Women in Cyber: Workplace Equality Will Take a Decade

Women in Cyber: Workplace Equality Will Take a Decade

Most women believe it will take a decade before they’re treated as equals in the cybersecurity sector, according to new research from the Chartered Institute of Information Security (CIISec).

Released ahead of International Women’s Day on Monday, the study revealed the challenges facing female cyber professionals today. According to the latest data, only around a quarter (24%) of the global workforce are women.

Not only do 57% believe it will take 10 years before true equality exists in the workplace, but a fifth (20%) told CIISec that it would never happen.

Among the challenges highlighted by the report are sexism that wasn’t disciplined, which has been observed or experienced by nearly half (47%) of respondents, and being passed over for promotion, cited by 42%.

Nearly half (46%) said they’d been paid noticeably less than male peers, and a similar number (48%) that they have been made to feel unwelcome in a “boys only club.” More than half (51%) have been the only women in their organization.

Most (56%) claimed better support and career progression would have a positive impact on things, while 47% said the same about getting more women into the industry.

CIISec CEO Amanda Finch argued that the industry risks stagnating unless employers make more effort to promote inclusion and diversity — not just because it’s the right thing to do but also to help alleviate crippling skills shortages.

It also makes good business sense, she told Infosecurity.

“Research by the Chartered Institute of Personnel and Development (CIPD), Gartner, Credit Suisse and others has found that stronger levels of diversity and inclusion can deliver a whole range of benefits — better financial performance, increased creativity and innovation, greater employee satisfaction, lower absenteeism and stronger talent retention,” she added.

“Attracting new talent into the industry is not only essential to ensure it has the skills it needs. It will give a whole range of individuals the opportunity to thrive in a new career, and in the long term protect the industry from stagnation.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese Hackers Stole an NSA Windows Exploit in 2014

Check Point has evidence that (probably government affiliated) Chinese hackers stole and cloned an NSA Windows hacking tool years before (probably government affiliated) Russian hackers stole and then published the same tool. Here’s the timeline:

The timeline basically seems to be, according to Check Point:

  • 2013: NSA’s Equation Group developed a set of exploits including one called EpMe that elevates one’s privileges on a vulnerable Windows system to system-administrator level, granting full control. This allows someone with a foothold on a machine to commandeer the whole box.
  • 2014-2015: China’s hacking team code-named APT31, aka Zirconium, developed Jian by, one way or another, cloning EpMe.
  • Early 2017: The Equation Group’s tools were teased and then leaked online by a team calling itself the Shadow Brokers. Around that time, Microsoft cancelled its February Patch Tuesday, identified the vulnerability exploited by EpMe (CVE-2017-0005), and fixed it in a bumper March update. Interestingly enough, Lockheed Martin was credited as alerting Microsoft to the flaw, suggesting it was perhaps used against an American target.
  • Mid 2017: Microsoft quietly fixed the vulnerability exploited by the leaked EpMo exploit.

Lots of news articles about this.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk