iSANZ
2026
Entry Information

Whether you’re a seasoned professional, rising star, or cutting-edge startup, the iSANZ Awards provide a platform to share your success and inspire others in the cybersecurity community. These awards not only celebrate excellence but also set the benchmark for industry standards and best practices.

In 2026, there are seven award categories to choose from. Our panel of judges will carefully select three finalists in each category. Each finalist will be evaluated against the judging criteria, with winners in each category unveiled at our gala awards dinner event on 21 October.

Award Categories

 

Attention all cybersecurity professionals! Don’t miss your chance to be recognised at the iSANZ Awards.

Entries for 2026 are now open, with finalists and winners to be celebrated at our gala dinner awards event in October.

Human Security Initiative / Security Awareness Campaign Of The Year
CISO of the Year
Start Up Or New Business Of The Year
Security Team Of The Year
Security Company Of The Year
Up & Coming Cybersecurity Star Of The Year
Cyber-Resilience Initiative of the Year

Human Security Initiative / Security Awareness Campaign Of The Year

This category celebrates organisations that have run an outstanding security awareness campaign that genuinely engaged their people and changed behaviour. Whether it was a phishing simulation program, a creative internal communications campaign, a compliance training uplift, or a culture-shifting initiative — we want to hear how you brought security to life for your people.

Who Can Enter:

This category is open to New Zealand based organisations that have designed and delivered a security awareness or behaviour change campaign within the qualifying period. Entries must be submitted by the organisation that ran the campaign. Vendors, technology providers, and security product or service sellers are not eligible to enter. Where a campaign was developed with the support of an external agency or provider, the entry must be led by the organisation itself.

Judging Criteria:
  1. Were the awareness objectives and target audience clearly defined, and were they met?
  2. How was engagement measured, and what evidence is there that the campaign resonated with its audience?
  3. Did the campaign result in a measurable change in employee behaviour or security culture?
  4. Was the campaign delivered creatively and effectively, and was it appropriate for the organisational context?
  5. Was it delivered within budget and timeframe, and could it be sustained or built upon?

Chief Information Security Officer Of The Year

Great security leadership isn’t just about managing risk — it’s about inspiring teams, influencing boards, and translating complex threats into clear organisational action. This award celebrates the leaders who do all of that, and make it look easy. Whether leading a team of one or one hundred, the best CISOs leave their organisation measurably safer and their people better equipped than they found them.

Who Can Enter:

This category is open for people who lead and manage security functions for organisations in New Zealand. A Chief Information Security Officer is the senior leader responsible for setting security strategy, advising the CE and Board on cyber risk and ensuring the security function is supporting and protecting their organisation.

 
Judging Criteria:
  1. Has the entrant held a hands-on full-time position as senior security leader during the previous 12 months (e.g., Chief Information Security Officer, Head of Security)?
    2. How does the entrant lead security outcomes to their organisation through their work?
    3. What evidence is given that the entrant is a cyber security champion who is committed to improving cyber security?
    4. What evidence is given that the entrant is a trusted security professional who makes a difference, mentors others, and is a “security doer”?
    5. What evidence is given that the entrant is a trusted and respected security professional who makes a difference within the organisation they work for and/or the wider NZ cyber security industry?

Start Up Or New Business Of The Year

This category celebrates the exciting, emerging, homegrown, start-ups turning kiwi talent into innovative products, services, and ideas that are making a real difference. Whether they’re tackling an unsolved problem, disrupting an established space, or bringing a fresh New Zealand perspective to a global challenge; these are the companies we think the industry should have on its radar.

Who Can Enter:

This category is open to new cybersecurity and information security businesses that were founded in New Zealand, are headquartered here, and have been operating for no more than five (5) years. The company must be New Zealand-majority owned and led by a New Zealand-based leadership team. This is an award for homegrown start-ups. New Zealand branches or subsidiaries of established international companies are not eligible.

Judging Criteria:
  1. Has the entrant demonstrated what problem their business is solving and a good understanding of this challenge?
  2. Has the entry demonstrated a good rate of revenue growth during the period of operation?
  3. Has the entry demonstrated they are successfully delivering quality services and/or products into the NZ or international market that make a difference to customer security?
  4. Has the entry demonstrated a values driven approach to building a company and is this sustainable?
  5. Has the entry provided evidence they are building a resilient, diverse and inclusive culture in their company?
  6. Has the entry demonstrated a successful, innovative approach to starting a security company in NZ?

Security Team Of The Year

This category celebrates the hardworking, high-performing security teams who are working every day to protect their organisation, mature their capabilities, and make New Zealand a safer place to operate digitally. Whether they’re a small but mighty team punching above their weight, or a larger team delivering excellence at scale, this award recognises the collective effort, culture, and impact that makes a security team truly outstanding.

Who Can Enter:

This category is open to outstanding information / cybersecurity teams who work closely together to achieve the best possible performance, creative contributions – and/or go above and beyond in contributing to information security inside their organisation.

