Back Theregister Fewer women than ever in UK's 'old boys' club' cyber industry
Younger workers often overlooked for senior roles due to historical issues and fears they’ll get pregnant, says survey
Erase social media tomorrow? Brits say yes 1 hour ago
Erase social media tomorrow? Brits say yes
The tech industry is hot for shopping bots, but they're years away 2 hours ago
The tech industry is hot for shopping bots, but they're years away
Singapore’s government creates a dating app 4 hours ago
Singapore’s government creates a dating app
RAM supply set to worsen, says Micron, as CEO celebrates ‘much higher’ prices 6 hours ago
RAM supply set to worsen, says Micron, as CEO celebrates ‘much higher’ prices
Azure maintenance mess disrupted hybrid clouds, VPNs, cloudy VMware services 9 hours ago
Azure maintenance mess disrupted hybrid clouds, VPNs, cloudy VMware services
The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021.
Gender diversity has long been an issue pervading the STEM fields, although in cybersecurity this is especially pronounced, both at senior leadership and education levels. This is despite evidence that girls regularly outperform boys in STEM subjects at UK schools when they do participate.
Not only are there still fewer women students in cybersecurity courses than those opting for computer science, but the percentage of women in the senior workforce (6+ years of experience) drops further to 12 percent – a figure that has remained broadly consistent since records began.
For context, the UK average across all industries for female-identifying workers is 48 percent. Across the digital workforce, as of last year’s data, the average is 30 percent.
The UK government interviewed various stakeholders in the cyber industry, finding that the barriers to senior leadership positions were structural – employers are purposely excluding women at higher levels.
History plays a part too – older heads remaining in their positions from back when gender diversity was a matter less discussed – but recruiters say employers are still holding women back based on their perceived family ambitions.
One recruitment agent was quoted in the report as saying: “When I’ve spoken to a business and said to them ‘why don’t you hire a more diverse workforce?’ You’ll get the normal common ones of ‘well if we hire a female, she’ll get pregnant, she’ll be off for 12 months,’ which isn’t right.”
Refusing to hire women based on assumptions or fears future pregnancy is a form of illegal gender discrimination that directly violates the UK's Equality Act 2010 .
Other common barriers to senior positions include assumptions they did not have the requisite technical skills for the role, and that cybersecurity is still seen as “an old boys’ club.”
“This tied into a broader finding that stereotypes women not being interested in cybersecurity continued to persist,” the report noted.
Palo Alto Networks execs apologize for 'hostesses' dressed as lamps at Black Hat booth
“A cybersecurity firm noted that during a career talk on cybersecurity, a group of girls walked out of the talk, and the careers teacher reinforced the perception that the sector did not appeal to women.”
The business told the government: “I went to the careers lady ‘What was the story with the five girls that left?’ And she went ‘Oh, cyber security is not really a girl’s job’.”
Jill Broom, head of cyber resilience at techUK, said the onus is on employers to work harder on breaking down the lingering stereotypes women in cybersecurity.
“Cybersecurity underpins our growth, our economy and the safety of our society, with the sector offering growing employment opportunities and career prospects,” she told The Register . “However, the underrepresentation of women in this industry remains a significant concern.
“A lack of gender diversity not only limits opportunities for women to benefit from this growing sector but also risks narrowing the range of perspectives and ideas that are essential to tackling increasingly complex cyber threats. Educators and employers must work together to challenge stereotypes, break down barriers and promote cybersecurity as an accessible and inclusive career path.”
Representation for other groups fared comparatively better.
This past year set a new record for neurodivergent workers in the cybersecurity industry, with 22 percent of UK staff identifying as neurodivergent.
The figure represents a sharp increase from 16 percent the year before, one that has grown each year consistently since the 9 percent reported in 2020, and exceeds the digital sector average of 19 percent.
“Cybersecurity is the most neurodiverse sector I have ever seen, and I think personally it’s celebrated, especially internally within the sector,” one respondent from a small cybersecurity business told the report's authors.
While this year’s results may prove especially welcome to the neurodiverse crowd, the report noted this may reflect the rising awareness of neurodiversity among employers, rather than a true increase in numbers.
The representation of ethnic minorities also remained at 19 percent, the same proportion as in 2025’s data, although this was a modest rise from 2024, in which 13 percent were from ethnic minorities.
