A Decade of Recognition: 2015 to 2026
Read the Hall of Fame end to end and a story appears. The work the field puts forward for honour has moved, year by year, from the perimeter to the people. This is what eleven editions show.
2015 to 2018: the perimeter years
The early Hall of Fame reads like a map of where the work sat at the time. The recurring individual categories were CISO of the Year, Personality of the Year, Woman of the Year and Penetration Tester of the Year. In 2015 Bryan Littlefair was named CISO of the Year and Phil Cracknell took Personality of the Year. The following years kept that shape: Troels Oerting in 2016, Gilbert Verdian in 2017, Jordan M. Schroeder in 2018. Penetration testing carried its own award through this period, with Ben Turner (2015), Mathew Ettelaie (2016) and Mark Harrison (2018) all recognised by name. The honoured organisations were product makers and consulting practices. Nettitude took Consulting Practice of the Year twice, in 2016 and 2017. The work being celebrated was the work of holding a boundary.
2019 to 2022: response, teams and the start of the pipeline
The middle of the decade brought teams forward. Banking and financial services teams, industry teams and not-for-profit teams appeared and reappeared, with HSBC recognised in 2019 and again in 2021 for its Fraud and Cyber Awareness work. Cyber Awareness Plan of the Year became a fixture, honouring the people who teach an organisation to defend itself rather than any single tool. The individual awards widened too. Jay Hira was recognised twice in 2022, as Personality of the Year and Influencer of the Year, a sign that the field had begun to value those who explain the work to others. Jim West, recognised in 2021, would return to the Hall of Fame later for a different reason.
2023 and the 2024 pause
The 2023 edition kept the broad shape of the preceding years, with Mel Migrino recognised as both Cyber Woman of the Year and CISO of the Year, and Bridewell honoured among the security companies. Then the programme paused. There was no 2024 edition. A gap year is easy to read as a setback, but it gave the organisers room to ask a harder question: across nearly a decade of categories, who exactly is the work meant to honour? The answer shaped what came next.
2025 to 2026: the people, named
The 2025 edition was the largest on record by category count, recognising Rebecca Taylor as Cyber Woman of the Year, Fene Osakwe as Cyber Personality of the Year and a long roster of products and services. For 2026 the panel reset the structure entirely. The categories became five individual awards (Rising Star, Professional, Leader, Influencer, Advocate) and five organisation awards (Community, Company, Product, Service, Team). Jubilian Ho Hong Yi was named the Rising Star, Victor Chang the Professional of the Year, Fene Osakwe the Leader of the Year, Paul Jackson the Influencer of the Year and Jim Earl West III the Advocate of the Year. On the organisation side, ISC2 Security Congress, Bridewell, Saviynt, THEOS Cyber Solutions and the Evalian Cybersecurity Team. Two names carry across editions. Fene Osakwe, recognised in 2023, 2025 and 2026, and Bridewell, recognised in 2023, 2025 and 2026. Sustained recognition of the same people and organisations, across a restructure, is the clearest evidence that the panel judges the work and not the fashion.
What the decade shows
Read together, the eleven editions trace a single movement. Recognition began at the tools and the boundary and ended at the named individuals and the small teams who carry the load. The categories changed, the programme paused, the structure was rebuilt, and through all of it one thing held. Nobody bought their way in.
About this report: it reads the publicly recorded Cyber Security Awards Hall of Fame for 2015 to 2026 and the categories and winners named in each edition. Figures describe the programme record (the 2015–2026 span, the 2024 pause, and the 2026 restructure into five individual and five organisation awards). It reports only real, named outcomes and does not publish individual nomination data or invented statistics.
About the report
What period does this report cover?
The Cyber Security Awards Hall of Fame from 2015 to 2026. Eleven editions were decided across that span; no edition was held in 2024, when the programme paused.
What changed in 2026?
The categories were restructured into five individual awards (Rising Star, Professional, Leader, Influencer, Advocate) and five organisation awards (Community, Company, Product, Service, Team).
Has anyone been recognised more than once?
Yes. Fene Osakwe was recognised across the 2023, 2025 and 2026 editions, and Bridewell was honoured across 2023, 2025 and 2026, including before and after the restructure.
Where does the data come from?
From the publicly recorded Hall of Fame and the categories and winners named in each edition. The report uses only real, verifiable outcomes and does not disclose nomination details.
Can I cite these findings?
Yes. The themes and programme facts are drawn from the named Hall of Fame and are intended to be quotable, with attribution to the Cyber Security Awards.