

advocacy rather than title alone. Those skills are becoming more important as AI moves deeper into organisations.

Good governance is not just policy or compliance. It is culture. It is whether people feel safe enough to speak early before issues become incidents. Whether they can question unintended consequences without being labelled difficult. Whether uncertainty can be acknowledged without losing credibility.

And still, many hesitate.

Some fear being seen as resistant to innovation. Others worry about appearing overly cautious in environments that reward speed. For women, there can be an added layer balancing technical credibility with expectations around communication style, confidence and presence.

This is where more honest conversations matter.

ISACA’s research shows only 38 per cent of organisations currently have a formal, comprehensive AI policy in place. At the same time, respondents identified misinformation, privacy violations, social engineering and intellectual property loss among the most immediate AI-related risks.

These are not future concerns. They are current governance challenges, and they do not sit neatly within one function or team.

Honest conversations are not about confrontation. They are about creating conditions where people can say what needs to be said.

That might look like a junior analyst questioning whether an AI system has been properly tested.

• A governance lead pushing back on unrealistic expectations around AI ROI.

• A leader admitting uncertainty rather than filling the space with confidence.

• A colleague asking who is missing from the decision-making table.

• A manager recognising the often invisible work of mentoring, inclusion and ethical advocacy happening alongside formal roles.

The security profession has always depended on people willing to surface uncomfortable truths early. AI raises the stakes, but the principle is the same.

There are signs of progress. AI literacy is increasingly recognised as essential across the workforce. Organisations are starting to acknowledge the complexity.

But responsible AI will not be delivered by technology alone. It will depend on whether organisations build cultures where people can question, challenge and speak openly about risk, accountability and inclusion.

AI governance cannot sit solely within IT. It requires legal, risk, privacy, HR, communications and executive leadership working together and listening to one another.

In security, some of the most important leadership happens quietly. Through advocacy. Through mentoring. Through raising concerns before they become problems. Through making space for others to be heard.

As AI becomes more embedded across organisations, the ability to have these conversations honestly, and early may prove to be one of the profession’s most important skills.

ABOUT THE AUTHOR

Jo has over 25 years’ experience in the security sector. She consults in risk and technology issues with a particular emphasis on governance and cybersecurity as a director with BRM Advisory. Jo is the Oceania Ambassador for global IT professional association, ISACA, and an ISACA Hall of Fame inductee. Jo is the former Vice President, Communities of the Australian Computer Society and Ambassador of the National Rural Women’s Coalition. She regularly provides strategic advice and consulting to the banking and finance, utilities, healthcare, tertiary education, retail and government sectors.

www.linkedin.com/in/jo-stewart-rattray-gaicd-4991a12

“YOU’RE

TOO EMOTIONAL FOR SECURITY”: RECLAIMING THE TRAITS THAT MAKE WOMEN EXCEPTIONAL IN CYBER SECURITY

I have lost count of how many times I have been told I am “too emotional.” It has come through formal feedback, passing comments, and carefully worded suggestions to dial something down. Each time, the reaction is the same: a flicker of doubt, followed by a quiet refusal to accept it.

I have worked in cyber security for more than sixteen years. I have built programmes, led campaigns, written books, spoken on stages and founded organisations. I have done all of that as my whole self including the parts others have chosen to label emotional.

And I am done treating that word as an insult.

Being told you are too emotional is not feedback. It is a signal about the culture you are operating in.

WHEN FEEDBACK ISN’T REALLY FEEDBACK

This experience is not unique. A senior cyber security leader I know was recently given formal feedback that she was “too emotional” at work. It was not tied to a specific incident or lapse in judgement. It was about how she works, how she engages, thinks and shows up.

A characteristic, not a behaviour.

When she tried to interpret it, the questions came quickly. Does it mean caring too much about the

LISA VENTURA

quality of work? Thinking deeply about decisions and their impact? Asking questions, challenging assumptions, pushing for better outcomes?

The problem is the word itself. “Emotional” becomes a catch-all, broad enough to mean almost anything and precise enough to explain nothing. It makes it difficult to understand what is actually being assessed, or what is expected to change.

In practice, it often becomes a container for traits that feel inconvenient. And inconvenient can mean unfamiliar, uncomfortable, or simply not aligned with how things have always been done.

THE DOUBLE STANDARD HIDING IN PLAIN SIGHT

The behaviours labelled as emotional in women are often praised in men.

Caring deeply about outcomes. Challenging what is not good enough. Showing visible investment in the work. In one context, this is called passion or drive. In another, it is framed as a problem.

The behaviour does not change. The label does.

If emotion is only an issue when it comes from certain people or shows up in certain ways, then professionalism is not what is being measured. Comfort is.

More specifically, how comfortable people are with women who do not minimise themselves to fit expectations.

THE SKILLS WE UNDERVALUE

Cyber security is, fundamentally, about people.

Phishing works because it exploits human behaviour. Social engineering succeeds because attackers understand how people think, trust and respond under pressure. Even the strongest technical controls can be undone by a single moment of hesitation, urgency or misplaced trust.

Empathy allows security awareness programmes to actually change behaviour rather than tick boxes. Emotional intelligence shapes how leaders communicate risk in a way that boards engage with. The ability to read nuance between what is said and what is not is what makes culture assessments meaningful.

These are not secondary skills. They are the difference between a programme that exists and one that works.

Yet they are the same qualities that are often dismissed as “emotional.”

WHAT SUPPRESSION COSTS

When women are repeatedly told the way they show up is a problem, the outcome is predictable.

Some adapt. They suppress the qualities that make them effective and perform a version of professionalism that takes constant effort to maintain.

Others leave.

The industry has spent years focusing on the pipeline problem attracting more women into cyber security. That work matters. But it avoids a harder question: what happens once they arrive?

If the culture signals, subtly or directly, that your natural way of working is a liability, staying requires

And that limitation does not belong to you.

LISA ON SOCIAL MEDIA

@cybergeekgirl

www.linkedin.com/in/lisasventura/

continuous self-editing. Over time, that becomes exhausting. Exhaustion turns into disengagement. And eventually, exit.

This is not just a pipeline issue. It is a culture issue.

THE CONVERSATION WE ACTUALLY NEED

The conversation we need is not about how women can better manage their emotions at work.

It is about what we mean when we use that language and what it costs when we do.

It costs trust. It strips away the very qualities that make people effective. It shapes how others see the industry, and whether they choose to stay in it.

And it undermines something we often claim to value: a genuinely human-centred approach to security.

You cannot build that by treating human qualities as a liability.

To every woman who has been told she is too emotional: you are not. You are not too much, and you should not have to reshape yourself to fit.

The empathy, the care, the instinct to question and push for better these are not weaknesses. They are part of what makes security work.

When they are dismissed, it is not a reflection of your professionalism. It is a reflection of someone else’s comfort.

www.facebook.com/lisasventurauk

www.instagram.com/lsventurauk

bsky.app/profile/cybergeekgirl.bsky.social

You can find examples of the talks she has done previously and of interviews, panel discussions and moderating/chairing events on her YouTube channel: www.youtube.com/@CyberSecurityLisa

AI AND CYBER SECURITY ASSOCIATION’S CHANNELS

x.com/AICyberSecAssoc

www.linkedin.com/company/aicybersecassoc

www.facebook.com/aicybersecassoc

ABOUT THE AUTHOR

Lisa Ventura MBE FCIIS is Founder and CEO of Unity Group Solutions Limited, a specialist cyber security awareness, strategic communications and thought leadership consultancy. She received her MBE from King Charles III in 2023 for services to cyber security and diversity, equity, inclusion and belonging. She is a Fellow of the Chartered Institute of Information Security, Founder and CEO of the AI and Cyber Security Association (AICSA), and author of Artificial Intelligence in Cybersecurity (Kogan Page, April 2026).

IT’S NOT ABOUT A SALARY: IT’S ALL ABOUT REALITY

I may have submitted this article late to the editors because, during the entire writing process, I found it hard to see my screen through the continuous tears of laughter.

Three boxes of Kleenex and a Valium later, I finally achieved the almost impossible; writing about salary guides without using any sarcasm, expletives or references to Dante’s Inferno. I am very happy to report to you all that I can now say I’ve seen the tenth Circle of Hell: it’s the room in which salary guides are written.

It’s not the concept of salary guides that evokes pain, laughter and torment all at the same time, like the screams emanating from Nurse Ratched’s mental ward. It’s the reason why they’re written in the first place. More to the point, the very companies that create salary guides are the same companies paid by clients to publish that information in the first place.

Conflict of interest? “No way”, some would utter, while looking up from their copy of The Wall Street Journal “It’s just how capitalism works.” That’s a fair point, but let me ask you this: is it OK for capitalism to raise expectations and then disappoint us severely? (Don’t answer that question)

A few months ago, Deany Jaghdour and I spoke on our podcast, Rejected or Selected, about the reality of modern-day salary guides. It’s no secret that companies such as Michael Page, Hudson, Hays and Seek, among others, publish their own guides on a regular basis, and some smaller boutique recruitment agencies create their own.

Apart from the obvious questions such as, “What am I doing with my life?”, “What are the odds of winning Powerball?” and “How much can I get for one kidney?”, here are some less obvious questions you should be asking when reviewing a salary guide:

WHERE ARE THE DISCREPANCIES?

According to Hays, a typical cybersecurity engineer role in Australia can attract between $110k and $180k with an average around the $150k mark. However, if I were to go on Seek (which I did) I would find only one cybersecurity engineer role that advertised, and this is at $103k yearly salary. Seek did not specify whether this was entry-level, mid or senior (If it were senior, we all have permission to storm this company’s headquarters by the end of the week).

I then looked at the Hays salary guide for the ‘typical’ salary of a GRC analyst (Side note: when you’re researching these roles and you type the word ‘analyst’ into a Google search, make sure you finish typing the whole word before your co-worker comes into your office to have a chat. Trust me!)

It shows a range from $90k-$180k with a median salary in the range $125k-$140k. That’s a big gap.

Then I went onto Seek again (after explaining to said co-worker that my search history is indeed quite innocent). One of the first roles (and one of very few) that came up gave me a salary range of $100k-$140k,

which made me think they’ve either taken their offer straight out of the Hays Salary Guide, or they’re expecting candidates with very diverse experiences. I then made my way onto the Hudson Salary Guide.

Now, Hudson’s is a little bit different in that it does not just give you a typical range, it breaks that range down into junior, mid and senior grades and, within those three grades, it also gives you a lower, mid and an upper range. (Well done, Hudson).

That last little discrepancy opened many more questions for me:

• Where were these companies getting this data from?

• Who was verifying these figures?

• When people submit data to contribute to these salary guides, how trustworthy are they?

• Why on Earth would anyone ever submit their own salary to feed the data in a salary guide?

WHO’S FUNDING THIS?

When you ask a toddler where the last cookie went. When their mouth has crumbs on it, there’s chocolate smeared on their hands and a look of guilt on their face that would make a prosecuting attorney salivate, it’s obvious they took the last cookie.

It’s also obvious that global recruitment agencies are putting together these salary guides to generate more business. Showing their expertise, increasing brand awareness, giving their clients bang for their buck: it’s all there. These salary guides are designed to help you in the same way that a crocodile that’s learnt to stand upright and put on a captain’s uniform is there to navigate you safely across the river.

We don’t simply go to a salary guide, look at our desired profession and say “Eureka, that’s what I’ll be making.” It’s not as simple as that, because these figures are all over the place. That’s not because the cybersecurity industry is a mess (that’s a subject for a different article), but because recruitment agencies make it their business to advise us on salaries on behalf of their clients.

Go to any job board Seek, Indeed, even LinkedIn and tell me how many jobs you see each day that have a specific salary listed in the advertisement. I can guarantee you: if the advertisement has been posted by an agency, there is little to no chance there will be a figure to give you any indication of how much you’ll make.

My first job in cybersecurity was as an awareness trainer with Water Corporation in WA. I was never given any indication of how much I’d make until after the interview (should have been a red flag right there, but, at the time, I was still a wide-eyed, naive newcomer). I shudder to think how many graduates and newbies to cybersecurity are being taken advantage of by small, mid and large-sized recruitment agencies alike.

The confusion and noise out there in salary guide land are intentional.

SO, WHAT DO WE DO?

Get educated by speaking with current cybersecurity professionals in your network, or attend networking events, conferences and meetups to cut through the

"This is one of the factors contributing to the atrocious gender pay gap we have in this country. If we don’t know what other people are making, then how can we negotiate our own salary?"

noise by speaking with those who can tell you exactly what the industry is like and how much you can expect to get paid.

