WICCON 2026

WICCON 2026

Well behaved women seldom make history
2026-10-29 , Main Hall

For a long time I believed cybersecurity was a meritocracy; Work hard. Be good at your job. Speak the truth. The best person gets the role.

That’s the story we like to tell ourselves.

After more than 10 years in the field, much of it as a CISO, I’ve collected enough experiences to file a bug report against that idea.
In this talk I’ll share some of the greatest hits from my career: interviewing for a CISO job that didn’t actually exist, being told I’d make a great CISO “one day” while already being one, spending six hours in an assessment where my cybersecurity skills were never tested, and being advised by a psychologist to focus on raising my kids instead of pursuing leadership.


The industry loves to tell women to adapt. Be less loud. Less confrontational. Dress differently. Speak differently. Be more strategic. Be less emotional.

So I tried that.

Spoiler: it doesn’t work.
Because the problem isn’t how women behave. The problem is the system evaluating them.

This talk isn’t about how I beat that system. It’s about what happens when you stop pretending the system works. It’s about the quiet ways talented people are pushed out of cybersecurity, and why the industry keeps reproducing the same leadership over and over again. And it’s about what we can actually do instead: amplify each other, open doors when we have the chance, and refuse to sand down the sharp edges that made us good at this job in the first place.

Cybersecurity loves talking about breaking systems.
Maybe it’s time we start with this one.

Cybersecurity loves to believe it’s a meritocracy. Work hard, be good at what you do, and the best person gets the job. But what happens when the system evaluating talent is broken?
In this talk, a CISO with more than a decade of experience shares a series of personal stories from inside the industry: interviewing for jobs that never existed, being told she might become a CISO one day while already being one, and failing a full-day assessment that never tested a single cybersecurity skill.
These experiences reveal uncomfortable truths about how hiring, assessments, and leadership selection actually work in cybersecurity, and who gets left behind.
This is not a talk about fixing yourself to fit the system.
It’s a bug report about the system itself.
Expect sharp edges, uncomfortable lessons, and a call to start hacking the culture of our own industry.

Ten year security expert. Much of which for the government.

Not a well behaved woman.