Judging Criteria:
  1. What measurable improvements did the team achieve? Does the nomination include evidence of risk reduction or improved resilience due to the security team’s actions and deliverables?
    2. Does the entry demonstrate continuous development and improvement of infosec and or cyber capabilities by providing a holistic security solution – ensuring strong defences while keeping in view evolving threats?
    3. Is the team contributing to the overall security strategy and business goals?
    4. Is the team fostering a learning environment, mentoring junior members, or upskilling across disciplines? Has the team invested in professional development, certifications, or training?
    5. Do the team members come together as individuals and a group to strengthen the way they work and create a strong team culture?
    6. Are there inclusive practices and efforts to build a healthy, sustainable team culture?
    7. How does the team forge security learning paths and transfer knowledge to retain top talent and break down skill-development barriers for aspiring new cyber professionals?

Security Company Of The Year

This award celebrates stand-out organisations that make security their business, rather than something that helps them in business. The security company of the year is awarded to the security company that has not only supported their customers and clients, but has worked to grow the security industry in Aotearoa New Zealand.

Who Can Enter:

Security company of the year entries are open to organisations that provide security services to other organisations. They could be a consultancy, a managed security services provider, a security vendor or other organisation that works to protect others’ cyber security. This category is a celebration of homegrown New Zealand security companies doing great work.

Eligible organisations must be based and registered in New Zealand, majority New Zealand-owned, led by a New Zealand-based Chief Executive, and if publicly listed, listed on the NZX.

Past winners include Vodafone (2015), RedShield (2016), Aura Information Security (2017, 2018), Defend (2019) and SafeAcademy (2021).

Judging Criteria:
  1. Has the entry demonstrated they are delivering high quality security services and/or products into the NZ market that make a difference to the security of others?
    2.Has the entry demonstrated a values driven approach to building a company and is this sustainable?
    3. Has the entry provided evidence they are building a resilient, diverse and inclusive culture in their company?
    4. Has the entry demonstrated a successful approach to bringing talented cyber security professionals into the industry and setting them up for success?

Up And Coming Cybersecurity Star Of The Year

This category focuses on our new cyber security professionals, celebrating the best and brightest who have recently joined our awesome, growing cyber security industry.

Who can enter:

This category is open to all individuals who are a newcomer to the world of Cyber / Information security in NZ with less than 3 years experience and who have made a positive and impressive impact to our community.

 

Judging Criteria:
  1. Does the entrant show excellent potential and have they demonstrated remarkable talents at an early stage in their InfoSec / cyber career. Qualities may include fresh thinking, determination, inspiration and communication?
  2. Is there a description of the role played by the entrant and evidence of how the entrant has shown innovation and leadership in developing and implementing successful projects, publications, activities or initiatives?
  3. Has the entrant demonstrated leadership and ability to think strategically about information security?

Cyber-Resilience Initiative of the Year

This category recognises organisations that have undertaken a significant cyber resilience program that has meaningfully strengthened their security posture. This could be a wide-scale cyber uplift program, a transformative infrastructure or architecture project, an incident response overhaul, a risk remediation initiative, or any other substantial effort that has made the organisation measurably more resilient against cyber threats.

Who can enter:

This category is open to New Zealand organisations (or New Zealand branches of mutli-national organisations) that have successfully delivered a cyber resilience, uplift, or security improvement initiative within the qualifying period and within their New Zealand organisation. Entries must be submitted by the organisation that implemented the initiative. Vendors, technology providers, and security product or service sellers are not eligible to enter on behalf of the client, but can support a submission.

Judging Criteria:

1. Were the objectives clearly defined, including the specific risk, vulnerability, or capability gap being addressed?
2. How was the success of the initiative measured, and was it demonstrably achieved?
3. Was the initiative delivered within budget and timeframe?
4. What measurable improvement to the organisation’s security posture or resilience can be evidenced?
5. How well was the initiative adopted across the organisation, and was stakeholder impact considered and managed?

 

Connect with iSANZ
on Social Media

iSANZ Entry Tip Sheet: How to Craft a Standout Entry

What makes an entry stand out?

2023 iSANZ Awards Finalists

 

Each year, our judges carefully examine the category entries, creating a shortlist of three finalists in each category. From this shortlist, the winner in each category is chosen after thorough deliberation – to be officially announced at our highly anticipated annual gala dinner event. The finalists listed below have been selected by the judges for the 2023 iSANZ Awards.

Security Project / Awareness Initiative Of The Year

This category recognises outstanding and successfully delivered information security projects or initiatives. It could be an amazing security awareness campaign, an organisational cyber uplift program, or some other awesome security project.

No results found.
No results found.

Senior Cybersecurity Professional Of The Year

This category recognises outstanding and successfully delivered information security projects or initiatives. It could be an amazing security awareness campaign, an organisational cyber uplift program, or some other awesome security project.

No results found.
No results found.

Start-Up Or New Business Of The Year

This category celebrates the best new security companies that are making their mark and helping to raise the cyber resilience of Aotearoa New Zealand.

No results found.
No results found.

Security Team Of The Year

This category celebrates high performing security teams that are improving the cyber security posture of their organisation day in, day out.

No results found.
No results found.

New Zealand Development Shop Of The Year

This award celebrates the teams of people across Aotearoa New Zealand who are building great secure-by-design software to ensure that their customers can safely and confidently use their software without having to harden it first, and can rely on the development team to factor in security at all stages of the development lifecycle.

No results found.
No results found.

Up-And-Coming Cyber Security Star Of The Year

This category focusses on our new cyber security professionals, celebrating the best and brightest who have joined our awesome, growing cyber security industry.

No results found.
No results found.
Share This