国产视频

In Short

A Human to Know: Jane Frankland

Conversations with the people who are changing the way we live our lives online.

janefranklandheadshot

There鈥檚 really no 鈥渢ypical鈥 individual in cybersecurity, and Jane Frankland exemplifies that fact. Jane, who entered the field with a background in textile design, is now the Managing Director of Cyber Security Capital.

Jane is also the author of the of the INSecurity: Why a Failure to Attract and Retain Women in Cybersecurity is Making Us All Less Safe. I recently spoke with Jane about her path into cybersecurity and the importance of diversity in the field. An edited version of the interview is below.

What prompted your interest in cybersecurity?

Well [laughing], I literally started a company. I had promised myself to never do sales, but I had ended up in a pretty hardcore sales job. When I met my boyfriend, who was a 鈥渢echie,鈥 he wanted to start a company together. At the time, I only knew about two areas of tech that interested me鈥擜I and security鈥攁nd since AI was too emerging in 1997, we went with cybersecurity. I thought it sounded really cool (kind of like James Bond), and in those days, we were mostly talking firewalls and intrusion detection systems; companies had just started using email, and most didn鈥檛 even have a website. Cybersecurity was much different than it is today. We specialized in , and within two years, we had a seven-figure business.

How have you seen the field evolve over the last twenty years?

I see both progress and stagnation. The language has certainly changed: it started as 鈥淚T security,鈥 or 鈥渋nformation security,鈥 and now we鈥檝e evolved to 鈥渃ybersecurity.鈥 My company began as a value-added reseller, selling high-availability servers and security solutions. Then, it became 鈥減enetration testing鈥; and now we largely refer to the practice as 鈥渆thical hacking.鈥 There鈥檚 also a lot more emphasis on people鈥攈ow they can be both your greatest vulnerability and your greatest asset. Since people are security, this is definitely a positive.

On the other hand, I see a huge leadership problem. It鈥檚 so easy to look and to say, 鈥渨e鈥檙e making the same mistakes,鈥 because we frequently are; we鈥檙e talking about the same things we were twenty years ago. This comes back to the fact that our job, as cybersecurity professionals, is not to secure. Our job is to reduce and mitigate risk in line with each organization鈥檚 risk appetite. In order to do that, we need to better communicate what our job is to the stakeholders we鈥檙e engaging with, like the CFOs or the CEOs or the board (if we even get to communicate with them). We also need to start with people and then move to processes, rather than neglecting overall strategy. Since CISOs are only in their position for an average of 22 months, they鈥檙e not in the job for long enough to affect necessary change. So the volume of cybersecurity roles has increased since I started, but there鈥檚 still a long way ahead.

What inspired you to write INSecurity?

When I first worked in security, I can remember so clearly that I had a female client鈥攁nd it was so exciting to find another woman in the industry; it was so massively rare. So I had noticed this lack of women in the field for a while. Then, in 2015, I picked up a report on women in cybersecurity, and realized the problem was worse than I originally thought鈥攁nd it was getting worse each year. I decided that it was time for me to write about it. There was no agenda. I just wanted to be a voice and add my perspective. So I did, and it was really well-received. A聽few months later, I thought it would be useful to turn my article into a report. I ended up contacting a publisher out of curiosity, and she told me I鈥檇 be crazy not to write a book.

How is the dearth of women in cybersecurity making us less safe?

Women see risk in a different way. There鈥檚 loads of data on it, and this is all covered in the book. Since our job in cybersecurity is to mitigate risk, we are inherently increasing our risk by not placing women in decision roles. Women also have a greater tendency to implement processes rather than just tech, meaning they鈥檙e more inclined to consider human behavior and design holistic solutions.

Cybersecurity seems to have a diversity problem that extends beyond just gender. Do you think that affects our safety as well?

Absolutely. We already know that when women are in leadership positions, other forms of diversity increase. And bringing in different types of people clearly has an impact on how we solve problems and mitigate risk. Professionals from different backgrounds with different experiences鈥攊f they鈥檙e younger, if they work in different areas, it doesn鈥檛 matter鈥攈ave unique skill sets and abilities, which makes us more secure when addressing problems. So when it comes to diversity beyond gender, we need to let data drive the discussion.

If you were speaking directly to women looking at the field of cybersecurity, what would you tell them?

Depends on whom I鈥檓 talking to! When I鈥檓 speaking with young girls, I use my voice as a tool鈥擨 bring stories; I talk about skills; I try to present the true promise of diversity in our industry and the intellectual diversity that already exists. You don鈥檛 have to be a techie. You can be a business person. There are lots of different fields that all play an important role. When I鈥檓 talking to people who want to pivot鈥攆rom auditing, from law, from teaching, from HR, or even from a PA role鈥擨鈥檒l speak to them about the industry and how easy a transition can be. Generally speaking, I try to normalize all forms of contribution to the cybersecurity field.

What about recruiters? How could they recruit more women into the field?

The (diverse) talent is there, but we have an inability to bring it in. There鈥檚 a problem both with HR and with hiring managers, but it鈥檚 also a larger issue of how recruitment actually occurs. Looking at CVs can indicate gender, age, ethnicity, and other factors that may implicitly influence how we select candidates. Panel interviews can make candidates uncomfortable and cause different people to converge on single opinions, which is not necessarily good. Because nobody comes into cybersecurity ready-made, we need to write the job from the ground-up. We need to train people upon entry and ensure that diversity of thought keeps organizations more secure.

More 国产视频 the Authors

Justin Sherman
Justin Sherman
A Human to Know: Jane Frankland