Back to Thoughts
Professional Essay · October 15, 2025

Beyond Good Intentions: A Male Leader's Playbook for Inclusive Cybersecurity Teams

Actionable strategies for male leaders and colleagues, enabling the creation of psychologically safe environments where all team members — especially women — can contribute their full capabilities to your security mission.

Ken Quigley — Head of IT Cybersecurity, BEWS & Affiliate Professor of Cybersecurity, Regis University

Deborah Barnes — Principal Information Security Engineer, Zebra Technologies

Combined cybersecurity leadership experience: 40+ years.

During my tenure at a Fortune 100 internet service provider, I encountered a humbling lesson about the difference between good intentions and effective allyship. I worked closely with an exceptional Principal Engineer — a colleague I'd collaborated with across two different organizations over many years. She had earned her way through individual contributor roles based on her strong technical skills and ability to find creative solutions to complex problems. She was, by any objective measure, one of the strongest engineers I'd ever worked with.

When we hit a roadblock with other departments, we convened a project review meeting with Principal Engineers from multiple groups — all of whom, besides my colleague, were male. After addressing the technical roadblock, I turned to the enormous task of host identification and made what I thought was a supportive gesture: I asked the other Principal Engineers to provide as much assistance as possible to help her with this critical work.

My colleague did me the professional courtesy of not quitting on the spot.

Instead, she later pulled me aside and, with remarkable grace, helped me understand my error. In trying to be helpful, I had inadvertently signaled to the entire room that she needed assistance not because of the project's scope, but because she might not be capable of handling it independently. I had undermined one of our most capable engineers while thinking I was supporting her.

What I didn't realize then, but understand clearly now, is that I had also created a security vulnerability. By undermining my Principal Engineer's authority in that meeting, I had effectively removed one of our most experienced threat assessment perspectives from the room. The other engineers were less likely to bring their best thinking to her questions, less likely to escalate concerns to her, and less likely to see her as a peer whose judgment they should trust. This wasn't about hurt feelings — it was about degraded security posture.

The Critical Paradox

The cybersecurity industry faces a critical paradox: we have a massive talent shortage while simultaneously underutilizing a significant portion of our available talent pool.

4 million unfilled cybersecurity positions globally — and counting.

20–25% of the cybersecurity workforce is women — a figure that has remained stubbornly stagnant despite years of diversity initiatives and good intentions.

87% improvement in decision-making effectiveness in diverse teams (McKinsey). In cybersecurity, that's not a social benefit — it's a mission-critical capability.

We talk extensively about the cybersecurity talent shortage — the millions of unfilled positions, the skills gap, the pipeline problem. Yet women represent only 20–25% of the cybersecurity workforce, a figure that has remained stubbornly stagnant despite years of diversity initiatives and good intentions.

This paradox exists because we've framed inclusion as a social good — something we do because it's right — rather than as a security imperative — something we do because it makes our teams more effective at their core mission. Both are true, but the second framing is what should be driving urgency in our industry.

Exclusion isn't just unfair. It's a critical security vulnerability that creates exploitable blind spots in our defensive posture.

The Security Case for Inclusion

Let me be direct: I'm not asking you to create inclusive teams because it's the ethical thing to do, although it is. I'm asking you to create inclusive teams because your current teams have security vulnerabilities that diversity can address.

Homogeneous Teams Create Predictable Defensive Patterns

When our teams think alike, we defend alike. We make similar assumptions about attacker behavior, similar decisions about risk prioritization, similar choices about what to monitor and what to ignore. Sophisticated adversaries don't attack our strongest defenses — they probe for the gaps created by our blind spots.

Diverse teams bring different mental models of how systems can be attacked, different intuitions about what looks suspicious, different experiences with how social engineering works across different populations. These differences aren't just interesting — they're operationally valuable.

The Facial Recognition Failure

Early facial recognition security systems failed catastrophically when deployed in diverse environments because development teams lacked inclusive perspectives. Companies including IBM, Microsoft, and Amazon had to rebuild core security features after discovering their systems couldn't reliably identify people who didn't match their developers' demographics.

This wasn't a social issue — it was a security failure with measurable business impact: systems that couldn't perform their core security function for significant portions of the population they were meant to protect. The cost of remediation far exceeded what inclusive development practices would have cost.

The WiCyS Reality Check

In a recent WiCyS member survey: 50% of respondents experienced intentional bias and 30% experienced unconscious bias in their cybersecurity workplaces.

