UK cyber sector reaches £14.7bn, but its biggest SME rival is ‘do nothing’
Government figures show more suppliers, higher revenue and investors backing smaller firms. Yet services hiring has stalled, and the SME customers many providers depend on still buy mostly what contracts demand

- Large firms earn 70% of cyber revenue, but small firms’ combined revenue rose from £790m to £1.27bn and they took the biggest share of 2025 investment.
- Small businesses slipped back on risk assessments, cyber policies and continuity plans, while 64% now rely on an external provider.
- A supply chain Cyber Essentials requirement in the planned Cyber Resilience Pledge is the clearest new source of SME demand, if large buyers enforce it.
The UK now has 2,603 companies selling cybersecurity products or services, 438 more than in the previous year’s study, according to the Cyber Security Sectoral Analysis 2026, published by the Department for Science, Innovation and Technology (DSIT) on 12 May. Their cyber revenue rose 11% to £14.7bn and gross value added climbed 17% to £9.1bn. On the headline numbers, the sector is in good health.
Underneath, the picture is less tidy. Employment grew by about 2,300 roles, or 3%, to roughly 69,600 full-time equivalents, the slowest growth the series has recorded since it began in 2018. Jobs at service companies and managed security service providers (MSSPs) were flat at around 42,400, after rising 14% the year before. Most of the new hiring came from product companies. And firms consulted for the study said their biggest rival in the small-business market is not another vendor but inaction.
The question for the hundreds of small consultancies, MSSPs and other providers that sell security to UK SMEs is whether the growth at the top of the market will reach their customers, or whether the next year looks like this one: more suppliers, chasing buyers who still do not think they need them.
More suppliers, flatter services hiring
The study, carried out for DSIT by Ipsos and Perspective Economics, combines company accounts, web data and a survey of 230 cyber firms run between July and October 2025. It describes a sector that is mostly small. Micro firms make up 58% of the 2,603 and small firms another 19%. Some 72% are mainly in services, including managed services and reselling, and the analysis counts 644 firms whose main offer is managed security.
Revenue, though, sits at the other end. Large firms earn £10.4bn, or 70% of the total, even though they are only 9% of providers. Small firms did grow faster than most: their combined cyber revenue rose from £790m to £1.27bn, and average cyber revenue per small firm went from about £2m to £2.5m. The number of providers earning more than £10m a year reached 241, up from 105 two years earlier. Service companies, including managed service providers and MSSPs, generated about £8.4bn, against £7.4bn a year before.
So services revenue rose while services headcount stood still. The report notes that the average cyber team shrank from 31 to 27 staff and reads the change as a possible sign of efficiency among the largest employers. For a small MSSP, the more practical reading is that the market is paying for output, not bodies, and that productivity is now part of the competition.
Investment has also shifted toward smaller firms. Dedicated cyber firms raised £184m across 47 deals in 2025, down 11% on 2024. But small firms took the largest share, £84m or 46%, and micro firms raised £43m, against £29m the year before. The study’s investor interviews also flag private equity interest in bundling MSSPs and niche specialists. “There’s a huge amount of money that’s going into the managed service provider space from private equity right now. Our view is that there will be a lot of consolidation that happens,” one venture capital investor told the researchers.
Why small buyers still say no
The demand side explains much of the frustration. In the report’s industry consultations, firms said “do nothing” remains their biggest competitor, with cost and low awareness holding back smaller organizations. “People are running on very lean margins and they don’t think they’ve got what they need to spend potentially on cyber security,” said one firm with more than 250 staff. A micro provider put the buying trigger more bluntly: “It’s almost never because they want to improve cyber security.” Most of its clients, it said, arrive because a contract demands it.
The government’s own buyer data, published on 30 April, supports that view. The Cyber Security Breaches Survey 2025/2026, based on a survey of 2,112 businesses, found that small businesses had slipped back on basic controls after improving the year before. The share of small firms doing cyber risk assessments fell from 48% to 41%, those with a formal cyber policy from 59% to 52%, and those with a business continuity plan covering cyber from 53% to 44%. Only a quarter (25%) of small businesses and 14% of micro businesses had heard of Cyber Essentials.
The same survey shows why outsourced providers still have a market to fight for. Some 64% of small businesses and 70% of medium businesses use an external cybersecurity provider, and the share of micro businesses doing so rose from 39% to 44%. Holding Cyber Essentials is also climbing among small businesses, from 5% to 12%. The customers are buying help. They are not yet buying much beyond the minimum.
What the pledge could change
DSIT paired the sector figures with a call for organizations to sign a Cyber Resilience Pledge, which it says will launch later this year. The pledge asks signatories to take three steps: make cybersecurity a board-level responsibility, sign up to the National Cyber Security Centre’s free Early Warning Service and require Cyber Essentials certification across their supply chains. Ministers have written to some of the UK’s leading companies asking them to sign, and the government is putting £90m toward cyber resilience across the economy.
“As threats evolve, businesses of all sizes need to step up and take practical action now,” said Baroness Lloyd of Effra, the cyber security minister, in the release.
The supply chain clause is the one that matters most to small-business providers. The sectoral analysis already shows how compliance moves demand. One micro firm described targeting law firms because, to access legal aid budgets, they needed Cyber Essentials, “and then what comes with that is selling all the add-ons.” A larger firm told the researchers that a supply chain baseline of Cyber Essentials would be easy for most companies to meet “because it’s not expensive”. If large buyers sign the pledge and enforce it, thousands of their smaller suppliers may need certification, a provider to get them there and someone to keep them compliant.
The catch is that a pledge is voluntary and has not yet launched. The Cyber Security and Resilience Bill, which will continue through Parliament after the King’s Speech, is framed by the government around critical national infrastructure and essential services such as energy, water, healthcare and data centers. Until large customers write Cyber Essentials into contracts, the regulatory pull on small businesses remains indirect.
What providers should do now
For security providers serving SMEs, the data points to three moves. First, price and package around compliance events, because that is when small buyers act. Cyber Essentials, supplier questionnaires and contract renewals are the moments to sell, and the follow-on monitoring is where recurring revenue sits.
Second, treat the flat services headcount as a warning on margin. Revenue is growing faster than staff across the sector, which suggests buyers and investors reward providers that deliver more per engineer. Small providers that still scale by hiring will find it harder to compete on price.
Third, decide early what consolidation means for the business. Investment is flowing to smaller firms, and the investors consulted point to private equity interest in bundling MSSPs. A provider with a clean recurring base and documented compliance work will have more options than one built on project fees.
The sector’s growth is real. But the small-business market will not grow on awareness campaigns alone. The providers that win the next year will be the ones that attach themselves to the contract terms SMEs cannot ignore, and make meeting them cheap enough to say yes to.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe freeSources
- Department for Science, Innovation and Technology, Ipsos and Perspective Economics, “Cyber security sectoral analysis 2026”, research and analysis, 12 May 2026. https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026/cyber-security-sectoral-analysis-2026
- Department for Science, Innovation and Technology, “Government steps up action to strengthen cyber defences as UK cyber industry continues to grow”, press release, 12 May 2026. https://www.gov.uk/government/news/government-steps-up-action-to-strengthen-cyber-defences-as-uk-cyber-industry-continues-to-grow
- Department for Science, Innovation and Technology and Home Office, “Cyber security breaches survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026




