Australia has spent the better part of a decade talking about the shortage of skilled cyber workers, and about the fact that so few of them are women. The two problems have never really been separate. Now, as generative AI rewrites how attacks are launched and how they are stopped, a fresh argument is gaining traction: the industry’s long-running gender imbalance is not simply a question of fairness, but a strategic weakness that the country can no longer afford to shrug off.
That is the case put by the Australian Strategic Policy Institute in a recent analysis, which points to a familiar and uncomfortable figure. Women account for roughly 17 per cent of the cybersecurity workforce in Australia. The number has barely shifted despite years of scholarships, mentoring schemes and awareness campaigns, and it sits well below the already modest share of women across the broader technology sector. The piece argues that this is more than a stubborn statistic. In an era where AI is changing the shape of digital threats, a narrow talent base leaves the nation defending itself with too few perspectives and too few hands.
Why the timing matters
The link between diversity and AI is not obvious at first glance, so it is worth spelling out. Attackers are already using generative tools to write more convincing phishing emails, to automate reconnaissance and to spin up malware variants faster than human analysts can catalogue them. Defenders, in turn, are leaning on AI to triage alerts, spot anomalies and close the gap created by too few skilled staff. Both sides of that contest depend on people who can anticipate how systems will be misused, who can spot the edge cases that a model was never trained on, and who can judge when an automated recommendation should be overridden.
That kind of judgement is sharpened by variety of experience. Research on both security and AI has repeatedly found that homogenous teams share blind spots, and that those blind spots become baked into the tools they build. A predominantly male workforce designing AI-assisted defences risks encoding assumptions that leave whole categories of harm, from certain forms of online abuse to fraud that disproportionately targets women and older Australians, poorly understood and poorly defended. The argument, in short, is that the threats are getting broader while the people meeting them are staying narrow.
Two ways of reading the problem
There is a genuine debate about how much AI changes this picture, and it is worth airing both sides rather than pretending the answer is settled. One view holds that AI makes the diversity gap more dangerous, because automation amplifies whatever assumptions its builders bring to it. On this reading, a security industry that keeps recruiting from the same shallow pool will simply hard-wire its existing blind spots into faster, more scalable systems, and the consequences will be harder to unpick once they are embedded in production tooling.
The competing view is more optimistic, and it is one that many in the sector quietly hope will prove true. AI is lowering some of the technical barriers that have historically kept people out of cyber roles. Tasks that once demanded years of scripting experience can increasingly be handled with natural-language prompts, and analytical work that leaned on deep tooling knowledge is becoming more accessible. If the industry plays it well, that shift could widen the on-ramp for career changers, for people without traditional computer science degrees, and for the women who have long been discouraged by the field’s reputation as a boys’ club. In that scenario, AI is less a threat to inclusion than an opportunity to reset who gets to do the work.
Both readings can be true at once. AI can expand the pipeline and entrench bias, depending on choices that are being made right now about how tools are designed, who is hired to design them, and whose problems the industry decides to treat as important.
The Australian stakes
For Australia, this is not an abstract concern. The country has set itself the goal of becoming a world-leading cyber nation by 2030, and it has done so against a backdrop of high-profile breaches at Optus, Medibank and a string of superannuation funds that exposed the personal data of millions. Every one of those incidents underlined how thinly stretched the defensive workforce already is. Estimates of the national skills shortfall run into the tens of thousands of unfilled roles, a gap that cannot realistically be closed while half the population remains largely absent from the field.
There is also a sovereignty dimension that fits neatly with the debate FluentSea readers have followed about home-grown AI capability. Australia wants to build and control more of its own digital defences rather than lean entirely on overseas vendors. That ambition depends on people, and specifically on a deep enough domestic bench to staff government agencies, critical infrastructure operators and the growing cluster of security firms serving the region. A workforce drawn from a fraction of the available talent makes that goal harder to reach, and it does so at precisely the moment when AI is raising the stakes on getting it right.
Organisations such as the Australian Women in Security Network have spent years trying to shift the numbers through community, mentoring and visibility, and initiatives run through AustCyber and the universities have poured funding into the pipeline. The persistence of the 17 per cent figure suggests those efforts, while valuable, have not been enough on their own to move a culture that still turns many women away before they start.
What happens next
The practical question is whether AI becomes the lever that finally breaks the pattern or the accelerant that makes it worse. That will be decided less by grand strategy than by everyday decisions inside companies and agencies: whether job ads keep demanding credentials that screen out capable people, whether AI tooling is built and tested by mixed teams, and whether the flexible, less gatekept entry points that automation enables are actually opened up rather than quietly closed.
Australia’s cyber strategy provides the ambition and the funding. Turning that into a broader, more resilient workforce will take employers treating inclusion as a security requirement rather than a corporate nicety. The argument now on the table is that in the AI era, the two have become the same thing, and that the country’s digital defences will be only as strong as the range of people building them.
Sources: ASPI Strategist.


















































