Blog
The CyberHire journal.
Writing for security leaders, hiring managers, and the people who actually do the work. No thought-leadership fluff. Opinions welcome.
-
The Cyber Security and Resilience Bill will not test your people
The Cyber Security and Resilience Bill raises the cost of weak cyber capability. Why CVs and certifications will not evidence it, and what would instead.
-
Cyber doesn't have a talent shortage. It has a broken filter.
Capable people cannot get hired. Employers are buried in applications. Both problems have the same cause, and it is not a shortage of talent.
-
The UK cyber skills shortage is now an assurance problem
UK cyber workforce supply is growing and the shortfall is shrinking, yet employers still cannot tell who can do the work. The problem has moved from supply to assurance.
-
How to assess a SOC analyst before you interview them
SOC hiring runs on certifications and trivia. Here is what a SOC analyst actually does all day, how to test each part of it, and what to probe at interview.
-
17 questions to ask a cyber assessment vendor before you buy
The questions that separate a real cyber security assessment platform from a generic testing tool with a security category, including the ones we would fail.
-
Work samples vs interviews: what the evidence actually says
Assessment vendors claim work samples beat interviews. The current research does not support that. Here is what it does say, and what it means for cyber hiring.
-
AI has broken the CV signal in cyber security hiring
Applications are up and every CV now reads well. What AI actually changed about cyber hiring, what a CV still tells you, and what to use instead of reading harder.
-
How to screen 200 cyber applicants without reading 200 CVs
Two hundred applications, one vacancy, and no reliable way to rank them. The practical method: invert the funnel, test first, and read CVs last.
-
The cyber skills gap is a validation problem hiding in plain sight
DSIT 2025 says the cyber workforce gap is improving. Look closer. We're producing more credentialed people, not more capable ones. The shortage is a validation problem.
-
Hands-on hiring: the alternative to trust-based cyber recruitment
Every other technical discipline tests skills before hiring. Cyber security is the last holdout. Hands-on hiring is the case for cyber catching up - and where to start.
-
Paper tigers: spotting the cyber candidate who can't do the job
The cyber industry is full of paper tigers - people who look great on a CV but have no idea what they are really doing. The practitioner read on how to spot them.