Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Artificial Intelligence (AI) Cybersecurity

Q&A: Noma Security CISO Diana Kelley on Women in Cybersecurity: Retention, Leadership, Networks, and AI

Teri Robinson

Aug 12, 2026

Among the major issues shaping cybersecurity today are the persistent underrepresentation of women in leadership and the rapid rise of AI agents. These themes connect through a common thread: organizations need better structures, support systems, and governance if they want people and technology to perform safely and effectively.

Tech-Channels asked Diana Kelley, CISO at Noma Security, why women continue to leave cybersecurity at higher rates, how hiring practices can unintentionally narrow the talent pool, and why personal and professional networks matter so much for advancement. Kelley also explained why agentic AI requires stronger governance, guardrails, and runtime controls. And, she says, security should be built in from the beginning rather than added after innovation is already underway.

Q. Why does cybersecurity continue to lose women in mid-career?

A. The attrition rate is having an impact. Some companies are quite good about hiring as close as possible to 50/50, but then women leave at a much higher rate. As for why, it’s Occum's Razor, right? It can be the obvious reasons. It's very often it's the long hours, and the lack of flexibility can be very hard.

Not to overgender, but women tend to be the caretakers in most families. Very often people are stuck between being the caretaker of the elderly parents, in addition to the children. And in some cultures and some organizations there sometimes can be genderism against women too. I think that that can be extremely hard. There's always this concern about are you technical enough, and if you're a woman it’s moreso. Some people get very exhausted with that.

Q. How do job descriptions affect whether women apply for cybersecurity roles?

A. A woman needs to see 80 percent to 90 percent capability in a job, and a man will apply it around the 50-60 percent mark. When I was at Microsoft, we would go back through, and rewrite our job descriptions with that in mind.

Q. The numbers for women at the top of the stack are shockingly low. Why are there still so few women in cybersecurity leadership roles?

A. We're 51 percent of the population, so anything below that, and something's wrong. You look at that and say, “why?” Each company is going to be different but what I can tell you is, it's not because there aren't capable women. There are.. I meet them every day at EWF (Executive Women’s Forum) and through WIIS (Women in International Security).

There are lots of extremely capable women who understand both the leadership in the business, the risk, and the technical components that you would need to lead in a cybersecurity role and be a CISO.

Q. What can companies do to find more women for leadership positions?

A. The other thing companies should be trying very hard to do is go out and make sure that they've networked in the right places to be able to find women. Networks are interesting things, they can get a little bit of a closed loop. If you're always talking to the same people, you just go into their groups. But how many of these folks are coming to an EWF or going to an RSA and maybe to the same parties or to the same VCs and maybe haven't expanded their network beyond a smaller group?

They really need to start reaching into networks where women are in leadership, like EWF. Ask yourself, have I looked beyond the normal network? When you say “we can't find anybody,” have you gone to a network you haven't been to before, where you know there's a strong ecosystem of very powerful women?

Q. What advice would you give women who want to advance in cybersecurity?

A. The most important thing is to network. Everybody knows that. But to be able to stay in a very difficult career where the hours can be grueling and it can be very hard to get support in security, a lot of times you cannot talk to your external peers about everything that's going on because you have a duty of care to the company. But create a network of support or find one. I always tell women, find your board of directors, seat your personal “board of directors.”

A board just doesn't go out and say, “Oh, we're just going to get these.” They say we need somebody who has this kind of skillset that is connected to this group. So, when you're creating your own board, say, “What do I need?”

I probably need an advocate inside my company who's going to go to bat for me to get me that next job. I probably need to have some somebody who's very well known in the industry that is going to advocate for me in other jobs that can connect me. And I probably need somebody on my board that is just the person who's going to be able to listen and go, “I get it.”

Q. What kind of support do women need from their professional networks?

A. I was talking to a friend going through something recently because there have been a lot of layoffs. And she basically monologued for the first 20 minutes of the call, then said, “You know, I just want to thank you for listening to me and saying ‘yes, uh huh, I get it.’” Instead of trying to create solutions immediately. We all need those kinds of people.

Q. Let’s switch gears to the topic of the moment—AI. How quickly has enterprise adoption of AI agents evolved?

A. Just since RSA, it's really clear that we've gone from the concept of agents and people saying, “You know, I'm going to fire my staff” or things like that, to organizations creating agents, using agents, or co-working with the agents of ChatGPT and Copilot that they're now using in their everyday work. That has coincided with we've also heard about agents doing things that they shouldn't. What we're seeing is that agents are LLM-driven software and if you give them access and the LLM has a goal to accomplish something. It's not a human being with a conscience that says, “Should I do this? Should I do that?”

Q. Why do agentic systems create new governance risks?

A. There are no consequences. It’s TCB, take care of business, get it done. And these agents, these models, have been trained on years and years and years of evasion techniques and attacking. So, they've got all of that to go through and use. It really puts a strong, strong line under what Noma has been saying since our inception, which is that to get the benefit of AI, and now to get the benefit of agentic AI, you need to have strong governance and guardrails and runtime controls.

These agents can do a lot of good for you, but you need to make sure that they're not going off the rails and doing something they shouldn't.

Q. Why should security be built into AI initiatives from the beginning?

A. I've been doing this for almost 40 years now. The whole reason I got in was that I was a network person. Somebody got onto my network. It was the mid-90s, and I didn't understand all the security aspects. I needed to learn that.

But for me, it's always been how do you take advantage of the technology in a way that doesn't allow the bad guys to turn against you, and you build the security in. We get so excited about the technology and about what it can do, and the business goes, “Yeah, you know, let's go do this.” And security's like, “We're not saying no. We're just saying we have to build the security, so we can go faster.” It's truly the brakes on the car. You take those turns a lot faster with brakes in there.

But I think exuberance gets the best of people sometimes, and the car maybe doesn't make the turn, and security comes along and says, “Let's get those brakes filled. Let's get back on.”

Two parallel shifts clearly are reshaping cybersecurity. When it comes to careers, organizations need to look beyond hiring numbers and address the structural reasons women leave, including inflexible work models, caregiving pressure, bias, and limited access to the networks that lead to leadership roles. For individuals, Kelley stresses intentional networking and the value of creating a personal “board of directors” that provides advocacy, connections, and emotional support.

And as AI continues to dominate, organizations should not treat governance as something to bolt on after deployment. Agentic AI can create substantial business value, but its ability to pursue goals autonomously makes guardrails, runtime controls, and security-by-design essential. For both talent and technology, the underlying lesson is the same: sustainable progress depends on building the right support structures before problems emerge.

 

 

Share on