Cyber doesn't have a talent shortage. It has a broken filter.
Capable people cannot get hired. Employers are buried in applications. Both problems have the same cause, and it is not a shortage of talent.
The industry has settled on an explanation for its hiring difficulties, and repeats it constantly. There are not enough people. We have a talent shortage. The answer is more graduates, more apprenticeships, more conversion courses.
The UK government’s own figures suggest that explanation is wrong, and has been for a while.
What is actually happening is two failures that look unrelated and are not. Capable people cannot get hired, applying to dozens of roles and hearing nothing. Employers cannot find anyone, buried under applications they have no way of telling apart. Those are the same failure viewed from either end of it, and the cause is that the instrument connecting the two sides, the CV, has stopped carrying useful information.
The shortage is closing while the door is shutting
The Department for Science, Innovation and Technology surveys the UK cyber workforce annually. Its 2025 edition, published in February 2026, found the annual workforce shortfall had fallen to 3,800 people, down from 11,100 the year before. The workforce grew 5% to roughly 143,000, and around 6,000 people graduate into it each year.
By the standard measure, in other words, the shortage is closing rapidly.
Now consider what happens to those graduates. Only 31% end up in cyber security roles. Their unemployment rate is 9% against a 5% average, so people who studied the subject with the famous shortage are nearly twice as likely to be out of work as the typical graduate.
The entrance is narrowing at the same time. In 2022, a quarter of cyber job adverts were open to candidates with under a year of experience. By 2024 that had fallen to 17%, while 63% of adverts asked for two to six years. Only 15% of recruitment into the cyber sector comes from career starters.
Supply is rising and the door is closing, simultaneously. That is not the signature of a shortage. It is the signature of a market that cannot identify what it is looking for.
The employer side of the same problem
A SOC analyst vacancy will draw somewhere between one and three hundred applications. That volume is not a pile to be read carefully; it is a wall to be got through, usually by someone with other work to do.
The wall has grown. LinkedIn’s own figures, reported last year, put applications across the platform at around 11,000 a minute, a 45% rise in twelve months. Workday recorded applications up 31% in the first half of 2024 against the same period the year before. Applying to fifty roles used to cost a week of evenings and now costs a prompt.
The more consequential change is not volume but uniformity. Any candidate can paste a job advert and their own history into a language model and receive a CV tuned to that specific advert, in the right register, with the right terms in the right order. The badly formatted application with three spelling mistakes has largely disappeared. Everything arrives looking competent, which sounds like an improvement and is the opposite of one. When every document clears the bar, the bar has stopped doing anything.
Why both failures are the same failure
A capable candidate with an unconventional background submits an application. It lacks the expected keywords, or the recognisable employer names, or the required years. It is filtered out, and nobody involved ever discovers whether that person could have done the work.
A candidate who writes well, or who used a better tool, progresses. They reach interview. They may be excellent. They may be unable to read a log file, which the hiring manager will establish roughly forty minutes into a conversation that cost a senior engineer their afternoon.
Neither party is suffering from a scarcity of people. Both are suffering from a filter that cannot see the thing it is being asked to judge.
It is worth being precise about what the CV ever measured, because it was never capability. It was weak evidence of two things: that a candidate had bothered to tailor their application, and that they could describe their own work clearly. Both were reasonable proxies for effort and communication. Both now cost nothing to produce. What remains is a document in which every applicant makes the same claims in the same order.
The response that makes it worse
Consider the position of a hiring manager holding two hundred applications, no reliable way to distinguish between them, and an obligation to justify a shortlist to somebody.
The rational move is to demand more experience. Not because years are a good predictor of capability, but because years are the only filter that survives being questioned. Nobody is criticised for shortlisting the candidate with five years at a recognisable employer.
This is precisely what the DSIT figures show happening across the market. Adverts drift towards two to six years, the entry-level door narrows, and every capable newcomer is pushed further from the profession they trained for. The industry then reports a talent shortage, which is true from where it is standing and entirely self-inflicted.
What it costs
The obvious costs are time and money. Interviewing is the most expensive stage of any hiring process, and an hour of a senior analyst’s time is an hour removed from the queue. If half of the people reaching interview cannot do the job, that discovery is being made with the most scarce resource available. Every re-run of a failed process carries advertising, agency and management costs a second time.
The less obvious cost is security risk, and it is the one with a figure attached.
IBM’s 2026 Cost of a Data Breach report put the global average breach at $4.99 million. Separately, reviewing a decade of its own data, IBM concluded that the cyber skills gap contributed a $1.76 million increase to average breach costs, and that more than half of breached organisations were operating with severe security staffing shortages.
Being short of capable security people is therefore not a human resources inconvenience with a soft cost attached. On IBM’s numbers it is among the more expensive conditions an organisation can carry into an incident. The people who might close that gap are currently being rejected for insufficient years on a document that no longer tells you anything.
What works instead
The alternative is not complicated, which is part of why its absence is frustrating. Rather than inferring capability from a description, put a representative piece of the work in front of the candidate and observe what they do with it.
