Skip to main content
BUSINESS-RESOURCE • 8 min read

Women in Cyber: Laura Reid on management, continuous learning, and advice for the next generation

As part of our ongoing series spotlighting cyber security leaders within our community, we sat down with Laura Reid, who runs the Continuous Security Testing team at Claranet. We talked about her path into the industry, how she approaches management and creating psychological safety, and the advice she'd give to anyone breaking into, or switching into, a career in cyber.

On her role and how she got into cyber

Laura leads a team of 14 pentesters at Claranet, overseeing the company's continuous pentesting service.

"I come from a pentesting background, that's what I did when I first got into the industry. In my present role, I run our continuous security testing team at Claranet, so still in pentesting, but now in the management side of it. I've got a team of 14 pentesters, which make up the managed service side of how we deliver pentesting. It's a lot more fast-paced, a continuous testing environment, bringing pentesting into more of a modern-day model.”

Her route into the industry wasn't planned from the start. Cyber wasn't even something she knew existed as a career option when she was younger.

"My career, in all honesty, started back at university. I didn't know I was going to get into cyber at any point in my teenage years, purely because I didn't know it was a thing back then. I didn't know at 16, 17 that you could do cybersecurity as a degree, it was an unheard-of thing.

I did computing at A-level, that was one of the subjects I was excelling in. It was that or the psychology route. When I went to university open days and sat in on the computing talks, I realised cybersecurity was something you could actually do.

I ended up at a talk at Leeds Beckett University where they did this really cool demonstration of hacking a computer, then hard drive analysis, this whole cool CSI thing I didn't know existed. So I kind of fell into it by chance, just from ending up at that talk."

A placement year set the direction for the rest of her career.

"I did a placement year at university at a company called Sec-1, which Claranet later acquired. From then on I knew that's what I wanted to do once I graduated. Sec-1 were kind enough to keep me on after I finished my degree, and I did about six years as a pentester."

On moving into training and mentoring the next generation

Before stepping fully into management, Laura spent time in a blended role helping train new pentesters coming into the industry, something she says shaped how she now approaches leadership.

"I moved into a more blended L&D role, still pentesting a lot of the time, but also helping train the new generation of pentesters coming through. People tend to join this industry quite junior, so it was my role to help put those pathways together and get them up to speed as quickly as possible. From there, I moved into the role I'm in now. I don't do the actual pentesting anymore. It's still a technical-focused role, I just don't do the day-to-day testing myself."

On mentors

Laura credits several people, from university lecturers to her first team leader, with shaping her early confidence in a male-dominated field.

"There were some mentors at university, some of my lecturers, who helped me find my place. When I first turned up, there were hardly any women in my course. It was very male-dominated, and that was intimidating. Walking into a packed lecture theatre with only a handful of women, you take a look at that and think, 'okay, I'm only 18, this is quite intimidating.'

Then as I got into the industry, my first-ever team leader was fabulous at instilling that confidence, that I do know what I'm doing. I think everyone has imposter syndrome, but as a woman in a male-dominated industry, that imposter syndrome feels almost expected, you do second-guess yourself more. He taught me a lot of what I ended up knowing as a pentester.

And there've been multiple people at Claranet over the years, too. I've got a really good blend of mentors I could go to for advice, who've helped me out one way or another as I've gone through my career."

On what she instills in new joiners

"A lot of it is: don't be scared of failing. There's this energy, especially in tech and cyber, that you should know everything from day one, and no one ever does. People move through their careers and forget they were a junior once. You end up scared to try things in case they don't pay off. The more people can say, 'I'm here to learn and do my role, and I'm going to try what I can,' and focus on their own development rather than comparing themselves to everyone else, the better, because there's so much to know in this industry, and that can be daunting. From the women-in-tech side specifically: genuinely own your role. I deserve to be here just as much as anyone else. It's not easy, but don't let that factor into how you think about your job or your career."

On the never-ending nature of learning in cyber

"Everything related to Mythos and the AI developments that have come out, that was never a thing when I first started. I've had to combat all of that now, 14 years since starting my degree. People don't always realize that everyone is still learning, there are seniors using learning platforms who've been testing for years and are still picking up new things. It's just a never-ending cycle of having to keep going. But that’s what makes it exciting."

On leadership, safe spaces, and admitting mistakes

Asked about the industry-wide challenges around burnout and the fear of admitting mistakes, Laura reflected on how she tries to create psychological safety on her team.

