Breaking Down Bias in the Cyber Stack
Kaleeque Pierce, Jess Hoffman
Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village
Overview
In "Breaking Down Bias in the Cyber Stack," Kaleeque Pierce and Jess Hoffman deliver a vital and interactive conversation exploring how systemic bias profoundly influences every facet of the cybersecurity industry, from initial threat modeling and security posture to crucial aspects like hiring practices and organizational policy. This marks the third consecutive year the duo has teamed up at Defcon, building on previous discussions about the impact of redlining on technological access and the importance of emotional intelligence in the workplace.

Key moments
- 0:00 Introduction to systematic bias in cyber
- 2:30 Kaleeque Pierce on overlooked soft skills
- 4:00 Ground rules and introducing persona activity
- 6:00 Audience shares initial cyber professional stereotypes
- 7:00 Challenging traditional 'IT look' stereotypes
- 8:00 Why specific, detailed personas are crucial
Breaking Down Bias in the Cyber Stack
Speakers: Kaleeque Pierce, Leadership in Financial Services; Jess Hoffman, Deputy CISO
Conference: Blacks in Cyber Village
YouTube: https://www.youtube.com/watch?v=OEMnm1GAYlQ
Overview
In "Breaking Down Bias in the Cyber Stack," Kaleeque Pierce and Jess Hoffman deliver a vital and interactive conversation exploring how systemic bias profoundly influences every facet of the cybersecurity industry, from initial threat modeling and security posture to crucial aspects like hiring practices and organizational policy. This marks the third consecutive year the duo has teamed up at Defcon, building on previous discussions about the impact of redlining on technological access and the importance of emotional intelligence in the workplace.
The core purpose of this year's talk, held within the Blacks in Cyber Village, is to dissect how identity perception shapes interactions within cybersecurity environments. By engaging leaders from government, industry, and defense in a candid dialogue, Pierce and Hoffman illuminate the often-overlooked human forces that subtly, yet significantly, determine an organization's security effectiveness and the career trajectories of its professionals. The session underscores the critical need for an equitable playing field in cyber, asserting that true equality benefits everyone and unlocks the full potential of a diverse workforce.
This discussion is particularly crucial in an industry grappling with a persistent talent gap and an ever-evolving threat landscape. Unaddressed biases can lead to homogeneous teams, blind spots in security strategies, and a failure to leverage the diverse perspectives essential for robust defense. By exposing these biases and fostering a deeper understanding of varying human experiences, the talk aims to inspire actionable change within organizations, promoting a more inclusive and ultimately more secure cyber ecosystem.
Background
▶ Watch: Introduction to systematic bias in cyber (0:00)
The genesis of this talk lies in the speakers' long-standing commitment to highlighting the often-neglected "soft skills" and human elements that underpin the cybersecurity domain. Kaleeque Pierce, with 28 years in IT including military experience and a focus on social engineering, threat engineering, and physical security, emphasizes that these skills are horizontal, spanning all areas of cybersecurity yet frequently overlooked. Jess Hoffman, a Deputy CISO with extensive experience at Defcon, echoes this sentiment, recalling previous talks on issues like redlining and its historical impact on access to technology for marginalized communities, which in turn affected diversity in the cyber field. Last year's discussion on emotional intelligence further paved the way for this year's focus on identity and perception.
The problem of bias in the cyber stack is multifaceted and deeply entrenched. The very existence of specialized "villages" like Blacks in Cyber or Latinx Village at conferences like Defcon speaks to a historical and ongoing lack of equity and equal opportunity across the industry. As Hoffman points out, while an ideal state would be one where such distinctions are unnecessary, the current reality necessitates these spaces to address specific challenges faced by underrepresented groups. The speakers challenge the audience to consider "why is there a Blacks in Cyber?" and confront the reality that not everyone starts with the same opportunities, even if they possess comparable skills.
Preconceived notions, or archetypes, about who works in cybersecurity often dictate how individuals are perceived and treated. These biases extend beyond obvious categories like race, gender, and culture, encompassing ageism, neurodiversity, physical appearance, and even immigration status. The speakers aim to move beyond theoretical discussions to explore the concrete ways these biases manifest in daily professional interactions, impacting everything from team collaboration and leadership dynamics to individual career progression and mental well-being. By creating a "safe space" for open dialogue, the session seeks to uncover the origins of these biases, examine their impact on behavior and decision-making, and ultimately encourage a shift towards greater understanding and inclusion.
