homepage
Open menu
Go one level top
  • Train and Certify
    • Overview
    • Get Started in Cyber
    • Courses
    • GIAC Certifications
    • Training Roadmap
    • OnDemand
    • Live Training
    • Summits
    • Cyber Ranges
    • College Degrees & Certificates
    • Scholarship Academies
    • NICE Framework
    • Specials
  • Manage Your Team
    • Overview
    • Group Purchasing
    • Why Work with SANS
    • Build Your Team
    • Hire Cyber Talent
    • Team Development
    • Private Training
    • Security Awareness Training
    • Leadership Training
    • Industries
  • Resources
    • Overview
    • Internet Storm Center
    • White Papers
    • Webcasts
    • Tools
    • Newsletters
    • Blog
    • Podcasts
    • Posters & Cheat Sheets
    • Summit Presentations
    • Security Policy Project
  • Focus Areas
    • Cyber Defense
    • Cloud Security
    • Digital Forensics & Incident Response
    • Industrial Control Systems
    • Cyber Security Leadership
    • Offensive Operations
  • Get Involved
    • Overview
    • Join the Community
    • Work Study
    • Teach for SANS
    • CISO Network
    • Partnerships
    • Sponsorship Opportunities
  • About
    • About SANS
    • Our Founder
    • Instructors
    • Mission
    • Diversity
    • Awards
    • Contact
    • Frequently Asked Questions
    • Customer Reviews
    • Press
  • SANS Sites
    • GIAC Security Certifications
    • Internet Storm Center
    • SANS Technology Institute
    • Security Awareness Training
  • Search
  • Log In
  • Join
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. Raising the Tide: Driving Improvement in Security by Being a Good Human
370x370_david-bianco.jpg
David Bianco

Raising the Tide: Driving Improvement in Security by Being a Good Human

October 1, 2020

They say “a rising tide lifts all boats”. On the surface you might think the Infosec tide is already pretty high. There are more open jobs than experienced people to fill them, making it a candidate’s market, and each day brings us new and interesting problems to work on so we’re never bored. Not all is well in the Infosec harbor though.

Our industry’s life-blood communication platforms are often filled with gatekeeping and toxic negativity. Security can be a very unwelcoming or even hostile field for some of us, and this is a problem for all of us. Not only do we have a moral obligation to treat others as we ourselves would like to be treated, but attacking and excluding those with different backgrounds and experiences discourages innovation and makes it harder to fill important positions. Keeping our networks safe is hard enough without driving out the very people who want to help.

So how can we reshape our professional community to create a more diverse, inclusive space where we can all bring our best ideas, find help and inspiration when we need it, and encourage professional growth for ourselves and for those around us? Ignoring the problem and hoping it will go away is not an option. Solving this problem is going to, at a minimum, require us not only to be good humans but to be actively good humans. We need to take positive steps to counter the negative forces within our community. It may sound like a tall order, but there are three simple things we can all start doing today that will raise the tide for everyone in security.

Bring Positivity

First, we need to look for ways to bring positivity with us into our professional lives to combat all the negativity already out there. There are many ways to approach this, but one of the easiest is just to make a habit of saying “thank you”.

We all have people who have helped us on our security journey. They could be a professor, a co-worker, a mentor, an open-source tool developer, or just someone who’s work you appreciate. Whoever they are and whatever they did for you, we need to encourage those who spend their time lifting people up. An email, a Tweet, or a quick word in person is all it takes to let them know what they meant to you. A little gratitude and encouragement go a long way.

Lend Your Voice to the Conversation

Being an actively good human, of course, means that you have to be active. Put yourself out there and participate in the community! Just like that mentor, coworker, or professor before you, you need to pay it forward and contribute. 

That may sound like a tall order, but the good news is there’s no one “right” way to do it. Use your knowledge, your experience, and your talents to contribute in any way that feels right for you. It’s sometimes hard to think of ways to contribute, especially if you are new to it, so here are a couple of ideas to use as a starting point:

  • Engage with people in the community on Twitter. Share your opinion and observations, respectfully of course. Ask and answer questions to encourage productive and positive conversation. 
  • If you learn a new skill or come up with a cool new technique, share it. It can be as simple as a blog post explaining it or as exciting as sharing it onstage at a conference. No matter who you are or where you are in your security journey, you have skills and experiences that the community could benefit from.

