The cybersecurity skills gap is one of the most persistent problems in UK technology, and the data behind it tells a more complicated story than most headlines suggest. Globally, ISC2’s most recent Cybersecurity Workforce Study puts the worldwide cybersecurity skills gap at around 4.8 million professionals. In the UK, the picture is different: the workforce has grown, entry-level hiring has fallen, and the type of shortage employers face has shifted from “not enough people” to “not enough people with the right, specific skills.”

This matters well beyond IT departments. A cybersecurity skills gap means slower breach response, thinner cover for smaller organisations, and a widening split between employers who can pay for scarce expertise and those who cannot. This article sets out the current UK figures on the cybersecurity skills gap, why it has proven so difficult to close, the role artificial intelligence is playing, and what employers and job seekers can practically do about it.

The UK Picture: What the Latest Data Actually Shows

Cybersecurity Skills Gap, The UK Picture

Before looking at causes and solutions, it helps to separate two things that are often conflated: a workforce shortage (not enough people) and a skills gap (people in post who lack specific expertise). The UK’s cybersecurity skills gap involves both, and they behave differently.

How the UK Gap Compares With Global Estimates

The UK government’s Department for Science, Innovation and Technology (DSIT) found that the UK cyber security workforce reached 143,000 professionals in 2024, a 5% increase on the previous year. Its estimate of the annual workforce gap, the shortfall between people entering the profession and the number needed, has narrowed sharply: from 11,100 in 2022 to 3,800 in the most recent report, driven largely by a 20% rise in graduate numbers.

That figure sits alongside a very different one. ISC2 estimates the UK’s cybersecurity skills gap at 93,000, using a global workforce-demand model rather than DSIT’s UK labour market survey. Neither number is wrong; they’re measuring different things. DSIT tracks the net annual shortfall in new entrants relative to demand, while ISC2 models the total additional headcount that organisations say they’d need to feel adequately staffed. When you see wildly different UK figures quoted elsewhere for the cybersecurity skills gap, the difference in methodology is usually why.

Separately, the UK’s dedicated cyber security sector, meaning firms that sell cyber security products and services rather than businesses with in-house security staff, generated £14.7 billion in revenue and £9.1 billion in gross value added in 2026, employing close to 70,000 people across more than 2,600 firms. That’s a distinct figure from the 143,000 broader workforce number and shouldn’t be confused with it when discussing the wider cybersecurity skills gap.

Regional Talent Hubs: London, Manchester, and Belfast

Cybersecurity employment in the UK isn’t evenly spread, and this regional imbalance is itself part of the cybersecurity skills gap story. DSIT’s registered office data suggests roughly 72% of estimated employment sits in Greater London and the South East, though the department itself notes this likely overstates the true regional concentration, since many employers have staff working across multiple UK locations rather than solely at their head office.

Belfast is the clearest counterpoint to a London-only narrative. Northern Ireland’s cyber security cluster, anchored by the Centre for Secure Information Technologies (CSIT) at Queen’s University Belfast, supports an estimated 2,778 jobs and over £258 million in direct gross value added for the local economy, with more than 100 cyber security businesses operating within three miles of Belfast city centre.

Government and industry have set a target of 5,000 cybersecurity professionals in Northern Ireland by 2030, backed by dedicated funding for doctoral training and master’s bursaries in cybersecurity and AI. For UK employers struggling to compete with London salaries, regional hubs like Belfast, alongside growing clusters in Manchester, Cheltenham, and Bristol, offer employers a genuine alternative talent pool for closing their own local cybersecurity skills gap, rather than a consolation prize.

Why the Gap Persists in 2026

Cybersecurity Skills Gap, Why the Gap Persists

If the UK workforce is growing and the annual shortfall is narrowing, why does hiring still feel so difficult? The answer lies less in the headline cybersecurity skills gap figure and more in where the shortage is actually concentrated.

The Entry-Level Paradox and Credential Inflation

DSIT’s research found that only 15% of UK cyber security recruitment in the past year was aimed at career starters, even as employers continue to describe the market as candidate-short. Part of the problem is credential inflation: roles advertised as “entry-level” frequently list certifications or years of experience that no genuine beginner could hold, which quietly closes off the bottom rung of the ladder while employers complain about a cybersecurity skills gap they’re partly creating themselves.

The pattern is self-reinforcing. Fewer entry-level roles mean fewer people gaining the two or three years of hands-on experience that turns a graduate into someone trusted with a live security incident, which in turn narrows the pool of people qualified for the mid-level roles employers actually want to fill. Anyone starting out can improve their odds by targeting roles genuinely built for beginners, such as the entry-level cybersecurity positions that don’t assume years of prior experience, alongside a properly structured cybersecurity internship that provides exactly the supervised, real-world exposure employers say they can’t find enough of.

