Why recognition · 7 min read

Recognition as retention: why naming the work keeps people in the field

A category we judge by a single test. Did this person's work hold up, and did anyone ever say so out loud.

To win in any individual category, a defender has to show evidence that their work held up under pressure. Not a job title, not a tenure, not a budget line. The specific thing they did, and proof that it worked. That criterion sounds like a high bar for an award. It is also, almost exactly, the thing most cyber security professionals never hear about their own work until the day they hand in their notice.

The industry talks about retention as a pay problem, then as a burnout problem, then as a tooling problem. Each of those is real. Underneath them sits something quieter. People leave roles where the work they did goes unnamed. A breach that never happened produces no story. A team that held together through a brutal incident gets a debrief and a return to the queue. Over enough years, a defender starts to wonder whether anyone outside the SOC could describe what they actually do.

The retention problem is partly a recognition problem

The reporting from the major bodies keeps circling the same theme. The Verizon Data Breach Investigations Report documents how much of the defensive load falls on small numbers of people responding fast under poor conditions. ENISA and the NCSC have both written, repeatedly, about a workforce stretched thin, with demand for skilled defenders outrunning the supply of them. The headline figure people remember is the shortfall. The figure they forget is the churn underneath it, because every analyst who leaves takes years of context with them.

Money matters in that equation, and so does the night-shift toll. But exit conversations across the field point at something that pay cannot fully fix. People want their contribution to be legible. They want a manager, a board, a peer, or a panel to look at the work and say, in plain terms, this was good and it mattered. When that never happens, the role becomes a treadmill. The defender keeps the lights on and the organisation keeps the defender, until a competitor offers the same treadmill with a slightly larger cheque.

Recognition does not replace fair pay or sane on-call rotations. It changes the meaning of the work that pay and rotations cannot reach. A person who has been named for what they did has a record that travels with them, and a reason to believe the field can see them.

What naming the work actually does

Consider a SOC analyst three years into a role nobody outside the team understands. She shortened dwell time on a live intrusion last winter by spotting a pattern the tooling missed. Her organisation knows. Her manager wrote two lines about it in a review. Then the queue refilled and the moment closed.

Now put that same piece of work in front of an independent panel that reads the evidence and decides on merit. The act of writing the nomination forces someone to describe, precisely, what she did and why it held. That description is the recognition, more than any trophy. It turns a half-remembered good night into a documented fact about a defender's career. When she is named a finalist, the people who report to her see that this kind of quiet, technical work is the kind that gets honoured, not the loud kind.

This is why a Hall of Fame that runs a full decade matters more than a single ceremony. A name chosen on merit in 2016 still means something in 2026, because the basis never changed. A defender can point to it years later. So can the next analyst deciding whether this field will ever see them, or whether the only way to be noticed is to leave.

Recognition the field can trust, or none at all

There is a failure mode here worth naming. Recognition only works for retention if the recognition is real. A defender knows the difference between an honour their employer purchased and one a panel awarded after reading the work. A bought trophy tells the team that budget wins. It can corrode morale faster than silence does, because it confirms the suspicion that the loud and well-funded get noticed while the careful go unseen.

So the standard has to be visible and the same for everyone. Judged against published criteria, so the result rests on evidence rather than spend. Never for sale, so the name on the certificate carries information about the work and nothing else. When those conditions hold, recognition becomes a signal a defender can carry with pride and an organisation can use to show its people they are seen.

FAQ

Recognition and retention

Why do cyber security professionals leave their roles?

Pay, burnout, and on-call demands drive much of the churn, and reporting from bodies such as ENISA and the NCSC describes a workforce stretched thin. Underneath those factors sits a quieter one: people leave roles where the work they did is never named or acknowledged.

How does recognition affect retention if pay is the bigger issue?

Recognition does not replace fair pay or sane rotations. It addresses a separate reason people leave, which is the sense that their contribution is invisible. Being named for specific work gives a defender a record that travels with them and a reason to believe the field can see them.

Why does it matter that an award cannot be bought?

Defenders can tell the difference between an honour an employer purchased and one a panel awarded after reading the work. A bought trophy signals budget, which can damage morale. A merit-based award carries information about the work itself, so the people who earn it can trust it.

What kind of work gets recognised?

The specific, evidenced thing a defender did, such as shortening dwell time on a live intrusion or holding a team together through a difficult incident. The judging rewards results that held up under scrutiny rather than seniority or visibility.