LevelBlue Named Premier Remediation Partner for SentinelOne Wayfinder Frontier AI Services. Learn More

How 6 Women in Cyber Are Rethinking Risk, Resilience, and Security Leadership

Established by the Canadian nonprofit Women Cybersecurity Society, Women in Cyber Day celebrates the contributions of women across the cybersecurity community and encourages the continued advancement of the profession. Observed annually on September 1, the day also provides an opportunity to spotlight the expertise and perspectives shaping what comes next in cybersecurity, especially as the industry rapidly transforms.

Cybersecurity has never had more frameworks, controls, benchmarks, metrics, or tools. Yet many organizations continue to navigate familiar challenges: determining what deserves attention first, measuring risk effectively, building resilience, and identifying where to begin as AI reshapes the technology landscape.

To recognize Women in Cyber Day, cybersecurity leaders from across LevelBlue were invited to share their perspectives on the issues shaping this new landscape. Across conversations spanning AI, resilience, visibility, trust, and risk management, a common theme emerged: organizations are succeeding not by chasing every threat or technology trend, but by developing a clearer understanding of what matters most, where risk exists, and how to make informed decisions in an increasingly complex environment.

 

What deserves the most attention right now?

One of the strongest themes across the conversations was prioritization. Security teams have access to more information than ever before, but deciding what requires immediate attention remains one of the industry's most difficult challenges.

"The hardest decision today is determining what deserves attention first," says Bindu Sundaresan, Director of Global Solution Architecture and Engineering. "There is no shortage of vulnerabilities, alerts, vendors, regulations, technologies, and emerging threats." Her advice is to focus on understanding which risks could materially interrupt operations, harm customers, or damage trust rather than becoming distracted by volume alone.

That challenge is becoming more nuanced as organizations adopt AI, cloud services, automation, and increasingly dynamic technology ecosystems. Vindhya (Vindy) Nagaraj, Director of Cyber Testing, elaborated, "One of the hardest things in security today is knowing what—or who—you’re actually securing. Three years ago, we were primarily thinking about users, endpoints, applications, networks, and data. Today, the environment is much more dynamic."

Shani Kahlon, Director-Cyber Defense and Deputy CISO, agreed, noting that "knowing what needs to be protected" has become dramatically more difficult as environments expand across AI agents, SaaS platforms, APIs, third-party integrations, and machine identities. The traditional idea of having a clear perimeter and a well-defined inventory is no longer realistic. "Before you can secure something, you need to know that it exists, who owns it, what data it handles, and what it can access. Asset visibility and understanding the relationships between assets have become just as important as the security controls themselves."

Anticipate threats and protect your business with LevelBlue.

Explore Services

Which cybersecurity practices should be left behind?

Several leaders pointed to a common issue: confusing activity with progress.

The cybersecurity industry has become exceptionally good at producing dashboards, reports, metrics, policies, controls, and alerts. Yet volume doesn't necessarily translate into resilience.

"Security teams should stop measuring activity as though activity equals protection," says Bindu. "More alerts investigated, more vulnerabilities closed, and more policies written do not necessarily mean less risk."

That perspective was echoed by multiple contributors, with Shani emphasizing that "Security teams should stop measuring success primarily by the number of vulnerabilities, alerts, or policies they manage. Instead, they should focus on reducing meaningful business risk and measuring outcomes, such as attack surface reduction, security coverage, resilience, detection and response capabilities, and the organization's ability to recover. The goal should not be to create more security activity; it should be to create better security outcomes."

As Vindy puts it, "I believe it's better to have a smaller number of well-understood controls that materially reduce risk than hundreds of controls that exist primarily to satisfy an audit."

At the same time, several leaders cautioned against swinging too far in the other direction. While security programs should avoid measuring success by activity alone, that doesn't mean foundational governance can be overlooked. Organizations are often eager to invest in new tooling, detection capabilities, and emerging technologies before establishing a clear understanding of their critical assets, business objectives, and strategic risks.

As Devon Kelly, Director of Advisory Services, observed, "Governance is the cornerstone of any organization. Without a strong governance, risk, and compliance (GRC) program, the entire house of cards falls apart." While governance may not always receive the same attention as technical controls, it plays a critical role in helping organizations understand what matters most and where security investments should be focused.

 

What assumptions should leaders challenge now and in the future?

One answer surfaced repeatedly throughout the discussion: security is not solely a technology problem.

Organizations often focus on tools and controls while overlooking culture, governance, ownership, and communication. Several participants noted that resilience depends on collaboration across the organization rather than being owned exclusively by the security team.

According to Indi Birak, VP of Advisory Practice, EMEA, the idea that "people are the weakest link" remains one of cybersecurity's most persistent misconceptions. Many risks stem from organizational culture, governance challenges, and processes that fail to account for how people actually work. "Addressing these issues results in informed and empowered people who are the key drivers to building and maintaining a resilient organization."

Another recurring theme: trust. As access models become more dynamic and AI introduces new forms of identity, organizations are rethinking how trust is established, monitored, and maintained. "Leaders need to challenge the assumption that trust is a one-time decision," said Bindu.

 

What skills will define the next generation of cyber leadership?

Cyber leaders of the future will need technical expertise combined with a strong ability to establish trust, connect cybersecurity decisions to business priorities, and navigate business acumen while making informed decisions (often with incomplete information). It's no small feat, but as technology contributes to rapidly evolve, so will the skills needed to forge successful cybersecurity leaders.

Jo Salisbury, Director of Sales, elaborated, "There are a lot of incredibly intelligent technical folks in cyber but without the ability to get out from behind the technology and connect cyber initiatives with the business, you aren’t adding value. Understanding the business you are protecting will enable you to align the decisions with what matters for the business in a prioritized way. Business resilience starts with people communicating and collaborating."

Devon agreed, emphasizing that the ability to communicate, be interpersonal, and have empathy for the limitations of another department's understanding of cyber is a major component of the job. "The ability to translate probabilistic risk into language a business leader can actually act on. So often I see people coming out of university, or transitioning into this field, who are excellent with the data and the technical side but can't bring an executive, an HR leader, or a business owner along with them. While those departments have some exposure to cybersecurity through their job, it isn't their specialty, and it was never going to be."

Bindu summarized it well: "Cybersecurity is often described as a race between defenders and attackers. I think it is also a race between complexity and understanding."

 

What gives cybersecurity leaders optimism about the future?

Despite the challenges associated with AI, every contributor expressed optimism about the opportunities emerging technologies can create.

"I am excited by the possibility of making security more adaptive. AI can help us move from waiting for alerts to recognizing patterns and anticipating where risk may emerge. It can reduce repetitive work and give security teams more time to think strategically," shared Bindu. "At the same time, we need to secure AI itself. We have to understand what data models use, who can influence them, how decisions are made, and what happens when the model is wrong. I am also interested in the connection between AI, zero trust, and quantum-resistant security. Zero trust helps us question access, AI helps us analyze change at scale, and post-quantum planning helps us protect information that must remain secure for many years. These are not separate technology trends. Together, they are changing how we define trust."

AI is already helping security teams process data, automate repetitive work, identify patterns, accelerate investigations, and improve prioritization. At the same time, it is creating entirely new questions around governance, visibility, trust, and accountability. Shani agreed, sharing that "While AI and automation introduce new risks, they also create an opportunity to fundamentally change how we operate security. We can automate repetitive work, improve detection and investigation, process significantly more data, and allow security teams to focus more of their time on strategic risk. I'm particularly excited about the possibility of moving from reactive security operations toward more proactive, intelligent, and adaptive defense."

There's obviously risk associated with AI, but the ability to reduce the overhead that historically overwhelmed security teams is exciting. Vindy elaborated, "The security professional of the future may spend less time manually investigating individual alerts and more time designing, governing, and supervising intelligent systems."

Jo summed it up well, saying, "It is an exciting time to be in cyber with the advancement of AI being a powerful tool for both attackers and defenders. With geopolitical tensions thrown into the mix, the importance of cyber security matters even more, not just to organizations but to our society globally." It just takes a bit of finessing to achieve it.

 

What's ahead?

Across every topic from AI and resilience to trust and prioritization, one message remained consistent: cybersecurity is ultimately a discipline of understanding. Understanding what matters, where risk exists, how systems connect, and how organizations can respond when conditions change.

As Women in Cyber Day recognizes the professionals helping shape the future of cybersecurity, these perspectives offer a reminder that effective security is defined less by the tools deployed and controls implemented, but more in the ability to make informed decisions with incomplete information, build resilience as a joint organizational and cyber effort, and create trust in an increasingly complex world.

 

Contributors

Thank you to the cyber leaders who contributed their insights for this piece:

  • Bindu Sundaresan, Director of Global Solution Architecture and Engineering
  • Devon Kelly, Director of Advisory Services
  • Indi Birak, VP of Advisory Practice, EMEA
  • Jo Salisbury, Director of Sales
  • Shani Kahlon, Director-Cyber Defense and Deputy CISO
  • Vindhya Nagaraj, Cyber Director-Testing

About LevelBlue

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

Discover how our specialists can tailor a security program to fit the needs of
your organization.

Request a Demo