Archive.fm

CyberWire Daily

2024 Cyber Talent Study by N2K and WiCyS. [Special Edition]

Maria Varmazis, N2K host of T-Minus Space Daily, talks with WiCyS Executive Director Lynn Dohm and N2K's Simone Petrella, Dr. Heather Monthie, and Jeff Welgan about the 2024 Cyber Talent Study.

N2K and WiCyS have come together under a common mission to attract, retain, and advance more women in cybersecurity. Together, we strive to support women throughout their career journey, and secure the future of our industry.

This groundbreaking report leverages skills data from the professional members of Women in CyberSecurity (WiCyS), and offers valuable insights into cybersecurity competencies within the industry. The Cyber Talent Study establishes a new benchmark for understanding the capabilities and potential of women in cybersecurity, and can be used to inform both individual training needs and organizational strategies for career advancement and skills enhancement.

Resources:

Landing page: WiCyS Partners with N2K to deepen understanding of cyber competencies within the industry.

Study Launch article: WiCyS Partners with N2K Networks for Pioneering Cyber Talent Study.

Key Takeaways:

Outstanding Performance: WiCyS members have demonstrated exceptional performance across several key areas of the NICE Framework, underscoring the importance of WiCyS’s training and development programs.

Strategic Insights: Analysis revealed remarkable strengths and areas for development, providing WiCyS with actionable data to tailor future programs and initiatives and ensure its members remain at the forefront of cybersecurity excellence.

Actionable Insights for Cybersecurity Workforce Development: The study revealed critical areas for targeted development to enhance cybersecurity workforce readiness. This insight empowers WiCyS to tailor its programs specifically to meet the diverse needs of its members, ensuring all participants are prepared to take on significant roles and lead in the cybersecurity industry.

Leadership Readiness Among WiCyS Members: The study highlights that WiCyS members are highly skilled and uniquely prepared for leadership roles within the cybersecurity industry.

Proven Expertise in Critical Cybersecurity Domains: The data show the outstanding capabilities of WiCyS members within the cybersecurity landscape. Excelling in nearly every N2K Functional Area mapped to the NICE Framework, WiCyS members have shown they not only meet but exceed the standards in key domains.

You can access the final report of the 2024 Cyber Talent Study here. Learn more about your ad choices. Visit megaphone.fm/adchoices

Duration:
40m
Broadcast on:
27 Jun 2024
Audio Format:
mp3

Maria Varmazis, N2K host of T-Minus Space Daily, talks with WiCyS Executive Director Lynn Dohm and N2K's Simone PetrellaDr. Heather Monthie, and Jeff Welgan about the 2024 Cyber Talent Study.


N2K and WiCyS have come together under a common mission to attract, retain, and advance more women in cybersecurity. Together, we strive to support women throughout their career journey, and secure the future of our industry.  


This groundbreaking report leverages skills data from the professional members of Women in CyberSecurity (WiCyS), and offers valuable insights into cybersecurity competencies within the industry. The Cyber Talent Study establishes a new benchmark for understanding the capabilities and potential of women in cybersecurity, and can be used to inform both individual training needs and organizational strategies for career advancement and skills enhancement. 


Resources:


Key Takeaways:

  • Outstanding Performance: WiCyS members have demonstrated exceptional performance across several key areas of the NICE Framework, underscoring the importance of WiCyS’s training and development programs.
  • Strategic Insights: Analysis revealed remarkable strengths and areas for development, providing WiCyS with actionable data to tailor future programs and initiatives and ensure its members remain at the forefront of cybersecurity excellence.
  • Actionable Insights for Cybersecurity Workforce Development: The study revealed critical areas for targeted development to enhance cybersecurity workforce readiness. This insight empowers WiCyS to tailor its programs specifically to meet the diverse needs of its members, ensuring all participants are prepared to take on significant roles and lead in the cybersecurity industry.
  • Leadership Readiness Among WiCyS Members: The study highlights that WiCyS members are highly skilled and uniquely prepared for leadership roles within the cybersecurity industry.
  • Proven Expertise in Critical Cybersecurity Domains: The data show the outstanding capabilities of WiCyS members within the cybersecurity landscape. Excelling in nearly every N2K Functional Area mapped to the NICE Framework, WiCyS members have shown they not only meet but exceed the standards in key domains.


