KEYNOTE: This conference was not built for you - Chantal Stekelenburg
Chantal Stekelenburg
Disobey 2026 · Keynote
Overview
Chantal Stekelenburg's keynote at Disobey 2026 delivers a powerful and analytically sharp critique of the systemic barriers preventing diversity and inclusion in cybersecurity conferences. Moving beyond a purely moral argument, Stekelenburg meticulously dissects how current practices, often driven by unconscious assumptions and comfort rather than malice, inadvertently exclude women and other underrepresented groups from speaking stages and, by extension, from shaping the future of security. Her central thesis is that "this conference was not built for you" for many, and that addressing this is not merely "the right thing to do," but an operational imperative for effective security.

Key moments
- 0:00 Introduction: Who are these conferences for?
- 2:00 Speaker's focus: Gender inclusion from experience
- 4:45 Conferences decide belonging long before CFP submission
- 5:30 Unconscious assumptions create barriers, not bad intent
- 8:20 Talent exists everywhere, but encouragement does not
- 10:00 Lack of role models impacts girls' career choices
- 11:30 Speaker's personal journey to become a role model
KEYNOTE: This conference was not built for you - Chantal Stekelenburg
Speakers: Chantal Stekelenburg, Founder of Women in Cyber Security Community Association (WiCa)
Conference: Disobey
YouTube: https://www.youtube.com/watch?v=x0tYgKgDuxI
Overview
Chantal Stekelenburg's keynote at Disobey 2026 delivers a powerful and analytically sharp critique of the systemic barriers preventing diversity and inclusion in cybersecurity conferences. Moving beyond a purely moral argument, Stekelenburg meticulously dissects how current practices, often driven by unconscious assumptions and comfort rather than malice, inadvertently exclude women and other underrepresented groups from speaking stages and, by extension, from shaping the future of security. Her central thesis is that "this conference was not built for you" for many, and that addressing this is not merely "the right thing to do," but an operational imperative for effective security.
The talk, delivered by a prominent figure in the Dutch cybersecurity community and founder of the Women in Cyber Security Community Association (WiCa), draws on extensive experience both on and behind the scenes of numerous conferences, including the all-women speaker event Wikon. Stekelenburg speaks directly from her experience as a white woman in cybersecurity, acknowledging that while she does not represent all forms of diversity, the failures to achieve even this "solved" diversity issue highlight deeper systemic problems. Her insights are crucial for anyone involved in organizing, speaking at, or attending security conferences, offering a roadmap for genuine inclusion that benefits the entire field.
This presentation is highly relevant to the cybersecurity community because it directly links the lack of diverse perspectives to tangible security failures. By demonstrating how a narrow understanding of who constitutes an "expert" leads to a narrowed threat model, Stekelenburg argues that a lack of inclusion is a fundamental vulnerability. The talk challenges the industry to treat diversity as a quality problem, requiring the same rigor and intentionality applied to technical security challenges, ultimately aiming to build a more robust and resilient security landscape.
Background
▶ Watch: Introduction: Who are these conferences for? (0:00)
The cybersecurity landscape, despite its rapid evolution and critical importance, continues to grapple with a significant lack of diversity, particularly concerning gender representation. Historically, the field has been dominated by men, a trend deeply rooted in societal conditioning that begins in childhood. Stekelenburg highlights how traditional gender roles, reinforced through seemingly innocuous choices like toys (dolls for girls, blocks for boys), types of compliments (appearance for girls, technical prowess for boys), and educational guidance (boys encouraged into STEM, girls often discouraged), steer women away from technical fields long before they even consider a career.
This early conditioning manifests in stark statistics: only around 20% of the global cybersecurity workforce are women. This minority status creates a cascade of challenges for women entering or working in the field, including increased performance pressure, a diminished sense of belonging, and higher dropout rates from technical education programs. The scarcity of visible role models further exacerbates the problem, making it difficult for young girls and aspiring professionals to envision themselves as experts or leaders in cybersecurity. Many women who do succeed often credit a specific role model for inspiring their path.
