Story: Empowering Women to Leadership in Cyber—USTTI Course
Our colleague Ariane (Legal, Compliance & Information Security) was invited to the US for the “Empowering Women to Leadership in Cyber” program run by the US Telecommunications Training Institute (USTTI) and the Global Cybersecurity Forum (GCF).
The two-week program took place in Washington, D.C., Boulder (Colorado), and Los Angeles and is aimed at women from the cybersecurity sector worldwide. 22 women from 18 countries took part in the program. Ariane was the first participant from Germany.
In this post, Ariane shares the program's content, the stops on her journey, and her personal impressions.
What is USTTI
The US Telecommunications Training Institute (USTTI) is a nonprofit organization that has provided tuition-free training for professionals and leaders in telecommunications, regulation, and cybersecurity since 1982.
Through a range of courses and training programs, USTTI aims to prepare professionals worldwide for leadership roles, help shape regulatory frameworks, and close the digital gender gap.
These free programs are supported by the US government as well as industry. One of the sponsors is ICANN, the Internet Corporation for Assigned Names and Numbers, the central organization for managing domain names and, as such, the most important institution in our industry.
The “Empowering Women to Leadership in Cyber” program and course content
The “Empowering Women to Leadership in Cyber” program specifically supports women in the cybersecurity field. It provides technical, strategic, and methodological knowledge for leading cybersecurity operations, building a security culture within organizations, and breaking down structural barriers to leadership. Alongside talks by international experts from government, industry, academia, and civil society, the program includes hands-on site visits and interactive workshops.
Right at the start of the program, we met Grace Koh, who shared insights from her work as an ambassador and former Special Assistant to the President for Cybersecurity Policy.
Besides various talks and sessions on different cybersecurity topics, such as cyberattacks in the context of AI, there were also a total of six sessions on the Principles of Leadership. These covered topics such as strategic leadership, talent development, communication, and project planning. These theoretical aspects were reinforced with hands-on examples and case studies, as well as interactive group sessions. We discussed various scenarios and got the chance to test our decision-making. It was especially reassuring to see that others would have made similar decisions, and it helped highlight where each of our individual strengths lay.
Throughout, the focus was on supporting women who have to assert themselves across different cultures and in male-dominated industries. One sentence from Grace Koh has stuck with me in particular: “If you deserve to sit at the table—sit at the table!”
To close out the program, there was one special highlight: a visit to ICANN's headquarters in Los Angeles. As an accredited registrar, ICANN is the central institution in our industry, which made this stop especially exciting for me. There, we had the opportunity to ask open questions and hear firsthand accounts directly from the source.
My takeaway from the program
I'm incredibly grateful for these two very educational weeks, and just as grateful for the many wonderful women I got to meet and spend this time with. We'll stay in touch, and there are already plans for joint projects. It was great to see that we're all dealing with similar challenges, and that despite our different roles, whether in government or the private sector, we can support one another, since we all bring different perspectives to the table.
A lot from these two weeks translates directly to my work at INWX. Topics like critical infrastructure, cyber hygiene, and the current threat landscape are directly relevant to our everyday work as a registrar. Whether it's securing our networks, handling security incidents, or implementing regulatory requirements like NIS2. I was able to build valuable connections and gather ideas for implementation and employee training. I also took a lot away on a personal level, and I'm already looking forward to what's next.



The program in detail
Washington—USTTI Office
In the first week of the training, we were welcomed by Jim O'Connor (Chairman and CEO, USTTI) at the USTTI office. To kick things off, both USTTI and GCF were introduced to us. Cameron Kiosoglous (Drexel University) introduced us to the leadership topics of the training and, together with the group, set expectations for the learning environment and our wishes for the outcomes of “Cohort 6” of the “Empowering Women to Leadership in Cyber” program. We were given the space to freely share our expectations and wishes for the program, especially around how we would treat each other and work together.
Jim O'Connor then gave us an overview of the costs of cyberattacks, current threats, and possible countermeasures. In small groups, we worked interactively to set priorities and develop our own cybersecurity strategy for a fictional country we invented ourselves. This was our first group exercise, and it gave us the chance to get to know each other and form a first impression. Developing a strategy together was genuinely fun.
Over the following days, Cameron Kiosoglous went deeper with “Principles of Leadership, Session 1” (the first of six total sessions), covering systems thinking, strategic leadership, and leadership development, including a self-assessment of our leadership qualities and a discussion of the barriers women face in the cyber industry, along with possible development plans. One of the highlights of the first week was Grace Koh (Vice President, Governmental Affairs). She shared her leadership experience from her work as an ambassador and former Special Assistant to the President for Cybersecurity Policy. Grace is a genuinely fascinating person, and her relaxed, open manner made it easy to follow along and ask open questions about her experiences. She made time for each of us individually and shared her contact details, giving us the chance to stay in touch with her anytime. One thing that stood out to me from her session was how she encouraged us in our abilities. She also reminded us that women often feel they need to know and understand everything before stepping into a situation, whereas men tend to approach it very differently. Be honest, friendly, and steady; you're allowed to make mistakes. Be honest, use your skills, and be willing to ask for help; you don't need to know everything. One sentence in particular has stayed with me: “If you deserve to sit at the table—sit at the table!”
The first week also included a site visit to the Cyber Bytes Foundation (led by Nancy Pattillo, Executive Director). She showed us how they're building their own cyber ecosystem there, how cyber education and outreach are structured, how the cybersecurity talent shortage can be addressed, and how targeted access can be created for women and underrepresented groups.
