CyberHire

The UK cyber skills shortage is now an assurance problem

UK cyber workforce supply is growing and the shortfall is shrinking, yet employers still cannot tell who can do the work. The problem has moved from supply to assurance.

For a decade the UK has talked about cyber security as a numbers problem. Not enough people, too many vacancies, a pipeline that needs filling. Every intervention has followed from that framing: more graduates, more apprenticeships, more bootcamps, more conversion courses.

The numbers have moved. The problem has not.

The government’s own research now shows supply rising and the shortfall falling, while employers report they still cannot find people who can do the work. That is not a shortage. That is a failure to identify capability, and it is a different problem requiring different tools.

I want to make a specific argument here, and it is not that anybody should be forced to sit an exam. It is this: for security-critical roles, organisations should increasingly be expected to hold evidence that the people performing those roles are actually competent to perform them. Not qualified on paper. Competent in practice.

That principle is already implicit in several things the UK has signed up to. It is nowhere stated explicitly. I think that gap closes over the next few years, and I think employers would be better off moving before it does.

What the government’s own data actually says

The Department for Science, Innovation and Technology publishes an annual study of the UK cyber security labour market. The most recent edition, Cyber security skills in the UK labour market 2025, was published on 2 February 2026, with main fieldwork running from 31 July to 18 October 2024.

Read the supply side and the demand side together and the picture is uncomfortable.

FindingFigureWhat it tells you
Annual UK cyber workforce shortfall3,800 in 2024, down from 11,100 in 2023The headline gap has collapsed
Cyber workforce size~143,000, growing 5% in 2024Supply is expanding, and faster than before
Businesses with a basic cyber skills gap49%Half cannot confidently do the fundamentals
Businesses with an advanced skills gap~30%Forensics, penetration testing and similar
Cyber sector firms reporting technical skills gaps in their own staff28%The specialists have the problem too
Job postings demanding 2-6 years’ experience63%Employers want the already-proven
Postings open to under 1 year of experience17%, down from 25% in 2022The entry door is closing
Cyber graduates entering cyber professional roles31%Two thirds of the pipeline goes elsewhere
Cyber graduate unemployment9% vs a 5% averageWe are producing people the market will not absorb

Those last three lines are the story, and almost nobody talks about them.

We are producing roughly 6,000 cyber security graduates a year, plus around 600 apprenticeship starts and about 2,500 people arriving through certification and private training. Fewer than a third of the graduates end up in cyber professional roles. Their unemployment rate is nearly double the average. Meanwhile only 15% of cyber sector recruitment comes from career starters, and around half comes from people already working in cyber.

So the pipeline is full and the door is shut. Employers are not short of applicants. They are short of applicants they are willing to bet on.

Why more people will not fix this

If the constraint were supply, rising supply would ease it. It has not.

The reason is straightforward once you have sat on the hiring side of it. An employer facing a stack of applications for a Tier 1 SOC role is not primarily worried about whether enough people applied. Two hundred did. They are worried about which of them can actually read a log and reason about what happened, and they have no reliable way to find out before committing senior analyst time to interviews.

Faced with that uncertainty, the rational move for any individual hiring manager is to demand experience. Experience is a proxy, and a weak one, but it is the only proxy that feels defensible when you have to justify the decision. So postings drift towards 2-6 years, entry-level demand falls, and the graduates we spent public money producing cannot get in.

That is a market failing to clear because buyers cannot assess the goods. Adding more goods does not help.

This is the part that makes it a policy problem rather than a hiring inconvenience. The country is funding a pipeline into a market that cannot evaluate its output. Every additional graduate makes the identification problem worse, not better, unless the ability to distinguish capable from plausible improves alongside.

Qualified is not the same as competent

The distinction matters more in cyber than in most fields, because the gap between describing security work and doing it is unusually wide.

A certification demonstrates that somebody passed an examination on a syllabus, usually a multiple-choice one, often some time ago. That is genuinely worth something. It is not the same as demonstrating they can work an incident. A CV demonstrates that somebody can describe their own experience in writing, which is now a task any applicant can complete in seconds with a language model. An interview demonstrates that somebody can talk about the work fluently, under conditions quite unlike the work.

None of these are worthless. All of them are proxies, and the proxies have been getting weaker.

On the evidence for what actually predicts job performance, it is worth being precise rather than repeating the usual vendor line. Sackett, Zhang, Berry and Lievens re-examined the field in 2022 in the Journal of Applied Psychology and found that decades of validity estimates had been systematically overstated by inappropriate corrections for range restriction. On their revised figures, structured interviews lead at .42, followed by job knowledge tests at .40, biodata at .38, work sample tests at .33, and cognitive ability at .31. Roth, Bobko and McFarland had independently put work samples at .33 seventeen years earlier.

Two things follow from that, and both are inconvenient for people selling assessment.