Stekelenburg's personal journey exemplifies this challenge and the proactive steps needed to counter it. Despite her own significant fear of public speaking, she made a deliberate choice to become a visible role model, engaging in podcasts, TV shows, and presentations, including a national campaign that resulted in shaking hands with the King of the Netherlands. This commitment led her to found the Women in Cyber Security Community Association (WiCa), which now boasts over 1,600 members, predominantly women, supporting each other in their cybersecurity careers. She is also a key organizer for conferences like Wikon, an event specifically designed to feature only women speakers, and plays a role in Defcon Holland and Hacker Hotel, demonstrating a deep engagement with the community's structural issues. This extensive background provides her with a unique vantage point to analyze why cybersecurity conference stages, despite claims of meritocracy, often fail to reflect the broader talent pool.
Key Findings
▶ Watch: Conferences decide belonging long before CFP submission (4:45)
Stekelenburg's talk unveils several critical findings that challenge conventional wisdom about conference organization and diversity. The core discovery is that the perceived lack of diverse speakers is not due to a shortage of talent or malicious intent, but rather a complex interplay of systemic assumptions and design choices that subtly, yet effectively, exclude underrepresented groups. "The problem is not bad intent. The problem is that this sentence quietly relies on a set of assumptions," she asserts, referring to organizers who claim they simply "pick the best talks."
Firstly, conferences operate on an unspoken assumption of equal access. This includes equal time and resources for crafting CFP (Call for Papers) submissions, preparing presentations, securing employer support, handling visa requirements, and critically, managing caregiving responsibilities. For many women, particularly mothers, these factors are far from equal, creating a significant barrier to entry. Secondly, the assumption of equally distributed confidence is flawed. Factors like prior rejections or the prospect of being "the only one" on stage disproportionately affect women and minorities, leading them to self-select out of submitting, regardless of the quality of their potential talk.
Thirdly, visibility is not equally safe for everyone. Women speakers often face online harassment, targeting, or the dismissive label of being a "diversity speaker." These real risks lead individuals to make different choices about public visibility, further reducing the pool of potential speakers. Finally, the assumption of equal network effects is incorrect. Personal networks play a crucial role in early CFP awareness, encouragement to submit, and access to pre-submission feedback, advantages often enjoyed by those already well-connected within historically male-dominated circles.
Beyond these foundational assumptions, Stekelenburg identifies that the "look and feel" of a conference—its website design and speaker pages—sends powerful, often exclusionary, signals. The prevalent aesthetic of dark backgrounds, neon accents, and high contrast, culturally coded as masculine in Western Europe's cybersecurity space, unconsciously communicates who the conference is for. When speaker pages are almost entirely populated by white men, it reinforces the perception that the space is not inclusive, deterring diverse individuals from even considering submission. This finding underscores that design choices are not neutral invitations; they actively shape who feels they belong.
Ultimately, the most profound finding is that diversity doesn't make systems secure because it's fair or the right thing to do; it makes them secure because it introduces friction and disagreement and visibility. This reframing from a moral argument to an operational argument highlights that a narrow group of experts, by definition, possesses a narrow threat model. Without diverse perspectives, critical vulnerabilities can be overlooked, as strikingly illustrated by the Apple AirTag example, where the initial design failed to account for stalking risks predominantly faced by women, necessitating a belated, costly security overhaul.
Technical Deep Dive
▶ Watch: Unconscious assumptions create barriers, not bad intent (5:30)
While Stekelenburg's talk does not delve into traditional cybersecurity exploits or code, it offers a profound technical deep dive into the systemic architecture of exclusion and the engineering principles required for effective inclusion within the cybersecurity conference ecosystem. The "technical" aspect lies in dissecting the underlying mechanisms and processes that govern who participates and, critically, how these mechanisms can be re-engineered for different outcomes.
The speaker meticulously breaks down the structural components that contribute to a lack of diversity, starting with the pre-CFP phase. She identifies several systemic assumptions that act as invisible filters:
- Equal Access: This assumes everyone has comparable time, money, employer support, visa opportunities, and childcare arrangements. In reality, these are often unequal, particularly impacting women who frequently bear a disproportionate burden of caregiving. A technical system designed without considering varying user constraints will inevitably fail certain user groups.
- Equal Comfort in Submitting: This overlooks the psychological barriers. Prior rejections, the fear of being "the only one" (e.g., the only woman of color on stage), or imposter syndrome can deter highly capable individuals. This is a human-factors engineering problem, where the system's interface (the CFP process) is not designed to solicit input from all potential users.
- Equal Safety in Visibility: For many, public speaking entails significant risks of online harassment or being tokenized as a "diversity speaker." When the "threat model" for visibility differs so drastically, individuals make rational choices to avoid it. A secure system must account for varied threat landscapes for its users.
- Equal Networks: Access to informal networks provides early CFP announcements, encouragement, and crucial pre-submission feedback. This creates an "insider track" that disadvantages those outside established circles. This mirrors a network architecture where certain nodes have privileged access to information and support.
Stekelenburg then moves to the visual and linguistic programming of conferences. She notes that conference websites, with their prevalence of black/dark backgrounds, neon green/red/blue accents, and high contrast, employ a visual language "culturally very coded as masculine" in Western Europe. This is not about colors being inherently gendered, but about their cultural gendering of design. These design choices, she argues, are not neutral; they are "invitations" that signal who belongs. Similarly, inclusive language in CFPs is paramount. Terms like "rockstar speaker" or "deep technical talks" can inadvertently filter out potential speakers who don't see themselves fitting a hyper-specialized, often male-coded, archetype. Replacing these with phrases like "all experience levels are welcome" or "practical lessons and failures are encouraged" removes unnecessary filters, expanding the pool of potential submissions. This is akin to optimizing an input validation system to accept a broader, yet still valid, range of inputs.
To counter these systemic biases, Stekelenburg proposes concrete engineering solutions for inclusion:
- Active Outreach: Instead of passively waiting for submissions, organizers must "actively find the speakers that you want." This involves direct engagement, connecting on social media, and utilizing resources like
she speaks cyber—a directory of women in cybersecurity speakers. This is a proactive data acquisition strategy, rather than a reactive one. - Blind Review Process: In the CFP review board process, an initial blind review phase (without names, genders, or identifying information) significantly reduces unconscious bias. Reviewers focus solely on content quality, clarity, relevance, technical depth/originality, and excitement level. This is a form of data sanitization or anonymization to ensure objective assessment.
- Layered Review: After the blind phase, a non-blind review allows for balancing diversity, followed by a final curation for overall topic balance. This iterative process ensures both quality and representation.
- Budgeted Inclusion: This involves more than just money; it's about allocating resources for flexibility. Offering flexible timing for speakers with caregiving responsibilities, providing travel compensation, and dedicating time for coaching and mentoring are crucial. This is resource allocation optimized for a diverse user base, recognizing varied needs.
The most compelling "technical" argument lies in the threat modeling analogy. Stekelenburg argues that "who we see as experts shape what we protect." If a security team is homogenous, their collective perspective on risks will be narrow, leading to an incomplete threat model. The Apple AirTag case serves as a poignant example: designed primarily by white men, the initial product overlooked the significant stalking risks predominantly faced by women. This oversight necessitated a year of "backtracking" and security improvements (e.g., pop-up alerts on non-owner iPhones/Androids), demonstrating how a lack of diverse perspectives in the design phase directly translates to security vulnerabilities and costly remediation. Diversity, therefore, is not a "soft skill" but a hard requirement for robust security engineering, introducing crucial "friction and disagreement and visibility" necessary for comprehensive risk identification.
Demo / Proof of Concept
▶ Watch: Lack of role models impacts girls' career choices (10:00)
While Chantal Stekelenburg's keynote does not feature a traditional technical demonstration of a cybersecurity tool or exploit, the entire presentation serves as a powerful proof of concept for the principles of intentional inclusion she advocates. Her own extensive work and the success of the initiatives she has founded or been involved with stand as empirical evidence that these strategies yield tangible results.
