
AI is gaining momentum, both in terms of the cyber-security threats it brings to UK businesses and individuals, as well as in the way we can defend against those threats. The Government’s latest Cyber Security Sectoral Analysis reflects just how quickly the work of cyber-teams is changing.
Automated tools may speed up parts of the job, but the output still needs to be understood and verified by people who know how systems should behave and who can instinctively recognise when something looks wrong. Developing that instinct can take years of practical experience. The wider the knowledge bank of those people, the more resilient we will be.
The need for that breadth makes the composition of the workforce increasingly important. Separate government research into cyber-security skills shows that women account for only 17% of the cyber-security workforce, with this lack of diversity becoming more pronounced among those with six or more years of experience.
Programmes such as CyberFirst have been essential in helping more girls and young women see cyber-security as a possible career, but the figures show that the sector’s focus cannot end when women enter the profession. Women also need support and opportunities to remain in technical roles as their careers develop.
Even when women enter cyber-security via a technical route, their careers often shift gradually towards management or coordination.
Some will actively choose that path. Others find that technical assignments have gone elsewhere before they have had enough opportunity to build confidence in their own ability. Male colleagues may be trusted with those opportunities sooner and given room to recover when something goes wrong, while women can feel they must be perfect before being offered the same chance.
Career paths often begin to diverge through decisions that seem unremarkable at the time. One colleague may be asked to solve the technical issue, while another keeps the project moving. As the same division repeats, the first becomes the obvious choice for specialist work and the second becomes known for organisation, even when both began with similar interests.
By mid-career, reversing that pattern becomes harder. New entrants may still have support from university or a graduate programme, and women who have spent many years in cyber-security have usually developed the confidence to stand by their judgement. Between those stages, people are expected to specialise with much less support around them, sometimes as the only woman in a technical team.
Professional communities can be particularly useful during that period because they offer somewhere to compare experiences without making every discussion about diversity. Conversations about secure systems or emerging threats can sit alongside questions about work culture, helping women remain connected to the technical interests that first brought them into cyber-security.
A wider network also provides examples of careers that may not be visible inside one organisation. Seeing how others have remained close to technical work can make that route feel more achievable.
Being exposed to technical assignments allows someone to develop skills that will last throughout their career. Solving complex problems gives people the opportunity to test their judgement, extend their knowledge and demonstrate what they can do. Once that experience is visible, further opportunities are more likely to follow.
Across conferences and industry events, women are still invited to speak about being ‘women in cyber’ when their real expertise lies in the work they do. Discussions of representation are absolutely worthwhile, but there should always be room for the subjects on which those women have built their careers.
A cyber-security conference with women speakers should be judged first on the quality of its cyber-security discussion. People attend to hear useful insight from practitioners, and the reason for putting someone on stage should be the knowledge they bring.
Professional recognition can reinforce the same idea. Through the National Cyber Awards, work that might otherwise remain inside one organisation can be brought to the attention of the wider industry.
For those earlier in their careers, seeing that work acknowledged makes a technical future easier to picture. It can also encourage employers to look again at people whose contribution may be substantial without being highly visible.
Many of the strongest practitioners are not the people most likely to nominate themselves. Often, it takes a colleague to recognise the value of their work and put it forward on their behalf.
As AI takes on more of our IT tasks, familiarity with any single tool will become dated quickly. Cyber-security professionals need to be able to pivot quickly, learn on the job and have enough understanding to question an AI solution when it does not fit the organisation in front of them. Code produced in seconds still needs to be reviewed by someone who understands what it is intended to do, and whether it is doing anything it shouldn’t. Automated analysis is incredibly powerful, but still needs a human to verify that nothing has been missed or hallucinated.
None of these skills appear overnight. They are built through repeated exposure to technical problems, which is why moving capable women away from hands-on work too early carries a real cost. By the point when their judgement should be deepening, the assignments needed to develop it may already have narrowed, and the sector may have reduced its ability to view problems from a variety of perspectives.
Bringing more people into cyber-security will remain important as AI changes the way attacks are carried out. The strength of the future workforce will depend on inspiring young women to join the sector, and ensuring that those who are already in cyber-security roles continue to receive work that challenges and develops them. Recognising what women have achieved - and continue to achieve - helps demonstrate that their contribution is valued, visible and essential to the future of the profession.
Dr Clare Johnson is an Advisory Board Member of the National Cyber Awards
Main image courtesy of iStockPhoto.com and Hiraman
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543