GCS Talent Briefing
Talent

Auditing Appears in 19% of UK Core Cyber Adverts. Auditor Appears in 3% of Titles.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
September 2026 · 8 min read
GCS Talent Briefing cover: The Contract Rate Rose 17%. The Salary Fell 7%. Only One Is A Pay Rise. Dark brand panel with the headline in white and red, a standfirst explaining that two halves of the same profession moved in opposite directions this year, and four stat chips: 575 pounds median contract day rate up 17.35%, 50,000 pounds median permanent salary down 7.41%, 6 April umbrella PAYE liability in force, four columns in the Kept Rate.

The governance skills UK employers ask for most often are buried inside job titles that never mention them. For a practitioner choosing a route, that gap between the skill and the label is the whole opportunity, and our view is that most candidates never see it, because they are searching on the wrong field.

Most people entering cyber security appear to search on job titles. Analyst roles, engineer roles, the occasional penetration tester. The Department for Science, Innovation and Technology analysed UK core cyber postings placed between January and December 2024 and published both halves of the picture.

Take the titles first. Of the 11,784 core cyber postings that carried an identifiable job title, security analyst accounted for 28%, security engineer 26% and security manager 22%. Security consultant took 8%, security specialist 5% and security architect 4%. Security or IT auditor accounted for 3%. Penetration tester accounted for 2%.

Now take the skills, across the wider set of 32,370 core cyber postings whose skill requirements DSIT classified. The title shares and the skill frequencies rest on different bases, titles on the subset with a title DSIT could extract, skills on the full classified set, so they are two readings of the same 2024 market rather than one list read twice.

One tag dominates that list and tells you nothing: "cyber security" itself, at 63%. Set it aside and the ranking reads vulnerability 20%, auditing 19%, ISO/IEC 27001 16%, risk management 16%, incident response 15%, risk analysis 14%, project management 14%. Four of those seven are governance skills: auditing, ISO/IEC 27001, risk management and risk analysis.

The demand is there. The word is not in the title.

Two bar charts comparing advertised cyber security job titles with the skills named in job adverts, from DSIT's analysis of UK core cyber postings placed during 2024. Security or IT auditor accounts for 3% of the 11,784 titled postings, while auditing is named in 19% of the 32,370 postings whose skills were classified.
The demand and the label point in different directions. Four of the seven most requested skills are governance skills. Auditor titles account for 3%.
19%of core cyber adverts name auditing
3%of titled postings say auditor
£60k-£75kGRC analyst band, UK-wide

What the sector says about itself

The same DSIT research records 28% of cyber security sector businesses reporting a technical skills gap among their own staff, up from 18% in the 2021 report, and describes the most commonly reported gaps as being "in areas like audit and assurance, digital forensics, and cryptography". DSIT does not rank those three, and we will not either. What matters is that audit and assurance is on the list at all, because it is not on the list most candidates carry in their heads.

What the pay data shows, and what it does not

Barclay Simpson's 2026 Cyber Security Salary Guide, last updated on 27 April 2026, reports bands across three salary columns, Central London, UK-wide and fully remote, alongside a contract day rate column. We have used the UK-wide column throughout, and the comparison does not survive a switch between columns, which is worth saying plainly.

On that column, an information security analyst in GRC is £60k to £75k and a junior information security analyst in GRC is £50k to £60k. A security operations analyst is £40k to £55k. The senior of those two GRC bands starts £5k above the top of the security operations band, so those two do not overlap. The junior GRC band does overlap it, between £50k and £55k, and that is the band most entrants will actually be offered. The honest version is therefore about the ceiling a governance route reaches early, not about the first number on the offer letter.

Higher up, the ranking depends on which column you read. UK-wide, the same guide gives head of IT risk £130k to £200k and head of GRC for cyber risk £120k to £150k, against head of security architecture £110k to £160k and head of cyber defence £125k to £145k. The bands move between the guide's columns, so we draw no conclusion about which route pays more at the top. The reliable reading is narrower: the governance route is not capped below the technical one.