“But Simon,” you’re probably yelling, “It’s rude to ask someone how much they get paid!”

Yes, it’s rude to start a conversation that way, but guess what? It should never be rude to ask someone that question. Here’s the thing: we’ve been gaslit continuously by Corporate Australia to believe this to be a faux pas and something to be avoided. This is one of the factors contributing to the atrocious gender pay gap we have in this country. If we don’t know what other people are making, then how can we negotiate our own salary? How can we empower ourselves to ask for a fair and equitable amount without knowing where the benchmark is?

The next time you’re at a networking function and you meet someone else in the cybersecurity industry, ask them how their job’s going, ask them what’s challenging them at work right now, and ask them how much money they get paid.

Like the legendary and hugely influential hip-hop figure, KRS-One, is very well known within hip-hop, but much less well known among the general public.” rapped on his track, My Philosophy , in 1988, “It’s not about a salary, it’s all about reality.”

www.linkedin.com/in/simoncarabetta

THE CONVERSATION THAT KEEPS HAPPENING

It usually comes up at the dinner table.

My parents-in-law are visiting from India. They come often, and time with them in Sydney settles into a familiar rhythm: long meals, unhurried conversation, a kind of presence that only family travel seems to allow. The food is generous, as always. The conversation drifts to work, family, who has called whom, whose children are doing what.

Somewhere between a second helping of paneer biryani and the tea, my wife says it again.

She should have been allowed to choose science. She wanted to be a doctor. She would have got to where she is now much sooner.

The table pauses. Someone nods. Someone offers something kind. Then it moves on. Tea is poured. Plates are cleared. The room settles, as though nothing has shifted.

This has been happening for years.

She is not bitter when she says it. She is not looking to provoke. She is naming something she has carried for a long time. Each time, the response follows a

pattern: warmth, acknowledgement, and a quiet move away from the discomfort.

The conversation happens. It just never lands anywhere.

The decision itself was made when she was sixteen. In India, that is when students choose their stream. Science, physics, chemistry, maths, biology if you are heading toward medicine or engineering. Or commerce, for a different path entirely. The choice shapes what comes next: university options, career trajectories, the edges of what feels possible.

She wanted science. She had always wanted to be a doctor.

Her older sister had struggled with the science stream. From that, a conclusion was formed. Science is too hard. Commerce is more practical. This will suit her better.

No one set out to limit her. It was a decision made the way many family decisions are carefully, with experience, and with assumptions that go untested. Her path narrowed through a quiet consensus that no one thought to question.

She studied commerce and did well. Over time, she built a career across industries and roles, not linear, but layered. Today, she works in professional services, specialising in cyber security. She is excellent at it. The breadth she brings has made her sharper than many who followed a more direct path.

And still, she did not get to choose the one she wanted.

That is the part the dinner table cannot quite hold.

I find myself thinking about this in a different context now in rooms where we hold what are called “courageous conversations.” They are thoughtful spaces. People listen. They speak carefully. Someone shares something real about being overlooked, or unheard, or passed over. The room receives it well.

And then, almost without noticing, the pattern repeats.

A pause. A shift. The next agenda item arrives on time.

The setting is different. The language is more refined. The room is more diverse than it might have been years ago. But the shape of the moment feels familiar. There is warmth. There is acknowledgement. And then, very little changes.

This is not about insincerity. The people in those rooms care. My parents-in-law cared. The pattern is older than any one of us.

Systems have a way of absorbing truth without being altered by it. They can hold a difficult conversation, even make space for it, and still return to their original shape.

Over time, it becomes clear that courage is not really tested in the conversation itself. Most rooms can hold a hard conversation for an hour. There is structure. There is permission. There is enough safety for someone to say something.

That matters. But it is not the hardest part.

What comes after is where it becomes real.

It shows up in small decisions. In what changes, and what does not. In whether the next decision is different from the last. Whether a path that once narrowed is widened for someone else. Whether the next sixteen-year-old is given a choice that another was not.

Whether the person who speaks up in a meeting is followed up with. Sponsored. Advocated for when they are not in the room.

This is where it gets uncomfortable. Because if it costs nothing, the system remains intact. It becomes informed, but unchanged.

And an informed system that does not shift can be harder to move than one that never heard the truth at all. It can point to the conversation as evidence that something was done.

My wife is not waiting for an apology. She is not asking for one.

What she does, each time she names it at the dinner table, is keep the truth present. She does not let it soften into something easier to forget. She ensures that a decision made for her, however well intentioned, is not quietly removed from memory.

There is a kind of courage in that. Not a single moment, but a pattern. The same sentence, said again. Another year. The same gentle response.

And it leaves a question sitting there, whether anyone picks it up or not.

Will the conversations we have today look the same in twenty years? Will the people who speak up still be naming the same things, in different rooms, to people who listened but did not act?

We often talk about courageous conversations.

There is value in speaking openly. There is value in listening well.

But neither, on their own, are what we mean by courage.

Courage begins once the conversation has ended. It lives in what changes because of what was said. In whether we widen paths that were once narrowed. In whether we revisit decisions made in someone else’s absence and ask if they still hold.

The conversation is not about courage. It is the beginning.

When the tea is poured and the plates are cleared, one question remains.

The conversation happened. We all heard it.

What changes now?

www.linkedin.com/in/jayhira

ABOUT THE AUTHOR

Jay Hira is a cyber security practitioner, lifelong learner, and advocate for inclusion. With nearly two decades of global experience, he has helped more than 100 organisations transform cyber risk into opportunity by making security simple, accessible, and a driver of growth. Known for his pragmatic, people-first approach, Jay simplifies complex challenges to deliver actionable advice that empowers teams and strengthens resilience. He values diverse perspectives and believes the best solutions arise from collaboration and continuous learning. Jay’s experience spans across the spectrum of attack, defence, architecture, governance, strategy, and transformation, with a strong focus on building high-performing, inclusive teams. He simplifies security, inspires authentic leadership, and ensures security serves as a force for good in every organisation.

WHY DIVERSITY OF EXPERIENCE ACROSS ENGINEERING, SALES AND MARKETING CAN CREATE STRONGER SECURITY LEADERSHIP

Cybersecurity leadership has traditionally been viewed through a highly technical lens, and for good reason. The sector has been shaped by engineers and architects who understand how systems work and where vulnerabilities sit. Yet, the role of security leadership is changing. Cybersecurity is no longer a narrow IT discipline or a technical problem to be solved once. Today, it is a business imperative spanning every function; from developers to business owners to the boardroom. This shift demands a broader kind of leader who not only deeply understands the technology, but can also connect it to customer needs, business priorities, market drivers and organisational change.

My own career has spanned engineering, sales and marketing, which has profoundly shaped how I view cybersecurity. Engineering brings a solution-oriented

mindset, discipline and awareness of the importance of solid foundations. Sales provides a direct understanding of customer pain points, business pressures and varying risk tolerances. Finally, marketing helps educate and brings clarity, ensuring that the overall strategy and positioning are aligned with what the market genuinely needs.

Together, these experiences have given me a comprehensive perspective. In cybersecurity this viewpoint matters, because our industry cannot afford to operate in silos. We need leaders who can combine technical development with a market-driven approach to create a truly unified business strategy.

FROM TECHNICAL AFTERTHOUGHT TO SECURITY BY DESIGN

Security has evolved significantly over the past two decades. In the past, it was often treated as an afterthought, something added after a product was built or a system deployed. It was frequently viewed as a ‘one-and-done’ compliance box to tick.

That mindset is no longer fit for purpose. The modern security approach requires organisations to constantly adapt to evolving technology while considering privacy, integrity and resilience from the outset. Security by design is now essential.

This is particularly important as organisations manage more data and identities (human and non-human) and serve customers across a variety of industries operating in increasingly complex regulatory environments. We have shifted from securing the parameters to securing the most valuable assets. We have shifted from static access control to a flexible, ‘just in time’ authentication and authorisation framework. Today, security serves as the essential trust layer, directly affecting customer confidence, brand reputation and competitive advantage.

WHY ENGINEERING NEEDS SALES AND MARKETING

Technical expertise remains critical for assessing system resilience and emerging threats. However, it is no longer sufficient. Security leaders need to know exactly how a security investment will reduce risk, support strict compliance mandates, enable growth and improve the user experience.

It is easy to focus solely on security features, architecture or specifications. Sales experience reinforces the critical importance of listening and

proves that the best security solution is the one that enables and de-risks the business in which an organisation operates.

Marketing also plays an important role in security leadership. Organisations need to understand exactly why a risk matters, how it specifically affects the business and what actions they can take. Strong marketing helps inform, drive value and bring proof and deliver outcomes. This is critical, because security decisions are rarely made by a single function. They involve technical stakeholders, financial leaders, compliance teams and boards.

EXPANDING THE DEFINITION OF DIVERSITY

The cybersecurity industry has made notable progress on diversity, but there is still work to do. Women in senior executive roles, including chief technology officers and chief revenue officers, remain in the minority. However, there is growing recognition that diverse teams deliver stronger outcomes.

This diversity could include gender, culture and professional background. Leadership teams benefit when people bring different lived experiences, career paths and ways of thinking. In security, where technologies constantly evolve and cyber threats become more sophisticated at a speed and scale never seen before, a narrow leadership profile limits how organisations understand risk and respond to change.

THE NEXT EVOLUTION OF SECURITY LEADERSHIP

Cybersecurity is now undergoing another massive shift. Artificial intelligence (AI) and post-quantum cryptography will reshape how organisations think about resilience and de-risking the business.

The future of the industry will be championed by wellrounded leaders who combine engineering discipline with market understanding and clear communication. That is how security becomes a strategic enabler of trust, resilience and growth.

www.linkedin.com/in/poupak-modirassari-enbom-a6284

MEET THE JUDGES FOR THE 2026

Tara Dharnikota CISO at Victoria University

Alana Lundy CIO and CISO for Depar tment of Social Services

Helen McLeish Chief Cyber Security Officer at East Metropolitan Health Service WA

Jackie Montado Chief Digital and Technology Officer at Wesfarmers Industrial and Safety

Maxine Harrison CISO from Depar tment of Energy, Environment and Climate Action

Cairo Malet Senior Manager / Deliver Lead - Cyber Security Services at Fujitsu

James Ng CISO at Insignia Financial

Sam Fariborz CISO at David Jones

Meagan O'Mahony Director of Security at Zip Co

Sana Rashed CISO at HSBC

Mona Sidhu Cyber Security Education and Awareness Manager at NSW Depar tment of Education

Principa Co at Deci

Sharin Yeoh Technical ISO at Systematic

Amazon

Tams ICF Exec Diversity Coachi

Dai Head Awa M
Jasmin
Nadia Regio Manag

6 AUSTRALIAN WOMEN IN SECURITY AWARDS

sy Wong of Security areness at edibank

McCrudden al Recruitment nsultant ipher Bureau

Derek Winter CISO at UNSW

Jenna Whitman Head of Security Operations and Deputy CISO at Vocus

Doris Tidd CISO at Intellihub

John Taylor Group Executive | CIO | CTO | CISO

a Hammoud nal Security ger - APAC at Web Services

sin Jowett cutive Coach & Consultant at ing To Thrive

Neha Sharma Industry CISO

Nikita Newell CISO at Lendlease

Tamsyn Harris Director of Scam Prevention at Optus

Dr Greg Adamson CISO at Depar tment of Transpor t and Planning

Hayley van Loon CEO of Crime Stoppers International

Kate Raulings CISO at Environment Pro tection Authority Victoria

Tharaka Perera CISO at Estia Health

Lukasz Gogolkiewicz Head of Cyber Security for Accent Group

Peter Gigengack Director Cyber Security | Capability at the Depar tment of the Premier and Cabinet of WA

Roxanne Pashaei Director Cyber Security Operations at Western Sydney University

Wayne Rodrigues Board MemberMembership Director at ISACA Melbourne Chapter

KAREN STEPHENS

Karen Stephens is the co-founder and CEO of BCyber. After more than 25 years in financial services, Karen moved into SME cybersecurity risk management. She works with SMEs to protect and grow their businesses by demystifying the technical aspects of cybersecurity and helping them to identify and address cybersecurity and governance risk gaps. She was named inaugural Female Cyber Leader of the Year at the 2023 at the CyberSecurity Connect Awards in Canberra and has been a finalist in 2024 and 2025 in the Australian Cyber Awards for Cyber Security Professional of the Year - Professional and Financial Services.

