About the Cybersecurity Audit Professional of the Year category
Who this award is for
This award is for the people who check that security controls do what they are supposed to. A recent nominee is a senior auditor at a gas utility who led the audit team's largest engagement and co-leads an industry group of IT audit directors.
Describe the findings that led to action and what changed afterward. If the work is mostly building controls and preparing an organization for its audits, Cybersecurity Compliance and Assurance Professional of the Year is the category for that, and someone who does both can enter both. Auditors who also assess risk can add Cybersecurity Risk Management Professional of the Year, and the audit or assurance program can be entered in Best Risk and Compliance Program.
Related categories to enter
Each category is judged separately, so you can enter a nominee in every category that fits their work, with a separate nomination for each. Tailor each nomination to that category's focus. Entering several related categories gives the work more than one chance to be recognized.
How entries are judged
An independent jury of security practitioners, analysts and CISOs scores each nomination on leadership, innovation and impact. Each nomination competes in its category against peers in a similar setting and region. Your entry package, any sponsorship and public votes do not affect the jury's scores.
Strong entries in this category show:
- Leadership — the audits the nominee leads and the standing they have with management, the audit committee and the teams they review.
- Innovation — improvements to how audits are done, such as continuous testing, data analytics, shared dashboards for evidence or a risk-based audit plan.
- Impact — findings that led to fixes, repeat findings eliminated, audit cycles shortened, risks raised before they became incidents. Pick the results the organization acted on.
The jury awards Gold, Silver or Bronze, or a Finalist badge, and results are published on this site and announced to the 600,000+ member Cybersecurity Insiders community. Every approved nomination also enters the separate Community Choice award, decided by public votes.
How to enter
Anyone can submit a nomination: the nominee, a colleague or manager, the organization, or an agency entering a client. The nomination form has a confidential field for detail that is shared with the judges and not published, such as internal figures, customer names or incident details. Deadlines, pricing and entry steps are on the How it Works page.