Unlocking the Power Of Neurodiversity In Cybersecurity

Embrace neurodiversity in cybersecurity for a resilient future.

August 14, 2023

Neurodiversity In Cybersecurity

Embrace neurodiversity in cybersecurity to close the skills gap and foster innovation. Discover the untapped potential of neurodivergent professionals in the industry, says Megan Roddie, senior security engineer at  IBM and co-author and instructor at SANS Institute.

For years, neurodiversity hasn’t had the representation it deserves across the cybersecurity community. While employers struggle to fill roles, thousands of neurodivergent professionals aren’t receiving ample opportunities to showcase their talents just because they may not communicate, socialize, or behave in “traditional” fashions.

We have experienced firsthand the ripple effects of an ongoing skills gap across cybersecurity that has led to widespread burnout and mounting stress across the sector. Gartner forecastsOpens a new window that by 2025, a lack of talent will be responsible for more than half of all significant cyberattacks. And according to a recent World Economic Forum surveyOpens a new window , 86% of business leaders believe a significant cyber incident is likely over the next two years, but 34% lack the necessary skills within their security teams to prevent it.      

Neurodivergent people are uniquely positioned to help alleviate the fundamental obstacles of the cybersecurity skills shortage. For example, they can maintain long durations of hyper-focused attention and understand how to engage colleagues with clear, concise communication that leads to effective problem-solving. In turn, organizations must ensure that neurodivergent people receive a seat at the table for hiring opportunities. Inclusivity is critical to tightening the skills gap and expanding our workforce.  

Embarking on the Journey to Neuro-inclusiveness 

In simple terms, neurodivergent (ND) people have brains that function in ways that are different than what is considered standard or “neurotypical” (NT). Examples of neurodivergence include but are not limited to autism, ADHD, dyslexia, dyscalculia, and synesthesia. These types of neurodivergence are not mutually exclusive, meaning an individual might be on the autism spectrum while also having ADHD.

Neurodiverse individuals face a wide range of challenges when acclimating to new workplace environments. However, for employers, it’s not about looking the other way regarding these obstacles. It’s about communicating properly and efficiently while understanding that equity is the priority. Enabling neurodivergent professionals with the right resources and guidance they need to succeed should be top of mind for managers. When we fail to account for their unique strengths, experiences, and challenges, we miss opportunities to build strong teams with unrivaled capabilities. 

These statistics underscore the importance of establishing a firm understanding of the realities faced by the neurodivergent community. Organizations should make a concerted effort to foster inclusion for prospective neurodivergent candidates. From educating employees on offensive stereotypes to adjusting recruitment strategies to attract more neurodivergent applicants, cybersecurity companies are uniquely positioned to lead a new era of diversity and inclusion. The ball is in their court. 

Advocacy for neurodiversity is crucial to developing the resilient workforce cybersecurity needs today. Considering life experiences shape how people approach work challenges, neurodivergent employees can offer unparalleled innovation, creativity, and problem-solving to their teams. The more a company can diversify its teams, the more productive and resilient they will be. In addition, employing neurodiverse talent also helps fuse different minds and perspectives within the organization breaking down siloes to create a positive organizational culture and healthy workplace environment. 

What Neurodiversity Means for the Future of Cyber 

With so much talent still needed across cybersecurity, making organizations more accessible to neuro minorities can help alleviate the shortage. Studies have shown that neurodivergent employees thrive in security environments. Rather than overlook this, organizations should harness the powers of this long-misunderstood population. They have a unique ability to influence impactful change for the better.  

A career in cybersecurity typically requires logic, discipline, curiosity, and the ability to solve problems and find patterns. As cyber threats grow in volume and velocity, security teams need professionals who can think outside the box to identify simplified solutions to complex challenges, such as zero-day vulnerabilities or new emerging attack vectors. These needs closely align with the skill sets of neurodivergent professionals, which can allow them to foster higher levels of proactiveness within their teams and facilitate effective approaches to critical cybersecurity threats. As such, heavy-hitting tech companies like IBM, Microsoft, Dell, SAP, and Google Cloud have put robust neurodiversity awareness and hiring programs in place.

In my own career as a neurodivergent professional, I’ve found that I can identify my strengths and weaknesses, as well as what I need versus what I can give. This has been something over the past few years that I really worked on and have shared to bring that awareness to managers and other people trying to get into the industry with autism – it’s important to always meet them halfway. Establishing clear lines of communication helps promote a healthy workplace environment where employees are empowered to be the best versions of themselves. 

Now more than ever, it’s time to bridge the cybersecurity skills gap with a more neurodiverse workforce. Creating dedicated programs will not only educate others about the neurodiverse population, but also help provide opportunities for candidates who deserve an equal playing field. My advice to other neurodivergent and/or autistic adults looking to break into the cybersecurity or IT field is to 

  1. Always continue learning: Your professional career is a marathon, not a sprint. Always seek opportunities to learn and improve, whether that’s through educational courses, professional development programs, or your own research. Navigating your career with a growth-first mindset is worth its weight in gold.  
  2. Connect with cybersecurity professionals for networking purposes: You never get a second chance to make a first impression. Don’t hesitate to reach out to contacts in the cybersecurity world for advice and guidance on how to break into the industry or advance in your role. 
  3. Never give up: Fortitude and perseverance are critical for all cybersecurity professionals. With the increasing rate of cyberattacks and the volatile state of our industry, challenges will arise – that is inevitable. And while you can’t always control what happens, what can be controlled is how you respond to it.  

There are so many groups out there that support and help drive awareness, and it’s only getting stronger. As we look ahead, incorporating neurodiverse members into cybersecurity is a strong step in the right direction for the future of the industry.

What steps have you taken to bridge the skills gap by creating a more neuro-inclusive workplace? Let us know on FacebookOpens a new window , TwitterOpens a new window , and LinkedInOpens a new window . We’d love to hear from you!

Image Source: Shutterstock

MORE ON SKILLS GAP

Megan Roddie
Megan Roddie is currently working as a Senior Security Engineer at IBM. Along with her work at IBM, she works with the SANS Institute as a co-author of FOR509, presents regularly at security conferences, and serves as CFO of Mental Health Hackers. Megan has two Master's degrees, one in Digital Forensics and the other in Information Security Engineering, along with many industry certifications in a wide range of specialties.
Take me to Community
Do you still have questions? Head over to the Spiceworks Community to find answers.