COLUMN

You don’t need an executive title to

affect change

Early in my career late last century (yes I am THAT old) I was often the youngest person in the room, and usually the only woman. I worked alongside colleagues and clients whose experience exceeded my actual age, and I regularly walked into situations where I was very aware I didn’t look like everyone else.

In those moments, it felt like a choice. Fight or flight.

If you know me, you might assume it was always “fight.” It wasn’t that simple. There were deep breaths in the hallway, the occasional confidenceboosting pose in the bathroom, and a steady stream of quiet self-talk before stepping into a meeting or presentation.

Was it hard? Yes. Did it always work? No. Does it still happen? Also, yes.

But there are ways to manage it.

We often think of leadership as something tied to a title, senior roles, large teams, formal authority. In reality, meaningful change rarely starts there. It is often driven by individuals who do not have the “right” title, but do have credibility, consistency, and the trust of those around them.

Influence, without authority, comes down to trust. Once people trust you, they listen. And once they listen, change has somewhere to start.

There is no quick fix here. It takes time. But a few things make a real difference.

Reliability matters more than most people think. Do what you say you will do, when you say you will do it. It sounds obvious, but consistency builds credibility. If something slips, communicate early. A quick note to reset expectations goes further than silence ever will.

Data helps your ideas land. Clear, evidence-based thinking makes it easier for others to see both the value and the impact of what you are proposing. It also shifts the conversation away from opinion and toward outcomes.

Treat “no” as information, not a dead end. It is easy to take it personally. It is More useful to ask what can be learned from it. And if the answer is not obvious, ask.

Feedback, when you can get it, is a great shortcut.

Influence, without authority, comes down to trust. Once people trust you, they listen. And once they listen, change has somewhere to start.

Build your support network deliberately. This is not just about mentors. It is about peers, advocates, and people who will back your ideas when you are not in the room. Change is rarely a solo effort.

None of this guarantee’s success. Some environments take longer to shift than others. Some will resist, even when the case is clear.

But change does not wait for a title.

It builds through small, consistent actions. Through showing up prepared. Through following through. Through earning trust over time and using it well.

The ability to influence outcomes, to shape decisions, to open doors for others these things are not reserved

for those at the top. They are practiced every day, often quietly, by people who choose to engage rather than step back.

You do not need to wait to be given permission to make a difference.

You just need to start acting like someone who already does.

www.linkedin.com/in/karen-stephens-bcyber

www.bcyber.com.au x.com/bcyber2

karen@bcyber.com.au youtube.bcyber.com.au/2mux

CAREER PERSPECTIVES

BEYOND DISCOMFORT: THE HARDEST CONVERSATIONS CAN SAVE LIVES

In security, we are trained to identify vulnerabilities, assess risk and act before harm occurs. Prevention is the standard.

Yet when it comes to our most vulnerable children we often wait until after a breach.

I spent years in law enforcement, witnessing crimes against children firsthand. What stood out was not only the actions of perpetrators, but a broader failure of prevention. Too often, children reach crisis points without the language, boundaries or confidence to speak up.

Why are we still waiting until harm has already occurred?

That question led to the creation of the Mummy Safety Security Project a movement grounded in frontline experience, translating law enforcement insight into practical, evidence-based prevention education for children, alongside professional

development for educators. The focus is simple: prevent harm before it happens.

THE UNCOMFORTABLE REALITY

The data is confronting.

The Australian Child Maltreatment Study found that 28.5 per cent of Australians have experienced child sexual abuse. In 2021, children under 18 accounted for 49 per cent of all recorded sexual assault victims.

But prevalence is only part of the story. Silence is the deeper issue.

Among survivors who engaged with the Royal Commission into Institutional Responses to Child Sexual Abuse, 57 per cent did not disclose until adulthood, with an average delay of nearly 24 years. eSafety’s 2025 Keeping Kids Safe Online research adds another layer: 74 per cent of children reported exposure to harmful online content, and 53 per cent experienced cyberbullying.

MARINA AZAR TOAILOA

These are not isolated incidents. They reflect a pattern where harm occurs, and children carry it alone.

If we know this, the question shifts. Not whether harm is happening but what we are doing to change the conditions that allow silence to persist.

WHY EARLIER MATTERS

The idea of starting these conversations at age two can feel confronting. For some, it raises concerns about innocence.

But body safety education at that age is not about exposing children to adult concepts. It is about building simple, age-appropriate foundations: understanding their body, recognising boundaries, and knowing who to trust.

By age two, children are developing language rapidly and beginning to understand rules and relationships. That window matters. Introducing these ideas early

allows them to become normal, not something introduced only in response to fear or crisis.

Children are already navigating the world. The question is whether we equip them to do so safely.

WHAT EARLY EDUCATION LOOKS LIKE

Effective early safety education is practical and consistent. It does not rely on a single conversation, but on everyday reinforcement.

It includes:

• Using correct anatomical language for all body parts. This reduces shame and supports clear communication if a child needs to disclose harm.

• Teaching body autonomy. Children are allowed to say no to physical contact, even in situations framed as polite or expected.

• Explaining private parts in simple terms, such as areas covered by clothing, and reinforcing that these should not be touched without clear,

appropriate reason and trusted supervision.

• Distinguishing between surprises and secrets, and making it clear that no one should ask them to keep secrets about their body.

• Building a trusted network of adults. Children should know who they can speak to and understand that if one person does not listen, they can keep telling until someone does.

None of this is complex. But it does require consistency and a willingness to have conversations that may feel uncomfortable at first.

WHERE RESPONSIBILITY SITS

Child safety does not sit with parents alone. It is a shared responsibility.

Educators play a critical role. When they understand the signs of harm, model appropriate language and build safety into everyday classroom culture, they become part of a child’s protective network.

At the Mummy Safety Security Project, this includes professional development across all levels from foundational child safety awareness and reporting obligations through to more advanced training in risk assessment and emergency response. Parent education is equally important, ensuring these conversations continue beyond the classroom.

The goal is not awareness alone, but capability.

PREVENTION IS THE STANDARD

In cyber security, we do not wait for an attack before implementing controls. We build frameworks, test responses and prepare people to act under pressure.

Child safety requires the same mindset.

Talking to a young child about their body, their boundaries and their right to say no may feel uncomfortable. But discomfort is not a reason to delay. In many cases, it is a signal that the conversation matters.

Because the alternative is silence.

And silence is where harm persists.

At its core, this is about giving children something simple but powerful: the language to speak, the confidence to use it, and the certainty that someone will listen.

That is where prevention begins.

www.instagram.com/mummysafetysecurityproject

www.linkedin.com/in/marina-azar-toailoa-66259511a

THE GALLAGHER SECURITY USER GROUP EVENT IN 2025 SETS AN ATTENDANCE RECORD

THE GALLAGHER SECURITY USER GROUP EVENT IN 2025 SET AN ATTENDANCE RECORD — WHAT DO YOU THINK CONTRIBUTED TO THAT SUCCESS?

Nicola: We host the Gallagher Security User Group (GSUG) event every two years, and in 2025 it was South Australia’s turn. We were delighted by the strong early interest from across the industry, which carried through to our highest-ever GSUG attendance. More than 100 valued industry colleagues joined us for the two-day event. Early in the planning process, we curated an agenda which acted as a real drawcard for the industry, drawing from insights from our annual Gallagher Security Trends Report which highlighted a need for more industry education. This data-led approach helped us secure engaging speakers, such as Jodie Lowe, Senior Product Owner, Information Communications and Technology at

the University of Sydney, alongside breakout and networking sessions to allow our attendees to make those all-important connections. Nearly half of attendees also opted in to take part in additional training at the conclusion of the event, which speaks to the engagement.

Tessa: While GSUG is held biennially, our ongoing marketing and communications efforts supported by a strong calendar of events, help foster sustained interest from the security industry. Gallagher speakers and guests from our Australian, APAC IMEA, and Global Head Office teams travelled to GSUG to meet, listen to, and learn from our End Users. Bringing people together in person makes a huge difference in this area. We know attendees value hearing real-world experiences of how our products support our End Users, and they also appreciate the

TESSA WILLIAMS
NICOLA JOHNSON

opportunity to network, and experience the Gallagher system in person. It’s all about the face-to-face and hands-on experience.

HOW DO YOU APPROACH DESIGNING EVENTS AND MARKETING STRATEGIES THAT TRULY ENGAGE THE SECURITY COMMUNITY?

Nicola: When planning major events, we collaborate closely with our sales and technical internal teams to understand the topics and content our Channel Partners and End Users want to learn more about. Drawing on our long-standing relationships across the industry and with our End Users, we weave these insights into events people genuinely don’t want to miss - and the results speak for themselves. Over the past 12 months, each of our registered events has seen stronger demand than the last. To truly engage our community, we set ourselves a high bar of running professional, high-quality events that reflect the strength of the Gallagher system itself, and our people who support it - and we look for ways to build on that success with every event we host.

Tessa: Our deep understanding of our audience allows us to design, host, and deliver events that meet the evolving needs of the security industry, ensuring attendees walk away with practical insights they can apply in their day-to-day work.

Having the right people is key, supported by our strong team of experts based across Australia who are committed to sharing knowledge nationwide. What happens after the event is just as important – like capturing and sharing key insights internally, whether that’s valuable conversations, requests for more information, or passing leads on to our broader Australian team.

IN YOUR VIEW, WHAT ROLE DOES COLLABORATION PLAY

IN STRENGTHENING

AUSTRALIA’S SECURITY INDUSTRY NETWORK?

Tessa: Collaboration plays a critical role in strengthening Australia’s security industry, particularly by creating space for people to learn and share beyond the walls of their own organisations. When industry professionals come together, they gain exposure to different perspectives, challenges, and solutions, some of which they may not encounter in their day-to-day roles.

Collaboration opens the door for honest discussion and practical problem-solving, and over time, that lifts the capability of the whole industry, not just individual teams.

COULD YOU SHARE SOME INSIGHTS INTO HOW YOU BALANCE CREATIVITY WITH THE TECHNICAL AND OPERATIONAL ASPECTS OF THE SECURITY SECTOR?

Nicola: Balancing creativity in a technical industry really comes down to how you tell the story. We try to keep it grounded in real examples and actual outcomes where Gallagher solutions have helped organisations solve something, work smarter, or get more value out of what they’re doing.

Creativity also plays a key role in the look and feel of our events and experiences. We place emphasis on quality and interaction, from the way a space is themed and designed to thoughtful touches like interactive elements, QR codes on tables, and branded merchandise.

These details elevate the experience and reflect the professionalism of the security sector, while still creating an engaging and memorable environment.

GALLAGHER’S PARTNERSHIP WITH BRAVEHEARTS IS AN INSPIRING EXAMPLE OF CORPORATE SOCIAL RESPONSIBILITY — WHY IS COMMUNITY INVOLVEMENT IMPORTANT TO YOU PERSONALLY AND PROFESSIONALLY?

Tessa: Community involvement connects directly to the impact of what we do every day. Our solutions play a role in keeping people, places,

and communities safe, and there’s a real sense of satisfaction in seeing the difference that can make beyond the technology itself. Gallagher’s purpose, which is to protect what matters most, resonates strongly with me, and partnerships like Bravehearts, a leading Australian child protection organisation, bring that purpose to life in a very tangible way. Supporting community organisations also helps them grow through stronger local connections, and being part of that journey is incredibly rewarding both personally and professionally.

Our Australian and state-based teams are encouraged to support important national and local community projects, from Bravehearts through to the Bloom PopUp Café in Melbourne and the Bennelong Cup in NSW. That collective effort strengthens our connection to the communities around us and to each other.

Nicola: I feel that same sense of purpose through Gallagher’s community involvement. It gives you a stronger connection to the work, and to the people around you.

Through our roles, we can give back and contribute to causes that extend well beyond our own organisation, which supports both personal growth, professional fulfilment, and most importantly – provides support to those who need it.

HOW DO INITIATIVES LIKE THE CHARITY GOLF DAY CONTRIBUTE TO BUILDING A STRONGER, MORE CONNECTED INDUSTRY CULTURE?

Nicola: Initiatives like the Charity Golf Day play an important role in reinforcing our responsibility to give back to the communities we operate in. They create an environment where industry can come together in a more relaxed setting, build genuine connections, and unite around a shared purpose that goes beyond business. Over time, the Charity Golf Day has become a flagship event on the industry calendar, with strong year-on-year growth that reflects how much the industry values opportunities to connect while contributing to something meaningful.