The primary demonstration of these principles is the Women in Cyber Security Community Association (WiCa). Founded by Stekelenburg, this organization has grown to over 1,600 members, predominantly women in the Netherlands. WiCa's monthly meetups, focused on networking, learning, and mutual encouragement, directly address the issues of unequal networks, lack of role models, and confidence distribution that Stekelenburg identifies as barriers. Its growth and active participation demonstrate that when a community is intentionally built to be inclusive and supportive, women are eager to engage and develop within the cybersecurity sector.
Furthermore, Stekelenburg's involvement in organizing conferences, particularly Wikon, serves as a direct, large-scale demonstration of effective inclusive practices. Wikon is explicitly designed to feature only women speakers, directly confronting the issue of representation on stage. The existence and success of such a conference prove that it is entirely possible to curate a high-quality speaker lineup composed entirely of women, thus dispelling the myth that there aren't enough qualified women to speak. Her personal journey, overcoming a significant fear of public speaking to become a prominent role model through podcasts, TV shows, and national campaigns, further reinforces the idea that intentional effort can shift individual and collective outcomes.
The "proof" also extends to the practical tips she provides for conference organizers, such as using inclusive language in CFPs, implementing blind review processes, and practicing active outreach. These are not theoretical constructs; they are strategies already "used by conferences that consistently improve their speaker diversity." By showing screenshots from the Wikon review manual, she demonstrates that a structured, bias-aware CFP process is not only feasible but actively implemented in successful inclusive conferences. In essence, Stekelenburg doesn't show a demo; she is the demo, and her work is the proof of concept for building genuinely inclusive and diverse cybersecurity communities and events.
Defensive Implications
▶ Watch: Speaker's personal journey to become a role model (11:30)
The defensive implications of Chantal Stekelenburg's talk extend far beyond conference organization, offering crucial insights for how the cybersecurity industry can strengthen its collective defenses. Her core argument, that diversity is an operational imperative for security, translates directly into actionable strategies for individuals, teams, and organizations.
Firstly, for conference organizers, the message is clear: intentionality is paramount. Defenders must move beyond passive calls for papers and actively cultivate a diverse speaker lineup. This means:
- Re-evaluating CFP Language: Scrutinize calls for papers for exclusionary terms like "rockstar" or "deep technical expert." Instead, use inclusive language such as "all experience levels welcome" and "practical lessons and failures are encouraged" to broaden appeal and remove unnecessary filters.
- Proactive Outreach: Do not wait for diverse submissions. Actively identify and encourage potential speakers from underrepresented groups through direct invitations, social media connections, and utilizing resources like
she speaks cyber. - Implementing Blind Review: Adopt a multi-stage CFP review process, starting with a blind review where speaker names, genders, and other identifying information are hidden. This mitigates unconscious bias, ensuring talk quality is the primary selection criterion. Subsequent non-blind stages can then be used to balance diversity and overall topic coverage.
- Budgeting for Inclusion: Allocate resources beyond standard speaker compensation. This includes offering flexibility for parents (e.g., timing talks around childcare), providing travel and accommodation support, and investing time in coaching and mentoring first-time or nervous speakers. These are investments in human capital that yield long-term returns in expertise and representation.
- Auditing Visual Design: Critically examine conference branding, websites, and promotional materials. If the visual language is culturally coded as masculine, it sends an unwelcoming signal. Inclusive design does not mean "pinkwashing," but rather ensuring the aesthetic appeals to a broad audience, signaling that "not one aesthetic is the default."
- Diversifying Speaker Pages: Actively work to ensure speaker pages reflect diversity. A page dominated by one demographic (e.g., white men) is a strong deterrent for others, signaling a lack of belonging.
Secondly, for security teams and organizations, the talk underscores the vital link between team diversity and robust threat modeling. If a security team lacks diverse perspectives, its understanding of potential threats and vulnerabilities will be inherently limited.
- Diversify Security Teams: Actively recruit and foster diverse talent within security departments. A team composed of individuals with varied backgrounds, experiences, and identities will naturally identify a broader range of threats and potential attack vectors. The Apple AirTag example serves as a stark warning: a homogenous team overlooked a significant stalking threat, leading to a reactive and costly security overhaul.
- Cultivate Inclusive Work Environments: Create a workplace culture where diverse voices are not just present but are actively heard, valued, and empowered to challenge assumptions. This "friction and disagreement and visibility" is crucial for uncovering blind spots and strengthening security posture.
- Support Employee Visibility: Encourage and support women and other underrepresented employees to speak at conferences, publish research, and take on visible roles. Provide mentoring, public speaking training, and resources to mitigate the unique risks they might face. This not only elevates individual careers but also provides crucial role models for the next generation.
In essence, the defensive implication is to treat inclusion as a critical security control. Just as organizations invest in firewalls, intrusion detection systems, and threat intelligence, they must invest in building diverse and inclusive environments. A diverse group of "experts" will inherently build a more comprehensive threat model, identify a wider array of vulnerabilities, and ultimately engineer more resilient and secure systems. Neglecting diversity is, in itself, a significant security risk, leaving organizations vulnerable to threats that a narrow perspective simply cannot foresee.
Key Takeaways
- Inclusion is an Operational Security Imperative: The lack of diversity in cybersecurity, particularly on conference stages, is not merely a moral failing but a systemic vulnerability that leads to incomplete threat models and tangible security blind spots, as exemplified by the Apple AirTag incident.
- Systemic Barriers, Not Bad Intent: Exclusion is primarily driven by unconscious assumptions and comfortable norms, not malicious intent. These include unequal access to resources, uneven distribution of confidence, varying safety risks associated with visibility, and disparate access to professional networks.
- Design and Language Shape Belonging: Conference website design (e.g., culturally masculine aesthetics) and the language used in CFP (Call for Papers) (e.g., "rockstar speaker") send powerful signals that can inadvertently deter diverse speakers. Intentional, inclusive design and language are crucial invitations.
- Active Strategies are Essential for Diversity: Waiting for diverse submissions is insufficient. Conference organizers must proactively seek out, encourage, and support speakers from underrepresented groups through direct outreach, blind review processes, and budgeted inclusion (e.g., flexible timing, mentoring, travel support).
- Diverse Perspectives Lead to Better Security Outcomes: A homogeneous group of experts will always have a narrower perspective on risks. True diversity introduces necessary "friction and disagreement and visibility" that is fundamental for identifying a broader spectrum of threats and building more robust and resilient security systems.
About the Speaker(s)
Chantal Stekelenburg is a prominent figure in the cybersecurity community, known for her passionate advocacy for diversity and inclusion, particularly regarding gender representation. As a white woman working in cybersecurity, she brings direct personal experience and a nuanced understanding of the challenges women face in the industry. Stekelenburg is the founder of the Women in Cyber Security Community Association (WiCa), a thriving organization primarily based in the Netherlands with over 1,600 members, dedicated to networking, learning, and mutual encouragement among women in the field.
Beyond WiCa, Chantal is a prolific conference organizer, having played key roles in events such as Apple Y 2025, Defcon Holland, and Hacker Hotel. She is also the organizer of Wikon, a unique conference designed exclusively for women speakers in cybersecurity, demonstrating her commitment to creating platforms for underrepresented voices. Despite openly admitting to a significant fear of public speaking, Stekelenburg has deliberately chosen to be a visible role model, engaging in podcasts, TV shows, and presentations, including a national campaign that led to her shaking hands with the King of the Netherlands. Her multifaceted involvement, from grassroots community building to high-profile conference organization and public advocacy, positions her as a leading voice in shaping a more inclusive future for cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Stekelenburg is a credible, committed speaker with real community-building credentials, and the AirTag threat-model reframe is the talk's only genuinely sharp technical hook. The rest is a competent, well-structured argument for inclusive conference design that any experienced organizer has already heard in some form — delivered well, but not advancing the conversation meaningfully beyond what's already circulating in DEI-focused security circles.
Heather Calloway (CISO) — SOLID
Stekelenburg makes a legitimate and underappreciated argument — that homogeneous teams produce narrow threat models — but the talk is primarily aimed at conference organizers, not security leaders. The Apple AirTag example is the sharpest moment, but it carries more weight than the surrounding structure earns.