"It's hard, and it's something I've had to really learn over the years. When I started out, you were terrified to put your hand up and say, 'I don't know' or 'I think I've made a mistake and need help.' With my team, it's about reminding them that I didn't know these things either back in the day, there's no stupid question. Mistakes don't get highlighted and dealt with if people don't feel like they can talk about them. So as much as I can, I bring my own experiences to the team, so they feel like this person's probably been in their shoes before, and they shouldn't feel scared to ask. Mistakes still happen even at a senior level, they're just different types of mistakes. It's a hard environment to get right."

On what surprised her about stepping into management

"How fast the technical world moves the minute you step out of it. You're in a management role, so it's not technical day-to-day, but you've still got the management piece plus the fast-paced world of cyber to keep up with, that's a hard blend to get right. It's also surprising how quickly you fall out of the routine of the day-to-day technical work once you step into leadership. You have to remind yourself how to do it so you can lead your team while they're doing it. And it's hard to take that step back and say, 'okay, I'm leadership now, I need to let the people who are really good at doing the work do it, and not keep jumping back in myself.' Beyond that, it's about creating space for your team to thrive rather than dragging them forward, keeping them included in the everyday strategic direction, which makes everyone want to work together and push forward. That's something I've worked out over the past few years."

On the top skills for anyone entering cybersecurity

"Knowing the basics is never really going to change. Even with the adoption of AI, having a genuine, fundamental understanding of computing, networking, and cybersecurity matters, AI can help you along, but it won't give you that full understanding. So: know the basics.

Communication and stakeholder management is another big one. Whether you're a pentester, SOC analyst, or anything else, how you converse with people, internally or externally, to get information across effectively is never going to change. When you're starting out, it's easy to get so focused on the tech that you forget the soft-skills side, which is just as important to being good at your role.

The third, whether it’s a skill or a quality, is that eagerness to keep going and keep learning, and understanding that you're never going to know everything, and that's okay. We've all got different strengths. Just wanting to constantly keep going is a main thing you need in cyber. This is crucial to building resilience: people burn out because they don't pace themselves."

Laura’s advice for staying motivated

"When you first start out, you think, 'I'm getting it, I know this.' Then you turn a corner one day and realize there's a whole world of information you didn't have a clue about, and it becomes daunting and overwhelming. Imposter syndrome feeds into a lot of this industry, everyone I know throughout my career seems to suffer with it. It's about taking a breath and thinking: it's okay, I'm doing what I'm doing, I'm on the right path, I'm just going to keep working at improving, and you'll get there. There are so many good people in the cyber industry you can lean on and get help from."

On what leaders in the industry should be talking about more

"I think as leaders we need to be the ones who are role models and lead by example, rather than pushing tasks off and saying, 'you guys figure that out.' It's really easy to take a step back too far in a management role, I've been guilty of this myself. You want your team to see you in the trenches with them. The industry is only ever going to get faster, more information, more tooling, more new techniques. As leaders, we need to be clear and confident in the direction we want our team to take, so burnout doesn't happen, and so we're empowering them and supporting their learning and development. That includes ensuring they've got the tools to be the best they can be."

On what she still geeks out on

"It hasn't been the same throughout my career. Right now, I'm really into vulnerability management, moving from just handing over a stack of vulnerabilities as a pentester into proper prioritization: how threat intelligence feeds into that, what's actually exploitable, what threat actors are doing, and using that to give organizations a wider view, the 'so what' of it all, moving from 'go and fix everything' to strategically helping people work through it.

I've seen both sides, being the pentester who dumps a report on someone's desk and says, 'here are all your issues, see you later,' and now helping customers make sense of what that actually means. Once you start looking at it from a threat-intel point of view, what exploits are out there, what industries are being hit by which vulnerabilities, it becomes really interesting."

On the responsibility that comes with translating technical risk into something a business can act on, without either causing panic or downplaying urgency, Laura sees it as a shift the industry still needs to make.

"I have customers who get overwhelmed by the sheer number of vulnerabilities out there, and it's not fair to just tell someone to deal with it now. We should be helping people put it into business context and understand what it actually means. For years, as an industry, we didn't really bother with that, we were just the people who found the holes, told you where they were, and left it on you to deal with it. It's nice that we're starting to shift that thinking now, to help prioritize, understand what's happening, and hopefully get ahead of potential threat actors. I think it's a really interesting space."

We left Laura with one quickfire, industry-old debate.

True or false: red teamers should know some blue team skills, and blue teamers should know some red team skills?

"True."

authorJoanna Duffy
Jul 20, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe