How to Fix the Diversity Gap in Cybersecurity

No ratings

Presented at BSidesRoc 2019 by

In this talk, we will discuss our brains and how we label and prejudge, hear experiences of underrepresented people in the space, what can be done to fill the gap, and how to increase and retain the number of qualified candidates in cybersecurity. What I’ve Learned About Students by Running a CTF Mike LisiN/AN/AThis is a talk geared toward students looking to get into the information security field. As an infosec professional and designer of a student-focused Capture the Flag competition held each semester for the past five years, I’ve had the opportunity to gather information about which areas in information security that students have shown strength in and where they’ve lacked some essential skills. I’ll discuss these areas and suggest resources that students can use to supplement their course curriculum to help position them better for internships and a job after graduation. More Tales From the Crypt…Analyst Jeff ManN/AN/A“More Tales from the Crypt…analyst” picks up with the speaker’s third “tour of duty” at NSA where he became one of the founding members of NSA’s first penetration testing or Red Team. While the thought of NSA hiring hackers or engaging in cyber warfare might be fairly common today, it was not always the case. Somebody had to be first, and the policies, procedures, methodologies, and rules of engagement had to be developed for not only conducting what we called Vulnerability and Threat Assessments, but for successfully navigating the politics, bureaucracy, and reticence of this often-misunderstood clandestine organization. The first NSA penetration testing team was assembled as a part of the newly formed center of excellence called the “Systems and Network Attack Center” (SNAC). To quote Charles Dickens, “It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness…” Come hear some war stories from the early days and see how this industry and the practice of penetration testing has evolved in the past 25 years.