By sharing what you’re good at with others, you’re not only helping everyone grow, you’re helping to drown out those negative voices. You’re also giving others the chance to be influenced by you. The experiences and innovations you share will fuel others’ innovations, which will fuel even more innovations. You may think that what you have to say is too small or too unoriginal to share, but it could be the start of something much larger down the line!

Turn Towards the Problems

Rising_Tide.png


In his 2016 commencement address at MIT, Matt Damon quoted some advice he was given by former president Bill Clinton: “turn toward the problems.” It’s not enough to just recognize that there are significant roadblocks for people trying to get their first job in our field. It’s not enough to silently condemn the pervasive hostility and discrimination that some face every day based on their gender, or the color of their skin, or whatever other arbitrary outgroup classification is imposed on them. It’s not enough to just point out that problems exist. We have to actually take steps to remove roadblocks, to counter toxicity, to boost visibility, and to provide equal opportunities for people affected the most by the darker aspects of our professional community. Again, how you do this is up to you and what you’re comfortable with, but here are a few ideas:

  • Mentor someone. Help a recent graduate get started in the industry, offer advice and guidance to a new coworker, or just share your expertise through your social and professional channels. 
  • Present! Assist a colleague with their conference presentation or do a joint presentation with them. 
  • Reach out. Lend a hand or a word of encouragement to those who have been targets of gatekeeping or toxic negativity, either in person or online.

Conclusion

By no means will following these simple steps solve all of our toxicity and exclusion problems, but they’re a good start. Think of them as a set of tools we can use to build the other tools we’ll need to actually solve the problems. First, we must generate more positivity in our professional discourse to counter the negativity that’s already out there. Next, we need to find ways to pay it forward and enable ourselves to be positive influences on others. Finally, once we’ve identified a problem, we need to take action to fix it or nothing will ever change. Ask yourself what you can do to make things better, even just a little better, and do it. 

It’s not enough that we individually believe that our industry needs to be more diverse and inclusive; if we want to change things for the better we must also demonstrate this belief whenever we can. Every little action adds up to normalize these beliefs in the community. If we all do what we can to make things better, together we’ll be able to raise the tide. 


This blog was inspired by David’s Keynote at the Threat Hunting and Incident Response Summit 2020. Listen to the presentation here:

Share:
TwitterLinkedInFacebook
Copy url Url was copied to clipboard
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kingdom of Saudi Arabia
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia (Slovak Republic)
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Swaziland
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Yugoslavia
Zambia
Zimbabwe

Tags:
  • Cybersecurity Insights

Related Content

Blog
sans_live_340x340_2.jpg
Cyber Defense, Cybersecurity Insights
March 10, 2022
The Return of SANS In-Person Training
Experience our new live training from wherever you are! Save $500 on select courses in North America when you register by 4/15.
No Headshot Available
Melanie Braddock
read more
Blog
Cybersecurity Insights
March 2, 2022
SANS + International Women's Day | Women Lifting Women
International Women’s Day is celebrated on March 8, and the 2022 theme is #BreaktheBias. We join in International Women’s Day (and every day) by recognizing and amplifying the achievements and contributions of women to cybersecurity.  You can join our live-streamed panel discussion at 11 am EST on...
370x370_jennifer-santiago.jpg
Jennifer E Santiago
read more
Blog
sans_live_340x340_2.jpg
Cyber Defense, Cybersecurity Insights
February 22, 2022
The New SANS Live Training Experience
Have you taken a SANS Live Training course lately? If it’s been a while, you’re in for a treat!
No Headshot Available
Melanie Braddock
read more
  • Register to Learn
  • Courses
  • Certifications
  • Degree Programs
  • Cyber Ranges
  • Job Tools
  • Security Policy Project
  • Posters & Cheat Sheets
  • White Papers
  • Focus Areas
  • Cyber Defense
  • Cloud Security
  • Cyber Security Leadership
  • Digital Forensics
  • Industrial Control Systems
  • Offensive Operations
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kingdom of Saudi Arabia
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia (Slovak Republic)
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Swaziland
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Yugoslavia
Zambia
Zimbabwe
  • © 2022 SANS™ Institute
  • Privacy Policy
  • Contact
  • Careers
  • Twitter
  • Facebook
  • Youtube
  • LinkedIn