The programme · 8 min read

The road to Awards 27

Nominations for the 2027 Cyber Security Awards open on 1 December 2026 and close on 28 February 2027. Here is the full calendar, who will be reading the entries, and what to have ready before the window opens.

Ninety days. That is the length of the nomination window for the 2027 Cyber Security Awards, from the morning it opens on 1 December 2026 to the deadline on 28 February 2027. Ninety days sounds generous until you try to describe three years of someone's work in a form, find the people who will vouch for it, and ask the person themselves whether they mind being put forward. Most of that can be done now, months before the window opens, and the nominations that score well tend to be the ones where it was.

This piece sets out the road to Awards 27 in one place: the five published dates, what the programme does at each stage, the panel that will read the entries, and what a nominator can usefully do between now and December. None of it is hidden. The dates sit on the nominate page, the judges are named on the judges page, and every one of the ten categories publishes its criteria. The reason for writing it down here is so that anyone thinking of nominating a colleague can plan backwards from the deadline instead of scrambling towards it.

The five dates on the road to Awards 27

Key dates for the 2027 Cyber Security Awards, as published in September 2026.
Stage Date What happens
Applications open 1 December 2026 The nomination form goes live for all ten categories.
Application deadline 28 February 2027 Nominations close.
Shortlist announcement 15 March 2027 The shortlisted entries in each category are published.
Judging period 15 March – 15 April 2027 The panel scores the shortlisted entries against the published criteria.
Winners announcement 28 April 2027 Winners are announced online.

1 December 2026 is the date to write down first, because everything else on the calendar is fixed relative to it. From that morning the form is live for all ten categories. A nomination can name a colleague, a peer, a supplier, a community, or the person writing it, and every entry goes to the same panel to be read on the same basis.

28 February 2027 is the deadline. A nomination submitted in the final week reads no differently to the panel than one submitted in December. What matters is whether the evidence in it holds up. Still, the people who leave it until the last weekend tend to submit the version they had rather than the version they meant to write.

Two weeks after the deadline, on 15 March 2027, the shortlist is announced. From that day the judging period runs to 15 April 2027, a month in which the panel works through the shortlisted entries in each category and scores them against the criteria published for that category and nothing else. On 28 April 2027 the winners are announced.

Five dates. The whole programme, from the first form to the last name read out, runs to them.

Who will be reading the entries

Thirty judges. The panel was refreshed in September 2026, as it is each edition, and now stands at 30 practitioners, chief information security officers and researchers. Three joined in this refresh. Leron Zinatullin is a CISO and a board and start-up advisor whose work covers AI governance. Fred Streefland is a global CISO for EMEA. Jean Carlos is a head of information security. Each of them brings the one thing the panel is built from, which is direct experience of the work the categories describe.

The judges who stepped down in the refresh have not been quietly removed from the record. They are listed publicly as panel alumni on the judges page, by name and role, so anyone can see who read the evidence in earlier editions. A panel that rotates in the open is a panel you can check. How the panel is assembled, and what its members are asked to set aside, is written up separately.

What the refresh does not change is the standard. Every nomination is read in full before a single score is given. A judge with a connection to an entry recuses themselves from scoring it. Sponsorship funds the events around the programme and has no influence on outcomes; no sponsor sees an entry or holds a vote. Recognition cannot be bought, and that sentence has governed the programme since it was established in 2014 and handed out its first awards in 2015.

How the winners are announced

Since 2025 the winners have been announced online, on the published date, to everyone at once. A winner does not have to be in a particular ballroom on a particular night to be recognised. The announcement reaches the people they work with wherever those people happen to be, and for a programme that has recognised excellence across more than 40 countries, that is the honest way to serve the field.

The stage did not disappear. Selected winners receive an exclusive hospitality package to collect their award in person at a partner conference, in Singapore, Vietnam, Thailand, Cambodia, Dubai or Denmark. The room moved closer to where the work happens.

Ten categories, and the question each one asks

Choosing the category is the first decision a nominator makes, and the one most often made in a hurry. There are ten. Five recognise individuals:

  • Cyber Security Leader of the Year
  • Cyber Security Professional of the Year
  • Cyber Security Advocate of the Year
  • Rising Star in Cyber Security
  • Cyber Security Influencer of the Year

Five recognise organisations:

  • Cyber Security Company of the Year
  • Cyber Security Product of the Year
  • Cyber Security Service of the Year
  • Cyber Security Team of the Year
  • Cyber Security Community of the Year

Each one publishes its own criteria, and the panel reads an entry against those criteria alone. So the useful question is what the work actually was. A CISO who rebuilt a security function over three years belongs in the Leader category. The analyst on that team who spotted the intrusion nobody else saw is a Professional entry, or a Rising Star if they are early in their career. The team as a whole is a Team entry. The same body of work can support more than one nomination, but each nomination has to answer the criteria of the category it sits in rather than borrow from the one next door. The categories page carries all ten, with the criteria for each.

What to do before 1 December

The window is 90 days. The preparation can start this week, and the people who nominate well usually do four things long before the form is live.

They ask the person. The strongest candidates are often the ones who would never put themselves forward, and a nomination that lands on someone unannounced is a nomination they may not be able to help with. A short conversation now means the nominee can point you to the dates, the numbers and the colleagues you would otherwise have to guess at.

They read the criteria for the category before they write a word. A panel scores what the criteria ask for. An entry that answers a different question, however impressive, gives the judges nothing to score.

They gather evidence the panel can check. What did the nominee do, over what period, and what changed because of it? A shipped fix, a public talk, a measured drop in time to detect, a programme that went from nothing to running. Dates and figures where they exist, and honesty about the limits where they do not. The journal has a longer piece on the evidence panellists look for and another on how to write a nomination the panel can judge.

And they find the people who will stand behind it. A manager, a peer, a customer, someone who watched the work happen and will say so. A nomination with a named person behind each claim reads differently from one that asks the panel to take a paragraph on trust.

None of this requires the form to be open. All of it is easier in October than in the last week of February.

Nominations open on 1 December 2026. The nominate page carries the calendar, the ten categories, and a Get notified sign-up that sends one email when the window opens and one at each milestone after it, nothing else. Between now and then, the only real question is the one every edition of this programme has asked since 2015. Who did the work, and who is going to make sure the panel gets to read about it?

FAQ

The 2027 Awards

When is the deadline for the Cyber Security Awards 2027?

Nominations close on 28 February 2027. They open on 1 December 2026, giving a 90-day window. The shortlist is announced on 15 March 2027 and the winners on 28 April 2027.

Can I nominate myself?

Yes. You can put forward a colleague, a peer, a supplier, a community you belong to, or yourself. Every entry goes to the same independent panel and is read against the same published criteria for its category.

Who judges the 2027 Awards?

An independent panel of 30 practitioners, chief information security officers and researchers, refreshed in September 2026. Judges are named on the judges page, recuse themselves from any entry they are connected to, and score against published criteria. Sponsorship has no influence on the result.

Is there a ceremony?

Winners are announced online on 28 April 2027, so recognition reaches every winner on the same day wherever they work. Selected winners receive an exclusive hospitality package to collect their award in person at a partner conference in Singapore, Vietnam, Thailand, Cambodia, Dubai or Denmark.

How do I hear when nominations open?

Use the Get notified sign-up on the nominate page or the home page. It sends one email when nominations open on 1 December 2026 and one at each milestone after that.