You can access the final report of the 2024 Cyber Talent Study here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

(music) You're listening to the Cyberwire Network, powered by N2K. (music) (music) Identity architects and engineers simplify your identity management with Strata. Securely integrate non-standard apps with any IDP, apply modern MFA, and ensure seamless failover during outages. Strata helps you avoid app refactoring and reduces legacy tech debt, making your identity systems more robust and efficient. Strata does it better and at a better price. Experience stress-free identity management and join industry leaders in transforming their identity architecture with Strata. Visit strata.io/cyberwire, share your identity challenge, and get a free set of AirPods Pro. Revolutionize your identity infrastructure now. Visit strata.io/cyberwire and our thanks to Strata for being a longtime friend and supporter of this podcast. (music) This episode is brought to you by Shopify. Forget the frustration of picking commerce platforms when you switch your business to Shopify. The global commerce platform that supercharges your selling, wherever you sell. With Shopify, you'll harness the same intuitive features, trusted apps, and powerful analytics used by the world's leading brands. Sign up today for your $1 per month trial period at Shopify.com/tech. I'll lowercase. That's Shopify.com/tech. (music) Maria Vermasas, N2K host of T-Minus Space Daily recently spoke with Wieces Executive Director Lynn Dome in a panel of N2K experts, including Simone Petrella, Dr. Heather Munthy, and Jeff Welgan, all about the 2024 Cyber Talent Study. (music) Hi, everybody, and welcome. My name is Maria Vermasas, and I'm thrilled to be here talking with a fantastic group of people today about the Cyber Talent Study. All right, before we get into that, before we get into what that is, I think it'd be great if we start first with introductions from each of our guests today. Lynn, you're at the top of my screen, so why don't you go first? I'm sorry, thank you, Maria. So, I'm Lynn Dome. I'm Women in Cybersecurity Executive Director. We often go by your acronym, W-I-C-Y-S, and we pronounce it Wiesis, like Wiesisters, because we're a global cyber sisterhood. So, our mission is to recruit, retain, and advance women in cybersecurity. We have over 9,800 global members and representation in 99 countries. In addition to that, we have 270 student chapters and 70 professional affiliates all around the world. So, each and every day, we're running many, many different programming efforts with the reach of over hundreds of thousands of individuals really driving the change that's needed within the Cybersecurity workforce. But it's important to note that we exist because we're at a critical workforce shortage. And our mission to recruit, retain, and advance women is bringing accessibility and opportunities for women to step in this space. So, that's what lead us to partnering with N2K and this very fabulous cyber talent study that we're going to be talking about today. Fantastic introduction, Lynn. Thank you. Keep in mind all those awesome things you said as we go through the next intro. Simone, why don't we go to you next? Man, Lynn, you have that so down pat that I don't think I could ever compete with that introduction. But I'm Simone Petrela, President of N2K Networks. And our mission is to provide strategic workforce intelligence for the cyber security profession. And that includes everything from the talent insights that we need using data to inform strategic decisions around the workforce and experience shortages that we experience in cyber security, how we think about learning plans and development. And it comes to training and developing that workforce. And most importantly, because of our name, it is not only N2K, but it stands for News to Knowledge. And so, providing the professional development through the daily industry news and current events that we get through organizations and podcasts like the N2K CyberWire. Awesome. And Jeff, over to you next. Yeah, great. And it's hard to follow these two. But my name is Jeff Wellgen. I'm the Chief Learning Officer at N2K. And really my role at N2K is to oversee our cyber talent insights team and capability as well as our training development team. So, you know, we get an understanding of workforce needs and are able to backfill those skill shortages and knowledge gaps with great training or at least training recommendations. I'm honored to be part of the study in the sense of just driving the mechanisms and capability to kind of analyze the data and get that data and provide some really great results. Fantastic. And absolutely last but not least Heather. Hi, Maria. My name is Dr. Heather Monty. I am a cyber workforce consultant with N2K. I've got over 20 years of experience in STEM workforce development, a former university dean and professor. And now I work with N2K and our customers, our clients to build out training plans for their cyber security team so that we can identify some of the skills gaps that might be on the teams. And how do we put together training plans and pathways, career pathways that are effective and that actually work? And so that's my role here. Awesome. Thank you. All four of you for those great intros. And as I sort of tease at the top of the show today, we're talking about the cyber talent study, which is what brought N2K and we cis together. And I'm super curious like how that conversation went on, how this came about. I kind