Tessa: The Charity Golf Day also shares the Bravehearts mission with our wider industry

community. For many attendees, it’s their first exposure to the work Bravehearts does and the difference it’s making. Without this annual event, we wouldn’t have the opportunity to engage more than 100 people in those important conversations or reach a new audience that Bravehearts may not otherwise connect with – as every dollar supports their incredible work.

It’s that shared experience that builds awareness over time. The fact it’s grown into the largest fundraising event delivered by a Bravehearts partner is something we’re genuinely proud of and it speaks to what can happen when people come together around a cause like this.

WHAT DOES FEMALE LEADERSHIP REPRESENTATION MEAN TO YOU WITHIN THE SECURITY INDUSTRY CONTEXT?

Both: Female leadership representation is incredibly important. Visibility really matters - seeing women in decision-making positions, having a voice at the table, and speaking at industry events helps create a more inclusive, balanced industry where different perspectives are valued and reflected in how we lead, innovate, and connect. When women are visible in leadership, it creates pathways for others coming

through the industry. Ultimately, it strengthens the industry by ensuring leadership reflects the communities and customers we serve.

WHAT ARE YOU MOST EXCITED ABOUT FOR 2026 AND BEYOND — EITHER FOR GALLAGHER SECURITY OR FOR YOUR PERSONAL CAREER GOALS?

Tessa: Looking ahead to 2026 and beyond, I’m excited about continuing to strengthen our connection with the communities we support while building on the strong relationships we have across the industry. I’m also excited about maintaining consistency in the market and continuing to unlock more for Australian customers by showcasing the power of our solutions and the real difference they make. Supporting engagement, education, and connection through our growing calendar of events and tradeshows remains a key focus for me.

Nicola: 2026 is shaping up to be an incredibly exciting year creatively. I’m looking forward to bringing our major events to life, particularly the upcoming Security Exhibition and Conference, and our Australian team conference, by designing new experiences that are engaging, memorable, and aligned with the Gallagher brand. Security Exhibition and Conference, as our largest trade show, presents a great opportunity to push creative boundaries through new stand designs, activations, and ways to connect with attendees.

IF YOU COULD GIVE ONE PIECE OF ADVICE TO WOMEN ASPIRING TO LEAD IN MALEDOMINATED INDUSTRIES, WHAT WOULD IT BE?

Tessa: Your credibility grows when you speak up early, take up space, and make decisions with confidence – even while you’re still learning. Most leaders, regardless of gender, are figuring it out as they go. The difference is that women are often taught to wait until they feel “ready”.

www.linkedin.com/in/nicola-johnson-273147b1

www.linkedin.com/in/tesswilliamsnz

TO THE SPONSORS

MADHURI NANDI

Madhuri Nandi is a cybersecurity leader with nearly two decades of experience spanning strategy, governance, risk, compliance, product, and engineering. Recognised as the Global Cyber Security Leader of the Year (2025 and 2026), she is known for building security programmes that balance business outcomes with human-centred leadership.

The questions we stop asking: courageous conversations through real cybersecurity leadership

Children ask questions adults tend to move past.

Why should passwords be stronger? Why shouldn’t we trust every link? What actually happens when something goes wrong?

They keep going until the answer makes sense.

In cybersecurity, that instinct matters more than we often admit.

Because many problems do not begin when systems fail. They begin earlier when questions stop, assumptions go unchallenged, and silence starts to feel normal.

Over time, a different pattern can take hold in organisations. The conversations that matter most become the ones least likely to be questioned. Processes continue because they always have. Teams adapt to pressure without always naming it. Burnout is reframed as resilience. Governance looks complete on paper while gaps quietly grow in practice.

Curiosity gives way to assumption.

I have seen teams praised for “always delivering” while operating under sustained pressure. The ability to absorb that pressure becomes valued more than the willingness to question it. Over time, that tradeoff is rarely made explicit—but it shapes culture all the same.

Some of the hardest conversations in cybersecurity are not technical. They are about whether the way we work is still sustainable. They ask leaders to look beyond dashboards, incident reports, and compliance metrics, and pay attention to what teams are actually experiencing.

I have also seen organisations become highly effective at demonstrating governance without necessarily strengthening accountability. Controls exist. Policies are documented. Reports are circulated. On paper, everything appears mature.

The real test comes when something unexpected happens and ownership is unclear.

One example stands out. During a review of access governance, the control looked solid: regular reviews, documented approvals, structured reporting. From a compliance perspective, it held up well.

But a closer look told a different story.

Reviews were being completed, often without full operational context. Access was approved because it had always existed, or because ownership had shifted over time without being clearly reassigned. No one was acting incorrectly. It was the slow accumulation of assumptions.

What changed was not the control itself, but the clarity around it. Ownership was simplified. Responsibilities were made explicit. Teams

She holds a Master’s degree in Cybersecurity Digital Forensics and currently serves as Head of Security at Nuvei and Chair of the AWSN National Board. Madhuri is the author of Cyber Smart and creator of a cybersecurity awareness framework focused on making security more accessible and practical for everyday users. She is a strong advocate for inclusive leadership, mentorship, and community building across the cybersecurity industry.

COLUMN

reconnected with the purpose behind the process, so it stopped being a routine exercise and became a meaningful control.

The improvement did not come from adding more processes. It came from restoring intent.

Courageous conversations also shape who gets heard and who does not. In many organisations, the same voices dominate by default. Operational perspectives often arrive late, if at all.

Yet some of the most useful insights come from those closest to the work: teams managing day-today risk, early-career professionals who still question what others have accepted, and people who approach problems from a different angle.

When those perspectives are included earlier, risks surface sooner and decisions tend to hold up better under pressure. Inclusion is not separate from security outcomes. It influences them directly.

This gap extends beyond the workplace. Cybersecurity awareness is growing, but understanding does not always keep pace. People know they should be careful, but not always why. The behaviour is there; the reasoning is thinner.

Children keep asking until something makes sense.

Organisations often stop asking once something sounds acceptable.

Perhaps courageous conversations are not about having the loudest voice in the room. Perhaps they begin with staying curious a little longer than is comfortable and not letting the first answer be the final one.

www.linkedin.com/in/madhurinandi

STUDENT IN SECURITY SPOTLIGHT

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest? I usually describe cybersecurity as the part of the digital world that quietly keeps everything safe.

So much of our daily life now runs through technology, whether it’s banking, healthcare, studying, or just staying in touch with people. Cybersecurity sits behind all of that, making sure our information stays private, systems stay reliable, and trust isn’t broken. It’s not just about computers or code, it’s really about protecting people in a world that happens to be digital.

What makes it so interesting is how fast it moves. There’s always something new happening, new threats appearing, new tools being built, and new ways attackers try to get in. Because of that, you’re always learning and adapting. A big part of the work is thinking critically and solving problems before they turn into real issues, which can feel a bit like being a step ahead in a constantly changing game.

I also like to point out that cybersecurity isn’t just one type of job. People often think it’s all coding or hacking, but it’s actually a really broad field. You’ve got areas like security analysis, incident

response, digital forensics, risk and governance, cloud security, penetration testing, and even security awareness and training. That means people with very different strengths can find a place in it, whether they’re technical, analytical, detail-focused, or strong communicators.

For me, the most meaningful part is knowing the work has real-world impact. You’re helping protect organisations and individuals from harm that isn’t theoretical, it’s happening every day. That sense of purpose is what makes the challenges worth it.

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

When I first thought about studying cybersecurity, I honestly pictured it as something very technical hacking systems, writing code all day, and using advanced tools to catch attackers. I thought the focus would be mostly on breaking into systems or defending them in a very hands-on, technical way.

While those elements definitely exist, my experience has shown me that cybersecurity is much wider and more human than I initially expected. It’s not just about tools or technical skills, but also about ethics, communication, risk management, legal considerations, teamwork, and critical thinking. I’ve come to understand that behind every system and every alert, there are real people and organisations who can be impacted by the decisions we make.

For example, when I started learning about areas like data privacy and digital forensics, it became clear that this field requires a lot of responsibility and attention to detail. It’s not just about finding information, but making sure it’s handled correctly, ethically, and in a way that can stand up to scrutiny.

Some of the technical topics, like networking, programming, and packet analysis, definitely took time to click. There were moments where it felt

SARA HASHI
Sara Hashi is currently studying a Bachelor of Cybersecurity at Deakin University
Bachelor of Cybersecurity student at Deakin University

challenging, but working through practical exercises helped everything make more sense. Over time, I started to feel more confident as I could connect what I was learning in theory to real-world situations.

Overall, my view of cybersecurity has shifted quite a bit. I now see it less as a purely technical discipline and more as a profession that blends technology with people, ethics, and problem-solving. It’s this combination that makes it both challenging and genuinely interesting.

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

After graduation, I am interested in securing a role such as a Cybersecurity Analyst, Security Operations Centre Analyst, or Junior Security Engineer.These roles interest me because they provide a strong foundation in understanding real security threats, monitoring systems, analysing alerts, responding to incidents. What motivates me is the practical nature of the work. I like the idea of investigating suspicious activity, identifying patterns,and helping organisations respond to cyber risks. I also think these roles would allow me to keep learning and gradually build stronger technical skills in areas such as networking, threat detection, vulnerability management, and incident response.

I am also motivated by the fact that cybersecurity has a direct impact on people and organisations. A good security professional helps prevent data breaches, protects sensitive information, and supports safer digital environments. That sense of purpose is important to me because I want a career where my work feels useful and meaningful. Starting in an analyst or junior engineering role would also give me exposure to different areas of cybersecurity, which would help me decide where I want to specialise in the future.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges? When I decided to pursue cybersecurity, the reactions around me were mixed.Some people were supportive and saw it as a strong career path because technology is growing and cybersecurity skills are in demand. Others did not fully understand what cybersecurity involved and assumed it was only about hacking or sitting behind a computer all day. I would not describe it as strong opposition, but there were moments where I had to explain my choice more clearly.

I had to explain that cybersecurity is not just one narrow area. It includes protecting data, securing networks, investigating,understanding privacy, and helping organisations manage risk. I navigated this by focusing on my own goals and continuing to learn more about the field.The more practical tasks I completed, the easier it became to explain why cybersecurity matters. I also reminded myself

decision because I could see how valuable cybersecurity is in almost every industry.

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations

The most influential factor in my cybersecurity journey so far has been the practical learning experience. Before completing hands-on tasks, many concepts felt abstract. However, when I started working with tools, analysing network traffic, writing programs, and completing security-related activities,the field became much more real to me. Practical work helped me understand that cybersecurity is not just about memorising definitions. It is about applying knowledge, solving problems, and thinking carefully about how systems behave.

For example, working with networking concepts, Wireshark, Python programming, and digital forensics tasks helped me see how different areas of cybersecurity connect. This has impacted my career aspirations by making me more interested in roles that involve investigation, analysis, and problem-solving. I enjoy tasks where I need to look at evidence, understand what is happening, and explain my findings clearly. It also showed me that I still have areas to improve, but that improvement comes with practice and consistency.Overall, handson learning has shaped my confidence and helped me see cybersecurity as a realistic and meaningful career path.

Recount the most memorable or significant event in your cybersecurity journey to date, highlighting why it left a lasting impression. One of the most memorable parts of my cybersecurity journey was completing practical digital forensics and network analysis tasks. These activities stood out because they showed me how cyber evidence can be collected, analysed,and interpreted. Instead of only reading about attacks or security concepts, I was able to work with evidence and tools directly. For example, analysing network packets or examining digital evidence helped me understand how much information can be found when you know what to look for.

It also showed me how careful and accurate cybersecurity work needs to be. A small detail, such as an IP address, timestamp, file name, or protocol, can change how evidence is interpreted. This experience left a lasting impression because it made cybersecurity feel real. It showed me that cyber incidents are not just theoretical problems; they involve actual systems, users, data, and consequences. It also helped me appreciate the responsibility that comes with working in the field. That experience made me more interested in analysis-based roles, especially areas such as digital forensics, incident response, and security monitoring.

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

Right now, most of my cybersecurity experience comes from hands-on university work rather than a formal job or internship, but it has still felt very real and practical.

Through my studies, I have spent time using tools and techniques like Python scripting, network analysis, digital forensics labs, secure coding exercises, packet inspection, and basic vulnerability

SARA HASHI

assessment. Working with Wireshark, for example, helped me actually see and understand what is happening in network traffic, and the programming tasks have pushed me to think more logically, automate little tasks, and troubleshoot on my own.