Retention, Burnout, and the Leaky Bucket

Hiring is only half the cybersecurity skills gap problem. DSIT’s data show that the proportion of UK businesses reporting a skills gap in incident response rose from 27% in 2020 to 48% in 2024, nearly doubling in four years. That’s not purely a training failure; it’s a capacity one: teams that are already stretched have less time to develop the specific, high-pressure judgment that incident response demands, and the resulting strain pushes experienced staff out just as they become most useful to their employer.

Industry surveys of senior UK security leaders point in the same direction. Firms hit by a cyber attack in the past year most commonly cited heightened demand on internal IT and security teams as the biggest operational impact, ahead of direct financial loss and service disruption, with a meaningful share of affected organisations taking between one and four weeks to recover fully.

Every incident that drags on adds to the pressure that eventually drives people out of the profession altogether. A properly rehearsed incident response plan reduces the load on individual analysts during a live breach, which is one of the more direct ways employers can ease burnout without simply trying to hire their way out of the cybersecurity skills gap.

A Narrowing Pipeline: The Diversity Problem

One of the more troubling aspects of the UK’s cybersecurity skills gap is that the workforce is becoming less diverse rather than more, at exactly the moment it needs a wider pool of talent to draw from. DSIT’s research found that just 17% of the UK cyber security workforce is female, against 48% of the UK workforce overall, while people with a disability represent only 8% of cyber security staff. Some 19% of cybersecurity professionals come from ethnic minority backgrounds, yet only 8% of those individuals hold senior roles.

Widening the pipeline isn’t just a fairness argument, though it’s certainly that. In a market with a genuine structural shortage, excluding large parts of the potential talent pool through inflexible hiring practices or an unwelcoming workplace culture makes the cybersecurity skills gap harder to close, not easier.

The Salary Premium

Scarcity shows up in pay as much as in vacancy counts. Recruitment data from across the UK cyber security market shows entry-level analyst salaries typically starting between £30,000 and £35,000, while experienced senior analysts and architects can comfortably clear six figures, and CISOs or senior security leaders in London and the South East can exceed £200,000 for the right role. UK employers benchmarking pay against figures more than a year old are almost certainly underestimating what it now takes to attract and keep people, which quietly widens their own cybersecurity skills gap even as the national picture improves.

The Role of AI in Closing (and Widening) the Gap

Artificial intelligence is starting to reshape the cybersecurity skills gap in two directions at once: automating some of the workload that contributes to burnout, while creating a new category of shortage of its own.

Where AI Is Easing Pressure on Security Teams

DSIT’s 2025 research found that just over half of UK cybersecurity businesses (53%) already have staff using AI tools in their day-to-day work, most commonly for triaging alerts and spotting patterns in large volumes of log data. Used well, this frees experienced analysts to focus on judgment calls that genuinely need a person, rather than sifting through low-value alerts by hand, and it’s one of the few near-term levers available for easing the cybersecurity skills gap without waiting years for new graduates to come through.

The New Skills AI Demands

The same research found that around two-thirds of UK cybersecurity businesses (65%) expect their need for AI-related skills to grow over the next year, yet only 42% say their staff have received any formal AI training. That gap between expectation and preparation is becoming its own recruitment headache, layered atop the existing cybersecurity skills gap, particularly for roles that combine security expertise with an understanding of how AI systems can be manipulated or misused.

Two specific specialisms are emerging fastest: AI-assisted threat hunting, where analysts use AI tools to spot patterns in data too large for a human to review manually, and AI system security, where the job is to protect AI models and pipelines themselves from manipulation, data poisoning, and misuse. Neither specialism existed in most job descriptions a few years ago, and formal training pathways for both are still catching up with demand. Employers who invest early in this niche, rather than waiting for a mature candidate pool to appear, are likely to find it easier to hire for in two or three years’ time.

Practical Strategies for UK Employers and Job Seekers

None of this has a single fix, but the strategies below are grounded in what’s actually working for UK organisations tackling their own cybersecurity skills gap, rather than generic advice that could apply anywhere.

Rethinking Entry-Level Requirements

Given how few roles currently target career starters, the most direct lever available to employers is simply to create more of them and be honest about which skills genuinely require years of experience and which can be taught on the job. Certifications such as CompTIA Security+ are designed for exactly this level and shouldn’t be treated as a bar to clear before someone’s considered employable. Stripping unnecessary experience requirements out of junior job adverts is a low-cost change that directly widens the entry-level pipeline.

