Who to put forward, and who gets overlooked
The strongest candidate is often the person who would never put themselves forward. Here is how to find them, and how to make the case.
A SOC analyst finishes a Tuesday night shift having spotted the one alert that mattered in a queue of four thousand that did not. She isolates the host, calls the on-call engineer, and writes the timeline before she goes home. By Wednesday morning the incident is closed, the customer never knew, and her manager mentions it in passing at standup. Nobody writes it down. Nobody thinks to. The work was quiet, it held, and it disappeared.
That analyst is exactly who a nomination is for. The problem is that she will never raise her hand, and the people who do raise their hands are often the ones whose work is easiest to see and hardest to verify. So the first job of anyone choosing a nominee is to look past the obvious names and find the person whose contribution would otherwise go on the record nowhere at all.
Start with the work, not the title
The instinct is to nominate by seniority. The Head of Security, the CISO, the person whose name is already on the org chart. Sometimes that is the right call. Often it is the lazy one, because a job title tells a panel what someone is responsible for, not what they did.
Reverse the order. Begin with a specific piece of work from the last twelve months and ask who actually carried it. The analyst who shortened dwell time on a live intrusion. The engineer who rebuilt an identity system that had quietly become the organisation's biggest exposure. The researcher who found a flaw, reported it through the right channel, and waited for the patch before saying a word. Once you have the work, the right person to nominate is usually obvious, and it is frequently not the most senior person in the room.
The candidates who get overlooked every year
Some strong people are missed so consistently that it is worth naming the pattern. The night-shift responder, whose best outcome is an incident nobody hears about. The internal engineer whose preventive work means the breach simply never arrives, which leaves no headline to point at. The person two or three levels below the executive who briefs the board, who did the analysis the briefing was built on.
Then there are the people outside the corporate frame entirely. The volunteer running a regional security community. The practitioner who mentors newcomers on their own time. Industry reporting from Verizon's DBIR and ENISA keeps showing the same thing: most damage is averted by ordinary, sustained defensive work rather than by single dramatic moments. That work has authors, and those authors are who the overlooked categories exist to catch.
Match the person to the right category
A good candidate in the wrong category looks weaker than they are. The 2026 programme is built around five individual awards and five organisation awards, and the distinction matters when you choose where to put someone forward.
An individual at the start of their journey who has already made a mark belongs in Rising Star, not against a twenty-year veteran. A practitioner doing exceptional hands-on work fits Cyber Security Professional. Someone shaping strategy and people belongs in Cyber Security Leader. People who change minds across the field, through writing, speaking, or campaigning, fit the Influencer and Advocate categories. Read the published criteria for each before you decide, because the same person can be a thin candidate in one category and a clear winner in the next.
Watch for the names that should not be there
Choosing well also means leaving some names out. A nomination loses its meaning the moment it rewards budget or visibility rather than work. Resist the candidate whose claim is mostly marketing, the vendor pitch dressed as a contribution, and the senior figure whose team did the work that the nomination quietly credits to them.
The test is simple. If you removed the job title, the press coverage, and the spend, would the contribution still stand on its own. If it would, you have a real candidate. If it would not, you are about to nominate a reputation rather than a person, and a panel reading the evidence will see the difference long before you do.
Make the case a panel can actually verify
A nomination is not a reference letter. The panel reads against published criteria, and it can only credit what it can check. So write down the specifics. What did the person do, over what period, and what changed as a result. Where evidence exists, point to it: a public advisory, a CVE credit, a conference talk, a measurable shift in how their team or organisation works.
Keep the claims defensible. Guidance from the NCSC and others is clear that strong security work is judged on outcomes and conduct, not on adjectives. A panel will trust "reduced mean time to contain across the year" far more than "exceptional". State what happened, attribute the numbers honestly, and let the work carry the weight.
Ask first, and ask the people around them
Two practical steps lift a nomination more than any phrasing. The first is to tell the person. The strongest candidates are often surprised to be put forward, and a quick conversation gives you the detail and the evidence you would otherwise be guessing at. It also respects them, which matters when the recognition is theirs to accept.
The second is to ask the people who worked alongside them. Colleagues remember the moments a manager missed. A peer can tell you about the night the candidate stayed on the call, or the time they handed credit to someone junior. Those details are what separate a nomination that reads true from one that reads polished.
The panel is independent, and recognition here is never bought, so if a name has been forming in your mind while you read this, the most useful thing you can do today is put that person forward.
Choosing who to nominate
Can I nominate someone who does not know I am putting them forward?
Yes, but it is better to tell them. A short conversation gives you the specific detail and evidence a panel needs, and it respects the person whose work you are recognising.
Do I have to nominate someone senior?
No. Seniority is not a criterion. Begin with a specific piece of work from the past year and nominate whoever actually carried it, which is often not the most senior person involved.
What makes a nomination strong?
Specifics a panel can verify. Describe what the person did, over what period, what changed as a result, and how you know. Point to public evidence such as an advisory, a CVE credit, or a measurable change in how their team works.
How do I pick the right category?
Read the published criteria for each. The 2026 programme has five individual and five organisation awards, and the same person can be a weak candidate in one category and a clear fit in another.
Can a nomination be bought or influenced?
No. Judging is independent, and recognition here is decided on merit and is never bought.