GCS Talent Briefing
Talent

One Person Deep

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
August 2026 · 8 min read
GCS Talent Briefing: One Person Deep. Dark editorial cover in the Garzon Cyber Solutions brand colours, with the headline One Person Deep, the line Cyber hiring got easier, cyber teams got shorter, and regulators started asking for people by name, and a panel reading 23% of UK cyber sector businesses have exactly one employee in the cyber role.

The UK cyber hiring market has swung decisively towards the employer. Teams have become smaller over the same period, and regulation has begun to name individuals rather than departments. The exposure lies not in the vacancy but in the depth behind it.

Most boards track cyber capability as a headcount question: whether the roles are filled, and if not, how quickly they can be. The market has largely answered that question. Recruitment is easier and less contested than at any point in four years. What has not improved, and on the available measures has deteriorated, is the number of people in a given organisation who can perform each critical security function without assistance.

The distinction is not semantic. A vacancy is work an organisation has not yet done; a single point of dependency is a liability it has already assumed, and one that typically appears on no risk register until the individual concerned resigns.

A looser market and a thinner bench

The Department for Science, Innovation and Technology publishes the most reliable UK picture, in its Cyber Security Skills in the UK Labour Market study. The 2025 report, based on 2024 fieldwork, records a clear loosening of the recruitment market. Among cyber sector businesses that had tried to recruit, 54% reported at least one hard-to-fill vacancy, against 70% in the 2023 study. Average vacancies per recruiting business fell from 8.2 in 2023, to 6.1, to 4.3 in the latest wave. DSIT’s own conclusion is worth quoting: these are “indicators that the cyber security labour market had shifted from being a candidate’s market to an employer’s market”.

That is the reassuring half of the evidence. The remainder is less so.

The same study finds that the typical cyber team has become materially leaner. The median number of employees in cyber roles at a cyber sector business now stands at three to four, against five to nine in the 2022 and 2023 studies. Around 23% of those businesses have exactly one employee in the cyber role, which is to say that the function and the individual are the same thing.

54%of recruiting cyber businesses had a hard-to-fill vacancy, down from 70%
3-4median cyber team size, against 5 to 9 in 2022 and 2023
23%have exactly one employee in the cyber role
69%of those with hard-to-fill vacancies have one at senior level

One qualification bears stating before the figure is taken into a board discussion: the DSIT population here is the cyber sector itself, rather than the in-house function of a general UK enterprise. The direction is nonetheless corroborated in DSIT’s Cyber Security Sectoral Analysis 2026, which estimates that the average cyber team within the sector fell from 31 staff to 27, and within large enterprises from 204 to 180.

A third finding completes the picture. Skills shortages have not disappeared; they have relocated upwards. Among cyber sector businesses reporting any hard-to-fill vacancy, the proportion with at least one at senior level, for roles requiring three to five years of experience, stood at 69%. DSIT is careful about the framing: that figure has remained higher than the 59% recorded in 2023, rather than rising afresh.

Infographic titled Easier to hire. Harder to replace. Three findings from the same DSIT study. Hard-to-fill vacancies fell from 70% to 54% among cyber sector businesses that recruited. Median cyber team size fell from 5 to 9 employees down to 3 to 4. Senior roles still hard to fill stands at 69% against 59% in 2023, among businesses with hard-to-fill vacancies, for roles needing three to five years of experience. Closing line: cheaper at the entry point, thinner in the middle, harder to replace at the top.
Three findings from one DSIT study, usually reported one at a time. Source: DSIT and Ipsos, Cyber Security Skills in the UK Labour Market 2025, reflecting 2024 fieldwork among cyber sector businesses.

Taken together, the three findings invert the commercial picture. Junior hiring has become cheaper and faster, team depth has thinned, and the experienced people who hold an organisation’s operative security knowledge have become harder to replace rather than easier. An employer’s market at the entry point is entirely compatible with acute scarcity at the point where the dependency sits.

Depth is a different question from headcount

Turnover in the sector is not dramatic. DSIT estimates that around 12% of cyber sector employees left their posts over an eighteen-month window, a rate it describes as broadly flat across three waves, with roughly six in every ten of those departures voluntary. For a professional discipline, that is an ordinary rate of attrition.

It ceases to be ordinary at a team of three. At that size a single resignation does not thin a function; it removes one.

A problem of institutional confidence sits on top of it. Nash Squared’s Digital Leadership Report 2025 found that more than eight in ten digital leaders believed they would retain most of their best people through the year, while a separate Nash Squared study of technology team members, cited in the same report, found that 44% expected to leave their employer during that period. Both are statements of intent rather than observed behaviour, and should be read as such. The material point is the gap between them, since retention planning is generally built on the leadership figure.

