About the Cybersecurity Risk Management Professional of the Year category
Who this award is for
This award is for people who help an organization decide which cyber risks matter and what to do about them. Recent nominees include a risk management specialist who runs the risk program and risk assessments at a cloud and network security provider, and a director of governance, risk and compliance at a security vendor who automated third-party risk assessments, with suppliers ranked by risk.
Risk, compliance and audit work often overlap, and many nominees do more than one. Enter here for the risk decisions, and add Cybersecurity Compliance and Assurance Professional of the Year for the controls and evidence or Cybersecurity Audit Professional of the Year for independent testing. The risk program itself can be entered in Best Risk and Compliance Program.
Related categories to enter
Each category is judged separately, so you can enter a nominee in every category that fits their work, with a separate nomination for each. Tailor each nomination to that category's focus. Entering several related categories gives the work more than one chance to be recognized.
How entries are judged
An independent jury of security practitioners, analysts and CISOs scores each nomination on leadership, innovation and impact. Each nomination competes in its category against peers in a similar setting and region. Your entry package, any sponsorship and public votes do not affect the jury's scores.
Strong entries in this category show:
- Leadership — who relies on the nominee's view of risk: the executives, risk committees or business owners they brief, and what those people decided as a result.
- Innovation — a clearer way to assess or express risk, for example putting it in financial terms, ranking suppliers by risk or automating assessments.
- Impact — risk reduced, or accepted with open eyes. Examples are top risks brought down, assessments done faster, suppliers onboarded sooner and losses avoided. Numbers from the risk register make this concrete.
The jury awards Gold, Silver or Bronze, or a Finalist badge, and results are published on this site and announced to the 600,000+ member Cybersecurity Insiders community. Every approved nomination also enters the separate Community Choice award, decided by public votes.
How to enter
Anyone can submit a nomination: the nominee, a colleague or manager, the organization, or an agency entering a client. The nomination form has a confidential field for detail that is shared with the judges and not published, such as internal figures, customer names or incident details. Deadlines, pricing and entry steps are on the How it Works page.