First, no single method is a crystal ball. A validity of .33 or .42 is a meaningful correlation, not a guarantee. Second, and more importantly, the word carrying that .42 is structured: same questions, trained interviewers, anchored scales, independent scoring. Almost nobody in cyber hiring runs one. What most organisations run is a conversation, and unstructured interviews are a well-documented weak predictor.

So the honest position is not that practical assessment beats everything else. It is that most organisations are currently relying on the weakest instruments available, applied inconsistently, and calling the result a hiring decision.

Where UK policy is already moving

Here is what I find interesting. Several parts of the UK framework already reach for the concept of workforce competence. None of them yet require anybody to demonstrate it.

The NCSC Cyber Assessment Framework. The CAF is the assessment structure sitting behind NIS regulation and GovAssure. Principle B6, Staff Awareness and Training, requires that people supporting an essential function have appropriate awareness, knowledge and skills to carry out their roles in relation to the security of network and information systems. Guidance is explicit that the level of training should vary with the role.

What the CAF does not do is prescribe how you establish that. There is no required assessment methodology, no mandated testing, no defined evidence standard for individual capability. Organisations are expected to conduct training needs analysis and evaluate the effectiveness of training activities, and the method is left to them. I want to be unambiguous about this, because it gets misrepresented: the CAF does not currently require practical assessment of anybody.

It does, however, create the shape of the expectation. If a regulator asks how you know your incident response people can respond to an incident, “they attended training” is an answer. Whether it remains a satisfying one is a different question.

The UK Cyber Security Council. Established with a Royal Charter, the Council sets professional standards and awards titles across four levels: Associate, Practitioner, Principal and Chartered. It operates a Standard for Professional Competence and Commitment, assessed through professional registration rather than examination alone.

This matters less for what it currently compels, which is nothing, than for what it establishes: a nationally recognised structure for saying that a named individual has been assessed against a competence standard for a specific specialism. That is the machinery a future requirement would need. Building it before anybody requires it is how professions usually form.

ISO/IEC 27001. This is the one most organisations have already signed up to, and the one people forget contains a competence obligation at all. Clause 7.2 requires an organisation to determine the necessary competence of persons whose work affects information security performance, ensure those persons are competent on the basis of appropriate education, training or experience, take action where they are not, evaluate the effectiveness of that action, and retain documented information as evidence of competence.

Read that again, because it is stronger than people treat it as. Certified organisations are already required to hold evidence of competence for security-relevant staff. In practice the evidence retained is a training record and a certificate, because “education, training or experience” permits exactly that. The obligation exists. The evidential bar is simply set where a CV line clears it.

The Cyber Security and Resilience Bill, and what it does not say

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to the Commons on 12 November 2025, had its second reading on 6 January 2026, and completed Commons committee stage in February 2026. At the time of writing it sits at committee stage in the House of Lords. It has not received Royal Assent.

The Bill updates the NIS Regulations 2018, extends the regulatory perimeter, and strengthens regulators’ powers. It is a meaningful expansion of the UK’s cyber regulatory framework.

It does not impose workforce competence requirements, and nobody should claim otherwise. Anyone telling you that incoming UK legislation will require you to test your security staff is selling something.

What is worth watching is the mechanism rather than the text. Frameworks of this kind typically set duties in primary legislation and put detail in secondary legislation, regulator guidance and assessment frameworks like the CAF. That is where a competence expectation would appear if it appears at all, and it would appear as an evidential standard rather than a mandated test. The question is not whether Parliament will require practical assessment. It is whether a regulator will one day ask an organisation to demonstrate how it knows its people are capable, and stop accepting a training log as the answer.

Lessons from NIS2

The EU offers a useful comparison, and it points the same way.

Under NIS2, Article 21(2)(g) requires essential and important entities to adopt basic cyber hygiene practices and cyber security training as part of their risk-management measures. Article 20(2) goes further for leadership, requiring members of management bodies to follow training so they gain sufficient knowledge and skills to identify cyber security risks. Recital 79 addresses human resources security; Recital 89 covers staff training and awareness.

Note carefully what that is and is not. NIS2 requires training. It does not require testing. There is no provision mandating that any individual demonstrate competence through assessment, and it would be a misrepresentation to say otherwise.

But observe the direction. Training obligations have moved from good practice into binding law on both sides of the Channel, and for management bodies they have become personal obligations. The gap between “you must be trained” and “you must be able to show the training worked” is one policy iteration wide.

Could insurers eventually care?

This section is analysis rather than established fact, and I want to flag that clearly.

I could not find authoritative underwriting material establishing that any cyber insurer currently assesses the individual competence of security staff. There is a great deal of broker and vendor commentary asserting that underwriters ask about monitoring coverage, response capability and whether a SOC is staffed around the clock. I have deliberately not cited any of it, because it is marketing material rather than primary underwriting documentation, and this article does not need weak sources to make its point.