Against that, some 34% of UK organisations report no formal succession planning at all, according to Hays UK Salary and Recruiting Trends 2026. The figure is cross-sector rather than cyber-specific, but one in three constitutes a governance finding in any discipline.

Regulation has started naming individuals

The second reason depth now matters more than headcount is that the regulatory direction has moved from departmental duties to named ones.

Under the Digital Operational Resilience Act, in application across EU financial entities since January 2025, the requirement is explicit. Article 5(3) requires firms other than microenterprises either to establish a role monitoring third-party ICT arrangements or to designate a member of senior management as responsible for that exposure and its documentation. Article 6(4) requires those same firms to assign responsibility for managing and overseeing ICT risk to a control function holding an appropriate level of independence, so as to avoid conflicts of interest. Article 5(4) requires members of the management body to keep their own knowledge current through regular training. The combined effect is not a single hire. It is a named third-party owner, an independent risk function, and a board obliged to demonstrate its own competence.

In UK financial services the model is sharper still. The Prudential Regulation Authority’s Supervisory Statement SS1/21 places overall responsibility for implementing operational resilience policy with the Chief Operations function, SMF24, and states that where the function is split, the PRA does not expect it to be split among more than three individuals. The obligation therefore attaches to a named and regulator-approved individual, and to a countable number of them.

Outside regulated finance the pressure is currently guidance rather than law. The Cyber Governance Code of Practice, published by DSIT with the NCSC in April 2025 and voluntary in status, asks boards to “agree senior ownership of cyber security risks” and to define ownership of cyber at both executive and non-executive director level. Against that expectation, DSIT’s Cyber Security Breaches Survey 2025/2026 found that only 31% of UK businesses had a board member or trustee taking explicit responsibility for cyber security, rising to 68% among large businesses.

The Cyber Security and Resilience Bill warrants observation rather than assumption. It sits in the House of Lords, with committee stage due to begin on 1 September 2026, and as drafted carries corporate penalties of up to £17 million or 4% of worldwide turnover in the higher band. It does not currently impose duties on named directors. A cross-party amendment tabled for committee stage, led by Baroness Morgan of Cotes, would permit a regulator to serve a penalty notice on a senior executive where a failure was attributable to their consent, connivance or neglect. The amendment has been neither debated nor decided, and should be read as a signal of parliamentary appetite rather than as a duty.

The pattern across the four instruments is consistent. Regulators are increasingly uninterested in whether a capability exists somewhere within an organisation. They wish to establish who owns it, whether that person is competent, and what happens in their absence. That is a question about depth, and headcount reporting cannot answer it.

Where the exposure lands

Regulatory. Where a rule names a role, an unfilled or unbacked role constitutes a compliance gap from the day it falls vacant rather than from the day an auditor identifies it. Under DORA and the PRA regime, the individual is the control.

Contractual. Enterprise security schedules routinely specify a named security contact, incident response availability, and notification windows measured in hours. Meeting a 24-hour obligation, as the Cyber Security and Resilience Bill proposes for regulated entities, requires more than one person familiar with the process. Annual leave does not suspend the obligation.

Certification. ISO 27001 requires an organisation to determine, ensure and evidence the competence of people whose work affects information security performance. A function held by a single undocumented individual is difficult to evidence and straightforward for an auditor to challenge.

Transactional. Key-person dependency is a standard diligence finding in acquisitions and funding rounds. It rarely breaks a transaction. It reprices one, or appears in the disclosure schedule, or converts into a retention condition attached to the founder’s own consideration.

Insurance. Proposal forms increasingly enquire about detection coverage, incident response capability and who performs it. Answers given at renewal are representations, and representations are tested at the point of claim.

The Depth Map

A team of three, and a team of three in which one person holds everything, are indistinguishable on an organisation chart. The instrument set out below is deliberately small: it can be completed in an afternoon by whoever runs security, and read by a board in ten minutes. For each critical security or compliance function, four fields are recorded.

Depth. The number of people who can perform the function unaided, to the standard the business requires. The test is performance rather than preparation: not how many have been trained, but how many have done the work. Any function scoring one is a single point of dependency and should be named as such.

Notice. The warning the organisation would in practice receive, being the contractual notice period adjusted honestly for what the individual would realistically work rather than what the contract provides.

Recovery. The elapsed time from departure to the function being restored at the required standard, by whichever route is realistic: hiring, promotion and training, or contracting in. The estimate should assume the handover that would not take place.

