Fene Osakwe has been honoured three times. Here is what for.
Three entries in the Hall of Fame, under three different category names, decided by three panels that never saw each other’s scores. This is what a record looks like when it is kept rather than marketed.
Fene Osakwe’s name appears in the Hall of Fame three times. Cyber Educator of the Year in 2023. Cyber Personality of the Year in 2025. Cyber Security Leader of the Year in 2026. Three years, three category names, and in between them a restructure that retired two of those categories and a pause year that ran no edition at all.
We are writing it down because a record only works if someone keeps it. A trophy is a photograph. A record is a line you can follow across a decade, checking each entry against the year it was decided in and the criteria that were published at the time. Most awards bodies hold the second thing and publish the first. This piece does the opposite, using one honouree as the worked example, and sets out what every honouree page on this site is supposed to carry so that the next forty are built the same way.
The three entries, as they were published
Not as a biography. As rows in a ledger, each one traceable to the page that recorded it on the day.
| Edition | Category, as published that year | Where it is recorded |
|---|---|---|
| 2023 | Cyber Educator of the Year | 2023 winners |
| 2025 | Cyber Personality of the Year | 2025 winners |
| 2026 | Cyber Security Leader of the Year | 2026 cohort |
There is no 2024 row, and there is no missing 2024 row either. The programme ran no edition that year. That gap is part of the record and it stays visible, because a Hall of Fame that quietly closes its own holes is not a Hall of Fame.
Two of the three category names no longer exist. Educator and Personality were both retired when the slate was restructured for 2026 into five individual awards and five organisation awards. Osakwe’s 2023 and 2025 entries did not move, get renamed, or get mapped forward into the new shape. They sit where they were decided, under the names they were decided under.
What each panel was actually reading
Here the record has an honest limit, and it is worth stating rather than papering over. The ten categories on the current slate each publish four named criteria, written down before the window opens. Educator and Personality are not on that slate. Their criteria as they stood in 2023 and 2025 are not published on this site, and we are not going to reconstruct them from memory to make a tidier article. What a reader can check for those two years is the category name, the edition, and the winner. That is the whole claim, and it holds.
The 2026 honour is different, because the criteria for Cyber Security Leader of the Year are on the category page in full. The panel scored four things:
| Criterion | What the page asks for |
|---|---|
| Leadership | “Evidence of exceptional leadership qualities, including the ability to inspire, motivate, and engage teams, stakeholders, and board members, and to communicate effectively with both technical and non-technical audiences.” |
| Contribution to the Industry | “Evidence of contributions to the cybersecurity industry through thought leadership, innovation, collaboration with peers, or active participation in industry initiatives.” |
| Achievement | “Evidence of significant achievements and recognition within the cybersecurity industry, including awards, publications, speaking engagements, or other measurable milestones.” |
| Developing Others | “Evidence of efforts to mentor and develop others in the cybersecurity industry, including the creation of training programmes, mentorship initiatives, or other educational activities.” |
Read the Achievement criterion again and you will spot something awkward. Prior awards are admissible evidence. A judge scoring a 2026 entry may legitimately count a 2023 or 2025 honour as one of the milestones the criterion asks for.
That is not a loophole, and it is worth being precise about why. Achievement is one criterion of four. A nomination that arrived carrying nothing but a shelf of earlier trophies would score on a quarter of the sheet and fail the rest, because Leadership, Contribution to the Industry and Developing Others all ask what the person did, for whom, and with what result. An award is evidence that somebody else once checked the work. It is not a substitute for the work.
The work behind the 2026 citation
The honouree page keeps this deliberately narrow, and so will we. Osakwe advises boards and executive teams on security strategy, with a record built across financial institutions, telecoms and governments. He speaks at international conferences on cyber risk, resilience and the relationship between security and the boardroom.