Building an Internal Talent Pipeline

Identifying which existing staff have an aptitude for security work, then investing in structured training and mentorship, addresses the cybersecurity skills gap without competing in an overheated external hiring market. This approach also tends to improve retention, since employees who see a clear route into more senior security roles are less likely to leave for it elsewhere. Encouraging staff to work towards recognised cybersecurity certifications as part of this pipeline gives both the employer and the employee a clear, structured route to follow.

Government Programmes Worth Knowing About

UK employers don’t have to solve the cybersecurity skills gap entirely on their own. TechFirst, a £187 million government programme delivered by DSIT and built in large part on the existing NCSC CyberFirst initiative, funds bursaries, apprenticeships, and school-level outreach aimed at growing the domestic tech and cyber talent pipeline, including a dedicated Women’s

Programme targeting at least 300 participants in high-demand technical roles. The scheme’s TechGrad strand alone aims to support several hundred undergraduate and postgraduate students a year, while industry partners such as Cognizant have committed to supporting thousands of graduates and researchers and reaching a million secondary school pupils over the coming years, specifically to widen the pipeline feeding into roles that would otherwise sit on the wrong side of the cybersecurity skills gap.

Employers can also look to structured apprenticeship routes such as the Cyber Security Technologist standard, which offer a genuine alternative to graduate-only hiring for organisations willing to invest in training over immediate experience. None of these programmes closes the cybersecurity skills gap on its own, but they materially lower the cost of building a pipeline compared with relying entirely on the open market.

When Outsourcing to an MSSP Makes Sense

For smaller organisations without the budget or scale to build a full in-house team, a managed security service provider (MSSP) can close the gap immediately rather than waiting on a hiring process. DSIT’s qualitative research found that a large majority of UK businesses already outsource at least some incident response work, often because even a technically capable in-house team simply doesn’t get enough exposure to live incidents to stay confident handling one. For SMEs in particular, this can be a more realistic response to the cybersecurity skills gap than competing with much larger employers for the same scarce specialists.

The overall trend is genuinely encouraging: the UK’s annual workforce shortfall has narrowed sharply, and government-backed pipeline programmes are starting to feed more people into the profession each year. What hasn’t improved much is the distribution of that progress. Entry-level hiring is still thin; incident response and advanced technical skills gaps have barely moved in five years; and the workforce is becoming less diverse rather than more. Employers who address those specific, well-documented gaps directly, rather than treating the cybersecurity skills gap as one undifferentiated problem to be solved by hiring more people, are the ones most likely to see it close within their own organisation.

FAQs

What is the current cybersecurity skills gap in the UK?

DSIT’s most recent labour market report puts the UK’s annual workforce gap at 3,800, down from 11,100 two years earlier, against a total workforce of 143,000. ISC2’s own model estimates the UK’s cybersecurity skills gap at 93,000, using a different, demand-based methodology, which is why you’ll see different figures quoted elsewhere.

Why is there a shortage of cybersecurity professionals in the UK?

It’s less a simple shortage and more a mismatch. Only 15% of UK cyber security recruitment currently targets entry-level candidates, which narrows the pipeline of people gaining the experience needed for mid-level roles, while specific skills gaps in incident response and advanced technical work have barely shifted in five years.

What certifications are most useful for closing the cybersecurity skills gap?

For entry-level roles, CompTIA Security+ is widely recognised and doesn’t assume prior experience. More advanced certifications, such as CISSP, demonstrate deeper expertise but typically require several years in the field first, so they’re better suited to progression than a first step.

How does AI affect the cybersecurity skills shortage?

It cuts both ways. DSIT research shows 53% of UK cyber security businesses already use AI to help triage alerts and analyse data, easing pressure on stretched teams, but 65% expect their need for AI-specific skills to grow, while only 42% have given staff any formal training in this area.

Are entry-level cybersecurity jobs hard to find in the UK?

Yes, and the data confirms it isn’t just perception. With only 15% of recruitment aimed at career starters, competition for the entry-level cybersecurity roles that do exist is intense, which is why structured internships and beginner-friendly certifications matter more here than they might for other careers.

Can smaller UK businesses afford to tackle the cybersecurity skills gap?

Often, yes, without matching a large enterprise’s hiring budget. Outsourcing specific functions, such as incident response, to an MSSP, investing in a well-rehearsed incident response plan, and upskilling existing staff rather than competing for scarce external hires are all lower-cost routes that UK businesses are already using at scale to close their own cybersecurity skills gap.