The mentor who built a team from nothing
A team award is given for the work of a group, not the reputation of its lead. So the question worth asking is how a group like that comes to exist in the first place.
The Cyber Security Team of the Year is judged on what a group did together, measured against published criteria, and never on the seniority of the person who signed the entry. That single rule changes who the award belongs to. It belongs to the people on the rota, the ones who carried a bad week between them, not to the title at the top of the org chart.
Which raises a harder question. Most strong security teams did not arrive fully formed. Someone started them. Often that someone was handed a budget for one role and a mandate that read, in effect, make us safer. Building a security team from that starting point is slow, unglamorous work, and the people who do it well tend to talk about it least. This is an attempt to describe what they actually do.
The people in the examples below are archetypes, drawn from patterns the panel sees year after year. The patterns are real. The composite stands in for many.
The first hire is a teacher, whether they planned to be or not
A team of one is not a team. It is a person holding a pager and a long list of things that could go wrong. The mentor who eventually builds something larger usually begins by accepting a fact most job descriptions hide. The first hire is hired to teach as much as to defend.
Consider the archetype. A lone security lead at a mid-sized organisation, the only person whose job is to think about attackers all day. The temptation is to hoard the work, because the lead is faster than anyone they could train. The mentor resists that. They write down how an incident gets handled, not because they enjoy documentation, but because a runbook is the first thing they can hand to a second person. The choice to teach instead of to do is the choice that makes a second hire worth making.
When the second person arrives, often a graduate or a switcher from IT support, the mentor does something quietly generous. They let the newcomer make the call on a real, low-stakes alert, then talk it through afterwards. The newcomer learns that judgement is allowed. That single experience, repeated, is how a one-person function becomes a unit that can cover a night shift without the founder awake at the keyboard.
The Verizon Data Breach Investigations Report has noted for years that the human element sits behind a large share of breaches. The mentors who build durable teams read that finding the other way round. If people are the surface most often exploited, then people, trained and trusted, are also the strongest control an organisation can grow.
Hire for the question, build for the night shift
Ask a mentor who built a team what they look for, and the answer rarely starts with certifications. It starts with how a candidate behaves when they do not know the answer. The skills shortage in cyber security is well documented by ENISA and others, and the mentors who built real teams treat that shortage as a reason to widen the gate, not narrow it.
So they hire the helpdesk engineer who kept asking why a ticket kept recurring. They hire the auditor who found the gap nobody wanted named. They hire the graduate who broke something in a lab and could explain, precisely, how. Tools can be taught in weeks. The instinct to pull a thread until it unravels takes longer to find and cannot be installed.
Then comes the part that separates a team from a collection of analysts. The mentor designs the work so that no single person carries the whole burden of being awake. On-call is shared and bounded. A bad night is followed by time back, not a quiet expectation of heroics. National guidance, including from the NCSC, keeps returning to the same defensible basics, multi-factor authentication, patching, logging, and a tested incident plan. A team that has rehearsed those together moves calmly when the real thing arrives, because the moves are familiar.
The mentor also does something that does not appear on any framework. They notice the quiet wins. The phishing email someone reported before it spread. The misconfiguration caught in review. They say the name out loud in the team channel. Recognition inside the team is the rehearsal for recognition outside it, and it costs nothing but attention.
The hardest skill is letting go
There is a moment every team-builder describes, usually with a slightly rueful smile. It is the first major incident the mentor watches from the side of the room while someone they trained runs it. They want to step in. They do not. They let the person they hired make the calls, ask the questions, and own the outcome.
That restraint is the whole point. A team built around one indispensable person is fragile, because the day that person leaves, the capability leaves with them. A team built by a mentor who learned to step back is durable, because the knowledge now lives in several heads and the next incident does not depend on any one of them. The mentor has made themselves replaceable, on purpose, and that is the achievement.
This is also why a team award, judged on merit, matters more than it first appears. When a panel reads the entry and sees a group that handled an incident well, mentored its juniors, and shared the load, it is reading the long, invisible work of someone who chose to teach rather than to dominate. The trophy, if it comes, names the team. The team knows who built it.
The standard we hold
The panel does not reward the loudest function or the largest budget. It reads what a team did, together, against published criteria, and it asks whether the work held. A mentor who built a strong team from a single role will rarely put their own name forward. That is the tell. The people who build the best teams point the credit outward, at the people they trained, and let the work speak.
If you lead a team like that, or you sit on one, the route is the same. Put the work on the record. Let it be read on merit. Recognition earned that way can be cited, and it will still mean something in ten years, because the basis never changes.
Building a security team
What is the first role to hire when building a security team?
Hire one capable generalist who can both defend and document. The first person sets the standard and writes down how the work is done, so the next hire has something to learn from rather than starting from nothing.
Should you hire for certifications or for aptitude?
Favour aptitude. Tools and certifications can be taught, but the instinct to ask the right question and pull a thread until it unravels is harder to find. Many strong analysts come from IT support, audit, or adjacent fields.
How do you keep a small security team from burning out?
Share the on-call load and keep it bounded, give time back after a bad night rather than expecting heroics, and name the quiet wins. National guidance such as the NCSC stresses rehearsed basics, which reduce the panic that drives burnout.
How does the Cyber Security Team of the Year judge entries?
It is judged by an independent panel against published criteria. The award measures what a team did together, including how it handled incidents and developed its people, not the seniority of its lead.