Key Findings
▶ Watch: Ground rules and introducing persona activity (4:00)
The interactive nature of the talk, centered around audience-generated personas and shared experiences, served as the primary mechanism for revealing pervasive biases within the cybersecurity industry. Several key findings emerged from these discussions:
- Stereotypical Archetypes for Cybersecurity Roles:
- Project Managers: Often perceived as women, neurotypical, highly punctual, adept at time management, strong communicators, and socially flexible. There's a "gross bias" associating women with multitasking and administrative tasks, often dubbed "pink coding."
- IT Leaders: Frequently stereotyped as older (40s+), white, male, arrogant, unhelpful, resistant to change, and vague in communication. This archetype often represents a challenging, unsupportive leadership style.
- ISSOs (Information System Security Officers): Envisioned as good communicators, not on the neurodivergent spectrum, highly educated (from "good colleges"), dressed in business casual, and typically male, often not black, reflecting a perceived lack of diversity in such positions. They are seen as organized "box-checkers" good at coordinating between technical and business-minded groups.
- DevSecOps Developers: A specific persona highlighted was a woman, an immigrant on an H-1B visa from India, introverted, highly dedicated to her DevOps board, working in a multinational team, and constantly interfacing with both local and overseas peer developers and cybersecurity teams for code reviews and standards. Her primary motivation is often job performance to maintain her visa status.
- General Cyber Professionals/Hackers: Contrasting the "old IBM image" of blue suits and ties, a common perception is of individuals who are unshaven, less clean-cut, and dress "like not necessarily rebel but like showing their song," almost an antithesis to corporate formality. However, this itself is a bias, as appearances can be deceiving.
- Impact of Non-Work Identity on Professional Interactions:
- Immigration Status (H-1B): The H-1B visa status was identified as a significant source of anxiety for employees, influencing their job performance motivation and creating vulnerability to exploitative practices (e.g., companies promising sponsorship then firing them or paying pennies). This impacts how they are perceived and treated, with assumptions about their availability for travel or late work.
- Cultural Background: Differences in cultural practices (e.g., Chinese New Year, fasting) can lead to misunderstandings or insensitivity in team dynamics, such as expectations for team lunches or work schedules.
- Ageism: Jess Hoffman explicitly noted seeing "a lot of agism going on in our industry."
- Physical Appearance: The discussion highlighted how attire (e.g., a three-piece suit at Defcon vs. casual wear), hairstyle (dreads), and even physical stature (a CISO standing on tiptoes in photos) influence initial perceptions and interactions, often leading to misjudgments about capability or role.
- The Reality and Cost of Code Switching:
- Definition: Code switching was defined as projecting different personality traits or altering personal lifestyle choices in an attempt to be successful, admitted, and accepted within a specific environment, often to conceal aspects of one's identity perceived as detrimental.
- Necessity vs. Authenticity: Many participants, especially from marginalized groups (black, women, H-1B holders), shared experiences of code-switching. This can involve adopting specific interests (K-drama, sports), changing communication styles ("changing the tone"), or altering dress to fit in.
- The "Luxury" of Authenticity: While some speakers, particularly those who have achieved senior roles, expressed a desire and ability to be their "truly authentic" selves, they acknowledged that this is often a "luxury" not afforded to everyone, especially those in precarious positions or early in their careers. The transition to authenticity often occurs after reaching a certain rank or in response to changing work environments (e.g., remote work during the pandemic).
- Consequences: Code-switching can be mentally taxing, prevent genuine connections, and lead to a feeling of not being fully seen or understood. It also means that leaders might not be serving all of their team members effectively by failing to recognize their unique challenges.
- The Importance of Understanding and Empathy:
- The speakers emphasized that understanding diverse experiences, rather than dismissing differences, is crucial. This involves not making assumptions based on appearances or backgrounds and creating "space for others to do whatever it is that's necessary for them to exist in that environment."
- Ignoring or writing off individuals based on bias can lead to missed opportunities, whether in sales, talent acquisition, or collaborative problem-solving. This lack of empathy impacts personal, professional, and organizational progression.
These findings collectively underscore that bias is not merely a social issue but a fundamental challenge that impacts the human-centric aspects of cybersecurity, directly influencing team effectiveness, innovation, and ultimately, an organization's overall security posture.