Exposure. Recovery minus Notice. This is the exposure window, expressed in weeks, and it is the figure the board should see. Recorded alongside it: what lapses during that window, which control fails, which contractual clause is placed at risk, and which regulatory duty is left without an owner.

Infographic titled The Depth Map, labelled A GCS Framework. For every critical security or compliance function, record four fields. 01 Depth: how many people can perform it unaided, to the standard the business needs; not trained, have done it. 02 Notice: the warning you would actually get, adjusted for what the person would realistically work. 03 Recovery: time from departure to the function running at standard again, by hire, promotion or contract. 04 Exposure, highlighted in red: Recovery minus Notice equals weeks, the number the board should see, alongside what breaks in that window. Closing line: any function scoring one on Depth is a single point of dependency, name it as such.
The Depth Map converts an invisible key-person dependency into a number a board has to accept or fund. The fourth column, Exposure, is the whole exercise.

The output is not a staffing plan. It is a risk statement in the language a board already uses, and it converts an invisible dependency into a quantity that someone must either accept or fund.

Three questions for the board

  1. Which of our security and compliance functions are one person deep, and who has formally accepted that as a risk?
  2. For each of those functions, what is the exposure window in weeks between that person leaving and the capability being restored to the standard our contracts and regulators expect?
  3. Where a contract, an insurance representation or a regulatory duty names a role or an individual, who is the deputy, and have they ever performed the work?

Where the answer to the third question is a name that has never performed the task, the deputy is a document rather than a control.

Infographic headed Before your next board meeting, titled Three questions worth asking. 01: Which of our security and compliance functions are one person deep, and who has formally accepted that as a risk? 02: What is the exposure window, in weeks, between that person leaving and the capability running at the standard our contracts and regulators expect? 03: Where a contract, an insurance representation or a regulatory duty names a role, who is the deputy, and have they ever performed the work? A red-bordered panel closes with the line: if the deputy has never performed the task, the deputy is a document, not a control.
Three questions for the board. The third is the one that usually produces a name nobody has tested.

The strategic takeaway

An easier hiring market is not the same thing as a safer one. Buying capability has become simpler at precisely the moment organisations have concentrated that capability into fewer people, and at precisely the moment regulators have begun to ask for those people by name.

Depth is now the variable worth managing. It can be bought as a permanent hire, rented through a fractional or virtual CISO arrangement, or borrowed from a delivery partner, and the appropriate answer differs by function. What cannot be defended, before a regulator, an acquirer or an insurer, is an inability to say which functions are one person deep.

Confidence note

DSIT labour market figures are drawn from the 2025 report, which reflects 2024 fieldwork, and its population is cyber sector businesses rather than in-house security functions at general UK enterprises. The senior hard-to-fill figure is based on the subset of those businesses reporting any hard-to-fill vacancy. Turnover and hard-to-fill vacancy proportions are described by DSIT as estimates, and it describes the turnover figures as bare minimum estimates. Nash Squared and Hays figures are self-reported survey responses, including statements of future intent, rather than observed outcomes. DORA and the PRA supervisory statement are in force. The Cyber Governance Code of Practice is voluntary guidance. The Cyber Security and Resilience Bill has not received Royal Assent, and the senior executive liability amendment described above has been tabled but neither debated nor decided.

Which of your functions are one person deep?

A focused conversation about depth rather than headcount: which functions should be owned permanently, which can be rented through a fractional arrangement, and which can be borrowed from a delivery partner. Recruitment is delivered on a contingency basis, so nothing is payable until a candidate accepts and starts.

Start the Conversation →

Sources: Department for Science, Innovation and Technology and Ipsos, “Cyber Security Skills in the UK Labour Market 2025”. Department for Science, Innovation and Technology and Perspective Economics, “UK Cyber Security Sectoral Analysis 2026”. Department for Science, Innovation and Technology, “Cyber Security Breaches Survey 2025/2026”. Department for Science, Innovation and Technology with the National Cyber Security Centre, “Cyber Governance Code of Practice”, April 2025. Nash Squared, “Digital Leadership Report 2025”. Hays, “UK Salary and Recruiting Trends 2026”. Regulation (EU) 2022/2554, Digital Operational Resilience Act, Articles 5 and 6. Prudential Regulation Authority, Supervisory Statement SS1/21, Operational Resilience. UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill. GCS Talent Briefings translate labour market evidence into the capability and governance decisions that boards and security leaders need to make. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent selling cybersecurity, compliance and technology to security and technology buyers, alongside marketing and technical colleagues.

#CyberTalent #KeyPersonRisk #SuccessionPlanning #DORA #OperationalResilience #Governance #GarzonCyberSolutions