In “Session 2” Cameron Kiosoglous covered mentoring, talent development, and ways to help women overcome career barriers. Another highlight for me was the session with Beth Porter (KITD). This session was an exciting mix of technical and organizational content. She spoke about cyber resilience in the age of AI and gave an update on the current threat landscape, taking AI models and agents into account. In her session, she covered current cyberattacks. What I enjoyed most was whenever we got to participate interactively. Beth gave each group a scenario to work through and had us develop a cybersecurity strategy for handling a security incident. We got to act as a CISO and then present our approach. That was especially rewarding for me and showed me where my strengths lie and that my actions and ideas for handling incidents actually line up with how other CISOs would approach it.
Talia Dweck (The Internet Society) led a scenario-based, interactive session on practical strategies for tackling complex cybersecurity challenges across different communities worldwide.
To close out the week, Cameron Kiosoglous covered communication and stakeholder management in “Session 3,” including effective communication approaches for public speaking and crisis communication, specifically in the context of women in leadership positions. A weekly recap with group discussion rounded off the week, summarizing the key takeaways and how they apply to the cybersecurity industry.
Boulder—Home of USTTI's Founder
The next stop on the trip took us to the place where USTTI's founder, Michael Gardner, lived until the end of his life.
Sean Gorman (CEO of Zehr.xyz) led a session on protecting critical infrastructure, covering the vulnerabilities it faces, how they can be exploited, and what measures should be taken to secure networks and critical infrastructure given today's threat landscape. Throughout his explanations, he covered both network and physical infrastructure. I found the topic of cross-referencing public sources, which affects every one of us, both fascinating and a little unsettling. This was followed by an in-depth Q&A session, where participants' open questions on the topic were discussed.
At the end of the day, a special reception took place in the evening, attended by Theresa Gardner, the wife of USTTI founder Michael Gardner, which allowed for personal conversations in an informal setting. She played a major role in founding USTTI by supporting Michael Gardner.
The leadership principles track continued with “Session 4” with Cameron Kiosoglous, focused on program planning and project management. We received practical tools for leading initiatives, workshops, and bootcamps, and learned how to steer projects efficiently from planning through to execution, particularly for training employees in cybersecurity. The goal was to achieve impactful results, deepen ideas around how cybersecurity topics are communicated, and at the same time promote the active participation of women in the global cyber workforce.
Los Angeles—ICANN Headquarters
Los Angeles was the final stop of the program for us. We kicked things off with a genuinely fascinating topic: cyber diplomacy, presented by Jim O'Connor. It explored what diplomatic action actually means in the digital space and how you can position yourself as a cyber diplomat. A perspective that once again made clear just how closely intertwined technology and international relations have become and how diplomatic communication can help. I found the comparison of cyber diplomacy to a game of billiards rather than chess particularly interesting, since along the way you keep encountering people beyond just your intended audience, creating an impact that's difficult to fully grasp. Cyber diplomacy means having the empathy to put yourself in someone else's shoes. Topics like compromise, negotiation, active listening, exchange, and especially “the art of talking without really saying anything” were core parts of the session.
This was followed by “Session 5” with Cameron Kiosoglous. This time, the focus was on cultural competence and advancing women into leadership positions, particularly in industries traditionally dominated by men. We looked at strategies for specifically empowering women, the cultural dynamics at play, and how to create equal opportunities. General challenges were also addressed here and discussed in groups, with some solutions found along the way.
My personal, absolute highlight was the visit to ICANN's headquarters. Naela Sarras (Vice President of Stakeholder Engagement, North America) and Andee Hill (Senior Director of the Global Domains Division at ICANN) first introduced ICANN's work and spoke openly about which skills and strategies actually work in the cybersecurity sector and which don't. We discussed real cases and had the chance to ask Andee Hill questions directly during a Q&A. I found these honest, firsthand accounts especially great. On top of that, as INWX and an ICANN-accredited registrar, we're closely connected to ICANN's work. Meeting these two women in person and having such an open exchange was genuinely valuable.
The day wrapped up with a session on cyber hygiene and culture with Jim O'Connor. It was a very hands-on look at the steps individuals, organizations, and even entire nations can take to minimize the impact of cyberattacks, a solid, practical close to a content-packed day. The comparison to “not showering” really stuck with me.
Another part of the leadership principles series was the final “Session 6” with Cameron Kiosoglous. This closing session covered the ongoing development of cybersecurity expertise: how national and organizational cybersecurity strategies can be shaped and how to influence political decision-making and drive systemic change. A particular focus was placed on how to actively advocate for greater participation of women in the cyber workforce.
The two training weeks wrapped up with the “Now What?” session. Together, we revisited the key takeaways from the entire program and discussed how each of us could translate what we'd learned into our own concrete development plans. We got to present additional ideas building on our originally submitted implementation plans and exchange thoughts with one another. For me, this was a truly valuable way to close things out, because it wasn't just about absorbing knowledge; it deliberately looked ahead: What am I taking away, and how do I actually put it into practice now? Some great ideas came out of it, both for INWX and for me personally.

Ariane Weik
Ariane possesses extensive expertise in topics such as compliance and information security. Through her engagement within ICANN, she has gained deep knowledge of applicable regulations and standards. In her articles, she makes these complex topics understandable and practical.