I have not yet worked in a cybersecurity role, and I am honest about that, but it is where I am heading. I am actively building my skills, growing my confidence, and preparing for entry-level opportunities by doing labs, projects, and practice scenarios whenever I can. I am also focused on developing a stronger technical portfolio so I can show what I can do, not just talk about it.

These academic and project-based experiences have been a valuable starting point for me. They have helped me figure out which areas of cybersecurity I enjoy most, and where I still need to stretch myself and keep learning.

Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?

My course has given me a really solid base to work from, especially in areas like networking, programming, cybersecurity fundamentals, digital forensics, and data analysis. Those core concepts feel important, because even though the tools and threats keep changing, the underlying ideas about how systems and networks work don’t.

At the same time, I’m very aware that studying on its own is not enough in this field. New attacks, technologies, and tools show up all the time, so I’ve had to take some ownership of learning beyond the classroom. For me, that looks like keeping up with security news, doing extra labs, trying out practical exercises, and paying attention to real-world case studies.

I’ve found the best mix is using university for structure and fundamentals, then layering my own learning on top to stay current. I feel like my program has given me the foundation I need, and I also know that if I want to grow in cybersecurity, I have to keep learning well beyond my formal studies.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?

I definitely see non-cyber skills as a big part of working in cybersecurity, not just a “nice to have.”

The technical side matters, of course, but it only gets you so far if you can’t explain what you’re seeing to other people. A lot of the job is helping non-technical teams understand what a risk actually means for them: why a vulnerability matters, why a control or policy is necessary, or what they need to do after an incident. If the explanation is buried in jargon, people either switch off or don’t take the right action.

That is where communication and people skills really come in.

Cybersecurity work is almost always collaborative. You are dealing with IT, management, legal, frontline staff, and sometimes clients, all looking at the same issue from different angles. Being able to listen, ask good questions, and adapt how you explain something helps build trust and makes it easier to get people on board with security decisions.

As you move further in your career, I think leadership and management skills become even more important. It is not just about fixing technical problems anymore. It is about making judgment calls, weighing up risk, and supporting teams through incidents that can be stressful and high-pressure. That human side of the work is just as real as the technical side.

Are you actively engaged in the broader cybersecurity community? If so, what has been your involvement, and how has it enriched your experience?

Yes, I do make an effort to stay connected with the wider cybersecurity community, especially with women in the field.

On LinkedIn, I follow industry professionals, women in cyber, and security-focused pages. People like Chantelle Ralevska, and platforms such as Cyber Daily and Women in Security Magazine, are really helpful because they share updates, career stories, events, and different pathways into the industry. Seeing those posts pop up in my feed makes cybersecurity feel much more real and reachable.

It has also been encouraging to see women talk honestly about their careers in security. It reminds me that there isn’t just one “right” way to enter the field, and that people have taken very different routes to get where they are. I try to keep up with current threats, local and global events, and professional conversations online, so I can link what I’m learning at university to what is actually happening out there.

All of this has helped cybersecurity feel less like just a degree on paper and more like a community I’m gradually becoming part of.

www.linkedin.com/in/sara-hashi-88b6892a8

in

Are you a student passionate about shaping the future of security? Do you have innovative ideas and insights to share with a global audience? Join us in contributing to the Women in Security Magazine and become a voice for the next generation of security leaders!

Why contribute?

Gain valuable exposure: Reach over 11000 subscribers globally and showcase your expertise to industry professionals.

Make an impact: Share your experiences, challenges, and aspirations to inspire others and shape the future of security.

How to get involved

Let us know you are interested. We will send you a series of questions of which you can choose which ones you would like to answer. Submit those back to us in an email. We will then edit to be a concise and flowing edited Q&A.

Don't miss this opportunity to be part of a vibrant community of students driving change in the security industry. Contact us today to learn more about how you can contribute to the Women in Security Magazine!

Contact: jane@source2create.com.au

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

When I first thought about cybersecurity as a career, my view was shaped largely by movies, TV shows, and the stories you see online. I imagined cybersecurity professionals as lone hackers sitting behind screens, constantly battling cyber criminals and breaking into systems. To me, the industry seemed to revolve almost entirely around offensive security and catching attackers.

As I’ve progressed through my studies and gained real-world experience, I’ve realised how different and much broader the reality is. Ethical hacking is certainly an important part of cybersecurity, but it’s only one piece of a much larger puzzle. Before starting university, I had no idea about the scale of the infrastructure and teamwork required to keep organisations secure. I wasn’t aware of Security Operations Centres, the role of incident

responders, or the many career paths that exist beyond the technical side, including governance, policy, risk management, privacy, and ethics.

Both my university studies and internship have helped bring those concepts to life. At university, I’ve been learning the theory behind areas such as incident response, ethical hacking, and SIEM technologies. Through my internship, I’ve had the opportunity to apply some of that knowledge in practice by investigating phishing emails, responding to alerts, and analysing real-world security events. Those experiences have shown me just how analytical and investigative the field can be.

Perhaps the biggest lesson I’ve learned is that cybersecurity is far less about individuals working in isolation and far more about people working together. Protecting digital environments requires collaboration across teams, disciplines, and organisations. It’s a field that combines technology, problem-solving, communication, and teamwork and that’s something I’ve come to appreciate far more than the image I had when I first started.

Upon graduation, which specific cybersecurity role do you aspire to secure employment in, and what motivates your choice?

After graduation, my goal is to start my career in a technical role, ideally as a Security Operations Centre (SOC) Analyst. I’m really interested in understanding cybersecurity at its core how threats are detected, how incidents are investigated, and how organisations defend themselves against constantly evolving risks. Working in a SOC would give me the opportunity to build that strong technical foundation and gain hands-on experience with the tools, processes, and challenges that security teams face every day.

As I continue to grow in my career, I can see myself gradually moving towards roles that combine technical knowledge with communication and strategy. One aspect of cybersecurity that I’ve come

LAUREN MAURO
Lauren Mauro is currently studying a Bachelor of Cybersecurity at the University of Technology Sydney (UTS)
Bachelor of Cybersecurity student at the University of Technology Sydney (UTS)

to enjoy is the human side of the profession. I find a lot of satisfaction in taking complex technical concepts and translating them into something clear and meaningful for different audiences. Whether that’s through report writing, policy development, or helping others understand security risks, I enjoy bridging the gap between technical and nontechnical stakeholders.

Long term, I would love to move into a leadership position, such as a Security Manager or Director. My ambition is not only to help shape security strategy, but also to support and develop the people around me. I believe that having a strong technical background will make me a more effective leader, allowing me to understand the challenges my teams face while helping organisations make informed decisions about their security future.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?

When I decided to pursue a career in cybersecurity, my parents were my biggest supporters. They could see how much I had always loved computers and technology, even as a child, and they encouraged me to explore a career that aligned with those interests. While I wasn’t entirely sure which path within technology was right for me, they helped me recognise that cybersecurity combined my curiosity, problem-solving skills, and passion for technology in a way that felt like a natural fit.

Not everyone understood my decision, though. Throughout high school, I was heavily involved in humanities subjects and performed well in them. At my all-girls school, technology-related subjects weren’t widely available or encouraged, so pursuing a career in cybersecurity wasn’t a common path. In fact, out of a graduating class of more than 100 students, only two of us chose to enter the technology industry.

Because of my academic background, many of my peers and even some career advisors were surprised by my choice. They often questioned why I would

move into such a technical field when my strengths appeared to lie elsewhere. At the time, those reactions made me second-guess myself. I wondered whether I truly belonged in cybersecurity and whether I was making the right decision.

Looking back, I realise much of that confusion stemmed from long-standing perceptions about who “fits” in technology careers. Cybersecurity and IT have traditionally been viewed as male-dominated fields, and there can still be assumptions about the types of people who succeed in them. Rather than allowing those perceptions to define me, I learned to trust my own interests and instincts.

What I’ve come to appreciate is that my humanities background isn’t separate from cybersecurity it’s one of my strengths. Cybersecurity is ultimately about people as much as technology. Strong communication, critical thinking, understanding human behaviour, and the ability to explain complex ideas clearly are all incredibly valuable skills. The further I progress in my journey, the more I realise that the qualities that once made others question my path are actually some of the reasons I belong in this field.

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?

My parents have been incredibly influential in shaping my early journey. Specifically, my dad has encouraged me to take risks, get involved and apply for every opportunity, even if I doubt my abilities. He has always been willing to speak to people on my behalf to help me network and always lets me know if there are any industry events I may be interested in. My mum has also been supportive, consistently pushing me to step out of my comfort zone and tackle new challenges.

Professionally, my mentors have played a massive role, especially my mentor Saba Bagheri. Saba

always helped me build my confidence and actively pushed me to attend industry events. She always took the time to listen, offered invaluable advice for the challenges I faced and provided much needed reassurance. Saba also introduced me to a completely different side of the industry I did not know existed, which is threat intelligence.

These influences have impacted my career aspirations exponentially. By introducing me to threat intelligence, Saba showed me how technical analysis links to understanding human behaviour and threat actors, which aligns with my desire to transition into a role more focused on communication. Furthermore, the immense support from my parents and the positive experience of having a mentor like Saba have inspired my long-term goal of moving into leadership. I want to become a manager or director so I can provide that exact same guidance and encouragement to the next generation of women in cybersecurity.

Beyond your academic studies, what practical experience have you gained in the field of cybersecurity through employment or internships?

I have actively sought out experience so I can build a strong foundation in both IT and cybersecurity. My first exposure to the industry was as an IT Helpdesk Intern at Navitas. In this role, provided technical support, resolved hardware and connectivity issues through a Jira ticketing system, and shadowed senior technicians. This experience was instrumental in developing my networking and troubleshooting skills.

Following that, I completed a Corporate Security Internship at Mastercard, where I gained significant hands-on cybersecurity experience. I worked directly on incident response projects, analysing malware behaviour, network traffic, and browser artefacts to identify indicators of compromise. I used industrystandard tools like Wireshark, VirusTotal, and CyberChef to conduct this analysis. Additionally, I investigated sophisticated phishing campaigns and

conducted data analysis on flagged communications to identify false positives. This data was delivered to Microsoft to help significantly improve their detection accuracy.

My time at Mastercard also allowed me to explore the strategic side of security. I developed a comprehensive security framework and risk mitigation strategy for a major corporate event, successfully securing stakeholder approval. I also produced security insight reports analysing major Australian breach case studies. These tasks helped me develop strong cross-team communication and report writing skills, and sparked my interest into moving to a non-technical role.

Do you believe there are areas in cybersecurity that deserve more emphasis in your coursework or areas that could receive less focus?

When I reflect on my coursework, there are definitely a few areas that deserve greater emphasis. One of the main gaps, in my experience, is a stronger focus on IT fundamentals within my specific degree. In my first year, I only had limited exposure to areas such as networking and operating system fundamentals, and because they were not fully revisited enough in depth later in the degree, it has been difficult to retain and build on that knowledge. As cybersecurity relies so heavily on understanding how systems, networks and infrastructure works, a stronger and more sustained foundation in those areas would be valuable.

From a cybersecurity perspective, I also think there could be more focus on defensive and operational security. Most of my subjects have leaned more towards the offensive side, which is definitely important as understanding

attacker methods helps you think more effectively about security. However, many entry-level roles in cybersecurity are in Security Operations Centres and other defensive environments, so I think degrees would benefit from more teaching around SIEMs, monitoring, alert triage and how to respond effectively in a defensive role.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management?

If yes, why?

Absolutely! Technical skills are the foundation of cybersecurity, but I genuinely believe that nontechnical skills are just as critical for long-term career success. The ability to communicate clearly, collaborate across teams, present findings to nontechnical stakeholders are all skills that are vital at the beginning of the career, but instrumental the further you progress.

A piece of feedback I received from a recruiter has stuck with me, where they mentioned that the managers of my team said that “you can teach cybersecurity, but you can’t teach soft skills and passion.” Technical knowledge can be trained and developed over time, but communication, curiosity and the ability to work well with others are qualities that are much harder to build.

This is why I believe universities should put more emphasis on developing soft skills as part of any cybersecurity degree. At the moment, at my university, many opportunities to build these skills, such as networking events and presentations, are optional. They should be embedded into the curriculum and should be mandatory. Cybersecurity professionals regularly need to brief leadership, write reports for non-technical audiences and work crossfunctionally with other teams, so preparing students for this reality is just as important as teaching them technicalities.

