Reports

What a decade of entries tells us.

Every year, defenders enter the Cyber Security Awards and an independent panel judges them on merit. That record is a rare view of the field. These reports read it carefully and point the spotlight back at the people who do the work.

The reports

Four reads, drawn from real entries

Each report stands on verifiable people and organisations, with external figures attributed to their published sources. Read whichever speaks to your work.

How these reports are built: they draw only on real winners and finalists of the Cyber Security Awards, a programme judged by an independent panel. External statistics are attributed to their original sources, and we invent no figures. See how winners are chosen.

FAQ

About the reports

Where does the data in these reports come from?

It comes from a decade of entries to the Cyber Security Awards, read alongside published findings from established sources such as the Verizon DBIR, ENISA, IBM and the NCSC. Every external statistic is attributed to its original source.

Do sponsors influence what the reports say?

No. The awards are judged on merit and cannot be bought, and the same holds for the reports. Sponsorship has no bearing on who is recognised or on the findings we publish.

How often are the reports updated?

The dated reports reflect the most recent edition and are refreshed each year as a new cohort is recognised. The 2026 reports are the current set.

Can I cite these reports?

Yes. They are written to be quoted and linked, with external figures attributed so you can trace them to source. For the judging process behind the data, see the methodology page.