Fewer Roles, Same Risk
UK core cyber job postings fell 33% in a single year. Threat volume did not fall with them. For boards, the distance between those two lines is no longer a recruitment issue. It is a control issue, and it is now measurable.
The divergence no one has priced
Two sets of numbers describe the UK cyber labour market, and they point in opposite directions.
On the demand side, the market has cooled sharply. DSIT’s Cyber Security Skills in the UK Labour Market 2025 recorded 32,370 core cyber job postings across the UK, a 33% fall on the previous year. The Government’s Cyber Security Sectoral Analysis 2026 shows sector employment growth slowing to 3%, the weakest rate since tracking began in 2018. ISC2’s 2025 workforce study found that among large organisations, 49% had imposed hiring freezes, 46% had absorbed budget cuts and 32% had made redundancies.
On the capability side, nothing has improved. Around half of UK businesses, 49%, still report a basic technical cyber security skills gap, and 30% report gaps in advanced technical areas. ISC2 found that 88% of respondents experienced at least one significant security consequence in the past year directly attributable to a skills shortage, and 69% experienced more than one.
Read together, these figures say something uncomfortable. Organisations are not hiring less because they need less security. They are hiring less because budgets contracted, and the risk did not contract with them. The exposure has not been removed. It has been transferred onto the people who remain, and onto controls that now depend on fewer hands.
A hiring freeze does not reduce risk. It relocates it, off the payroll and onto the control environment, where it is far harder to see.
Why this is not a recruitment market story
It is tempting to read the 33% drop as a market correction after the post-pandemic hiring surge. Partly, it is. But the operational consequence is not cyclical, and three effects compound quietly.
Key person concentration becomes systemic
In a lean team, one person typically holds the working knowledge of the identity platform, another owns the SIEM tuning, a third carries the entire evidence trail for ISO 27001 or SOC 2. This is rarely documented and almost never tested. ISC2 found 75% of professionals expect to stay with their employer over twelve months, but that figure falls to 66% over two years. On a two-year view, roughly one in three of the people holding your undocumented controls intends to leave. That is not a people risk. It is a single point of failure sitting inside your control framework.
Control decay outpaces control design
Controls do not fail loudly. Access reviews slip from quarterly to occasional. Vulnerability remediation SLAs quietly stretch. Third-party assessments are marked complete on the basis of a returned questionnaire that no one had time to challenge. Every one of these is invisible on a dashboard and highly visible in an audit, a breach, or a customer’s security review.
Outsourcing arrives without assurance
Some 31% of UK businesses and 58% of public sector organisations already outsource elements of cyber security. That is a rational response to constrained headcount. The problem is what sits underneath it: 23% of businesses that outsource are not confident they are receiving value for money. Capability has been bought without a mechanism to verify it. In practice, the organisation has converted an internal capability gap into an unmanaged supplier dependency, and moved it off the risk register in the process.
The commercial exposure
For a board, the relevant question is not whether the security team is under strain. It is what that strain costs, and where it surfaces first.
Regulatory. The Cyber Security and Resilience Bill is currently before the House of Lords and will materially expand the population of UK organisations, including managed service providers and parts of the supply chain, subject to statutory security and incident reporting duties. Organisations operating in the EU are already inside NIS2, and financial services firms have been operating under DORA since January 2025. Every one of these regimes assumes the existence of a named, competent, resourced function. “We could not recruit” has never been a recognised defence.
Contractual. Enterprise procurement and vendor security reviews increasingly ask for named control owners, defined response times and evidence of continuous assurance. A thin team does not lose a bid loudly. It loses it in the security questionnaire stage, months before anyone in the commercial function understands why the pipeline slowed.
Transactional. In diligence, an under-resourced security function is priced. It appears as a remediation cost line, a warranty, or an indemnity. Founders and CFOs preparing for a raise or an exit routinely underestimate how directly the security operating model converts into valuation.
Insurance. Cyber insurers now underwrite on control maturity and operational evidence, not policy documents. Degraded controls translate into higher premiums, lower limits or coverage exclusions that only become apparent at the point of claim.
None of these costs appear in the line item saved by leaving a role unfilled. All of them are larger.
The capability ledger: a better operating model
The organisations handling this well have stopped asking whether they can hire and started asking how they own the capability. There are four levers, and headcount is only one of them.
1. Buy. Permanent hiring, used deliberately and only where the capability is core, continuous and institutional. Security leadership, security architecture and identity fall here. These roles carry the organisational memory and should not be rented.
2. Rent. Interim and contract specialists for defined, time-boxed capability: a penetration test programme, a cloud security remediation sprint, a certification push. DSIT’s own research notes that penetration testing specialists are among the hardest to retain because market demand for their skills is so high. Attempting to hold that capability permanently, at a lean scale, is usually a poor commercial decision. Rent it, use it hard, release it.
3. Borrow. Fractional and advisory capacity. A fractional CISO or vCISO arrangement gives an organisation board-grade security judgement at a fraction of the fully loaded cost of a permanent hire, and gives it immediately rather than in the four to six months a competitive search realistically takes.
4. Build. Internal development, aimed at the gap the market has actually identified. Employers consistently report that entry-level candidates lack job-ready skills rather than credentials. Organisations willing to convert graduate potential into operational competence, with a structured programme rather than an aspiration, acquire loyal capability at materially below market rate. This is the lever most organisations claim to use and fewest actually fund.
The discipline is not in knowing the four levers. It is in mapping every material control to one of them, in writing, with an owner. That document is the capability ledger. Most organisations have never produced one, which is precisely why capability gaps only become visible after an incident.
Three questions for the board
Leaders do not need to become security specialists. They need to ask three questions and be able to withstand the answers.
1. Which of our security and compliance controls currently depend on a single individual, and what is our documented position if that individual resigns this month?
2. For every capability we have outsourced, what evidence do we receive, how often, and who inside the organisation is competent to challenge it?
3. What is our stated position on cyber capability in our next regulatory submission, customer security review and funding round, and would it survive scrutiny today?
If any of the three cannot be answered clearly in a single meeting, the gap is not in the hiring plan. It is in the operating model.
The strategic takeaway
The market has done something useful. By making headcount scarce, it has exposed how many organisations were treating recruitment as a substitute for a security operating model. Hiring was never the strategy. It was the easiest available proxy for one.
The organisations that emerge from this period stronger will not be the ones that hired the most. They will be the ones that mapped their capability deliberately, resourced it across four levers rather than one, and could evidence it on demand to a regulator, an insurer, an enterprise client or an acquirer.
That is a commercial advantage, and it is available now, at lower cost than a headcount-led approach ever was.
Which of your controls depend on one person?
A focused conversation about your security capability model: what you should own permanently, what you should rent, and what you can borrow. Recruitment is delivered on a contingency basis, so nothing is payable until a candidate accepts and starts.
Start the Conversation →Sources: Department for Science, Innovation and Technology, “Cyber Security Skills in the UK Labour Market 2025”. Department for Science, Innovation and Technology, “Cyber Security Sectoral Analysis 2026”. ISC2, “2025 Cybersecurity Workforce Study”. UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill. GCS Talent Briefings translate labour market evidence into the capability and governance decisions that boards and security leaders need to make.
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent inside cybersecurity and compliance across the sales, marketing and technical sides of the industry.