Technology Resilient Company of the Year
Criteria
About this award
The Technology Resilient Company of the Year is bestowed upon an organisation that demonstrates exceptional resilience in the face of technological challenges and disruptions. It recognises companies that have implemented robust technology infrastructure, effective cybersecurity measures and comprehensive disaster-recovery plans to ensure continuity of operations and to safeguard against cyber threats. The recipient exemplifies innovation, adaptability and proactive risk management in navigating the evolving technology landscape.
Who may apply
Organisations. Submissions must be authorised by a company representative with the appropriate level of authority.
Basis of evaluation
Entries are assessed against the organisation's readiness to implement a Digital Trust Ecosystem Framework (DTEF), using the maturity levels of the Capability Maturity Model Integration (CMMI) - from Initial (reactive and unpredictable) through Managed, Defined and Quantitatively Managed to Optimizing (stable, data-driven and built for continuous improvement). For each area, an organisation selects the level that best describes its current practice.
Dimensions assessed
- Direct and monitor (governance, risk management, measurement): a documented digital/IT strategy aligned to business goals; a risk-management framework that considers digital-trust factors such as privacy and security; regular reviews of digital-trust practices; and defined KPIs or KRIs tracked through regular reporting.
- Culture (values, ethics, behaviours): an actively fostered culture of ethics and integrity; staff training on privacy, security and trust; open, reprisal-free reporting of trust-related issues; and customer feedback on trust perceptions.
- Architecture (technology infrastructure, design principles): robust security measures such as encryption and access controls; a defined approach to maintaining and updating infrastructure and addressing vulnerabilities; regular testing with mitigation plans; and tested disaster-recovery and business-continuity plans.
- Enabling and support (resources, processes, skills): documented and practised processes for privacy, security and incident response, including breach communication protocols; regularly evaluated information systems; and transparent, accountable decision-making.
- Emergence (collaboration, innovation, ecosystem dynamics): active participation in industry forums and openness to partnerships that enhance digital-trust posture.
- Human factors (awareness, skills, behaviours): the proportion of staff in IT, cybersecurity, GRC and privacy roles and their certifications; metrics tracking employee awareness; a culture of continuous learning; recognition of contributions to digital trust; and human-centred, usable security and UX design.
Evidence
Applicants provide company details, an overview of market presence and offerings, and supporting documentation. Detailed responses should be specific and concrete; generalised answers generated by AI engines are not considered.