The part the panel could weigh sits in one sentence: he turns technical risk into language directors can act on. Plenty of strong technical leaders never manage that, and their organisations pay for it later, when the budget conversation happens after the incident instead of before it. Leadership in security mostly shows up as things that did not happen, which makes it genuinely hard to evidence. Someone who can get a board to move early leaves a trail a judge can follow.
None of that is ours to embroider. His own site describes him as a cyber security advisor, international conference speaker and mentor with over a decade of experience, and lists both the 2025 and the 2026 Cyber Security Awards honours among his recognitions. Independent corroboration of a claim is exactly what the criteria mean by checkable, and it is the reason the honouree pages carry outbound links to a subject’s own record rather than asking anyone to take ours on trust.
The second name that carries across the same three editions
Osakwe is not a statistical oddity, which matters, because one repeat honouree proves nothing and two start to describe a method. The consultancy Bridewell appears in the same three editions, also under three different category names.
In 2023 it took Best Security Company of the Year in the over-150-staff tier. In 2025 it was named Best Cyber Security Service Provider of the Year. In 2026, after the restructure collapsed those tiers, it was named Cyber Security Company of the Year. Same firm, three panels, three sets of criteria, one continuous record.
What the two examples have in common is not a relationship with the programme. It is that both kept producing work that different groups of judges, reading different criteria in different years, arrived at independently. Sustained recognition across a restructure is about the strongest evidence available that a panel is judging the work rather than the fashion, and it is the finding that a decade of recognition rests on.
What an honouree page has to carry
Ten of these pages exist. The Hall of Fame runs to eleven editions, so most of the record has not been written up yet. Building the rest as a batch only works if every page carries the same five things, which is why we are putting the template on the record here rather than in a style guide nobody outside the office reads.
The fourth rule is the one that takes discipline. It is very easy to fill an honouree page with a career summary scraped from a profile, and the result reads well and means nothing. The page is a citation, not a bio. Everything on it should be something a judge either read or could have read.
The fifth is the one that costs us something and is worth it anyway. Pointing away from our own page is how an independent record behaves. If our version of an honouree’s story cannot survive comparison with theirs, the problem is our version.
Before 1 December
Nominations for the 2027 edition open on 1 December 2026 and close on 28 February 2027. Somewhere in your organisation there is a person whose record would read like the three rows at the top of this page if anyone bothered to write it down, and who will not write it down themselves.
Read the four criteria for the category you think they belong in. Then put them forward. Self-nomination is welcome and read on exactly the same terms, so if the person is you, that is not a disqualification either. The panel scores the evidence, and nothing else reaches the room. You can read how winners are chosen before you write a word.
Fene Osakwe
The honouree page: the 2026 Leader citation, the record, and the links to check it against.
A decade of recognition
Eleven editions read end to end, including the 2024 pause and the 2026 restructure.
Cyber Security Leader of the Year
The four published criteria, and what a winning record in this category looks like.
The record, and how it is kept
How many Cyber Security Awards has Fene Osakwe won?
Three. Cyber Educator of the Year in 2023, Cyber Personality of the Year in 2025, and Cyber Security Leader of the Year in 2026. Each was decided by the panel sitting that year against the criteria published for that category.
Why is there no 2024 entry?
The programme ran no edition in 2024. The gap is left visible in the Hall of Fame rather than closed over, because the record is only useful if it shows what actually happened.
Do the 2023 and 2025 categories still exist?
No. Cyber Educator of the Year and Cyber Personality of the Year were both retired when the slate was restructured for 2026 into five individual and five organisation awards. Earlier entries stay under the names they were awarded under and are not mapped forward.
Does a previous award give a nominee an advantage?
Each edition is scored cold, with no carried-forward credit or seeded shortlist position. The only place a prior honour counts is where a category names it as evidence, such as the Achievement criterion in the Leader category, which is one criterion of four.
Who else has been recognised across multiple editions?
Bridewell was honoured in 2023, 2025 and 2026, under three different category names, spanning the restructure. It is the second worked example of sustained recognition in the Hall of Fame.