For context, DSIT put the median advertised salary for a UK core cyber role at £55,000 and the mean at £58,800. The £60k to £75k GRC band starts above the advertised median for the whole category. The junior GRC band straddles it.

Three cautions, because the difference between a briefing and a recruitment advert is what it admits. This is one firm's survey of its own market and the sample size is not disclosed. A band is not an offer. And the guide's own figures resist a tidy story: 62% of candidates cited low advertised salaries or day rates as their biggest job-seeking challenge, while 87% of employers described themselves as somewhat or very aligned with candidate salary expectations. Those are different populations answering different questions, so they sit uneasily together rather than contradicting each other outright.

Why the band sits where it does

The entry-level gap is not a reward for governance being harder. It follows from where the work sits relative to money.

Security operations protects revenue that has already been earned. It is essential, it is measured against a budget, and when it works nothing happens. Governance work releases revenue that has not been earned yet. The ISO 27001 certificate that clears a procurement gate. The SOC 2 report an American buyer wants before it signs. The supplier assurance pack a regulated financial client needs before it can place a contract, sharpened by DORA where that client is an EU financial entity. The NIS2 duties reaching into supply chains across the EU. The Cyber Security and Resilience Bill, at Lords report stage as at 16 September 2026 with third reading, consideration of amendments and Royal Assent all outstanding, would extend the UK perimeter further again if enacted.

Work standing between a customer and a signature is priced against the contract. Work sitting inside a cost line is priced against the budget. Same employer, different arithmetic.

It also explains why the route is underused. Governance work is not visible. It happens in a procurement portal, a risk register and a document pack, not on a screen full of alerts. It photographs badly, and practitioners choosing on how security-shaped a job looks tend to choose the lower band.

The Assurance Line

Everything from here is our reading of the evidence rather than a finding in it, except where a source is named, and the confidence note below sets out which is which. A practitioner can test any role, held or offered, against four questions, ordered by how much each one moves the price of the work.

Gate. Does the output clear a gate somebody else is waiting on? A remediated vulnerability rarely does. A completed certification, a signed-off risk acceptance or a returned assurance questionnaire routinely does. Work on the critical path of a commercial decision is scarce and priced accordingly.

Signature. Does the output carry a name, a date and an assertion that can be relied on months later? Audit and assurance produces statements someone else acts on and may challenge. Alert triage produces a closed ticket. The first is a professional judgement, the second a task.

Scarcity. Is the skill on a published gap list, or only on the list candidates assume? Audit and assurance appears on DSIT's. Test the assumption against a source rather than against the internet's opinion of what is in demand.

Transfer. Does the skill survive a change of employer, tooling and sector? ISO 27001, risk management and supplier assurance transfer intact from fintech to manufacturing. Fluency in one vendor's console does not, and transferability is what converts experience into negotiating position.

A role that scores four out of four is worth taking at a discount. One that scores none is worth leaving, whatever the title says.

What this route is not

It is not the easy way in. The craft is different rather than lighter: the work is writing, questioning, and holding a position in front of people who would prefer a softer answer. It suits people who read a control objective and an invoice with equal attention.

It carries a real risk. Governance roles that are allowed to become administrative stay administrative, and the pay follows. The distinction that matters is whether you own a risk decision or only document one. Ask which, in the interview, before the offer.

It is also not a substitute for technical grounding. The practitioners who reach the top of those bands can read a network diagram and a cloud configuration, and know when an engineer is managing them. Governance without technical literacy tends to become a form-filling function, and the market prices that honestly.

A branded panel headed The Assurance Line, setting out four tests of what a cyber security role is worth: Gate, Signature, Scarcity and Transfer, closing with a pay comparison of an information security analyst in GRC at £60k to £75k against a security operations analyst at £40k to £55k.
The Assurance Line: four tests you can score any role against, held or offered.

Three questions to ask yourself

  1. In my current role, whose signature is waiting on my output? If the answer is nobody's, I am being priced against a budget rather than a contract.
  2. Of the skills I am building this year, which ones survive my employer, my tooling and my sector? Which ones do not, and what is the plan when they expire?
  3. When I last searched for a role, did I search on titles or on skills? If it was titles, how much of the governance work sitting inside those analyst and engineer adverts did I never open?

