Exclusion Is a Vulnerability: Patching the Gender Gap in Tech - Willem

Willem

Disobey 2026 · Main Stage

Watch on YouTube

Visual summary for Exclusion Is a Vulnerability: Patching the Gender Gap in Tech - Willem by Willem
Visual summary for Exclusion Is a Vulnerability: Patching the Gender Gap in Tech - Willem by Willem

Key moments

  1. 0:00 Introduction: Exclusion as a vulnerability in tech
  2. 2:00 Talk outline: How to debug bias in tech
  3. 3:45 Current data: Low percentage of women in ICT
  4. 5:50 EU Digital Decade goals for female ICT workforce
  5. 7:55 Understanding bias: Definition and systemic nature
  6. 8:50 Hiring bias: Resume callbacks and gender stereotyping
  7. 11:00 Interview panel effects on hiring decisions
  8. 12:00 Everyday bias: Microaggressions post-hiring

Exclusion Is a Vulnerability: Patching the Gender Gap in Tech

Speakers: Willem, Incident Responder, KPN System Integrator Division

Conference: Disobey

YouTube: https://www.youtube.com/watch?v=CWX_aax6z1A

Overview

In a compelling presentation titled "Exclusion Is a Vulnerability: Patching the Gender Gap in Tech," Willem challenged the prevailing notion of the tech industry as a pure meritocracy. He argued that the persistent gender gap is not merely a social issue but a significant vulnerability that compromises the integrity, security, and innovation potential of the entire technology sector. Framing bias as a "bug" in the system, Willem meticulously presented data and research to illustrate how systemic biases lead to a "leaky pipeline" for women in tech, resulting in substantial talent loss and tangible business risks.

The talk aimed not to assign blame but to identify and rectify systemic issues within the tech culture. Willem, an incident responder himself, approached the problem with a security mindset, advocating for the implementation of specific "controls" to "debug bias" and monitor progress. His analysis spanned from hiring practices and everyday interactions to the impact on open-source contributions and the development of artificial intelligence, ultimately concluding that the exclusion of diverse talent creates measurable security blind spots and economic losses.

Willem underscored the urgency of addressing this vulnerability, particularly as the European Union aims to significantly expand its ICT workforce. The presentation served as a critical call to action for the industry to move beyond superficial acknowledgments of diversity and to implement concrete, data-driven strategies to foster a truly inclusive and merit-based environment, thereby strengthening the sector against its self-inflicted weaknesses.

Background

▶ Watch: Introduction: Exclusion as a vulnerability in tech (0:00)

The pervasive gender gap in the technology sector is a widely acknowledged issue, yet its implications, particularly from a security perspective, are often underestimated. Willem commenced his talk by highlighting stark statistics from Eurostat, revealing that the percentage of women in ICT jobs across the European Union has grown by a mere 2.3% over seven years, reaching an average of nearly 20% by the end of 2024. While some countries like Estonia and Romania show higher percentages (around 27%), others like the Czech Republic, Greece, and Italy lag significantly (around 15%), indicating a systemic rather than localized problem. With an estimated 10 million ICT professionals in the EU, this translates to over 8 million men and nearly 2 million women.

This imbalance stands in stark contrast to the European Union's ambitious "Digital Decade" roadmap, which aims to double the ICT workforce to 20 million by 2030, with at least 25% of these roles filled by women. Achieving this goal would require expanding the female ICT workforce from nearly 2 million to 5 million in just six years—a monumental task given current growth rates. Willem posed a crucial question: why do some countries perform better than others in attracting and retaining women in tech? His answer pointed to bias as a primary contributor to what he termed a "leaky pipeline."

Historically, the field of computing was far more gender-nuanced. Willem reminded the audience of pioneers like Ada Lovelace, the ENIAC 6 (six women who programmed the first electronic general-purpose computer), Grace Hopper, and Margaret Hamilton. Before World War II and into the late 19th century, software engineering was often considered a female occupation, with men predominantly focused on hardware. The shift towards a male-dominated field, particularly after the war, was a cultural rather than a technical evolution, laying the groundwork for many of the biases observed today. Understanding this historical context is crucial for grasping why the problem exists and how deeply ingrained some of these biases have become within the industry's foundations.

