Cyber Security Advocate of the Year.
Most of the people who decide whether an organisation gets breached never read a threat report. This category honours the people who reach them anyway, and the panel scores them on who they brought along, not how loudly they spoke.
The 2026 Advocate of the Year
Jim West was named Cyber Security Advocate of the Year in 2026, recognised for the long, patient work of putting the case for security in front of people who do not work in it. He had been honoured by the programme before, as Cyber Personality of the Year in 2021, the kind of repeat recognition the Hall of Fame is built to record.
A decade of winners sits in the Hall of Fame.
What the panel scores against
Advocacy is easy to claim and hard to prove. The panel works against published criteria, and the strongest entries answer four questions plainly. Who did the nominee reach who would not otherwise have listened. What did those people do differently afterwards. Can the change be checked by someone other than the nominee. And did the work widen the field, drawing in people who had been kept out or had counted themselves out.
An advocate earns this honour by moving people, not metrics. A talk that filled a room matters less than the apprentice who took up a place because of it, or the small business owner who finally turned on multi-factor authentication after a session pitched in plain language. The panel reads for that human aftermath.
What a winning record looks like
Strong nominations in this category trace a line from the nominee to a person who changed. A school that runs a security club because someone volunteered to start it. A team that reports incidents earlier because someone made it safe to admit a mistake. A career that began because an advocate answered a cold message and kept answering. The work is checkable, and the people it reached can speak to it.
Weak nominations count audiences. Conference stages, podcast downloads, post impressions. Those numbers describe the size of a megaphone, and the panel reads past them to the question that decides the category: did anyone become safer, or join the field, because of this person. Reach without that answer is just noise at scale.
The criteria the panel scores against
The Cyber Security Advocate of the Year award recognises an individual who has made a significant impact by championing awareness, education, and inclusion in cybersecurity. It celebrates advocates who work to raise the profile of the industry, promote diversity, and inspire stronger cyber resilience across society — those who use their voice and influence to create meaningful change and empower communities.
- 01Enforcing Awareness
- Evidence of efforts to raise awareness of cybersecurity risks and promote best practices among individuals, organisations, and communities.
- 02Enforcing Diversity
- Evidence of initiatives, policies, or advocacy that promote diversity and inclusion, encouraging underrepresented groups to enter and thrive in cybersecurity roles.
- 03Contribution to the Industry
- Evidence of contributions to advancing the cybersecurity profession through thought leadership, innovation, or collaboration with peers.
- 04Achievement
- Evidence of significant achievements and recognition in advocacy, including measurable impact, campaigns, or awards.