Technical Deep Dive
▶ Watch: Audience shares initial cyber professional stereotypes (6:00)
While the talk "Breaking Down Bias in the Cyber Stack" primarily focuses on the human element and soft skills, its title explicitly links these biases to the "cyber stack"—the entire technological and organizational infrastructure that underpins cybersecurity. The core technical deep dive here is not into specific vulnerabilities or exploits, but rather into how the discussed biases can create vulnerabilities, impede effective security operations, and ultimately weaken an organization's security posture.
- Threat Modeling and Risk Assessment:
- Bias in Identifying Threats: If a diverse range of perspectives is absent during threat modeling sessions, teams may overlook potential threat vectors or adversary motivations relevant to marginalized user groups. For example, if a security team is homogeneous, they might not adequately consider social engineering tactics that exploit cultural norms or language barriers, or specific threats targeting diverse employee populations.
- Underestimation of Risks: Biases against certain technical roles (e.g., dismissing the input of a junior GRC analyst from a non-traditional background) can lead to critical risks being downplayed or ignored. If an IT leader is "resistant to change" or "arrogant," they might dismiss valid security concerns raised by their team, preventing the adoption of necessary security controls or updates.
- Secure Software Development (DevSecOps):
- Impact on Code Quality and Security: The persona of an H-1B DevSecOps developer, highly motivated by job performance due to visa status, highlights a potential risk. Such an individual might be less likely to raise concerns about aggressive deadlines or pressure to bypass security best practices if they fear jeopardizing their employment. This can lead to the introduction of vulnerabilities into the software supply chain or applications.
- Collaboration Barriers: In multinational DevSecOps teams, cultural and language barriers, compounded by biases, can hinder effective communication between developers and security engineers during code reviews and the implementation of coding standards. Misunderstandings or a lack of psychological safety can prevent the identification and remediation of critical security flaws.
- Security Operations (SOC Analysis & Incident Response):
- Stereotypes in SOC: The "nerdy looking white male sock analyst" stereotype, while not inherently negative, can create an environment where individuals who don't fit this mold (e.g., a "young Nigerian African GRC analyst") are not fully integrated or their unique analytical approaches are undervalued.
- Incident Response Effectiveness: During incident response, effective communication and collaboration are paramount. If biases lead to a lack of trust or communication breakdowns within the incident response team, or with affected business units, it can significantly delay detection, containment, eradication, and recovery, amplifying the impact of a breach. Language barriers or cultural differences, if not sensitively managed, can also impede effective crisis communication.
- Policy, Governance, Risk, and Compliance (GRC):
- Policy Gaps: Biases can inadvertently be baked into security policies. For instance, policies around remote access, data handling, or even acceptable use might be designed with a homogeneous workforce in mind, creating unintended burdens or non-compliance issues for diverse employees.
- Audit Effectiveness: If auditors (like the "black senior IT auditor assigned to a three-letter agency") face implicit biases, their findings might be scrutinized differently, or their access to necessary information might be subtly impeded, compromising the objectivity and effectiveness of security audits.
- Human Factors in Security:
- Social Engineering: The speakers explicitly mention social engineering. Understanding human biases is critical for both defending against and recognizing social engineering tactics. Attackers often exploit preconceived notions, cultural expectations, or anxieties (e.g., an H-1B visa holder's fear of job loss) to gain access or information. A security team lacking diverse perspectives might struggle to anticipate these nuanced social engineering vectors.
- Insider Threat: Unaddressed biases and a lack of inclusion can foster environments of resentment or alienation, which are known factors that can contribute to insider threat risks. Employees who feel undervalued or discriminated against may be less loyal or more susceptible to external pressures, potentially increasing their risk profile.
In essence, the "technical deep dive" into bias reveals that the human element is not separate from the cyber stack but deeply interwoven with it. Biases, when left unexamined, create "human vulnerabilities" that can be just as, if not more, damaging than technical flaws. They impact decision-making, collaboration, and the psychological safety necessary for a truly resilient and secure organization.
Demo / Proof of Concept
▶ Watch: Challenging traditional 'IT look' stereotypes (7:00)
The talk itself was structured as an interactive "demo" and "proof of concept" to illustrate how biases manifest and influence perceptions in real-time. Rather than showcasing a technical exploit or a software demonstration, the speakers orchestrated a highly engaging group exercise that directly involved the audience in confronting and dissecting their own preconceived notions.
The core of the "demo" involved splitting the audience into groups and tasking them with creating detailed personas of cybersecurity professionals. The speakers encouraged the audience to go beyond generic descriptions, prompting them to consider specifics such as race, gender, age, cultural background, physical appearance (height, hair, attire), and even personality traits or career motivations. Examples provided included:
- A "young Nigerian African GRC analyst."
- A "black senior IT auditor assigned to a three-letter agency."
- A "Mexican-American woman, it's her first job in cyber, there's a language barrier."
- A "nerdy looking white male sock analyst with glasses."
- An "IT leader, white, older, 40s plus, male, arrogant reputation, not helpful, short, vague, resistant to change."
- An "ISSO manager, good at speaking to people, not on the spectrum, went to a good college, higher education, dresses business casual at work, probably not black."
- A "DevSecOps developer, a woman, immigrant on an H-1B visa from India, a little bit of an introvert, lives and dies by the DevOps board, working to interface with multinational teams, motivated by staying employed and top job performance."
After creating these detailed personas, each group presented their archetype, often sparking immediate reactions and additional insights from other attendees. For instance, the project manager persona, described as "very tough" and professionally dressed, led to a project manager in the audience validating some traits but challenging the "softspoken" stereotype often associated with her Asian ethnicity.
The exercise continued by having groups discuss how they would interact with these personas during an "incident and situation," forcing attendees to consider how their biases might affect outcomes. The speakers then broadened the discussion to include personal experiences with code switching – how individuals adapt their personality or appearance to fit into a professional environment. This segment included compelling anecdotes, such as Kaleeque Pierce's deliberate choice to wear a disarming Asian-style hat at Defcon to encourage interaction, or a senior leader's journey from strict professional dress and avoiding "black networks" to embracing authenticity after reaching a certain career rank.
This interactive approach served as a powerful proof of concept, demonstrating in real-time how deeply ingrained biases are, how they influence immediate perceptions, and how they shape the professional experiences of individuals within the cybersecurity community. By externalizing these archetypes and discussing their implications, the audience directly experienced the central thesis: that identity perception is a critical, often unacknowledged, factor in the cyber stack.
Defensive Implications
▶ Watch: Why specific, detailed personas are crucial (8:00)
The insights gleaned from "Breaking Down Bias in the Cyber Stack" carry significant defensive implications for cybersecurity organizations. Addressing systemic bias is not merely a matter of social justice; it is a strategic imperative that directly enhances an organization's resilience, innovation, and overall security posture. Defenders should consider the following actionable steps:
- Re-evaluate Hiring and Retention Strategies:
- Bias Training: Implement mandatory, recurring unconscious bias training for all hiring managers and interviewers. This helps identify and mitigate biases related to race, gender, age, appearance, and background during recruitment.
- Diverse Interview Panels: Ensure interview panels are diverse in composition to provide varied perspectives and reduce the likelihood of a single bias dominating the assessment process.
- Skills-Based Assessments: Prioritize objective, skills-based assessments over subjective criteria or "culture fit" that can inadvertently perpetuate homogeneity. Focus on what candidates can do rather than what they look like or where they come from.
- Support for H-1B Employees: Organizations must recognize the unique vulnerabilities faced by H-1B visa holders. Provide clear, consistent support and legal guidance, and ensure management is trained to understand and mitigate anxieties related to visa status, preventing potential exploitation or the suppression of critical security input.
- Foster Inclusive Team Dynamics and Psychological Safety:
- Leadership Training: Train leaders, from project managers to CISOs, in emotional intelligence, situational awareness, and understanding diverse experiences. This includes recognizing the signs of stress or anxiety (e.g., in H-1B employees) and actively creating space for individuals to express concerns without fear of reprisal.
- Promote Authenticity: Encourage employees to be their authentic selves by modeling this behavior from the top down. Actively challenge the necessity of code switching by creating an environment where diverse communication styles, appearances, and cultural expressions are accepted and valued. This builds trust and encourages open communication, which is vital for identifying and addressing security issues.
- Cross-Cultural Communication: Provide resources and training for effective cross-cultural communication, especially in multinational teams. This helps bridge language barriers and understand different work ethics or communication norms, improving collaboration in DevSecOps and incident response.
- Integrate Diverse Perspectives into Security Processes:
- Threat Modeling Workshops: Actively seek diverse participants for threat modeling and risk assessment workshops. Including individuals from varied backgrounds (different roles, ages, ethnicities, cultures, neurotypes) can uncover a wider range of potential threats, vulnerabilities, and attack vectors that might otherwise be overlooked by a homogeneous group.
