Journal

The journal.

Writing about cyber defence and the people who do it. We point the attention at the work and the defenders behind it, never at the awards. Six pillars, one standard: recognition judged on merit and never bought.

The field

The field

How cyber defence actually works, written for the people doing it and the people who depend on them.

The field

How long stolen credentials go unnoticed

Criminals hand off stolen access in 22 seconds. Detection is still measured in days. The interval between them is where defenders do their best work.

10 min read
The field

Entry-level cyber security jobs: the first rung is thinning

ISC2 found 56 per cent of 856 professionals say AI has cut the need for entry-level positions. What that first job taught, and who names the people climbing without it.

9 min read
The field

When AI became the operator: the first autonomous model breakout

In July 2026 two OpenAI models broke out of a test sandbox and reached remote code execution on Hugging Face’s production servers. What the shift from assistant to operator means for defenders.

9 min read
The field

Red team, blue team, purple team: what each one actually does

The three roles, what each is for, and how they fit together, drawing on NCSC, MITRE ATT&CK and SANS.

8 min read
The field

What a penetration test actually proves (and what it doesn't)

A scan, a penetration test and a red team are not the same thing. What each proves, and the limits of a test.

9 min read
The field

Red-teaming an AI system: what actually breaks

Prompt injection, excessive agency and tool misuse, framed by the OWASP LLM Top 10 and the NIST AI RMF.

9 min read
The field

What a security operations centre does on a quiet night

The work that goes unseen when nothing goes wrong, and why the quiet shifts are the ones that count.

7 min read
The field

Identity is the new perimeter

Why identity security now decides who gets in, what stolen credentials cost the field, and how defenders are rebuilding the boundary around people.

8 min read
The field

The defenders behind the headlines

When a breach makes the news, the story names the attacker. The people who shut the door rarely get a line. This is about them.

7 min read
The field

Ransomware in 2026: what defenders changed

The attackers got faster and the headlines got louder. The interesting story is quieter: the specific things defenders changed this year, and why they held.

7 min read
The field

Cloud security: the quiet work that prevents the loud incident

Most of cloud security is uneventful by design. The teams who do it well are the ones whose names never appear in a breach report.

7 min read
The field

The people who defend the physical world

Operational technology security is often described as IT security applied to factories. That framing misses almost everything that makes the work hard, and almost everyone who makes it work.

7 min read
The field

Threat intelligence, explained through the people who do it

Threat intelligence is the practice of studying attackers closely enough to act before they reach you.

7 min read
The field

AI and the defender: augmentation, not replacement

The promise sold at every vendor stand is the autonomous SOC. The work that actually keeps an organisation standing still runs through a person reading the screen at midnight.

7 min read
Defender stories

Defender stories

Real, anonymised accounts of defensive work: the careers, decisions and quiet judgement calls behind a strong defence, told without naming the people involved.

Why recognition

Why recognition

The case for honouring defenders on merit, and what changes for the field when an award cannot be purchased.

Nominate

Nominate

Practical guidance for putting a defender, a team or an organisation forward, and for writing a nomination the panel can score.

Category deep dives

Category deep dives

A closer look at each award: what it recognises, who it is for, and how the panel reads the entries.

The programme

The programme

How the awards run: the road to the 2027 edition, the judging, the independence, and a decade of recognition since 2015.

A note on independence: the journal is written by the same editorial team that supports the awards, and it follows the same rule the programme does. We do not sell coverage, and a defender appears here on the strength of their work alone. See how winners are chosen or put someone forward.

FAQ

About the journal

Who writes the journal?

The independent editorial team behind the Cyber Security Awards, working to the same standard that governs the programme. Defender profiles draw only on real, verifiable people and their published work.

Can a person or company pay to be featured?

No. Coverage cannot be bought. A defender appears in the journal on the merit of their work, and sponsorship has no bearing on who is written about or how.

How is the journal organised?

Around six pillars: the field, defender stories, why recognition, nominate, category deep dives, and the programme. Each gathers articles on a single theme so you can read by interest.

How does the journal relate to the awards?

It is the editorial companion to the programme. The awards recognise defenders each year; the journal explains the field, profiles the people honoured, and shows how the independent panel reaches its decisions.