These aren't just HR statistics. They represent the systematic removal of defensive capabilities from security operations.

When we consistently dismiss input from certain team members, we create blind spots. When we assume technical competence based on demographic patterns, we misallocate our strongest analytical resources. When we make team members feel unsafe raising concerns, we eliminate the early warning systems that catch threats before they become incidents.

The Unconscious Bias Reality Check

Before we can address bias, we need to understand what it actually is — because most of the male leaders I work with believe they don't have it, and that belief is itself a significant vulnerability.

How Bias Actually Works

The human brain processes 11 million bits of information per second but can only consciously handle about 40. To manage this overwhelming input, our minds create shortcuts — mental models that help us make rapid decisions based on pattern recognition. This cognitive efficiency is generally adaptive. In leadership contexts, it creates specific and measurable problems.

Unconscious bias isn't about character flaws or conscious prejudice. It's about how our brains, shaped by decades of societal messaging and cultural conditioning, automatically categorize and evaluate people. Intelligence, good intentions, and progressive values don't immunize us from these automatic responses — in fact, believing we're immune makes us more vulnerable to them.

The Attack Surface Metaphor

In penetration testing, we map attack surfaces — all the points where systems can be compromised. Unconscious bias creates human attack surfaces that sophisticated adversaries actively exploit.

When we consistently underestimate the capabilities of certain team members, we create patterns that attackers can leverage through social engineering. When we're more likely to question the judgment of women than men in equivalent situations, we create decision-making vulnerabilities. When we allow certain voices to dominate threat assessment discussions, we create analytical blind spots.

Your biases are not just personal failings — they're organizational vulnerabilities.

Common Patterns: Recognizing Your Own Blind Spots

The "Brilliant Jerk" Tolerance Problem

Most security teams have at least one — the technical genius whose interpersonal behavior would be career-ending in other contexts, but whose skills are considered too valuable to lose. Research consistently shows that "brilliant jerk" tolerance disproportionately affects women and minorities, who are held to stricter behavioral standards while exceptional technical talent in dominant group members excuses behavior that drives away diverse talent.

The security cost: you retain one difficult genius while losing the diverse perspectives of everyone who leaves because of them.

The Confidence-Competence Confusion

Security culture often rewards confident assertion over careful analysis. Team members who speak with certainty get more airtime than those who accurately represent the uncertainty inherent in threat assessment. Research shows that confidence displays are culturally conditioned — and that the correlation between confidence and competence is much weaker than we assume.

The security cost: you optimize for the appearance of certainty over actual analytical quality.

The Sponsorship Gap

Mentorship — giving advice and guidance — is relatively gender-neutral in cybersecurity. Sponsorship — actively advocating for someone's advancement, putting your reputation behind their capabilities — shows significant gender gaps. Male leaders sponsor people who remind them of themselves. Women in cybersecurity receive mentorship; they rarely receive sponsorship.

The talent cost: you develop diverse talent without advancing it, creating a pipeline that feeds your competitors when people leave for organizations that will actually promote them.

The Playbook: Moving Beyond Good Intentions

Everything above is context. This section is action.

Meeting Dynamics: Where Inclusion Happens or Doesn't

Amplification: When a team member makes a point that gets overlooked, explicitly restate it and credit them: "I want to come back to what [Name] said earlier about the lateral movement pattern — that's worth examining further." This works because it uses your positional authority to redirect attention without creating confrontation.

Structured turn-taking for threat assessments: In high-stakes security discussions, explicitly solicit perspectives from each team member before moving to consensus. "Before we decide, I want to hear from everyone — [Name], what's your read on the attack vector?" This isn't about being procedurally correct; it's about ensuring you get all available analytical perspectives before committing to a defensive posture.

Question attribution: Pay attention to whose questions get answered directly and whose get redirected. If you notice a pattern where certain team members' questions are consistently addressed to someone else in the room, intervene: "Actually, [Name] asked that — [Name], do you want to respond to what he suggested, or did you have a different direction in mind?"

Technical Authority: Establishing and Protecting It

Explicit capability signaling: Before meetings where your team member will be the technical lead, establish her authority explicitly with stakeholders: "This is [Name]. She's leading our threat detection initiative and is our primary expert on the attack vectors we're discussing today." This is not condescending — it's the same thing you'd do for any technical lead, and the research is clear that women receive this framing far less often than men.