If you are on the hiring side of this

The 19% and the 3% read as a warning from the other side of the desk. An advert titled security analyst that asks for ISO 27001 and audit experience in the body is pointed at the detection and triage population while describing governance work, so it is likely to attract applications that do not match the brief, and likely to take longer to fill than the brief assumes. We will take that apart properly in a follow-up.

The strategic takeaway

The evidence supports a narrow claim, so we will make the narrow one. Governance skills are named in a substantial share of UK core cyber adverts while auditor titles are rare, the sector reports audit and assurance among its own skills gaps, and the £60k to £75k GRC analyst band reaches above both the operations band and the advertised median. A practitioner choosing on how technical a role looks is choosing on the one variable the data does not reward. Proximity to a signature is the better bet, and it is available without a change of employer.

Confidence note

Confirmed. DSIT job title shares, drawn from the 11,784 core cyber postings with an identifiable title placed January to December 2024. DSIT named skill frequencies, drawn from 32,370 core cyber postings over the same period. DSIT median advertised core cyber salary of £55,000 and mean of £58,800. DSIT's description of the most commonly reported technical skills gaps as being in areas including audit and assurance, and the 28% against 18% in the 2021 report. Barclay Simpson's published UK-wide salary bands and its 62% and 87% survey figures, from the guide last updated 27 April 2026. The Bill's parliamentary stage as at 16 September 2026.

Assessed. The commercial explanation for the entry-level pay gap, namely proximity to a revenue event rather than difficulty of the work. The proposition that candidates search predominantly on job titles rather than on skills. The proposition that candidates under-select governance routes because the work is less visible. The claim that governance roles permitted to become administrative stay administrative and are paid accordingly, and that governance without technical literacy is priced as a form-filling function. The four Assurance Line tests and their ordering. All are our reading of the evidence rather than findings in it.

Not known. Barclay Simpson's sample size and composition are not disclosed, so the bands cannot be weighted. No published source we found separates advertised salaries by governance versus technical specialism within core cyber roles, so the pay comparison rests on one recruiter's data set. And no source measures what candidates believe is scarce, so the mismatch between reported and assumed scarcity is asserted here, not evidenced.

Register your interest with Garzon Cyber Solutions

We are a young firm and we say so. Garzon Cyber Solutions was built around cybersecurity, security compliance and GRC hiring, and the founder handles the recruitment work personally rather than passing it to a delivery desk. Recruitment is contingency only, so nothing is payable by a client until a candidate accepts and starts, and no CV goes anywhere without the candidate's explicit permission for that specific role.

If you are a cybersecurity, GRC, cloud or technology professional and you want a conversation about where your experience is actually priced, register your interest through the Garzon Cyber Solutions Website. Coverage is UK, EU and Americas.

Sources: DSIT, Cyber security skills in the UK labour market 2025, published 19 September 2025, updated 2 February 2026, analysing job postings placed during 2024. The 2026 Barclay Simpson Salary Survey and Recruitment Trends Guide: Cyber Security, last updated 27 April 2026. UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, page updated 16 September 2026.

median contract day rate, up 17.35%
£50,000
median permanent salary, down 7.41%
6 April
umbrella PAYE liability in force

Over an almost identical window, the six months to 9 September 2026, the same source puts the median permanent salary for that role at £50,000, down 7.41% from £54,000 a year earlier, across 779 permanent advertisements.

ContractorUK's September 2026 snapshot points the same way, with a median advertised cyber day rate of £569 against £538 in August. That is a different measurement, though: one month across cyber roles generally, on 28 live listings. It agrees on direction and corroborates nothing.

Treat the precision with care more broadly. The permanent advertisement count in the IT Jobs Watch series jumped sharply year on year, which usually signals a change in how job titles are matched rather than a sudden expansion of the profession. What survives the caveats is the direction: contract is repricing upwards, permanent is repricing down.