of want the origin story for this study. Simone, Lynn, which one of you wants to take that? You want to answer like, how did this get started? Go ahead, Simone. Yeah, I'm happy to kick it off. So one of the, I think, things that's very important to us here at N2K is around, you know, we take our whole livelihood. Our meat and potatoes is dealing with how to provide data that tackles and can make an impact on the cyber security workforce shortage, challenge shortage, experience shortage, however you want to categorize it. And that includes, and one of the things that we have always felt very passionately about is that you can't solve that problem if you also don't incorporate diversity into that conversation. Because we're not going to be able to make a demonstrative impact if we only focus on what is sometimes an under representation of women and minorities in the field. And so having connected with Lynn, first at an event in Minneapolis, we really shared a common vision around how do we encourage and propel more women to get into the field. But I'd say even more importantly, how do we think about those drop-off points when there's that glass ceiling or how do you actually get women to stay in cyber security and STEM fields? And so we started to sort of talk about how we could work together to help WESIS as an organization. A. Tell its great story about the mission that it's doing and what it's contributing to getting more women into the field, but also provide some perspective on how do we maintain and provide really aligned programming that kind of solves some of these problems that we see throughout the entire journey of women in the cyber security field. Yeah, Lynn, anything to add to that? Because I know WESIS has been doing fantastic work around getting women more involved in cyber security in general and also up leveling them. So I'm so curious, your view on the study and the need. Yeah, I mean, the need really came from Simone and I syncing up at that event about a year ago, which was just a great conversation as it started. And then we started looking at how can we partner and solve and tackle this challenge together. So WESIS last year started investing some time and attention and looking at retention for women in cyber security. And what is the state of inclusion? And through that study, we discovered some really important findings. And one of those was that there's a women experience sources of exclusion at a higher level than most individuals in the cyber security workforce, which would be men, and that source of exclusion is coming from career growth and advancement. And so we started looking at, well, how are women performing in cyber security as cyber security practitioners and in their careers. And that's what led us to exploring further of what capacity is the state of women's cyber security and what is their level of performance. And we were able to utilize the N2K's nice diagnostic assessment to do that. And that's what led us to, you know, moving forward with this study and to be able to report on these findings is not only do we want women to get into cyber security, but we want them to stay. And we want them to advance into careers because of it. And we felt like this study was an interesting way for us to look at what is their performance. What are their areas of strength and how could they leverage that to advance in their careers. And so that led us to this important study. Awesome. I do want to get into the results of the study and that's my champion at the bit for that part. You did mention the nice framework that the nice diagnostic, I should say, Jeff, this feels like a good moment for you to come in and just tell us a little bit about what that is. Yeah, no, I appreciate the opportunity. So we have fortunately a few years ago created a diagnostic assessment or tool that's aligned to the nice framework. So essentially, we're asking a number of questions in that assessment that align to key roles, knowledge areas, task areas of the nice framework. And by doing that, we're then able to analyze the results of those questions in relation to those knowledge areas. This is even more supported by collecting a few tidbits of extra information from some participants. So like understanding experience levels, understanding what we call a functional grouping, which is an additional taxonomy that N2K has added to our analysis of the framework. Meaning like, you know, generally speaking, what kind of functional group do you work in in cyber security? Are you in analysis, offensive security operations, GRC, etc. So we have that layer on top of it as well. So by getting results of performance data on those questions combined with experience levels and combined with like a functional perspective allows us to really parse out the data in meaningful ways and kind of say, hey, this group of people perform this way or more junior people are outperforming in one area or underperforming in another area. So that is really the tool that allows us to deploy really great insights into this workforce. I'll also kind of make a plug. Nice. Just did an update to the framework this past March. So we're actively working to update our diagnostic to reflect those newest changes. So there's some pretty significant changes in that and we're excited to be releasing that soon. Maria, one thing I just want to sort of like kind of comment on is one of the biggest challenges that we have in the profession and we talk about cyber workforce as an industry is around data collection. And