From “Whatever We Are” to “Influencers”: On Being Shortlisted for Cyber Scribe

Futuristic cityscape illuminated by neon lights, featuring a large digital emblem with a book and quill surrounded by laurel leaves, while figures in dark cloaks observe the scene.

A few days ago we received an email saying that we had been shortlisted for Cyber Scribe at the Security Serious Unsung Heroes Awards 2026.

Graphic design featuring the text 'Unsung Heroes Awards!' in a comic book style, with bold colors and dynamic layout.

We aren’t particularly serious or heroic… so, we had to Google pretty much all of that.

After that, we know the awards have been running in the UK for ten years. Cyber Scribe is a new category for cybersecurity blogs and newsletters, and seven names made the shortlist. There are people from Bora, IASME, BforeAI, EPAM and other parts of the security industry.

And then there’s us, from Murcia.

Mostly, we are just guys from ITRES who investigate things because they look interesting, broken or both.

Our English comes mainly from RFCs, vendor calls, GitHub issues, conference talks and years of clicking accept privacy notice in Deepl. On a good day we are probably somewhere between B2~C1 and the customer understood the email.

So yes, getting shortlisted for a writing-related award in the UK was unexpected.

And, obviously, it makes us happy.

Look at me, I’m an influencer

We make fun of influencers quite a lot. LinkedIn makes this very easy. Every morning somebody (wearing a hoodie?) discovers things like zero-trust, zero-day, or anything with a zero for the first time and writes four lines with sixteen emojis about it. Somewhere, an image carousel is explaining ransomware to CISOs. Somebody else is selling a course (well, many).

A character in a gray outfit sitting in an office chair, making a hand gesture and appearing animated, with the text 'SECURITY INFLUENCER' displayed prominently.

Still, influence itself is a useful and powerful idea.

You can spend days, weeks or months finding something genuinely interesting, prove it, screenshot it and leave it in a private repository so you and four colleagues know about it. Stupid, isn’t it? But the moment you share it, things can happen.

A vendor fixes something. Another researcher reproduces the issue and finds the part you missed. A SOC uses the technique. Months later, the work appears in a CVE reference, an advisory or some article you had no idea existed.

That is influence too… and probably the kind we care about. This argument, unfortunately, brings us dangerously close to becoming influencers ourselves. But, we promise not to launch a course.

Whatever we are

Depending on the week, LABS @ ITRES can look like vulnerability research, offensive security, reverse engineering, detection engineering, AI security or guys spending far too much time with a cheap piece of hardware.

We have gone from messing with LLM weights to turning patches into reconnaissance material, with plenty of questionable hardware decisions in between. Calling ourselves researchers sometimes feels too academic. Bloggers is technically difficult to deny at this point. Content creators still sounds like something that should come with a ring light.

Maybe we don’t need a particularly good answer. In short, it all depends on having a question, enough curiosity to answer it, and, in the end, something good enough to make it worth publishing.

So, whatever we are, we seem to have found a way of keeping ourselves busy.

So, Cyber Scribes?

The ceremony is on 20 October, and we have been invited.

This is slightly outside our normal operating environment. Terminals, test labs and virtual machines are familiar. An awards ceremony for something we wrote, considerably less so.

We are genuinely happy to be there. As we’ve already mentioned, there are six other names on the Cyber Scribe shortlist, coming from very different parts of the security world, and being included among them already feels important enough without trying to make it bigger than it is.

Now we have flights to book, people to meet and probably several opportunities to discover that our spoken English is considerably worse than our written English.

The result can wait until October.

Until then, we’ll keep opening tabs in the terminal window.

See you in London.