Reflecting on your journey thus far, would you, with the benefit of hindsight, make any changes to your career trajectory? If yes, what adjustments would you consider?

There are a few things I would approach differently with the benefit of hindsight. The most significant change I would make is starting my job search and opportunity hunting much earlier. I would encourage myself to begin looking for internships, cadetships and industry programs at the end of first year, so that applications and experience could be lined up for second year onwards. This would allow me to learn content from university more tangibly and learn from successes and rejections.

I would also push myself to be far more proactive in general. Applying for things feels daunting early on, especially when you feel like you do not have enough experience yet, but this mindset can hold you back. Most opportunities are designed with students in mind, and the only way to find out if you are a good fit is to just apply.

Finally, I would have invested more time and energy into networking from the beginning. Attending industry events, connecting with professionals and building relationships early in your degree, even just with your university professors, opens doors that applications cannot. Some of the most valuable things I have gained in my career so far have come through people, so if I could go back, I would have prioritised building connections from day one.

Have you actively sought employment opportunities in the cybersecurity field, and if so, what has been your experience with the application and interview process?

I have actively sought out opportunities in IT and cybersecurity, and the application process has taught me a lot about patience and persistence. One of my internships came from referral, which meant the process was relatively straightforward and involved

an informal interview. However, my more recent roles, including a cadetship and internship, involved a much more lengthy process.

Typically, the process began with a resume screening, sometime followed by a psychometric test. From there, it would move into the interview stage, which could take several forms. This included phone screenings, recorded online interviews where you are given questions and asked to record your responses, and in some cases group interviews and assessment centres. After that initial round, there were usually one or two further interviews with managers or senior stakeholders. Across multiple applications, I found this process regularly stretched over several months, which can feel discouraging.

The most important lessons I took from this experience are patience, preparation and confidence. It is easy to feel deflated when a process drags on or when you do not hear back for weeks at a time, but persistence is essential. Preparing thoroughly in advance, researching the company and practicing your responses makes a huge difference. My biggest piece of advice, especially to other students just starting out, is to be yourself throughout the process, fake the confidence until it becomes real and present yourself professionally in your tone and demeanour. Hiring managers respond to authenticity and enthusiasm, and those qualities are just as important as your technical knowledge!

www.linkedin.com/in/lauren-mauro-325853269

LAUREN MAURO

In a casual conversation with someone unfamiliar with the field, how do you articulate the excitement and potential of a career in cybersecurity, aiming to spark their interest? I usually describe cybersecurity as the point where tech meets real life. It’s not just code and systems it’s the stuff people rely on every day. Banking, healthcare, and even how we get around; all of it runs on digital infrastructure, and cybersecurity is what keeps that from being exploited or falling apart.

What makes it interesting is that it never sits still. The threats change constantly, so you’re always thinking on your feet. Some days it does feel like solving a puzzle, but it’s not abstract there’s a real consequence if you get it right (or wrong).

It’s also more varied than people expect. There’s the technical side, of course, but also forensics, policy, risk, even understanding human behaviour, such as people clicking, trusting, or making mistakes. So you don’t have to fit a single mould to belong in the field. There’s room for different ways of thinking, which is part of what makes it such a good career to grow into.

Reflecting on your initial perceptions of cybersecurity when you first considered studying it, how does the reality of your experiences today compare?

When I first looked at cybersecurity, I saw it as a very technical space—hands-on, tool-driven, quite narrow in scope. That’s what I expected going in.

But the more time I’ve spent on it, the more that initial view has shifted. It’s not just about tools or systems. It’s about how everything connects networks, people, data, trust. You start to see the bigger picture pretty quickly, especially when you’re working in areas like AI-driven threat detection. There’s a lot of thinking involved. You test things, question assumptions, try again. It’s less about knowing all the answers and more about staying curious and being willing to adapt as things change.

When you decided to pursue a career in cybersecurity, how did your parents, peers, or career advisors react? Did you encounter any opposition, and if so, how did you navigate those challenges?

I was pretty lucky, to be honest. I’ve got a really supportive circle around me, so when I decided I wanted to move into cybersecurity, the response was overwhelmingly positive. My family and friends were just glad I’d found something I genuinely cared about and wanted to pursue properly.

It also helped that I already knew a few people building careers in this field. Seeing what they were doing made it all feel a bit more real and more achievable. They’ve been generous with advice too, which makes a difference when you’re still finding your feet.

I didn’t run into any real pushback. If anything, the encouragement made it easier to commit and keep going, especially in those early stages where you’re figuring things out as you go.

Who or what has been the most influential factor in shaping your journey in cybersecurity so far, and how has it impacted your career aspirations?

SHAFIA HUSNA
Shafia Husna is currently undertaking her Doctor of Philosophy at Adelaide University
Doctor of Philosophy student at Adelaide University

A big turning point for me was getting involved in research-focused cybersecurity projects. Working on things like intrusion detection, network security, even bits of malware analysis and cryptography, it shifted how I saw the field. It stopped feeling like just a career path and started to feel like a space where I could ask better questions and actually contribute to solving problems that are still evolving.

I’ve also had strong guidance along the way. My academic mentors have been incredibly supportive not just in a formal sense, but in how they’ve encouraged my curiosity and pushed me to think more broadly about where cybersecurity is heading, especially with AI in the mix. That has certainly played a big role in shaping what I want to do next.

At this point, continuing into advanced research feels like a natural step. I’m hoping to take that further through my PhD focused on cybersecurity, privacy, and AI.

Given the rapid evolution of cybersecurity threats, do you feel that your academic program adequately keeps pace with the industry’s current landscape?

My academic studies have given me a strong foundation in key areas such as network security, programming, cryptography, system security, and research methods. These fundamentals have been incredibly valuable because, while cybersecurity is constantly evolving, the core principles remain the backbone of the profession.

What I have appreciated most about my studies is the balance between theory and hands-on learning. Being able to

apply concepts through practical exercises and experimentation has helped me develop a much deeper understanding of how cybersecurity works in real-world environments.

At the same time, I believe some of the most valuable learning happens outside the classroom. Cybersecurity is a field that rewards curiosity, and I have found it important to explore personal projects, participate in online learning opportunities, and engage with the wider security community. Keeping up to date with industry news, emerging threats, new technologies, and current research has helped me better understand how quickly the field changes and has reinforced the importance of continuous learning throughout a cybersecurity career.

What aspect of your cybersecurity studies excites you the most, and why?

What excites me most about cybersecurity is its growing connection with artificial intelligence. I am particularly interested in understanding how cybersecurity principles can be applied to machine learning and deep learning systems, and how these technologies can be developed and secured responsibly.

I find it fascinating that many traditional cybersecurity concepts and techniques remain highly relevant, even as AI and machine learning introduce new challenges and opportunities. Seeing how established security practices can be adapted to protect modern AI-driven systems highlights the importance of strong cybersecurity foundations.

Working on projects that sit at the intersection of cybersecurity and AI is especially rewarding because it feels like being part of a field that is still rapidly evolving. There is so much innovation happening, and the opportunity to contribute to securing emerging technologies makes the work both meaningful and exciting. It is an area that constantly pushes me to learn, adapt, and think about the future of technology.

Conversely, which aspect of your studies do you find least interesting or useful, and how do you navigate through it?

As someone who genuinely enjoys learning, I would not say there is any part of my studies that I find completely uninteresting or without value. That said, there are certain topics that do not capture my attention as much as others, particularly when they are less connected to the areas of cybersecurity that I am most passionate about or when they are taught in a highly theoretical way.

When I come across subjects that feel less engaging, I try to focus on the bigger picture. Cybersecurity is such a broad field that having knowledge across a wide range of topics is just as important as developing expertise in a specific area. Even the modules that are not my favourites often provide valuable context and help strengthen my overall understanding of technology, security, and risk.

I also make an effort to connect what I am learning back to real-world applications. Understanding how different concepts contribute to protecting systems, responding to threats, or building stronger security practices helps me stay motivated and appreciate the role each subject plays. In the end, I see every learning opportunity as another piece of the puzzle that helps me grow into a more capable and wellrounded cybersecurity professional.

Considering the holistic requirements of a future role, do you see the need for additional training in non-cyber skills, such as interpersonal communication or management? If yes, why?

Absolutely. While technical knowledge is essential in cybersecurity, I believe that strong communication, teamwork, leadership, and decision-making skills are just as important for long-term success.

Cybersecurity professionals often need to explain complex risks and security concepts to people who do not have a technical background, whether that

is senior management, clients, policymakers, or the general public. Being able to communicate clearly can make a huge difference because even the most effective technical solution has limited value if people do not understand it or know how to act on it.

The field also requires a great deal of collaboration. Whether responding to incidents, working on projects, writing reports, presenting findings, or making difficult ethical decisions, cybersecurity is rarely a solo effort. Success often depends on how well you can work with others, adapt to different situations, and make informed decisions under pressure.

For my own career goals, particularly in research and academia, these skills are especially important. I’ve always wanted to be able to communicate complex ideas in a way that is accessible to different audiences, collaborate with researchers and industry professionals, and contribute meaningfully to discussions that go beyond purely technical considerations. While my academic studies have helped me develop many of these skills through group work, presentations, and research projects, I believe that additional training and experience in these areas can be incredibly valuable. Developing both technical expertise and professional skills is what helps create a well-rounded cybersecurity professional.

www.linkedin.com/in/shafia-husna-805539246

SHAFIA HUSNA

How We Got Cyber Smart addresses cyber safety, cyber bullying and online safety for elementary school-aged children.

Lisa has partnered with Cool.Org , and her content is found on the Department of Education website .

Staying safe from cybercrime –more than not clicking links

It was a quiet Tuesday evening, and Jack’s parents assumed he was in bed reading.

He and his twin sister, Olivia, had only recently been allowed to use their devices in their rooms at night strictly for reading. From the hallway, the soft glow under Jack’s door looked exactly as it should.

Inside, though, Jack wasn’t reading.

Curled up in bed, he was scrolling through Chit Chat. A few funny videos turned into more, and then the algorithm shifted. Before long, he’d landed on a stream of “Top 10 Scariest Things Caught on Camera.” Each clip led to another. He told himself he’d stop after the next one, then the next.

Eventually, he put the device down. But the room didn’t feel the same.

The shadows seemed heavier. Ordinary house noises, a tap, a creak felt sharper, closer. He pulled the blanket up and tried to settle, but his mind kept replaying what he’d seen. Sleep came late, and when he woke in the night, it didn’t come back easily.

By morning, it showed.

“You look exhausted,” his mum said over breakfast. “I thought you were reading last night?”

Jack hesitated. “I wasn’t really reading. I was watching videos.”

His dad looked up. “Scary ones?”

Jack nodded. “Yeah… kind of.”

Olivia glanced over. “That explains why you jumped when the toaster went off.”

Jack gave a small, embarrassed smile. “I thought something had exploded.”

His mum sighed, but gently. “We trusted you with the device in your room. It’s not just the content, it's the screen itself. That bright light tells your brain it’s still daytime.”

“And once your brain’s switched on like that,” his dad added, “it’s hard to settle back down.”

Jack looked at his toast. “I didn’t think it would affect me that much.”

There was a pause.

“We’re going to make a few changes,” his mum said. “Not as a punishment just to help you get proper rest.”

His dad continued, “We’ll adjust the parental settings. At night, your tablet will only open your e-book app.”

“And we’re adding a wind-down period,” his mum said. “No devices at all for two hours before bed.”

Jack expected to feel annoyed. Mostly, he just felt tired.

“Okay,” he said. “That’s fair.”

His mum smiled. “And since you’re getting older, we can move your bedtime back slightly but that extra time stays screen-free.”

That evening, Jack left his device at the charging station after dinner. He and Olivia played chess for a while. Then a shower, and an actual book.

When he got into bed, the room felt different again but this time, in a good way. No lingering images. No edge to the silence. Just quiet.

Olivia poked her head in. “You alright?”

“Yeah,” Jack said. “I think so.”

He switched off the lamp and fell asleep quickly, the kind of sleep that doesn’t need effort.

By morning, the difference was obvious. No yawning through breakfast. No jumping at small sounds.

“Better night?” his mum asked.

Jack nodded. “Way better.”

From then on, he was more aware of what he watched and when. The device stayed part of his routine, but with clearer boundaries.