so there's lots of opportunities to sort of understand and collect data on, you know, what positions are out there or how many openings are there for jobs. But where you start to, I think one of the things that was most exciting to us is that with working with we says, you can look at that external data around what are the roles people are filling in what are they in. But then you're now looking at you're collecting another data input around the performance of the individuals themselves, and you can compare them against that role. And so that's really powerful because you're turning pure data collection into insights that like the individual members can use to understand where they want to go. But then we as organizations can kind of get a better sense of what is the impact of these for, you know, of where women go. How do we think about how to keep them in the field. What does that pathway look like. So that's just, you know, data. Everyone likes to talk about data and machine learning and AI, but that's where it really becomes compelling. Yeah, and an organizational change can happen after that point. Yeah, go ahead Lynn. Yep. Yeah, and another great and thank you for this Simone is because another great area for us as a nonprofit sitting in this space is it helps us. Identify areas of growth opportunity and some gaps and how could we as a nonprofit build programs to help bridge that gap and help overcome some of those challenges that are identified here. So not only is an opportunity for our recess members to participate in the actual assessment and study, but also as a way for us as a nonprofit to be able to develop very intentional programming for making, you know, for helping overcome some of the challenges. Fantastic. Well, we've teased a little bit about the study. So let's get into the data. Heather, this feels like a good time to bring your voice in. Do you want to walk us through either maybe we go by functional groupings or I don't know if there's a way that you prefer to sort of look through this data set because there's quite a lot there. But I'm thinking maybe it makes sense to go through the groupings first. Would you like to walk us through it? Yeah, let's, let's do a review of the, the N2K functional areas. So what N2K has done what Jeff has started talking about a little bit is what we've done is we've taken the nice specialty areas and created these what we call functional areas are functional groups to really just, you know, group this information at a higher level. One thing I really, I really like about how this study was done is that some things that we do know about women in STEM fields and women in male dominated fields specifically that oftentimes when you are looking at yourself and your own skills. Women in particular will breathe themselves lower on a self assessment, then men will, men will actually rate themselves higher than what they actually are. So you don't get a true, you know, sort of benchmark of where your team is so if you're managing a team you're leading a team of 30 cybersecurity professionals and you all ask them to rate themselves on these particular skills. Generally speaking, the men are going to rate themselves higher, the women are going to rate themselves lower, even that that's not a true understanding of where they actually are. And what I really like about how this study was done is this is hard data showing. This is where we assist members really excel compared to the rest of the people that have taken this particular assessment. And we've what we found is there are four different functional areas that we just members excelled above and beyond the other people that have taken this assessment and the four areas are these communications and network security, cyber workforce training awareness, cyber IT leadership and management, and then IT policy and GRC or governance risk and compliance. So generally speaking, the, the, the, the weakest members that took this assessment, those are the four areas that they really excel. What we did find when you look at it across all of the different nice specialty areas and like Jeff was saying earlier, there has been some changes to the nice framework. This is using the current version of the nice framework using those different specialty areas. And we assist members excelled in nearly all of the different specialty areas on on the nice framework so I really think it shows that some of the things that we just is doing building this community of people who are supporting women in cyber security and helping them develop skills, the things that that Lisa's is doing is working, but I also think it shows that there is, you know, there were a lot of people that took the majority of the people that took this assessment identified as being in sort of a junior role. But we see things like leadership and policy and strategy and, you know, cyber security awareness and some of these more higher level, you know, strategic initiatives that are happening across the board at a, at a company. We've got junior members that are excelling in those particular areas. So I really think the show is that companies have a lot of potential talent in their, in their, in their junior teams, and figuring out ways to expand upon that potential and help them grow within that company, you know, through a career specific training, you know, leadership development, that kind of thing. Yes, Jeff, I see you wanted to add something. Yeah, no, I just wanted to maybe elaborate and just added one point of minor