Key Findings

▶ Watch: Current data: Low percentage of women in ICT (3:45)

Willem's presentation unequivocally established that the exclusion of women in technology is a profound vulnerability, not merely a societal concern. He meticulously detailed several key findings that underscore the detrimental impact of this gender gap on security, innovation, and business performance.

Firstly, bias is a systemic bug: Willem defined bias, drawing from the American Psychology Association, as a "tendency, inclination or prejudice towards or against something or someone." He likened it to a "bug" in the system, emphasizing that everyone possesses biases, but crucially, these biases manifest consistently enough to be detectable and countered through systemic controls. This "bug" infiltrates various stages of the tech pipeline, from hiring to daily interactions.

Secondly, pervasive hiring bias leads to a "leaky pipeline": Research on resume callback studies and gender occupational stereotyping demonstrates how subconscious biases lead to female names being overlooked for "male ICT jobs," and vice-versa for "female jobs." With a heavily male-dominated industry, this naturally perpetuates the imbalance. Willem warned that the advent of AI in recruitment could exacerbate this problem by encoding existing biases into automated systems. He also highlighted the interview panel effect, where all-male panels tend to hire more men, further reinforcing homogeneity.

Thirdly, everyday bias acts as a "deterioration of function": Beyond hiring, women in tech face persistent microaggressions and role assumptions, such as being interrupted in meetings or assumed to be responsible for coffee. Willem compared this constant low-level friction to the performance degradation of a Windows operating system over time, in contrast to the sustained performance of macOS. He argued that these seemingly minor "bugs" accumulate, leading to a significant "deterioration of function" for female workers.

Fourthly, bias impacts technical merit and security: A striking open-source study revealed that when names and genders were removed from Git commits, women's contributions were accepted significantly more often. Conversely, when gender information was present, male commits were favored. This finding is fundamental, showing that code quality is often secondary to the identity of the contributor. Willem hypothesized that this bias could extend to bug bounty programs, where reports from women might be disregarded, creating serious security blind spots for organizations.

Fifthly, accumulated bias creates a "toxic environment" and talent exodus: The relentless pressure from stereotyping and unpatched "subtle bugs" culminates in a toxic environment, which Willem powerfully equated to a DoS attack on female ICT workers. Research from the Capora Center (2017) indicated that 50% of women in tech experience harassment or discrimination, and 78% report imposter syndrome driven by external factors. The devastating consequence is that 50% of women quit their tech jobs before age 35, with one in four leaving the tech industry altogether. This translates to a staggering 1 in 8 (12.5%) of all female ICT employees abandoning the sector prematurely, at a time when the industry desperately needs more talent.

Finally, diversity delivers measurable business and security advantages: Willem cited research from McKinsey and Boston Consulting Group, showing that diverse companies have a 25% higher chance of outperforming less diverse companies, and those with above-average diversity achieve 19% higher innovation revenue. Critically, diverse teams are less prone to security blind spots and produce AI models that are themselves less biased. The economic cost of gender inequality in the workforce is immense, with the World Bank estimating a global GDP loss of $160 trillion by 2016. These findings collectively demonstrate that addressing the gender gap is not just ethical, but an imperative for robust security, sustained innovation, and economic prosperity.

Technical Deep Dive

▶ Watch: Understanding bias: Definition and systemic nature (7:55)

Willem, drawing on his background as an incident responder, framed the issue of gender inequality in tech through a distinct security lens, conceptualizing bias as a fundamental "bug" in the system. This metaphor extended to describing the cumulative effect of bias as a Denial of Service (DoS) attack on female ICT workers, overwhelming them until the "system stops working." This technical framing allowed for a rigorous analysis of how seemingly social issues have profound technical and security implications.

The "debugging bias" process began with an exploration of its manifestation in critical technical workflows. In the realm of recruitment, hiring bias isn't just about human prejudice; it's increasingly becoming a concern for AI-driven recruitment tools. As Willem noted, if current hiring managers, predominantly male, tend to "hire people that look like us," then AI algorithms trained on historical hiring data will inevitably learn and perpetuate these biases. This means that instead of mitigating bias, automated systems could amplify it, creating a "faulty influx" of talent and reinforcing homogeneous teams. The speaker highlighted that when homogeneous teams work on AI models, they are likely to infuse existing biases into the software itself, leading to biased outputs and potentially discriminatory applications. This isn't just an ethical problem; it's a technical flaw that can compromise the fairness, accuracy, and trustworthiness of AI systems deployed in critical applications.

