State of Cyber Defence 2026
Once a year, the people the field puts forward tell you where the work is moving. This is what the 2026 cohort was recognised for, and what it signals.
Sharing the signal, not the data
The single clearest technical theme of the year is federated defence. Prof. Victor Chang’s recognised work trains intrusion-detection models locally and shares only what they learn, so organisations bound by regulation can still benefit from a wider threat picture. It answers a problem every regulated defender knows: the data that would help your peers is the data you are not allowed to send them.
Response is regional, and it is senior
The recognition of Paul Jackson, who leads Kroll’s cyber risk and investigations practice across Asia-Pacific, points at where serious incident response now sits. The first hour of a breach is decided by people with regional reach and standing, not by a generic playbook. Verizon’s annual DBIR has reported for years that the large majority of breaches involve a human element. The cohort’s answer is human too: experienced responders who know their region.
The pipeline is the priority
Two of the year’s honourees are, in effect, about supply. Jim West was recognised for training and mentoring newcomers through TopCyberPro, and the Rising Star, Jubilian Ho Hong Yi, already mentors others while early in his own career. The skills gap is the slow emergency of this field, and the people the panel honoured are spending their time on it.
What it means for the year ahead
If 2026’s recognised work is a leading indicator, the next edition will reward defenders who make security portable across organisations, who shorten the distance between detection and decision, and who bring people in. None of that is a product launch. All of it is people.
About this report: it reads the publicly announced 2026 Cyber Security Awards cohort and what each honouree was recognised for, set against established external sources where relevant (for example, Verizon’s DBIR). Programme figures refer to the 2026 edition and the 2015–2026 Hall of Fame. It does not publish individual nomination data.
About the report
Where does this report’s data come from?
From the publicly announced 2026 Cyber Security Awards cohort and what each honouree was recognised for, read alongside established external sources such as Verizon’s DBIR. It does not disclose individual nomination details.
How often is it published?
Annually, after each edition is decided, with the date of last update shown on the page.
Can I cite these findings?
Yes. The themes and programme figures are drawn from the named, real 2026 cohort and are intended to be quotable, with attribution to the Cyber Security Awards.