Who Defends the World 2026
Look at where the year’s honoured defenders sit on a map, and a picture forms. This is the geographic and sector spread of the real 2026 cohort, read as one field.
Two centres of gravity, one field
Place the 2026 honourees on a map and the cohort does not scatter evenly. It clusters. A run of recognised work sits across Asia-Pacific, and a second run sits in the United Kingdom. The remaining honourees operate across borders rather than from a single desk. That shape is worth reading carefully, because it tells you where the people doing the recognised work actually are.
The APAC cluster
Singapore appears more than once. Jubilian Ho Hong Yi was honoured as Rising Star while early in his career, and Victor Chang, the Professional of the Year, was recognised for federated intrusion-detection research carried out in the region. THEOS Cyber Solutions, the Service of the Year, runs its practice from Singapore as well. Hong Kong adds Paul Jackson, the Influencer of the Year, who leads cyber risk and investigations across Asia-Pacific. Four of the ten honourees, then, work in or from this part of the map, which is a meaningful share for a programme with British roots.
The UK cluster
The United Kingdom holds the second cluster. Bridewell, named Company of the Year, has been recognised by the programme across several editions and works from the UK. The Evalian team was honoured for the security work it delivers from there too. These are organisations rather than individuals, which is its own signal: in the UK the recognised work this year ran through teams and firms as much as through single names.
The cross-border honourees
Not every honouree fits a pin on the map. Fene Osakwe, the Leader of the Year, and Jim Earl West III, the Advocate of the Year, work across regions through writing, mentoring and governance. The Saviynt Identity Cloud, the Product of the Year, and the ISC2 Security Congress, the Community of the Year, are by design international. They are the connective tissue of the cohort, the part that explains why two clusters still read as one discipline.
Sectors, not just geography
The map has a second axis. The honoured work runs from research and intrusion detection (Victor Chang) through managed service and investigations (THEOS, Paul Jackson), into identity and product (Saviynt), into consultancy and team delivery (Bridewell, Evalian), and out to the people side of the field, mentoring, advocacy and community (Jim Earl West III, the ISC2 Security Congress). No single sector dominates. The defenders the panel honoured sit at different points of the same supply chain of trust.
What the map means
The headline is plain. The work that earns recognition in this field is no longer concentrated in one capital. It is spread across APAC and the UK and stitched together by people and organisations that operate everywhere at once. For anyone deciding where to look for serious defenders, the 2026 cohort is a useful first map.
About this report: it maps the publicly announced 2026 Cyber Security Awards cohort by where each honouree works and the kind of work each was recognised for. Locations describe the honourees’ own bases and practices, not a ranking of countries. Programme figures refer to the 2026 edition (ten awards across five individual and five organisation categories) and the 2015–2026 Hall of Fame. The report does not publish individual nomination data, and recognition is judged on merit and never bought.
About the report
Where does this report’s data come from?
From the publicly announced 2026 Cyber Security Awards cohort and the publicly stated bases and roles of each honouree. It does not disclose individual nomination details.
Why are some honourees described as cross-border rather than placed in one country?
Several 2026 honourees, including the Product and Community winners and two of the individual leaders, work across regions by design. The report records that rather than forcing a single pin onto the map.
Does a bigger cluster mean a country is better at cyber defence?
No. The clusters reflect where this year’s honourees happen to work. They are a description of the cohort, not a league table of nations.
How often is the report published?
Annually, after each edition is decided, with the date of last update shown on the page.
Can I cite these findings?
Yes. The geography and sector spread are drawn from the named, real 2026 cohort and are intended to be quotable, with attribution to the Cyber Security Awards.