clarification to that, the points that Heather made actually the WESIS members outperformed all others who have taken our diagnostic in every nice category, you know, part of the previous version. So there's seven categories and the nice framework, analyze, collect and operate, operate, maintain, investigate, oversee, govern, protect and defend and be securely provisioned. They've since had some new names assigned to them. The point, though, that I'm really highlighting is that WESIS members did better in all those areas than all other participants when we kind of compare those two groups, which is, which is amazing. And I think it really kind of made us start thinking about, well, what's WESIS doing? You know, like, is this, is this something that can be attributed back to WESIS specifically and how they support their members, or, or is it something else? And, you know, I think we're still, you know, getting our heads around that, but I think WESIS has done a lot of really great programming and I think there's something there to it. So I could almost turn it over to Lind to elaborate on that point, too, where, where they've supported members. I would say, Lind, what was your reaction when you saw that? You must have been like, heck yeah. You know, just hearing it here today, I'm like, it's celebrating again once again. It's like something, you know, worthy of being celebrating for all our WESIS members. And, and so WESIS being the community to not only advance in your careers, but also pay for additional opportunities. This is what we do. I mean, we're here to put together initiatives to be able to grow and advance and develop our members into their cybersecurity careers and provide those advanced opportunities for where they go ahead. But a lot of our initiatives are focused around, you know, more skill development in providing different training, different programs. What's unique about WESIS is the wraparound services is not only are we interested in putting a programming effort together, but it's also about having technical mentors in that to have asked me anything to have open office hours to develop a cohort, because we know that their community, the strength really lies in the community and the effective communication that they have amongst themselves. And so all of our programs are really focused around growing and developing that cohort experience, and everyone to lean in on one another through their career advancement, and also have that network now. It's about forming and building that network and instead of women working in silos, not only in their jobs, but not having a community to have around them. We're helping, you know, fulfill that void that currently exists for a lot of folks in the industry. We'll be right back. Enterprises today are using hundreds of SaaS apps. Are you reaping their productivity and innovation benefits, or are you lost in the sprawl? Enter SAVI security. They help you surface every SaaS app, identity, and risk, so you can shine a light on shadow IT and risky identities. SAVI monitors your entire SaaS attack surface to help you efficiently eliminate toxic risk combinations and prevent attacks. So go on. Get SAVI about SaaS and harness the productivity benefits. Fuel innovation while closing security gaps. Visit SAVI.Security to learn more. The IT world used to be simpler. You only had to secure and manage environments that you controlled. Then came new technologies and new ways to work. Now employees, apps, and networks are everywhere. This means poor visibility, security gaps, and added risk. That's why CloudFlare created the first-ever connectivity cloud. Visit cloudflare.com to protect your business everywhere you do business. [MUSIC] Members of WESIS and people who took this specific study, one could argue that they're more career-motivated. They, in a way, sort of self-selected, one could say. But at the same time, I imagine we could also extrapolate the findings from this study and think about how it can apply to women across the cyber workforce in general. I'm just curious. Any thoughts on that? Maybe Heather, I haven't heard as much from you. Any thoughts on that there? Yeah, I think this goes to show what I was saying earlier. When we're looking at recruiting, attracting, and retaining cybersecurity talent, when you're trying to build a diverse team, you've got to look at some of the things that make qualified applicants self-select out. Out of that hiring process. While we see in this diagnostic, we see in the data that women are excelling in a lot of different areas within cybersecurity. But when we start putting out job descriptions where we're looking at level one or level two analyst type of role and we're listing out 15, 20 different pieces of software they want to have somebody to have experience with. Maybe the mindset is, let's just put this out there and see what we get, let's see who applies. The issue is that women look at that in general, women look at that and go, I don't need 100% of these requirements, so I'm not even going to bother applying. And so they self-select out. So by really understanding sort of where the workforce is, where we see the strong points of the women in cybersecurity members, the weakest members. And then really having that understanding of how we do our hiring process when we're looking at, okay, we need to get more people in the door, we need to get more people more qualified people applying for these jobs. How do we do that? So what can we change about our recruiting process? What can we