- Policy Review for Bias: Conduct regular reviews of security policies, procedures, and controls for implicit biases. Ensure policies are equitable and accommodate cultural differences, varying work styles, and diverse needs, rather than inadvertently creating barriers or disproportionate impacts on certain groups.
- Strengthen Social Engineering Defenses:
- Awareness Training: Enhance social engineering awareness training by incorporating examples that reflect diverse cultural contexts and psychological vulnerabilities. Acknowledge that attackers exploit biases and anxieties (e.g., fear of job loss for H-1B employees) to gain unauthorized access.
- Human-Centric Security: Emphasize a human-centric security approach that recognizes employees as both the strongest and weakest links. By understanding and addressing their concerns, organizations can empower employees to be better defenders.
- Leadership Accountability:
- Metrics and Reporting: Establish metrics for diversity, equity, and inclusion (DEI) within security teams and hold leaders accountable for progress. This includes tracking representation in hiring, promotions, and leadership roles.
- Mentorship and Sponsorship: Create formal mentorship and sponsorship programs to support underrepresented groups in their career progression, providing guidance and advocating for their opportunities.
By proactively addressing the biases highlighted in this talk, cybersecurity organizations can build more resilient, innovative, and effective teams capable of navigating the complex and ever-evolving threat landscape. This shift from simply managing technical risks to nurturing an inclusive and understanding human ecosystem is a critical defensive strategy for the modern cyber era.
Key Takeaways
- Bias is Pervasive and Multidimensional: Systemic bias extends beyond race and gender, encompassing age, culture, neurodiversity, physical appearance, and immigration status, affecting every aspect of the cyber stack.
- Identity Perception Impacts Security Outcomes: Preconceived notions about individuals in various roles (e.g., project managers, IT leaders, DevSecOps developers) directly influence how they are treated, their opportunities, and ultimately the effectiveness of security processes.
- Code Switching is a Common, Often Necessary, Survival Tactic: Many professionals, particularly from marginalized groups, feel compelled to alter their authentic selves to fit in and succeed, though this often comes at a personal cost.
- Authenticity is a Goal, Not Always a Luxury: While being one's authentic self is ideal for building genuine connections and trust, not everyone has the professional or personal security to afford this luxury, especially early in their careers or with precarious employment statuses like H-1B visas.
- Empathy and Understanding are Critical Defensive Tools: Actively seeking to understand and validate diverse experiences, rather than dismissing differences, is essential for building inclusive teams, robust security strategies, and effective incident response.
- Inclusion Strengthens Security Posture: Addressing biases and fostering an equitable environment is not just a social imperative but a strategic security advantage, leading to more diverse perspectives in threat modeling, better collaboration in DevSecOps, and a more resilient overall security posture.
About the Speaker(s)
Kaleeque Pierce is a seasoned professional currently holding a leadership position in financial services. With approximately 28 years of experience in the IT industry, including significant exposure through military service, Pierce has developed a keen affinity for the "soft skill" side of cybersecurity. His expertise particularly lies in areas such as social engineering, threat engineering, and physical security. He emphasizes the horizontal applicability of these skills across all cybersecurity domains.
Jess Hoffman is a prominent figure in the cybersecurity community, currently serving as a Deputy CISO. Based in Philadelphia, Hoffman has a long-standing presence at Defcon, having participated for "quite a few years." She is known for her leadership roles and her commitment to fostering inclusive conversations within the industry. This talk marks her third collaborative effort with Kaleeque Pierce, building on previous discussions about the impact of redlining on technology access and the importance of emotional intelligence in cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent community panel that does what it sets out to do: surface how systemic bias shapes team dynamics, hiring, and organizational security culture in ways the industry rarely discusses on a main stage. The Blacks in Cyber Village is the right lane for this content, and the interactive persona exercise is a genuinely useful pedagogical device. But the ideas stay at the level of 'bias is bad and here's why it matters for security' without producing new frameworks, data, or transferable tools that would make this stick beyond the room.
Heather Calloway (CISO) — SOLID
A well-intentioned and experientially grounded conversation about how bias shapes team dynamics, hiring, and security decision-making — but it stays in problem-articulation mode longer than it should. The framing is right; the institutional accountability mechanism is missing.