A particularly illuminating example of bias impacting technical output was presented through an open-source study concerning Git commits. This research investigated the acceptance rates of code contributions based on the gender and name of the committer. The results were stark: when the gender and name were visible, male coders' commits were accepted significantly more often. However, when this identifying information was removed, women's commits were accepted at a higher rate. This finding is profoundly technical because it demonstrates that the quality of the code itself can be overridden by subconscious bias related to the contributor's identity. For open-source software, this means that potentially higher-quality contributions from women might be overlooked, leading to less qualitative code bases and missed opportunities for innovation.

Extending this observation, Willem posited a critical security implication for bug bounty programs. If bias influences the acceptance of regular Git commits, it is highly probable that it also affects the evaluation of bug bounty reports. A report submitted by a woman, especially if her name or gender is identifiable, might be "disregarded because you are being a woman," rather than assessed purely on the technical merit and severity of the vulnerability reported. This creates a severe security risk for organizations. Discarding valid vulnerability reports due to contributor bias means leaving critical systems exposed to exploitation, directly compromising the organization's security posture. This scenario illustrates how a seemingly social bias can directly translate into exploitable technical vulnerabilities.

The accumulation of unpatched "subtle bugs" of bias and stereotyping leads to a "toxic environment," which Willem precisely defined as a DoS attack. In this analogy, the "system" under attack is the female ICT worker. A DoS attack doesn't need to breach defenses; it simply needs to overwhelm. Constant microaggressions, interruptions, and the pressure of imposter syndrome—driven by external factors—overwhelm the individual, leading to a "deterioration of function" and ultimately, system failure (quitting the job or the industry). This framing transforms an abstract social phenomenon into a concrete, actionable security incident, demanding a structured "patching and monitoring" response, much like any other critical system vulnerability.

Demo / Proof of Concept

▶ Watch: Hiring bias: Resume callbacks and gender stereotyping (8:50)

While Willem's talk did not feature a live technical demonstration or a traditional proof of concept involving code or exploits, the entire presentation served as a powerful conceptual demonstration. The speaker's "proof of concept" was built upon a rigorous compilation of statistical data, academic research, and real-world examples, all meticulously presented to validate his central thesis: that exclusion is a vulnerability.

He leveraged Eurostat statistics up to 2024 to demonstrate the slow growth of women in ICT jobs across the EU, providing concrete numbers like the 2.3% increase over seven years and the current 20% average female representation. The EU Digital Decade goals (20 million ICT workforce by 2030, 25% female) served as a benchmark against which current failures were measured.

The impact of bias was substantiated by citing numerous studies: resume callback studies illustrating gender-based discrimination in hiring, research on gender occupational stereotyping, and findings on interview panel effects. The most compelling "proof" for the technical audience was the open-source study revealing that women's Git commits were accepted significantly more when their identity was anonymized, compared to when their name and gender were known. This specific example directly demonstrated how bias interferes with a core technical process, validating the speaker's claim that merit is often not the sole determinant.

The "demo" of the vulnerability's impact was further reinforced by statistics on talent retention, such as the 50% of women quitting tech jobs before age 35, and the business case for diversity, citing figures from McKinsey (25% higher outperformance) and Boston Consulting Group (19% higher innovation revenue). Finally, the World Bank's estimate of $160 trillion global GDP loss due to gender inequality by 2016 provided a macro-level "proof" of the immense economic cost of this vulnerability. In essence, Willem's talk used data as its most potent demonstration, meticulously building a case that treated social biases with the same analytical rigor applied to technical security flaws.

Defensive Implications

▶ Watch: Everyday bias: Microaggressions post-hiring (12:00)

Willem's talk, "Exclusion Is a Vulnerability," culminated in a clear set of defensive strategies and "patches" designed to address the systemic "bugs" of bias within the tech industry. His approach emphasized implementing controls and monitoring mechanisms, reflecting a security professional's mindset to debug and fix a compromised system.

The primary defensive measure is to cultivate a truly merit-based system. This means moving beyond rhetoric and actively ensuring that individuals are judged and valued solely on their contributions and capabilities, not on their identity. This requires a fundamental shift in organizational culture, driven from leadership down to every employee, where codes of conduct are not just written but rigorously followed.