The scary videos could wait for daylight.

www.linkedin.com/in/lisarothfield-kirschner

howwegotcybersmart.com

WOMEN IN SECURITY MAGAZINE CONTRIBUTORS

1. AMANDA-JANE TURNER

Author of the Demystifying Cybercrime series and Women in Tech books. Conference Speaker and Cybercrime specialist

2. RACHEL CHOONG

Cyber Security Senior Project Manager

3. WENDY NGCONGO

Cybersecurity Architect | Data | Cloud | AI

4. SAMANTHA FINAN Independent CISO

5. NAGAMMAI SHANMUGHAM CISO Standard Chartered

6. STEPHANIE UZAMA

GRC Analyst and Consultant

7. SANDRA ESTOK

Founder & CEO, Way2Protect | Author | Speaker | Podcast Host

8. ISABELLA SCHULZ Graduate Consultant

9. CRAIG FORD

Head Unicorn – Cofounder and Executive Director, Cyber Unicorns. Australian Best Selling Author of A Hacker I Am, Foresight and The Shadow World book series. vCISO – Hungry Jacks, Wesley Mission, PCYC and Baidam Solutions

10. JO STEWART-RATTRAY

Oceania Ambassador, ISACA

11. LISA VENTURA MBE FCIIS

Chief Executive and Founder, Unity Group Solutions Limited/AI and Cyber Security Association

12. SIMON CARABETTA

Cyber Security Workforce Skills and Education | Podcaster | DEI advocate

13. JAY HIRA

Cyber Director – Financial Services, KPMG

14. POUPAK ENBOM

Chief Market and Business Development Officer, Yubico

15. KAREN STEPHENS

CEO and co-founder of BCyber

16. MARINA AZAR TOAILOA

Founder of the Mummy Safety Security Project

17. NICOLA JOHNSON

National Events Manager – Australia, Gallagher Security

18. TESSA WILLIAMS

National Marketing Manager – Australia, Gallagher Security

19. MADHURI NANDI

Madhuri Nandi, Head of security at Nuvei, AWSN Board Chair, author of Cyber Smart

20. SARA HASHI

Bachelor of Cybersecurity student at Deakin University

21. LAUREN MAURO

Bachelor of Cybersecurity student at the University of Technology Sydney (UTS)

22. SHAFIA HUSNA

Doctor of Philosophy student at Adelaide University

23. LISA ROTHFIELD-KIRSCHNER

Author of How We Got Cyber Smart | Amazon Bestseller

INTELLIGENCE-DRIVEN THREAT HUNTING: HOW SOCS FIND WHAT ALERTS MISS

Talk to any threat hunter long enough, and beneath the polished case studies and conference talks, the same frustrations surface. Hunting is supposed to be proactive. In practice, it often feels reactive. You are chasing whispers of activity through log noise, querying SIEM fields that barely reflect real attacker behavior and writing detections against technique descriptions that were never meant to be operationalized directly.

CYBERSECURITY EXPLAINED: WHAT IT IS AND HOW TO START FROM ZERO

It's not just about hackers in hoodies on movie screens. It covers everything from protecting your Instagram account to securing hospital patient records to defending a country's power grid from foreign attackers. The scope is enormous and that's exactly what makes it one of the most exciting fields to be in right now.

WHY WORLD QUANTUM DAY 2026 IS A WAKE-UP CALL FOR CYBER DEFENDERS

For years, "Q-Day", or the moment a quantum computer becomes capable of shattering our current public-key encryption, was treated like a Y2K ghost story. It was always a "someday" problem. But as we sit here in 2026, the data tells a different story. The inflection point has arrived, and the window for proactive defense is closing faster than many anticipated.

READ BLOG READ BLOG

SHADOW AI: WHY YOUR BIGGEST AI THREAT MAY COME FROM WITHIN

Organisations are adopting AI tools and systems at breakneck speed. But without proper governance policies, staff education and authorised AI tools, organisations invite the emerging risk of shadow AI into their environments

THE PSYCHOLOGY OF BAD CODE PART 5 – SHINY NEW TECH

Using a brand-new technology, language, and/or framework, even when it’s not necessarily the best thing to use. Especially if it’s untested, and there’s little guidance or tools available for it. An obsession with using what’s new, over what’s best for the situation.

COMMON API SECURITY PITFALLS AND BAD PRACTICES

APIs Are The Second Top Entry Point For Cloud Compromise, At 16.5%.Nearly Half Of Organizations

Identify Managing API Sprawl As Their Top Concern, Followed By Maintaining Accurate Inventory.

READ BLOG

READ BLOG

READ BLOG

SECURITY AWARENESS TRAINING: BEYOND COMPLIANCE CHECKBOXES

This analysis examines security awareness training beyond compliance through technical, strategic, and governance lenses. It synthesizes current research, regulatory developments, and practitioner insights to deliver actionable guidance for security leaders, enterprise architects, and board-level decision-makers navigating this domain.

AI IMAGE-TO-VIDEO GENERATION FOR UK CREATIVE WORKFLOWS

AI image-to-video systems rely on motion inference. The model analyses a source image, identifies visual elements such as edges, depth and subject placement, then predicts how these elements might move across multiple frames. Frame interpolation fills the gaps between predicted positions, producing smooth transitions that simulate camera movement or object motion.

PUTTING CLIMATE INTO PRACTICE: BUILDING AN INVENTORY MANAGEMENT PLAN

In corporate sustainability, it is common practice to outsource GHG data management to third-party software platforms or consultants. For many organizations, this is a highly practical way to establish a baseline. But outsourcing execution should never mean distancing yourself from the underlying data and methodology.

FROM THE SOC TO THE BOARDROOM: REDEFINING CISO LEADERSHIP

With Women in Cybersecurity Podcast

In this episode, we sit down with Renata Vincoletto, Chief Information Security Officer at Civica, to explore what it truly means to lead with impact in today’s high-stakes cyber landscape. Renata shares her journey leading enterprise-wide cybersecurity and risk strategies that protect critical services and sensitive data, while navigating the realities of complex, missioncritical environments.

I LOVE CHALLENGING OTHERS TO GO FURTHER IN THEIR CAREER'

With Women in IT podcast

As a General Manager, Margrith’s goal is to grow the market share for Kaspersky across Australia and New Zealand and ensure the regional office runs like clockwork. However, her role stretches far beyond this remit and covers every aspect of the business. Margrith jokes that she could be an HR professional, a real estate manager or even a facilities manager because her colleagues often ask for help and advice on a wide range of issues

INSIDE CYBER MINDS

With LufSec Cyber Security

In this episode, we dive into:

• Why combining AI/ML and blockchain is a game-changer for financial transaction security

• How smart contracts, anomaly detection, KYC/AML, and crossborder payments are evolving under this convergence

• Engineering lessons from scaling secure enterprise systems to shaping next-gen fintech security architectures

• The challenges ahead: explainability, privacy, quantumresistance, and governance in financial cyber-defense

INSPIRING LADIES OF CYBER PODCAST

With Woman in Red Jenee is a cybersecurity pioneer, entrepreneur, and woman of incredible determination. Her journey is a testament to the power of hard work, resilience, and passion. From navigating her way into the tech industry as a young girl, to building a successful business that's revolutionizing the way we approach cybersecurity, Jenee's story is one for the ages.

HERE COME THE AI BROWSERS

With Security Now

With a new episode every Tuesday, Security Now tackles the latest in cyber crime and hacking, plus tips on how to protect yourself and your business. Frequently discussed topics include passwords and authentication, malware, ransomware, digital identity, data privacy, zero-day exploits and much more

SECURITY YOU SHOULD KNOW

With Cisoseries

Security You Should Know is a focused 15-minute podcast that connects security solutions with security leaders. Hosted by Rich Stroffolino, each episode presents a cybersecurity vendor trying to solve a specific problem, with two security expert panelists asking questions to learn more about the solution.

WHEN “OPPORTUNITY” KNOCKS, DON’T ANSWER.

With Hacking Humans

Another popular podcast from CyberWire, Hacking Human focuses on the social engineering schemes, phishing scams and similar criminal exploits making big impacts around the world. Recent topics have included how AI-generated scams have infiltrated the world of fiber crafts and how AI-generated images and videos are used to promote fake product endorsements by celebrities and medical professionals.

ILLUMINATE ADVERSARIES WITH CYBER THREAT INTELLIGENCE

With Blueprint Podcast

Blueprint Podcast comes from the SysAdmin, Audit, Network, and Security (SANS) Institute, a private company in the U.S. that specializes in information security and cybersecurity training. Previous topics have included the current and future state of security operations, privacy laws and what it takes to write a cybersecurity book. The podcast also features interviews with global cybersecurity experts.

LLM RESEARCH AND CISO LIABILITY

With The Security Detail

In episode two of The Security Detail, Audra interviews Liz Wharton, founder of Silver Key Strategies, about her research on using large language models (LLMs) to analyze SEC 8-K filings and other public reporting to gain cybersecurity insights. Liz is an attorney who has two decades of legal, public policy, and business experience, including in cybersecurity. The interview also covers the heightened liability security executives face when reporting material incidents to the US Securities and Exchange Commission (SEC).

TALKS DATA PRIVACY, MENTORS/SPONSORS

With CISOs in Cars

Kunal Agarwal drives Kelly Haydu, VP, Information Security, Technology & Enterprise Applications, in a Tesla Cybertruck around SF at the RSA Conference as they discuss building rapport with engineers, building a data privacy practice, and moving from QA to head of cybersecurity. They talk about data breach reporting and how public companies can approach cybersecurity

HOW AI AGENTS WILL NEGOTIATE YOUR VENDOR CONTRACTS

With Cloud Security Podcast

The Cloud Security Podcast is a weekly video and audio show that explores the ever-evolving world of cloud security. Through in-depth conversations with top cloud security experts, industry leaders, and frontline practitioners, the podcast delivers valuable insights, practical strategies, and real-world stories that help listeners stay ahead of emerging threats and best practices.

MINUTES TO MELTDOWN: CYBER RECOVERY WHEN IT COUNTS

With Hacker Valley Studio

This weekly podcast from Hacker Valley Media, a cybersecurity creative media agency, touches on the latest cybersecurity news, AI in cybersecurity, zero trust tactics, hacker culture and how to accelerate your cybersecurity career, just to name a few topics. From current events and the latest cybersecurity technology to job advice and interviews with top security experts, this podcast covers it all

ZERO TRUST NETWORKS

Authors // Razi Rais and Christina Morillo

This practical book provides a detailed explanation of the zero trust security model. Zero trust is a security paradigm shift that eliminates the concept of traditional perimeter-based security and requires you to "always assume breach" and "never trust but always verify.

BUY THE BOOK

CYBERSECURITY CAREER GUIDE

Authors //Alyssa Miller

Self-analysis exercises to find your unique capabilities and help you excel in cybersecurity

How to adapt your existing skills to fit a cybersecurity role

Succeed at job searches, applications, and interviews to receive valuable offers

Ways to leverage professional networking and mentoring for success and career growth

BUY THE BOOK

GREENER DATA

Author // Jaymie Scotto Cutaia

Empowering other industries' digital transformation, our innovators from around the globe share their timely insights to inspire positive and ever-lasting change and sustainability.Building upon the insights and success stories shared in the first book, “Greener Data – Volume Two” BUY THE BOOK

SWITCHING TO CYBER

Authors // Josiah Dykstra and Helen E. Patton

Is your job changing? Or are you considering a career switch, and the exciting yet daunting world of cybersecurity is calling your name? You’re not alone. Switching to Cyber is your roadmap to navigating this dynamic field, proving that age is just a number when it comes to building a fulfilling and impactful career in cybersecurity.

BUY THE BOOK

HUMAN FACTORS IN CYBERSECURITY

Author // Nikki Robinson

Cybersecurity isn’t just a technical problem; it’s a human one. Human Factors in Cybersecurity equips you to tackle today’s digital threats by designing systems that respect how cybersecurity professionals actually think, behave, and make decisions.

BUY THE BOOK

DEEP DIVE: EXPLORING THE REAL-WORLD VALUE OF OPEN SOURCE INTELLIGENCE

Author // Rae L. Baker

In Deep Dive: Exploring the Real-world Value of Open Source Intelligence, veteran opensource intelligence analyst Rae Baker explains how to use publicly available data to advance your investigative OSINT skills and how your adversaries are most likely to use publicly accessible data against you.

BUY THE BOOK

CYBER-SMART PARENTING: PROTECTING YOUR CHILD IN THE DIGITAL AGE

Author // Cybersecurity Parents LLC

Cyber-Smart Parenting: Protecting Your Child in the Digital Age gives you the tools, strategies, and confidence you need to safeguard your child's digital life. Whether you're worried about social media, gaming, screen time, or online predators, this easyto-follow manual shows you how to take control - even if you're not tech-savvy.

