A decade of the Cyber Security Awards
One criterion has governed the programme since the first envelope was opened in 2015. The work has to be real, and a panel has to be able to read it.
To win, a nominee must show evidence a panel can read, weigh, and stand behind. That sentence has held since 2015, before the first trophy was handed out, and it still governs every category in 2026. The categories have changed. The names on the list have changed. The criterion has not.
This is the history of the Cyber Security Awards told the way the programme prefers to tell it: through the people who were recognised, and the one rule that decided who they were. The first edition ran in 2015. The eleventh ran in 2026. In between, defenders across the field were named for work that mostly happened in the quiet, and the basis for naming them never moved.
The first edition, 2015
The 2015 programme set a shape that the next decade would recognise. Bryan Littlefair took CISO of the Year. Phil Cracknell was named Personality of the Year. Vicki Gavin won Woman of the Year, with Noha Amin highly commended. Ben Turner of Nettitude took Penetration Tester of the Year, with Gavin Watson of RandomStorm close behind. On the company side, Egress won Best Security Company of the Year and Crypta Labs took Cyber Security Start-Up of the Year.
Read that list back and a pattern shows itself. These were practitioners, named for things they had done, not for things they had bought. Egress was an encryption company building real products. Crypta Labs was working on quantum random number generation. The penetration tester award went to someone who actually broke into systems for a living and wrote it up. From the start, the programme rewarded the work rather than the marketing around it.
The years that built the Hall of Fame
From 2016 onward the programme widened without losing its centre. Troels Oerting and Mike Loginov took CISO honours in the middle years. Rik Ferguson was named Personality of the Year in 2017, the same year Jane Frankland won Diversity Champion. Yoti, recognised as a start-up in 2016, went on to become a name the wider industry knows. David Ferbrache, long associated with national cyber policy, was Personality of the Year in 2018.
The company categories tracked the field as it matured. Proofpoint, FireEye, Digital Shadows, and Bridewell all appear across these years, named for products and services that customers actually used under pressure. Bridewell is worth pausing on. The firm won across multiple editions, including 2023 and again in 2026, which is the kind of repeat recognition that only a merit process produces. A panel reading the evidence each year kept arriving at the same answer independently.
Teams were honoured too, and this is where the programme often did its quietest good. Banking and financial services teams from Barclays, HSBC, and Yorkshire Building Society were named for defence work that, by its nature, the public never sees. A fraud and cyber awareness effort. An internal team that held a line. Recognition reached the people whose success looks like nothing happening at all.
The pause, and the return
The programme ran each year through 2023, then paused. There was no 2024 edition. Awards that exist to sell entries do not pause, because the revenue does not pause. A merit programme can, and this one did, returning in 2025 rather than running on momentum alone.
The 2025 edition arrived with the standard intact. Rebecca Taylor of Secureworks won Cyber Woman of the Year. Fene Osakwe took Cyber Personality of the Year, having already been recognised in earlier editions, another repeat that a panel reached on the evidence in front of it. Dr Franck Courbon of Cambridge and Ethicronics was named Cyber Security Influencer of the Year. The company awards recognised work from Yubico, Barracuda, and Index Engines, among others. The gap of a year changed nothing about how the result was reached.
The 2026 restructure
For 2026 the categories were rebuilt. The individual awards became five clean lines: Rising Star, Professional, Leader, Influencer, and Advocate. The organisation awards became another five: Community, Company, Product, Service, and Team. The sprawl of earlier years, with its many product subcategories, gave way to a structure a reader can hold in their head.
The winners followed the same logic as the first edition eleven years earlier. Jubilian Ho Hong Yi was named Rising Star. Victor Chang took Professional of the Year. Fene Osakwe won Leader of the Year. Paul Jackson took Influencer of the Year, and Jim Earl West III won Advocate of the Year. On the organisation side, Bridewell was Company of the Year, Saviynt Identity Cloud took Product, THEOS Cyber Solutions took Service, the Evalian team won Team of the Year, and ISC2 Security Congress was recognised as Community of the Year.
The shape of the programme changed. The thing it measures did not. A panel still read the evidence and let the result fall where it pointed.
The standard we hold
A decade is long enough to test whether a thing means what it says. Plenty of awards launched in 2015 and have since become line items in marketing budgets, sold by the category. This one took a harder road and kept to it. Judging stayed with an independent panel reading against published criteria. The result stayed unpurchasable.
That is why a name in this Hall of Fame still carries weight in year eleven. The basis did not drift, so the early winners mean exactly what the recent ones do. When you read the list, you are reading a record of work that held up under scrutiny, year after year, from a SOC analyst on a Tuesday night shift to a CISO who steadied an organisation through a bad week. The programme exists to point the spotlight at them. It has done so for a decade, and the criterion that decides who stands in it has never been for sale.
A decade of recognition
When did the Cyber Security Awards start?
The first edition ran in 2015 in the United Kingdom, honouring individuals, teams, and companies across the field. Winners that year included Bryan Littlefair, Vicki Gavin, and Egress.
Was there a 2024 edition?
No. The programme paused, so there was no 2024 edition. It returned in 2025 with the same merit standard, recognising winners such as Rebecca Taylor and Fene Osakwe.
How did the categories change in 2026?
For 2026 the categories were restructured into five individual awards (Rising Star, Professional, Leader, Influencer, Advocate) and five organisation awards (Community, Company, Product, Service, Team).
Has the judging standard changed over the decade?
No. Across every edition since 2015, judging has been done by an independent panel against published criteria. Recognition has never been for sale.