Specific, actionable controls include:

  1. Structured Interviews: To counter hiring bias and the interview panel effect, organizations must implement standardized, structured interview processes. This involves asking consistent questions, using clear evaluation rubrics, and potentially anonymizing initial application stages to reduce subconscious prejudice.
  2. Clear Promotion Criteria: Ambiguous promotion pathways are fertile ground for bias. Companies should establish transparent and objective criteria for career advancement, ensuring that decisions are based on measurable achievements and skills, rather than subjective impressions or "fit" that can easily be influenced by bias.
  3. Mentoring, Amplifying, and Sponsoring Talent: Proactive support systems are crucial. Mentoring provides guidance, amplifying ensures women's voices and contributions are heard and recognized, and sponsoring actively advocates for their advancement. These actions directly combat the effects of microaggressions and imposter syndrome by building confidence and visibility.
  4. Verify Effectiveness with Data: Just as security systems require continuous monitoring, efforts to combat bias must be data-driven. Organizations should collect and analyze internal statistics on hiring, promotion, and retention, similar to the Eurostat data Willem presented. This allows for the identification of areas where "patches" are working or where new "bugs" are emerging.
  5. Conduct and Believe Exit Interviews: A critical, yet often overlooked, defensive control is to conduct thorough exit interviews and, crucially, to genuinely listen to and believe the feedback from departing employees. If women are leaving due to a toxic environment or bias, their reasons must be taken seriously and acted upon. This provides invaluable insights into systemic issues that might otherwise remain hidden, allowing organizations to fix the "leaky pipeline."
  6. Increase Visibility and Accountability: Bias often thrives in the shadows. Defenders must actively work to make bias visible by encouraging open dialogue, empowering individuals to speak up, and ensuring that issues are addressed promptly and effectively. This collective responsibility helps dismantle the "DoS attack" environment and foster a culture of respect and equity.

By implementing these "controls" and consistently "monitoring" their impact, organizations can begin to "patch" the systemic vulnerabilities caused by gender bias. This defensive posture not only improves the working environment for women but also strengthens the organization's overall security, innovation capacity, and talent retention, turning a significant vulnerability into a strategic advantage.

Key Takeaways

  • The gender gap in tech is not merely a social issue but a critical vulnerability that compromises the industry's security, innovation, and talent pool.
  • Bias acts as a systemic "bug" that infiltrates every stage of the tech pipeline, from hiring practices (e.g., resume callback bias, interview panel effects) to daily interactions (microaggressions, role assumptions).
  • The cumulative effect of unchecked bias creates a "toxic environment," akin to a DoS attack on female ICT workers, leading to high rates of attrition (50% of women quit tech before 35, 1 in 4 leave the industry entirely).
  • Bias directly impacts technical merit, as evidenced by studies showing Git commit acceptance rates influenced by gender, and potentially creating security blind spots in areas like bug bounty programs.
  • Diverse teams demonstrably outperform homogeneous ones, leading to 25% higher chances of outperformance, 19% higher innovation revenue, fewer security blind spots, and the development of less biased AI models.
  • Patching this vulnerability requires implementing concrete "controls": establishing truly merit-based systems, utilizing structured interviews, defining clear promotion criteria, actively mentoring and sponsoring talent, verifying effectiveness with data, and critically, listening to exit interview feedback to address root causes.

About the Speaker(s)

Willem is an incident responder working for KPN in their system integrator division. He identifies himself as one of the "92%" of male colleagues within his division at KPN, highlighting the gender imbalance he addresses in his talk. His professional background in incident response informs his analytical and systems-oriented approach to identifying and "debugging" bias within the technology sector. Willem's perspective is rooted in a desire to fix systemic issues through implementing effective controls, much like one would address a security vulnerability.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A well-intentioned talk that commits the exact sin it warns against: dressing up a familiar argument in technical metaphor without doing the hard technical work. The security framing is cosmetic — DoS analogies and 'patching bias' language don't transform HR policy into security research. The underlying data is real but years old and widely cited elsewhere.

Heather Calloway (CISO) — WEAK

Willem brings a sincere, systems-minded framing to a real problem, but the talk doesn't close the gap between the research it cites and the institutional decisions that would actually change anything. The security metaphor is a stylistic choice, not an analytical one — and no one in a position to act leaves with a clear mandate.

→ Top-rated talks at Disobey 2026

All talks from Disobey 2026