change about our job descriptions so that they're more attractive to the right people versus we're just going to shoot for a unicorn and see what we see what we get. Yeah, yeah, it's a familiar issue, not just in cyber, but in a lot of tech world jobs as well, that whole unicorn hunting phenomenon. So a question to the group, I'm always curious when we do studies like this about things that might have surprised you from the results. Anyone find anything surprising from these results that you were really just, wow, that's interesting. One, I think the outperformance was surprising. I think this is not an easy diagnostic. It's very difficult. So to see across all nice categories was surprising. You'd expect maybe some here and some there, but 100% that was surprising. I think the other thing that leaves me questioning and hungry for more information is around representation. Because when we looked at the representation of recess members who took this and we're asking them, well, what field or what functional area do you associate with, we see really low representation in operational technology and engineering and in data engineering and analytics. Now, you could make an argument that maybe there's just those are smaller functional fields in cybersecurity. So maybe the smaller representation there, it correlates to just the broader cybersecurity field. I don't know, but I don't think that's the case. I mean, we only had three members in our 399 participants who identified in operational technology and engineering. And we're talking about ICS SCADA systems and just based on experience, working with people in those roles, they're male dominated subsets of the field. So I'm really interested in figuring out that a little bit more and just kind of learning a little bit more about how is that true? Do we have a real big deficit in those areas? And if so, what can we do to help promote more diversity in these niche parts of the cybersecurity industry? That's a great point. That makes me think of a whole bunch of possible cultural reasons that could contribute to that, but I won't conjecture since this is not my study. Well, I think it's a fair point, Marie. I mean, you're the host of T-minus and you're a space nerd, right? Like, you probably see this in that field too, in aeronautics and space, probably less women representation there too, I'm just guessing. It's even less than cybersecurity in my anecdotal experience coming from cybersecurity going into space. I was like, wow, it's even worse in space. But the Queen B phenomenon is a phrase that sometimes comes up and I remember it came up a lot in my cyber years. I don't know how much we want to get into anything like that, but it's certainly sometimes some women self-select out because they go, I don't need things for women. I'm doing just fine on my own. That kind of stuff is for women who need help and I don't need help. And that's a whole other cultural discussion. Again, that is a very silent thing. I'll just leave it alone. I'll just leave that there. Yeah. But Simone, I see that you wanted to add something as well. Yeah. Well, one thing that surprised me and yet didn't surprise me at the same time was we obviously saw a kind of a really high volume of respondents that identified as more junior in their roles. And that was across the board, especially in technical roles. And I will caveat this to say it's hard to tell from the data whether because we had a separate management leadership category, whether everyone kind of flowed over there. But it did strike me to see how much the levels of technical identification in roles that are technical in nature, like at the junior level, it started to drop off. And we saw less and less representation at the mid and senior levels. And I know something that Lynn and I have talked about and we see this is incredibly passionate about is the idea of when are women selecting out in the middle of their journey in cyber security as a profession. And why are they choosing to leave? And there's all kinds of cultural phenomenons and things like that. But the reason I found that so interesting is because it's not only around the membership and the women who are part of we, but it's about all those corporate partners and like the industry that and the ecosystem that surrounds it to say, what do we do? What do we now need to do or what do we need to promote so that organizations are prepared to support the development of individuals and women in particular and anyone in a minority. Once they're on that career journey, and that's not just support in technical training or career pathing, all those are important to, but then what are the cultural implications, how do you prevent them from wanting to step away potentially from the workforce. Yeah, sort of like once they're we're trying to get people through the door, but once they're in what happens next and people kind of go. Hmm, I don't know, not much left for me there. Yeah, Lynn, please go ahead you're having these conversations every day so I'm so curious to hear your thoughts. Yeah, and that's why it's really important to have more data and to be able to dig in deeper into this information is for our employer partners to really put intentional actions in place to to avoid these pitfalls that women are experienced in their career and to piggyback on our state of inclusion assessment it is showing that women are experiencing that glass ceiling around six to 10 years within their career. So what are we doing to overcome this challenges and now