What the divergence is actually telling you

The temptation is to read this as arbitrage. Leave the payroll, keep the skills, collect the premium.

That misunderstands what the premium is for. Employers are not paying £575 a day because a contractor is a better analyst than the person at the next desk on £50,000. They are paying it because they want capability without a permanent liability, and in 2026 they want that more than they did in 2025.

The Barclay Simpson 2026 cyber security salary guide gives the reason in the employers' own words. Some 40% of those using interim support cite specific projects as the driver, and 23% cite supporting business as usual. Meanwhile 83% said they were likely to recruit during 2026, but 76% planned base pay rises of only 1% to 4% for the people already there, with 17% planning 5% to 10%.

Budgets are moving, then, but into work that has a defined end. A day rate is a variable cost that leaves the profit and loss account when the project closes. A salary is a fixed cost that does not. The premium on the rate is the price of that flexibility; the discount on the salary is what the employer keeps for carrying you through the quiet quarters.

You are not being offered more money for the same thing. You are being offered more money to absorb a risk the permanent market absorbs on your behalf.

The change that most candidates have not priced

While the rate gap widened, the machinery underneath contracting changed.

Finance Act 2026, which received Royal Assent on 18 March 2026, inserts a new chapter into Part 2 of the Income Tax (Earnings and Pensions) Act 2003. For payments made on or after 6 April 2026, joint and several liability for PAYE applies where an umbrella company sits in a labour supply chain.

The detail matters, because it is widely reported incorrectly. Liability does not sit with whichever agency happens to be directly above the umbrella. It sits with the agency holding the contract with the end client, at the top of the chain. In a chain running client to first agency to second agency to umbrella, HMRC's guidance makes the first agency and the umbrella the liable parties; the second, nearest the worker, is not liable at all. Where no agency sits between client and umbrella, liability passes to the client. It is absolute, with no reasonable excuse or due diligence defence.

HM Treasury's policy paper sets out the scale of the problem. At least 700,000 workers were engaged through umbrella companies in 2022 to 2023, at least 275,000 of them, likely significantly more, by an umbrella that failed to comply with its tax obligations. Some £500 million was lost to disguised remuneration avoidance schemes that year, and the measure is expected to protect around £2.8 billion across the scorecard period to 2029 and 2030.

The policy target is non-compliant intermediaries. The effect on a candidate is more immediate. When an agency becomes liable, without defence, for tax it does not itself deduct, it stops treating its umbrella panel as an administrative convenience and starts treating it as a credit risk. Panels shrink, diligence lengthens, and marginal arrangements that quietly improved take-home pay disappear.

Set that against the status question. Barclay Simpson found 54% of cyber contractors working outside IR35 while 86% said they preferred that arrangement, a gap of 32 points between what practitioners want and what the market gives them. ContractorUK's September sample is harder still, with only 25% of listings stated as outside IR35.

So the headline rate rose in the same year the route to receiving it got narrower, better policed and more expensive to administer. Both are true. Only one appears in the advertisement.

The Kept Rate

Multiplying a day rate by 220 and setting it against a salary is the most common and most costly error in this decision. The number that matters is not the advertised rate. It is the Kept Rate, and it survives four columns.

Utilisation. Billable days, not calendar days. Assume a realistic gap between engagements, time off you now fund yourself, and the days lost to finding the next contract. A rate that looks decisive at 230 days looks ordinary at 180.

Deduction. The full stack between the client's invoice and your bank account: employer National Insurance and the apprenticeship levy inside an umbrella assignment rate, umbrella margin, pension you now fund alone, and the accountancy or insurance costs of a personal service company where one is viable. Ask for the illustration in writing before you accept, and ask who holds the client contract in your chain.

Duration. The length of the engagement and, more importantly, the notice inside it. A twelve-month contract with a one-week notice clause is a one-week contract described optimistically. Notice is the only part of a contract that tells you what your income actually is.

Deposit. What the engagement puts into your evidence base. Project work builds depth in a named system, a named framework, a named migration. It rarely builds the two things that promote people into security leadership: ownership of a control across multiple cycles, and a documented record of decisions made under real pressure. The difference between contracting that compounds your market value and contracting that quietly flattens it is whether you can point at outcomes you owned rather than tasks you delivered.