The figure is aligned with the digital sector average of 20 percent, and exceeds the UK’s pan-industry average of 16 percent.
However, the representation of these groups suffers at the senior levels.
The proportion of ethnic minorities in senior positions stands at 9 percent, a low figure that has persisted for the third year running, and one that is considerably down from the 15 percent high of 2021.
As for explanations, the report offered few.
“Ethnicity was hardly mentioned and was not generally felt to be an issue, despite the quantitative findings suggesting ethnic diversity at senior levels has remained lower than in the 2021 to 2023 studies,” it stated.
“Most commonly, participants did not offer any concrete suggestions for enabling the progression of staff from diverse backgrounds into senior cybersecurity positions. Some employers stated that career development was open to everyone and was based on merit.”
For neurodivergent security pros, it was not their technical abilities holding them back, but some said a lack of soft skills may hinder them in senior-role scenarios.
“They’re more than capable of doing a leadership role,” said one small cybersecurity business. “It’s just they might not be soft-skilled enough to deal with difficult teams, difficult conversations. But to be honest, I’ve seen some fantastic people who are neurodiverse in leadership roles.”
Disabled people are continuously absent from the workforce too, occupying just 9 percent of UK roles and 5 percent of senior positions.
This is both less than the digital sector average of 15 percent, and significantly less than the UK’s pan-industry average of 18 percent. ®
Fewer women than ever in UK's 'old boys' club' cyber industry
Younger workers often overlooked for senior roles due to historical issues and fears they’ll get pregnant, says survey
Erase social media tomorrow? Brits say yes
So why are more and more people snorting their daily fix of cat videos, men fighting and political propaganda
Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud
PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud
The tech industry is hot for shopping bots, but they're years away
What's good for human shoppers does not work with probabilistic AI agents
OpenAI apes AWS Marketplace while Anthropic remains stubbornly Microsoftian
Singapore’s government creates a dating app
Team that gave the world Bluetooth COVID tracking swipes right on algorithmic matchmaking
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
AI models keep posting screenshots showing sensitive data from inside tech companies
AI models keep posting screenshots showing sensitive data from inside tech companies
EXCLUSIVE Microsoft tells nonprofits their deleted M365 data isn't coming back
Microsoft tells nonprofits their deleted M365 data isn't coming back
Google ending ChromeOS support two years early
Google ending ChromeOS support two years early
FBI to ShinyHunters: 'We know how to find you'
FBI to ShinyHunters: 'We know how to find you'
Microsoft's Copilot super app comes with a meter attached
Microsoft's Copilot super app comes with a meter attached
Hot Dog! America's new chatbot is packed with wieners Just ask America.gov and you'll receive a favorite July 4th food.
Hot Dog! America's new chatbot is packed with wieners
Just ask America.gov and you'll receive a favorite July 4th food.
Huawei boss claims homegrown AI chip sales top Nvidia in China The chips may not be as advanced, but they won't get banned at a moment's notice, Eric Xu says
Huawei boss claims homegrown AI chip sales top Nvidia in China
The chips may not be as advanced, but they won't get banned at a moment's notice, Eric Xu says
Add one more AI worry to the nightmare scenario: self-replicating prompt injections It's a worm attack, AI-style
Add one more AI worry to the nightmare scenario: self-replicating prompt injections
It's a worm attack, AI-style
Zuckerberg touts enterprise AI push because Meta would never do anything to damage your reputation New business unit to be led by former MongoDB CEO 'CJ' Desai
Zuckerberg touts enterprise AI push because Meta would never do anything to damage your reputation
New business unit to be led by former MongoDB CEO 'CJ' Desai
AMD's 192 GB Gorgon Halo prices might leave you petrified Regular pricing starts at $6,799 - all that memory doesn't come cheap
AMD's 192 GB Gorgon Halo prices might leave you petrified
Regular pricing starts at $6,799 - all that memory doesn't come cheap
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Firefox 157: Could bold new look be just what Mozilla needs?* Yet another new version of Firefox, with a significant reskin
Firefox 157: Could bold new look be just what Mozilla needs?*
Yet another new version of Firefox, with a significant reskin
KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user
KDE turns 30 and someone's brought an AI-native desktop proposal
Akademy talk imagines Plasma assembling itself around a personal model of each user
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
