The UK cyber skills shortage is one employers are building
The government’s cyber skills report puts demand for entry and early-stage cyber roles at half its 2022 level. But the roles cyber security firms find hard to fill are experienced ones, and employers are shrinking the route to them

- DSIT has dropped its estimate of the UK cyber workforce gap, citing the limits of the data and reduced demand for roles.
- At cyber security firms, hard-to-fill vacancies cluster at three to nine years’ experience, the level a shrinking junior intake would feed later this decade.
- Three fixes sit with employers: a fixed share of entry-level hires, apprentice supervision written into senior roles and a published salary on every advert.
The Department for Science, Innovation and Technology (DSIT) published Cyber security skills in the UK labour market 2026 on 29 September, the eighth edition of an annual study carried out for it by Ipsos and Perspective Economics. Its first finding is plain: “Growth in the UK cyber security workforce is slowing.” The report puts the workforce, counted across every sector, at about 145,900 people in December 2025, up 2% (2,900 people) on the previous study, against 5% growth from 2023 to 2024.
Among cyber security businesses – the firms that sell cyber products and services – 53% expected to grow their workforce, down from 67% in the previous study. The report has also dropped its estimate of the UK’s cyber workforce gap, saying it rested on assumptions forced by the limits of the data, and citing reduced demand for roles.
The same day, recruiter Robert Half published research putting cyber security top of the technology skills UK employers are seeking, at 54%. That is Robert Half’s own survey, run by an independent firm in June 2026 among 500 hiring managers and 1,000 professionals in the UK across six professional fields, technology among them.
Put side by side, the familiar story of employers wanting cyber skills the market cannot supply looks back to front. The government’s data describes a shortage of experienced people and a crowd of would-be juniors with too few places to start. The UK’s cyber problem is less a skills shortage than an entry-level jobs shortage, and employers are the ones creating it.
Where the junior roles went
Core cyber job postings, drawn from the Lightcast database, rose 7% in 2025 after a 33% fall the year before. But core postings fell 51% between 2022 and 2025, and the report says the fall was driven mainly by entry and early-stage roles: postings asking for less than two years’ experience fell 53% and those asking for three to five years 49%, against 23% for six to nine years.
Of the 2025 postings that stated a minimum, only 16% asked for under a year’s experience, down from 25% in 2022, and the report puts demand for entry and early-stage roles at half its 2022 level. More than 70% of postings give no usable experience level, so the report treats these shares as indicative. Graduate supply keeps rising. Cyber security graduates grew 14% to 7,950 in 2023/24, and 11% of the 2022/23 cohort were unemployed about 15 months after graduating, against 6% of all graduates. “I am finding more and more people are now scrapping over these entry-level jobs,” one micro cyber security business told the researchers.
The shortage sits further up the ladder
The report does find a shortage. Of cyber security businesses that tried to recruit, 53% had at least one hard-to-fill vacancy. Among those firms, 56% struggled to hire people with three to five years’ experience and 35% principal-level staff with six to nine years, up from 16% in the previous study. Entry-level and graduate roles troubled 23%. The base is small, at 66 firms, but the report says most shortages remain in roles needing at least three years’ experience.
Those findings are connected. A principal with six to nine years’ experience in 2026 started work around 2017 to 2020. On that logic, every entry-level role not advertised in 2024 and 2025 is a mid-level candidate missing later this decade. One large private sector employer put it directly: “if you don’t have enough entry-level roles, where do you get seniors from later?”
Interviewees also felt that automation of routine monitoring work is thinning out the security operations center (SOC) analyst jobs that long served as the first rung. Apprenticeships are going backwards too. Starts on cyber security apprenticeships in England fell 15% in 2024/25, from 590 to 500, while starts across all digital apprenticeships rose 21% to 31,410.
What hiring managers should change
The government’s CyberFirst initiative is ending, the report notes, giving way to a broader TechFirst program. Neither creates a junior job. Only employers can, and three changes need no new policy.
Rebuild the entry route. Of 2025 core cyber postings that set an education requirement, 77% set a bachelor’s degree or equivalent as the minimum and a further 10% asked for a postgraduate qualification. Some employers and recruiters told the researchers that entry-level roles increasingly require prior IT experience, such as help-desk work. Hiring managers should reserve a fixed share of cyber hires for people with under a year’s experience, open some to non-graduates and make the move from IT support into security a planned path rather than a lucky break. “I think once you get to a certain size, you should be putting in an entry-level pathway,” one large private sector employer said.
Make apprentices part of senior roles. One large cyber security business told the researchers it would like to run apprenticeships and placements but had no senior person in an office for an apprentice to sit beside. That is a problem hiring can solve. Principal-level roles, now harder to fill than a year earlier, can be advertised with apprentice supervision written into the job.
Publish the salary. In 2025, 76% of core cyber job postings carried no salary information, up from 70% in 2023, which the report reads as a continued decline in salary transparency. Some interviewees felt unrealistic pay expectations were drawing applicants into roles they lacked the skills for, particularly at entry level. Postings that did state pay averaged £60,800, while cyber security graduates in full-time work reported a median band of £30,001–£35,000. A published band is the cheapest filter an employer has.
The government has stopped estimating the cyber workforce gap. Employers should start measuring their own part in it, beginning with one number: how many of this year’s cyber hires had less than a year’s experience. If the answer is none, the next senior shortage is being made in-house.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe free- Department for Science, Innovation and Technology (research by Ipsos and Perspective Economics), “Cyber security skills in the UK labour market 2026”, research and analysis, 29 September 2026. https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2026/cyber-security-skills-in-the-uk-labour-market-2026
- Robert Half, “Nearly half of UK employers plan to expand technology teams as demand for AI, cyber and cloud skills grows”, press release (via ResponseSource), 29 September 2026. https://pressreleases.responsesource.com/news/107643/nearly-half-of-uk-employers-plan-to-expand-technology-teams/