Run the four columns honestly and a £575 day rate resolves into a number you can set beside £50,000. Sometimes it wins comfortably. Sometimes it does not win at all. The comparison is arithmetic, not instinct, and almost nobody does it before handing in their notice.

Three questions to ask yourself before you move

How many days can I honestly bill next year, and on what evidence? If the answer comes from optimism rather than the last two years of the contract market in your specialism, you do not yet have a plan.

Under the April rules, who holds the contract with the end client in my chain, and can the agency tell me without checking? That is the party carrying joint and several liability, and an agency that answers immediately and precisely has done its work. One that cannot map its own chain is a supply chain risk you would be joining, not a partner.

Am I moving towards a rate or away from one? The Barclay Simpson survey behind the 2026 guide found 70% of cyber professionals placing remuneration in their top three reasons for moving, while only 21% felt very confident in the job market. Money is the stated reason for most moves in a market where few feel secure, which is exactly the condition in which people accept a headline number and discover the deductions afterwards.

The strategic takeaway

The divergence between contract and permanent pricing is not an inefficiency waiting to be exploited. It is the market pricing risk, correctly, and then offering to sell that risk to you at a discount to what it would cost the employer to keep.

Whether that is a good trade depends on your utilisation, your deductions, your notice terms and what the work does to your evidence base. All four are knowable in advance. The people who do well out of this market are not the ones who noticed the rate gap. They are the ones who priced it before they moved.

One second-order point is worth holding onto. Permanent salaries falling while contract rates rise does not mean permanent roles are worth less. It means employers are separating work that must be owned from work that must merely be done. If your role sits in the first category, your position is stronger than the median suggests, and it is strongest where you can show what would fail if you left.

Where GCS fits

Garzon Cyber Solutions is a young firm and we do not claim a placement history we have not earned. What we do have is a founder who spent his career inside cybersecurity and compliance, selling into security and technology buyers, and who runs the recruitment work personally.

Recruitment is contingency only. Nothing is payable by a hiring company until a candidate accepts and starts, and no CV goes anywhere without your explicit permission for that specific role.

If you are weighing a contract against a permanent move this quarter, register your interest through the Garzon Cyber Solutions Website. You will get a straight answer, including when the answer is that the move is not worth making.

Register your interest

A straight answer on whether the move is worth making, including when it is not. Contingency only, and nothing moves without your permission.

Start the Conversation →
Subscribe to GCS Insights

Confidence note

The salary and day rate figures are advertised market data, not settled pay. IT Jobs Watch and ContractorUK both report asking rates from job advertisements, the IT Jobs Watch contract median rests on the 81 of 124 advertisements that quoted a rate, and the ContractorUK September median rests on 28 live listings. The two sources measure different things and should not be read as confirming one another. The Barclay Simpson figures are self-reported by surveyed employers and practitioners, and the 83% recruitment figure covers recruitment generally, with no employment type specified. The umbrella company workforce and tax loss figures are HM Treasury and HMRC estimates, described as such in the policy paper, with "at least" and "around" carried from the original wording; the £2.8 billion is a forecast across a scorecard period, not a realised saving. The joint and several liability rules are confirmed legislation in force under Finance Act 2026, not proposals. The four-column analysis in The Kept Rate is our own framework, not a finding from any of these sources.

Sources
IT Jobs Watch, Cyber Security Analyst contract and permanent market data, six months to 5 and 9 September 2026. ContractorUK, Cyber Security Day Rate, September 2026. Barclay Simpson, 2026 Salary Survey and Recruitment Trends Guide: Cyber Security. HM Treasury and HMRC, Tackling Non-Compliance in the Umbrella Company Market, policy paper. Finance Act 2026, section 24, and HMRC Employment Status Manual ESM2420 and ESM2425.
Cyber Security CareersGRCTalentComplianceRecruitmentSalary Benchmarks
← All Insights Get in Touch →