ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Bridging the UK’s cyber-security talent gap

Jamal Elmellas at Focus-on-Security explains why the UK has the worst cyber-security workforce gap in Europe

 

It’s well-known that workforce levels are in crisis in the cyber-security sector. The workforce gap stands at 5.5 million, up 9% equivalent to 440,000 new jobs, but the gap is growing faster at 13% and now stands at approximately 4million, according to the ISC2 Cybersecurity Workforce Study.

 

However, the report also breaks down those statistics by geography and the forecast for the UK is not looking good. 

 

In the UK, the workforce grew 8% which compares favourably with growth worldwide at 9% and across Europe at 7%, revealing the sector is expanding. But the workforce gap ie the number of cyber-security professionals needed in the UK is up 29% year-on-year and stands at 73,439. That’s more than double the rate at which the gap is increasing globally.

 

In fact, it is the highest in Europe, followed by Spain (23%) and the Netherlands (10%), while France and Ireland actually saw a fall of 3% and 18%, respectively.

 

It’s important to note that this deficit of almost 30% describes the total number of personnel needed rather than the skills gap of specialist skills which are in short supply. Cloud security, for instance, is currently the number one sought-after skillset with 35% of teams reporting they have this gap on their team.

 

In contrast, the workforce gap is used to describe the number of cyber-proficient personnel needed to get the job done so we are looking at a general lack of resource and specialist talent as a whole.

 

A backwards step

What the figures mean in real terms is that while our cyber-security sector appears healthy, demand is so high that it will not only outstrip supply but could well prevent our tech sector from being able to advance, leading to some regression. We can expect cyber-security staff to become overburdened and standards to slip, for example, resulting in businesses being less well defended.

 

The report notes that over half of businesses worldwide (57%) say their business is already at a moderate or extreme risk of cyber-security attack due to staffing shortages. These are leading to shortcuts being taken with respect to risk assessment and management, process and procedure, configuration, and the patching of critical systems.

 

And it’s a problem further being exacerbated by cutbacks that are seeing cyber-security firms typically cut between 10-20% of their headcount, reduce spend on technology and software licensing in bid to survive the economic slowdown. 

 

A difficulty finding talent was given as the top answer for why the cyber-security gap is so pronounced (41%), closely followed by insufficient budget (34%) and a failure to offer a competitive wage (30%).

 

Yet also key was the misaligning staff resources , with too many in some areas and not enough in others, which almost a quarter said was an issue in their organisation. This suggests that some of the pressures organisations are dealing with could be eased by better workforce planning. 

 

Looking to the future it’s clear that the UK has its work cut out when it comes to dealing with the cyber-security shortages. Unlike other countries where the demand is less acute, the UK won’t be able to simply focus on retention and the upskilling of staff from related disciplines such as IT. There will need to be a concerted effort and investment in onboarding new recruits and in supporting their professional development. 

 

Addressing the gap

Organisations will also need to begin to think outside the box by looking for aptitude rather than experience when it comes to recruits. At the present time, experience is the dominant criteria that hirers look for, with 86% favouring senior level cyber-security experience.

 

Today, 45% said they were reluctant to hire entry level employees with little experience and admitted they were overly reliant on education and degrees as part of their selection criteria. Attitudes are changing though with 51% saying they are changing their hiring criteria to recruit from non-security backgrounds. 

 

It’s also important to look at the workforce gap in the wider context of technological change. We know that automation has the power to dramatically reduce workloads and soon we’ll see AI and machine learning (ML) augment security roles, helping to qualify threats and provide possible mitigation options or produce the documentation needed for reporting and Governance, Risk and Compliance (GRC) tasks. 

 

So perhaps what the sector also needs to do as part and parcel of that workforce planning is to critically assess which future skillsets it needs. The issue then becomes not a matter of do you have sufficient boots on the ground but do you have the right boots on the ground? Rather than needing a team of ten, can you function with six if between them you have those essential skillsets?

 

That’s perhaps one of the most fascinating insights to come from the ISC2 report which found almost 60% of those questioned thought the negative impact of worker shortages could be mitigated by filling key skills gaps. 

 

For the candidate, it’s imperative they look to upskill in these areas. The study found 84% of those questioned had no/minimal knowledge or only some/moderate knowledge of AI or ML, for instance. Understanding how demand is likely to manifest could then give them the edge, making career planning and knowing how to specialise crucial.

 

Admittedly this has not always been easy as there have been no clear cut definitions for particular roles but we are now seeing much more clarity in this area thanks to the UK Cyber Security Council’s efforts in identifying career pathways in its Cyber Career Framework

 

Using technology to do the heavy lifting, workforce planning to anticipate the skills needed and accurately assign staff, and less prescriptive out-dated recruiting practices could all significantly alleviate the problem of the workforce gap facing UK businesses.

 

In order to do so they will need to make some marked changes or risk developing major holes in their defences. 

 


 

Jamal Elmellas is COO at Focus-on-Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543