BUY THE BOOK

TOBI & BYTEY – MISSION: FIREWALL KNIGHTS

Authors // Smart Kids Academy and Catarine Zadieka Tobi is a curious boy who loves computers, and his best friend Bytey is no ordinary robot – he’s a living data byte from the digital world! When Clara, guardian of the Cloud Kingdom, sends out an urgent message, the two friends are pulled into a dangerous mission: stop the evil Virena and her army of cyber villains from taking over the magical Cloud Castle.

BUY THE BOOK

DIGITAL WORLD: HOW TO CONNECT, SHARE, PLAY, AND KEEP YOURSELF SAFE

Author // Carrie Anton

Digital devices put a whole world at your fingertips. Play a game, listen to music, do research for school, read a story, or make a video -- anywhere, anytime. Connect with friends and family in fast and easy ways. Post photos and share ideas and inspiration. And that's only a small part of it.

BUY THE BOOK

ELLE GETS A MOBILE PHONE: CYBER SAFETY CAN BE FUN [INTERNET SAFETY FOR KIDS] (DIARY OF ELLE: CYBER-SAFETY CAN BE FUN!)

Authors // Nina Du Thaler and Helena Newton Ten-year-old Elle is bursting with excitement — she's finally getting a mobile phone for her birthday! But before her big day arrives, her friends start sharing stories she wasn't expecting to hear. Maya received horrible anonymous messages and didn't know who to turn to. Lucy racked up a phone bill so enormous her parents nearly fell off their chairs. And when a mobile phone goes missing on the bus, Elle learns that even losing a device can lead to a whole new set of worries.

BUY THE BOOK

ROHAN AND THE MAGIC SCREEN (CYBER SMART KIDS ADVENTURES)

Author // Sonali Sinha

When Rohan’s tablet suddenly glows with a bright, sparkly light, he never expects a tiny robot named Byte to pop out of the screen!

Byte has an important mission — to teach Rohan and his friends how to stay safe online.

BUY THE BOOK

DIGITAL DAN AND CYBER CITY

Authors // Lemi-Ola Erinkitola and Ruchi Sharma Cyber City is a high-tech town featured in our new, upcoming children’s book on cybersecurity. Filled with fun, curious characters, an adventure in this city will help your child understand how to remain safe online. The first character introduced in the Cyber City books is Digital Dan, the leader of the city, who takes the form of a cloud.

BUY THE BOOK

THE LEARNING HUB

CYBERSECURITY FUNDAMENTALS

In this introduction to the field of computing security, you will be given an extensive overview of the various branches of computing security. You will learn cybersecurity concepts, issues, and tools that are critical in solving problems in the computing security domain.

CS50'S INTRODUCTION TO CYBERSECURITY

This is CS50's introduction to cybersecurity for technical and nontechnical audiences alike. Learn how to protect your own data, devices, and systems from today's threats and how to recognize and evaluate tomorrow's as well, both at home and at work.

HERE

CYBERSECURITY CAPSTONE AND CASE STUDIES

Hands-on experience analyzing cybersecurity incidents to identify threat tactics and assess vulnerabilities you can talk about in interviews

CYBERSECURITY ESSENTIALS

The course discusses the cybersecurity TRIAD, social engineering, identity and access management (IAM), cryptography, common network attacks, and secure network design. It provides students with a foundation for getting started in the cybersecurity field.

VISIT
VISIT HERE
VISIT HERE
VISIT HERE

THE LEARNING HUB

DIGITAL SHIELD: CYBERSECURITY FOR DATA AND SYSTEM PROTECTION

This course empowers you with the knowledge to protect systems, networks, and data, develop skills to adequately respond to cyberattacks, understand the risks of cybersecurity, and identify vulnerabilities while managing information security.

MODERN SECURITY OPERATIONS

Learn to modernize security operations with Google’s Autonomic Security Operations (ASO) framework and Continuous Detection, Continuous Response (CD/CR) methodology. Gain insights into detection, response strategies, and adaptive threat management.

UNDERSTANDING THE DIGITAL SUPPLY CHAIN AND ITS STAKES FOR HUMANITARIAN ACTORS

Understand the hardware, software and connectivity supply chains, their actors, vulnerabilities, and associated cybersecurity risks.

QUANTUM-SAFE DIGITAL INFRASTRUCTURES: CHALLENGES AND SOLUTIONS FOR GOVERNANCE

This course will help you to specify quantum threats and take appropriate governance actions. Learners will be able to take a leading role in effecting the migration to quantum-safe digital infrastructures. VISIT

TRY IT: ETHICAL HACKING

Want to know more about ethical hacking? Sign up for our free course and learn about ethical hacking and offensive security. The course is conveniently self-paced, and will also introduce you to the legal boundaries that distinguish “ethical” from “unethical” hacking, and the careers ethical hackers can pursue.

FINDING YOUR CYBER SECURITY ANALYST ROLE

In this course, you'll transform the overwhelming cybersecurity landscape into a personalized career roadmap designed for your success. We guide you in exploring the industry's key roles while simultaneously uncovering your own distinct hard and soft skills. This culminates in empowering you to confidently select and plan for a bestfit role that aligns your personal strengths with real-world demand.

QUANTUM MANAGEMENT

Check Point's Quantum is the best Threat Prevention solution on the Market! It offers uncompromising Security, consistently preventing both known and unknown Zero-day attacks.

HOW IS AI USED IN CYBER SECURITY?

Discover the transformative role of artificial intelligence in safeguarding digital landscapes with our free course, how is AI Used in Cyber Security. This comprehensive program explores the integration of AI technologies in modern cybersecurity practices, providing insights into how AI-powered tools identify and neutralize threats in real time.

JOB BOARD

CLOUD SOLUTION ARCHITECT - CLOUD & AI INFRASTRUCTURE | MICROSOFT

FULL TIME INDONESIA

RESPONSIBILITIES

• Create business value by translating customer challenges into actionable solutions aligned to high ROI customer outcomes. Ensure a seamless, connected experience that fosters satisfaction, loyalty, and long-term value.

• Lead architectural design sessions and deliver secure, scalable, and resilient infrastructure solutions aligned to customer business goals using frameworks like CAF and WAF.

• Partner with technical and sales teams to identify opportunities and develop tailored solutions to drive expansion and business value realization.

CYBER SECURITY OFFICER - MEA | ENVISION ENERGY

FULL TIME UNITED ARAB EMIRATES

KEY RESPONSIBILITIES

HQ–Region Bridging & Strategy Alignment

• Act as the primary interface between HQ cybersecurity teams and MEA markets.

• Translate global policies into localized, implementable solutions and requirements.

CLOUD ARCHITECT | WOMEN IN TECH

FULL TIME RUSSIA

ABOUT THE ROLE

In this role, you will design, configure, and implement cloud-based solutions that meet client requirements, ensuring delivery is on time, within scope, and aligned to high-quality standards. You will take ownership of technical delivery across Azure environments, working

• Provide structured feedback to HQ on regional regulations, customer needs, and competitive gaps

from detailed designs to build, patch, and configure systems while ensuring adherence to security and change control processes.

SECURITY OPERATIONS LEAD / GOVERNANCE OWNER | ABB

FULL TIME INDIA

YOUR ROLE AND RESPONSIBILITIES

In this role, we are looking for a Security Operations Lead – Governance & Risk Management to join our Industrial Automation Digital Organization. The role requires an experienced security professional with strong expertise in Security Operations (SecOps) governance, risk management, vulnerability management, incident response oversight, and security posture management across hybrid environments.

The candidate will be responsible for establishing and governing the Security Operations framework for Azure-primary SaaS environments spanning cloud, on-premises, edge infrastructure, Kubernetes platforms, databases, and customer deployments. APPLY

CYBER DEFENSE ASSOCIATE | ACCENTURE MIDDLE EAST

FULL TIME SAUDI ARABIA

RESPONSIBILITIES:

• Monitor security alerts from tools such as SIEM, antivirus, endpoint protection, firewall, and email security systems.

• Review and escalate suspicious activities, phishing emails, malware alerts, and unauthorized access attempts.

• Assist in basic incident response activities, including collecting evidence, documenting findings, and supporting remediation steps.

• Perform daily security checks and prepare operational security reports.

• Support user access reviews and help ensure access rights follow company policies.

APPLY HERE

PRINCIPAL ENGINEER, PLATFORM & SECURITY | STUFF

FULL TIME NEW ZEALAND

WHAT YOU’LL BRING

• Extensive experience in senior platform engineering, DevOps, cloud infrastructure or security leadership roles.

• Hands-on experience designing and implementing zero-trust network architecture, service mesh, and application security controls at scale.

SECURITY ENGINEER | MIND DETECT

FULL TIME SOUTH AFRICA

RESPONSIBILITIES

• Secure our data, endpoints and networks

• Ongoing preparation, monitoring, and response to security incidents

• Build, maintain, enhance and oversee SIEM solutions.

• Risk management:

• Deep expertise in cloud platforms, Infrastructure as Code, CI/CD and modern software delivery practices.

APPLY HERE

• Conduct pen-testing and threat hunting to find weaknesses in defence systems to improve overall security

APPLY HERE

SENIOR INFORMATION SECURITY CONSULTANT | EY

FULL TIME ITALY

KEY RESPONSIBILITIES

This position is a leading role in designing, developing, and accessing all aspects of security for market leading regional and global systems based primarily on Cloud technologies. As a security consultant for EY Regional Technology Hub you will be an individual contributor capable of supporting multiple project

teams operating in the latest technologies of Cloudbased, Agile developed systems, using automated deployment from CI/CD pipelines.

APPLY HERE

JOB BOARD

SENIOR ANALYST, CYBERSECURITY OPERATIONS & RESPONSE | FOX ROTHSCHILD

FULL TIME USA

ESSENTIAL FUNCTIONS

• Support the day-to-day operation and execution of the Firm’s Cybersecurity Operations & Response program.

• Assist with the administration and continuous improvement of the Firm’s threat and vulnerability management program.

• Develop, maintain, and update associated playbooks, policies, standards, and procedural documentation.

• Participate in cyber event response activities, including investigation, containment, remediation, and recovery efforts.

• Serve as a primary resource for security operations monitoring and incident triage activities.

STRATEGIC CYBER SECURITY CONSULTANT | GOOGLE

FULL TIME FRANCE

RESPONSIBILITIES

Learn more about benefits at Google .

• Manage a small team of Consultants.

• Build a trusted advisor to clients, cultivating and maintaining strong relationships with key client stakeholders.

• Design, position, and co-deliver security consulting projects that leverage the complete breadth of

Mandiant's security services portfolio to provide a unified and cohesive experience for clients, while developing proposals, presentations and other documents for projects.

APPLY HERE

INTERNAL CYBER DEFENCE CONSULTANT | RICOH EUROPE

FULL TIME UNITED KINGDOM

BLUE TEAM LEADERSHIP & OPERATIONS

• Leading and coordinating the virtual Blue Team, including SOC analysts, incident responders, threat hunters and defensive engineers

• Setting strategic direction, improving processes, and supporting skill development across the defensive capability

• Acting as a senior escalation point during investigations and major incidents

APPLY HERE

SENIOR CYBER INTELLIGENCE CENTER SECURITY ANALYST | DELOITTE

FULL TIME GREECE

YOUR ROLE

Be part of Deloitte’s Cyber Intelligence Center and conduct advanced cyber security analysis/ threat hunting activities using known adversary tactics, techniques, and procedures as well as indicators of

attack, to detect adversaries that may have bypassed conventional controls remaining undetected in our clients’ networks and systems.

APPLY HERE

APPLY

We need your support to continue this important initiative into its 8th year.

JOIN US IN MELBOURNE FOR 2026

The 2026 Awards will be hosted in Melbourne. To ensure this initiative continues, we invite you to partner with us as a sponsor.

Your sponsorship will help us continue to celebrate and elevate the achievements of women in security across Australia.

SPON S ORSHIP

Packages available from $6,000 to $50,000 Custom packages tailored to your organisation’s needs

OPPORT U NITIES

To discuss how you can support and sponsor next year’s awards, please reach out to Aby at Aby@source2create.com.au .

We look forward to partnering with you to make the 2026 Australian Women in Security Awards our best yet.

Turn static files into dynamic content formats.

Create a flipbook
Women in Security Magazine Issue31 by source2create - Issuu