So the honest position: there is no evidence that insurers require practical assessment of people today.

What follows is inference. Cyber underwriting has matured by progressively converting vague assurances into verified controls. Multi-factor authentication moved from a question to a condition. Endpoint detection moved from a differentiator to a baseline. The pattern is consistent: as loss data accumulates, insurers stop accepting self-declaration for whatever correlates with claims.

Human capability is unusually hard to verify, which is why it has been left alone. It is also plausibly one of the larger determinants of whether an intrusion becomes a claim, because the difference between an alert triaged correctly at 3am and one dismissed is a person. If a reliable way to evidence that capability becomes available at reasonable cost, it would be surprising if underwriting ignored it indefinitely. That is a prediction, not a finding, and it should be read as one.

What proportionate competence assurance would look like

If this is where things are heading, the version worth arguing for is narrow. The version worth arguing against is a new certification treadmill.

A sensible regime would say something like: for designated security-critical roles, regulated organisations should be expected to retain evidence that the people performing those roles have demonstrated the competencies the role requires.

Five properties matter.

Risk-based. This should apply to roles where failure has consequences for an essential function, not to everybody with a login. Most jobs do not need this and applying it to them is how good ideas become despised.

Role-specific. A detection engineer and a GRC analyst do not share a competence profile. A generic “cyber competence” standard would be worse than nothing, because it would be satisfiable by people who cannot do either job.

Technology and method neutral. The requirement should be to hold evidence, not to buy a particular product or sit a particular exam. Practical assessment is one route. So are professional registration, scenario exercises, observed operational performance during incidents, accredited training with meaningful evaluation, and structured internal review. Organisations should choose what fits.

Auditable. Whatever evidence is held should be capable of being shown to a regulator and understood by one. That means it needs to record what was assessed, against what standard, when, and with what result.

Periodic. Competence decays and roles change. Evidence from six years ago about a technology stack that has since been replaced is not evidence about today.

The obvious failure mode is checkbox compliance. Any regime like this will attract vendors offering a certificate that satisfies the auditor without measuring anything, and organisations that would rather buy the certificate than find out the answer. That risk is real and it is the strongest argument against doing this badly.

The defence against it is to insist the evidence relates to the actual work. Not whether somebody can define Kerberoasting, but whether they can find it in a log set where several accounts legitimately request the same kind of ticket. Not whether they hold a SIEM certification, but whether they can write a query that finds the thing. If the evidence does not distinguish between people who can do the job and people who can describe it, it is not evidence of competence and it should not count as any.

What this means for employers now

Nothing in this article is a current legal obligation beyond what ISO 27001 already asks of certified organisations. But three things follow that are worth acting on regardless.

You probably already owe someone an answer to this question. If you hold ISO 27001, clause 7.2 already requires documented evidence of competence for staff whose work affects information security. Most organisations satisfy it with training records. That is compliant. Whether it would survive a serious question from a regulator after an incident is a different matter, and the time to find out is not during the incident.

The evidence is more useful to you than to any regulator. The reason to know whether your SOC team can actually investigate is not compliance. It is that you would like to know. Most organisations have never established this in any structured way, and the ones that discover a gap usually discover it at the worst possible moment.

The identification problem is costing you good candidates right now. Two thirds of UK cyber graduates are not entering cyber roles, and entry-level demand is falling while employers compete for the same experienced people. If you could reliably identify capability without relying on years of experience as a proxy, you would be hiring from a pool your competitors have written off. That is a commercial advantage available today, with no legislation required.

Why this matters to us

I should be straight about the interest here. CyberHire is a managed technical screening service, and we exist because I got tired of trying to infer technical ability from CVs, certifications and interview performance while building a SOC team, and being wrong often enough to notice.

So we have a stake in this argument. Take the piece accordingly.

But the principle is bigger than any product, including ours, and I would rather it were argued properly than adopted lazily. CyberHire is one implementation of one part of it, at the point of hire. It does nothing about the competence of people already in post, which is the larger question. The policy objective should never be “organisations should buy assessment software”. It should be that organisations responsible for defending critical systems can demonstrate that the people doing the defending are able to do it.

If that ever becomes an expectation, the market will fill with products claiming to satisfy it, most of which will measure the wrong thing. The time to argue about what good evidence looks like is before that happens, not after.

One honest sentence

The UK has spent a decade solving a supply problem that its own data now suggests is largely solved, while the harder problem underneath it, telling who can actually do the work, has gone almost entirely unaddressed.

Sources and further reading

ISO/IEC 27001:2022 clause 7.2 (Competence) is referenced from the published standard, which is available from BSI and ISO under licence and is not linkable in full.

Stop reading CVs. Start reading evidence.

See what the evidence looks like.

The hiring intelligence report is the deliverable: ranked candidates, skill-level performance, integrity findings, and where to press each one at interview.

Discuss a live role Request a sample report