In practice that means replacing “do you understand phishing” with a case they have to actually work.
That question cannot be answered from a syllabus. The candidate either understands what consent-based abuse looks like when every conventional signal is green, or they do not, and no amount of CV polish or rehearsed interview technique closes the gap. The answer exists only inside the artefact in front of them.
Run that across every applicant under identical conditions, scored the same way, and the output is the thing a CV structurally cannot provide.
Why it resolves both sides at once
For the employer, the guesswork moves out of the expensive part of the process. Interviews are spent on candidates already known to be capable, which means fewer of them, better use of senior time, and less rework when a hire does not survive probation. Over time the standing capability of the team rises, which is the variable IBM has just attached $1.76 million to.
For the candidate, it is frequently the first fair hearing they get. The career changer, the self-taught engineer, the returner, the person without a conventional degree: none of them present well against a keyword filter, and any of them may be able to do the work. An hour of practical assessment settles in their favour what no amount of CV rewriting ever will.
One mechanism, both failures. That symmetry is unusual, and it is the reason I think this is the answer rather than merely an answer.
What the evidence actually supports
It would be convenient to present practical assessment as a solved problem. It is not, and anyone claiming otherwise deserves scepticism.
Selection methods are scored on how well they predict subsequent job performance, on a scale where zero is no better than chance and one would be perfect prediction. Nothing in hiring approaches the top of that scale; the strongest methods available sit between roughly 0.3 and 0.45. The most substantial recent re-examination of that literature, published in the Journal of Applied Psychology in 2022, placed structured interviews at 0.42, job knowledge tests at 0.40 and work sample tests at 0.33.
Two conclusions follow, and the second is the useful one.
Practical assessment improves the odds rather than removing the risk. And structured interviews score higher than work samples, which is inconvenient for anybody selling assessment, including me.
The qualifier carrying that 0.42 is “structured”: identical questions in a fixed order, trained interviewers, scoring criteria agreed before anyone is seen, marked independently by more than one person. Very few organisations run anything resembling that. What they run is a conversation, and unstructured conversations are a well-documented weak predictor.
The honest comparison is therefore not practical assessment against a rigorous structured interview. It is practical assessment against reading two hundred largely identical documents and then having a chat. Against that, the case is not close.
Why the market has not moved
Three reasons, none of them good.
The work sits in the wrong place. Building a fair, role-specific practical assessment takes real effort from exactly the senior engineers who have none to spare, so it does not get built and CV screening continues by default.
Most hiring managers believe they can identify capability in an interview, and many genuinely can. That belief is also beside the point, because the question is not whether you can assess one candidate in forty-five minutes. It is which five of two hundred people are given one of those forty-five minutes, and interviewing skill contributes nothing to that decision.
And the current approach fails invisibly. Demanding five years of experience is a defensible decision even when it is the wrong one, while interviewing an unconventional candidate who does not work out feels like a personal misjudgement. Nobody ever learns about the strong candidate rejected at CV stage, so the error generates no feedback and therefore no pressure to change. That, more than disagreement, is why this moves slowly.
Where CyberHire sits in this
I am not a neutral observer, so it is worth stating the interest plainly.
I built CyberHire after running into this from the hiring side. Building a SOC team, several hundred applications arriving, hours spent trying to infer from CVs and interviews who could actually do the work, and getting it wrong often enough to notice. What existed at the time was built either for training people or for hiring software engineers.
CyberHire runs the screening as a managed service. You provide the role and the applicants you already have; we build hands-on labs specific to that role, run the candidates through them, and return a ranked shortlist with the evidence behind each name. Nothing is built or operated by your team.
The product is not the argument, though. An organisation that took the principle and implemented it internally, with its own scenarios and its own people, would be better off than one that did nothing, and I would rather that happened than nothing happened.
The proposition worth accepting is considerably smaller than buying anything: stop determining who can do the work by reading about it, and watch them do a portion of it instead.
One honest sentence
We are not short of people capable of this work; we are short of ways to recognise them, and until that changes the industry will continue training people it declines to hire while insisting nobody can be found.
Related reading: the policy and regulatory dimension of this argument is covered in the UK cyber skills shortage is now an assurance problem. For the practical method, start with how to assess cybersecurity candidates, or how to screen 200 applicants if the pile is already in front of you.
Sources
- Cyber security skills in the UK labour market 2025 - Department for Science, Innovation and Technology, published 2 February 2026.
- IBM 2026 Cost of a Data Breach Report - IBM newsroom, 29 July 2026.
- The cybersecurity skills gap contributed to a USD 1.76 million increase in average breach costs - IBM.
- Job seekers, some using AI, flood LinkedIn with 11,000 applications a minute - eWeek, reporting LinkedIn and Workday figures.
- Revisiting meta-analytic estimates of validity in personnel selection - Sackett, Zhang, Berry and Lievens, Journal of Applied Psychology, 2022.
Stop reading CVs. Start reading evidence.
See what the evidence looks like.
The hiring intelligence report is the deliverable: ranked candidates, skill-level performance, integrity findings, and where to press each one at interview.