we have data to help support what we've always heard. You know what we've always heard all along and now we finally have some data and some real good valuable insights to share with others so that we could start, you know, making a difference. So follow up question for you and then recommendations to organizations and we've touched on this a little bit, but truly I mean this is not some on an individual to take on and be like I'm going to change everything we need organizations to really step up and make some big changes so what what do organizations need to know. Organizations need to listen to this podcast and to understand that this is a launching pad like this is an opportunity for them to take the information from the cyber talent study and utilize it as a tool. And to be able to understand that these are the main areas and pinpoint those challenges and to start really having these conversations about what are we going to look at our internal talent to ensure that they're not stuck in these common pitfalls that are being identified. Also, if you balance the diverse talent that are on your teams at around five to six years of an individual being in their career to ensure that they have a very clear career growth and advancement mapped out in front of them and as a direct manager to those individuals that they're being very, you know, they're paying attention. They're paying attention to the data that's being reported. And if the value of their team is really crucial to them that they would really pay attention to that career growth. So, I'm going to add to them as well. Any other advice for organizations in terms of takeaways here I just want to Simone go ahead. Totally. I mean totally agree with when everyone should listen to this podcast. So let's get it out there. But, you know, to sort of add on to that, you know, organizations, you know, I'm going to throw the gauntlet at organizations to say those that are investing in talent development. They are sponsoring organizations and events that are committed to this. And then be able to also invest the time and the attention internally to be able to absorb it and fry that career path. And I think it's really easy for organizations to say, we're going to put our name on this and we're going to do it, but then they're not committing to actually executing on the strategic vision to make that a reality and actually move the needle when it comes to changing the dynamic of women in the cyber security workforce. So, you know, my recommendation to them is forward to the partnerships, create the relationships, but then do the work internally to understand what is your cyber security talent strategy. It is the largest operating expense that you have in your budget. I don't care how much money you have for tech. The biggest operating expense you have is in people. So you are already wasting money and you can spend it more efficiently for the little bit that you have if you actually come up with a plan for them. Men, women, minorities, anything. Yeah. Yeah. Yeah. No, that gauntlet has been thrown everybody. It's down. Let's do it. Yeah. I mean, this is not a, and this is not to disparage a study at all. This topic is not new. And I'm so glad to see that there's data around it. And it's been a very hard problem to get around because of all the many different facets to, you know, what a career growth is, you know, social dynamics, everything. I mean, it's been discussed ad nauseam. So it's so wonderful to see the actual data that people can look into it. They can dive into it and really sink their teeth in and try and figure out how to make it relevant. And their organization and also for the people and their teams. It's really fantastic stuff. So, Jeff and Heather, I know I haven't heard from you in a little bit. I wanted also get any thoughts from you about what you would like to see maybe organizations do with this information. Heather, do you want to go first? Yeah, I think that this is, this really does show that there are a lot of opportunities for we cis members to step into leadership positions. And so making sure that, you know, as an organizational leader that you've got the things in place to be able to help those people that, you know, have really figured out that they're good at these kinds of things. How can they progress in your organization versus silently going and looking for other jobs elsewhere, and you lose that talent, you lose that, that organizational knowledge and maybe even that industry knowledge. So figuring out ways to, you know, really identify who these people are that are in your company that you know that they want to progress in their career and helping them do that that you've got something, you know, some sort of career pathway or some sort of mechanism that they can learn about the different opportunities in the company and make it easy for them to make that shift, whether it's a lateral shift, whether it's a promotion, whatever it may be. Don't put in things, processes and policies and things like this that make it difficult for them to do that and then you end up losing that, that knowledge. Yeah, I was just going to say I think I would like to maybe just highlight that this is just the start, you know, and it should be a start for any organization wherever they're at in this journey that and I think it's important for organizations to realize it's important to start. But it's even more important to continue on with the journey. Like, I'm excited about looking at this in the future again with