The interruption intervention: When a team member is interrupted, don't let it pass. A simple "Let's let [Name] finish" in the moment, without drama, is sufficient. The goal is to make interruption costly enough that it stops happening, not to create confrontation.

Direct assignment vs. "help" framing: Assign work directly to the appropriate person rather than asking others to "help" them. "This is [Name]'s project — coordinate with her" signals authority. "Help [Name] with this" signals that she can't manage it herself, regardless of your intent.

Hiring and Promotion: Where Structural Change Happens

Structured interviews: Identical questions, identical evaluation criteria, recorded assessments made before discussing candidates. This doesn't eliminate bias, but it reduces the opportunity for post-hoc rationalization of biased decisions.

The "culture fit" audit: "Culture fit" is the most common cover for affinity bias in hiring. Require anyone who uses this term to specify exactly what cultural element they're identifying and why it's relevant to job performance. If they can't, the objection doesn't stand.

Sponsorship as explicit responsibility: Identify high-potential women on your team. Assign yourself explicit responsibility for their advancement. Bring their names into conversations where opportunities are being discussed. Put your reputation behind their capabilities in contexts where they're not present to advocate for themselves.

Psychological Safety: The Foundation Everything Else Requires

None of the tactical interventions above will work sustainably in an environment where team members don't feel safe raising concerns, reporting mistakes, or challenging assumptions. Psychological safety — the belief that one won't be punished for speaking up — is the foundation that makes diverse teams actually perform better rather than just looking diverse.

The Measurement Imperative

Security professionals understand that you cannot improve what you cannot measure. The same principle applies to inclusion.

Start measuring: Who speaks in your meetings, and for how long? Whose ideas get credited, and to whom? Who is nominated for high-visibility assignments? Who leaves your team, and what do exit interviews reveal? Who advances, and at what rate compared to peers with equivalent performance reviews?

These metrics will be uncomfortable. They will reveal patterns you don't want to see. That discomfort is the point — it's the same discomfort you feel when a vulnerability scan reveals attack surfaces you didn't know existed.

The question is whether you respond to that discomfort by closing the vulnerabilities or by questioning the scanner.

The Honest Conclusion

I am still learning. The story I opened with happened years into a career where I considered myself a supporter of women in technical fields. Good intentions are necessary — they motivate the effort required to actually change. But they are not sufficient, and treating them as sufficient is how well-meaning leaders continue to create environments that drive away the talent their organizations need.

The cybersecurity industry's talent shortage is real. The gender gap in our field is real. The connection between them — the talent we're not retaining because we haven't created environments where it can thrive — is real and measurable.

Think of inclusion as the best vulnerability scanner your team already has. Different backgrounds and experiences surface threats that homogeneous teams systematically miss.

Building genuinely inclusive teams isn't just the right thing to do — it's the strategically correct thing to do for your organization's security posture. The question is not whether you have good intentions. The question is whether your actions match those intentions — and whether your team's security posture reflects the full diversity of human threat intelligence available to you.

Selected References

Buolamwini, J., & Gebru, T. (2018). Gender shades: Intersectional accuracy disparities in commercial gender classification. Proceedings of Machine Learning Research, 81, 1–15.

Catalyst. (2020). Why diversity and inclusion matter: Quick take.

Eagly, A. H., & Carli, L. L. (2007). Through the labyrinth: The truth about how women become leaders. Harvard Business Review Press.

Edmondson, A. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2), 350–383.

Hewlett, S. A., Marshall, M., & Sherbin, L. (2013). How diversity can drive innovation. Harvard Business Review, 91(12), 30.

(ISC)². (2022). Cybersecurity workforce study.

McKinsey & Company. (2020). Diversity wins: How inclusion matters.

Moss-Racusin, C. A., Dovidio, J. F., Brescoll, V. L., Graham, M. J., & Handelsman, J. (2012). Science faculty's subtle gender biases favor male students. PNAS, 109(41), 16474–16479.

Rock, D., & Grant, H. (2016). Why diverse teams are smarter. Harvard Business Review.

Sandberg, S. (2013). Lean in: Women, work, and the will to lead. Knopf.

Women in CyberSecurity (WiCyS). (2023). State of women in cybersecurity report.

Beyond Good Intentions: A Male Leader's Playbook for Inclusive Cybersecurity Teams © 2025 by Ken Quigley and Deborah Barnes. All rights reserved.

↑ Back to top