Summary
- UK government data cited in the article puts women at 17% of the cyber sector workforce, falling to 12% at senior level.
- Samantha Jennings argues that broader educational and career backgrounds can challenge shared assumptions and strengthen cyber resilience.
- She calls for less restrictive hiring, non-degree routes, mentoring, sponsorship, and clearer progression into security leadership.
By Samantha Jennings, Head of Operations at Avella Security
Cybersecurity has a blind spot problem.
Our industry exists to identify risks others have missed, challenge assumptions and anticipate what an adversary might do next. Yet if the people responsible for doing that have broadly similar backgrounds, education and career paths, there is a danger they will also share similar assumptions.
That is why, this Women in Cyber Day, I believe we need to change the way we talk about diversity in cybersecurity. Diversity is a resilience issue. And if we accept that premise, it requires action.
The UK Government’s Department for Science, Innovation and Technology latest cyber skills Labour Report shows women account for just 17% of the cyber sector workforce, compared with 30% of the wider digital workforce and 48% of the UK workforce. At senior level, female representation falls to 12%.
Those figures expose a significant imbalance and raise the question of what perspectives, questions, and ways of thinking we miss because whose voices are absent or unheard.
When security suffers from a failure of imagination
There is a lesson from the wider security world that feels particularly relevant.
Following the September 11 attacks, the 9/11 Commission examined how such an enormous threat had not been anticipated or prevented. Its report identified failures in four areas: imagination, policy, capabilities and management, with imagination described as the most important.
For me, that finding was a lightbulb moment in understanding the importance of diversity in security. If a failure of imagination can leave us vulnerable, then who we involve in imagining threats matters. People with different backgrounds, experiences and ways of thinking bring different frames of reference. They ask different questions, challenge different assumptions and may see risks that others overlook.
Threat actors look for the route we have not considered and exploit assumptions we have failed to question. If everybody tackling a problem has followed a similar educational and professional route, we increase the possibility of collective blind spots.
The action for cyber leaders is to start treating diversity as part of resilience planning. When assessing the strength of a security function, ask whether you have the breadth of experience required to challenge your own assumptions, as well as the technical capabilities to respond.
There is no single route into cyber
My own route into cybersecurity was anything but conventional.
I did not study computer science or start my career as a coder. I loved English and the power of language. I studied Business and Finance before becoming an Account Director, Commercial Manager and Bid Manager in recruitment advertising. At one point, I even worked abroad as a holiday entertainer.
On paper, none of that looks like an obvious route to becoming Head of Operations at a cybersecurity company.
In practice, every experience gave me skills I rely on today.
Being an Account Director taught me about people, relationships and communication. Bid management taught me how to translate requirements for different teams, from finance and HR to IT and client services, and bring them together towards a shared goal. Working as an entertainer taught me confidence and adaptability. Throughout those roles, curiosity encouraged me to ask a question that remains important in cybersecurity: is there another way of looking at this?
Cyber needs more than technical expertise
Technical expertise is fundamental. We need people who understand systems, networks, vulnerabilities, architecture and emerging technologies. But technical experience alone does not create cyber resilience.
An organisation can have sophisticated security controls and still be vulnerable because somebody does not understand a process, an employee responds to social engineering, a board does not grasp the significance of a technical risk or teams cannot communicate effectively during an incident.
Cybersecurity also needs communication, psychology, creativity, empathy, critical thinking and commercial understanding.
We need people who can translate a technical vulnerability into language a board can act upon. We need people who understand how humans behave under pressure. We need creative thinkers because adversaries are creative.
Employers should reflect that in how they define cyber roles. Separate the technical skills genuinely essential on day one from those that can be developed, and give greater weight to transferable skills and potential.
Stop shrinking the talent pool before people apply
The government’s research identifies persistent barriers to improving diversity, including negative stereotypes about the industry and the cost of degrees and technical qualifications.
Cybersecurity itself can reinforce those barriers through acronyms, certifications, specialist terminology and highly specific job requirements.
It can send an unintended message: unless you studied the right subject, gained the right certification or started experimenting with computers at an early age, this industry is not for you.
There are encouraging signs. Among cyber businesses that had recruited, 63% said they had hired through non-degree routes and 41% had run talks or events in schools, colleges or universities to attract more diverse applicants.
Those actions need to become the norm. We should audit job descriptions for unnecessary barriers. Challenge jargon. Make transferable skills visible. Create non-degree entry routes. Engage with schools and communities. Show people the breadth of careers that exist across cyber.
Getting women through the door isn’t enough
Recruitment is only the start. If we recruit different voices but those voices disappear as we move up the organisation, we have not solved the problem.
Leaders need to measure progression as seriously as recruitment. Look at who receives stretch opportunities, who has access to mentors and sponsors, whose ideas are heard and who progresses into positions where security decisions are made.
We must create mentoring and sponsorship programmes. Make role models visible. Develop pathways into leadership. And build cultures where challenging an assumption is valued rather than interpreted as challenging authority.
Make Women in Cyber Day a catalyst for action
The case for action is becoming harder to ignore. The UK cyber sector is growing rapidly, making the question of who builds its future increasingly important. The Government’s Cyber Security Sectoral Analysis 2026 shows that the sector now employs 69,600 people across 2,603 firms and generates £14.7bn in annual revenue – an 11% increase in just one year.
Women in Cyber Day gives us an opportunity to celebrate the women already protecting organisations, infrastructure and communities. But celebration needs to translate into change.
We need to broaden entry pathways. Remove unnecessary barriers. Invest in mentoring and sponsorship. Create routes into leadership. Engage girls earlier. And measure whether different voices are genuinely being heard, rather than only counting how many people have been hired.
If cyber is going to keep pace with an evolving threat landscape, we need people who bring different experiences, ask different questions and see problems from different angles.
This Women in Cyber Day, the question should not be how we help more women fit into cybersecurity. It should be: what could cybersecurity become if more of them had the opportunity to shape it?
| About the author | |
|
Samantha Jennings is Head of Operations at Avella Security, a managed security service provider supporting organisations across a diverse range of global industries. She leads strategic and operational excellence across consultancy delivery, finance, marketing and quality assurance. Samantha is particularly passionate about inclusive hiring and creating pathways for underrepresented talent to build successful careers in cyber security. |
|