with we says, and, you know, let's, let's, let's go through another diagnostic in a year or two, whenever the right time is and keep track of it. And let's use this data as a starting point and a long journey to make adjustments where adjustments are needed, you know, sometimes that is in training and development plan. And what can we composition to members or employees to help them in their career goals as it relates back to the organization. Sometimes it's it's refining job descriptions to Heather's point earlier, how can you use the data to better reflect job descriptions and include, you know, make sure you're, you're being inclusive in those descriptions so you don't exclude potential candidates. Sometimes it's part of a retention strategy. So the data I think that I want to highlight here is this is giving us insight into a static moment across some leases members who participated. But what it will do for us long term is start evaluating and looking at these other components that Lynn was highlighting earlier like how does it tie into the diversity component. How does it tie into training programs? How does it tie into how we think about recruitment. So I'm excited about, you know, taking that journey and kind of, you know, seeing where the data can take us next time as we look at it long with some longevity. Fantastic. I know we're starting to wrap up and we're coming close to the end of our time. I just want to give everyone a chance to do sort of a parting thought that thoughts may be what's next in the more short term. I know we've talked a bit about, you know, we need to revisit the study, maybe in a year or two, but in the shorter term, what is next? Maybe Lynn will start with you. Well, first of all, we're going to take the time when the study gets released to celebrate recess members. I mean, let's just say here outperforming all other participants in all the categories is quite an accomplishment. And like Heather showcased, you know, for junior folks to be performing at like these leadership roles like this is a time to really be empowered by that data. And for our recess members to just, you know, pat themselves on the back and say, what are we going to do with this ourselves. The second thing is beyond the lookout of what's to come, not only more assessments available in the future to identify more additional data, but also training programs that are going to help support some of the findings of the study itself. So there's a lot to unpack here. And there's a lot to be super enthusiastic and excited about additional programming efforts moving forward. So we're really excited. Fantastic. I'll go. Heather, if you want to go next, then Jeff, then Simone, I'll have you wrap up. Yeah, my advice is really more for the individual person who is trying to either get into this field or maybe progress in your career is to apply for the job. You see the job postings on LinkedIn, indeed, wherever they may be. And if even if it says there's 908,000 applicants already apply for the job. I would say, you know, for my parting thought is that, you know, we have a little bit self promoting here. We have this capability to help organizations get the same kind of insights into their own workforce. And I think the intelligence we can provide to those organizations and the key leaders who are making those decisions on their talent and talent strategy. There's a solution for you, and you can be empowered to do something with that data. So I would leave with leave any listeners with that thought that, you know, feel free to reach out to us. We are passionate about this mission set, just, I would say workforce intelligence around cyber and how do we can support teams. So we're, we're happy to support you and your, your talent upon the strategy to. Last word to you, Simone. Well, I think first and foremost, my, my kind of what's next immediately is, you know, Lynn and I have talked about, we are very committed to taking this message out on the road. We're going to be presenting the findings of our study at the upcoming Nice Conference. That's the National Initiative for Cyber Security Education. So they have their annual conference will be presenting there. And we'd like to keep using any form we can, and any stage we can to sort of proselytize the importance of the work we're doing, the type of insights you can get from collecting this type of data. Understanding the WESIS message and understanding how you can implement it in your own organization. And I think that that has to be put on a bigger and bigger stage over time. And then, you know, as far as what's next for, for NTK, I'm really excited to see where we start to make recommendations on programming with WESIS and where, like, what that looks like for them and how do we actually get the feedback on what programs they implemented and how do we track, you know, what is working and kind of where folks are on their journeys in this field. Fantastic. Lynn, Heather, Jeff, Simone, thank you. All four of you for joining me today and for walking me through this fantastic cyber talent study. I'm looking forward to seeing everything that comes out of the study and all the follow-up steps. This has been a great chat, so thank you all for joining me today. That's Maria Vermasas, host of NTK's T-minus Space Daily, along with WESIS Executive Director Lynn Dome, and NTK's Simone Petrela, Dr. Heather Munthy, and Jeff Wellgen. You can find more information about the 2024 cyber talent study in the show notes. [MUSIC] (beeping) [BLANK_AUDIO]