The Shortage Is Over. The Standard Went Up.
The UK cyber workforce gap has closed by two thirds in three years, and the wage premium has collapsed with it. For practitioners, that is not bad news. It is a different game, and the people who understand what actually changed will be paid more, not less.
For most of the last decade, the cybersecurity profession sold itself on a single promise: there are not enough of us, so the market will pay. Every conference keynote, every training provider advert, every careers article repeated the same line. Millions of unfilled roles. A shortage without end.
That promise has quietly expired.
The Department for Science, Innovation and Technology now puts the UK cyber workforce at roughly 143,000 people, growing at about 5% a year. The annual shortfall, the number of professionals the market needs but cannot find, has narrowed to around 3,800. Three years earlier it stood at approximately 11,100. The gap has closed by around two thirds while the workforce itself has continued to grow.
The pricing followed. The wage premium attached to cyber roles over comparable IT roles has fallen to about 12%. In 2022 it was around 33%. The median advertised salary for a core cyber role now sits near £55,000, with London mean earnings at £69,800 against a UK cyber average of £58,800.
Read those two data points together and the conclusion is uncomfortable but useful. Being a cybersecurity professional is no longer, by itself, a scarce asset. The scarcity has moved somewhere more specific, and the practitioners who find it will out-earn the ones still relying on the old story.
What actually changed
The shortage did not end because the problem was solved. It ended because supply caught up at exactly the point where demand was thinnest.
Around 6,000 cyber graduates now enter the UK market each year, a figure that grew by roughly 20% in a single academic year. Add apprenticeships and career changers and the bottom of the pyramid has filled fast. Meanwhile, entry-level positions fell to 17% of core cyber job postings, down from 25% in 2022. Roles requiring two to six years of experience now account for 63% of core postings.
The distribution tells you everything. Employers want people who have already done the work. Some 52% of recruitment into cyber roles comes from the existing cyber talent pool, against 15% from career starters. Cyber graduate unemployment runs at about 9%, against roughly 5% across all graduates.
That is not a shortage of people. It is a shortage of proof.
DSIT’s own framing has shifted accordingly, from increasing supply to matching supply against evolving demand. The policy language has caught up with what hiring managers have been doing for two years.
The demand did not disappear, it specialised
At the same time, the ISC2 2025 Cybersecurity Workforce Study, covering 16,029 practitioners globally, found that 59% of organisations report critical or significant skills needs, up from 44% the year before. Some 95% report at least one skills need.
Hold those figures against the closing UK workforce gap and the apparent contradiction resolves itself. Organisations are not short of security people. They are short of specific capabilities inside the security people they already have.
The named gaps are precise: AI and machine learning security at 41%, cloud security at 36%, risk assessment at 29%, application security at 28%, and security engineering and governance, risk and compliance at 27%.
Those are not entry points. They are the mid-tier band where 63% of the postings sit, and where the pay premium migrated when it left the profession as a whole.
The certification trap
Here is where most practitioners misallocate their capital, and it is worth naming plainly because the industry profits from the confusion.
ISC2’s hiring managers research found that 90% would consider a candidate whose only relevant background is prior IT work, and 89% would consider a candidate holding only an entry-level cybersecurity certification. In other words, the formal barrier to entry is far lower than the profession advertises.
Yet 38% of those same organisations list CISA as a requirement on entry-level postings, and 34% list CISSP, both of which require five years of documented experience before they can be awarded. The requirement is not a filter. It is an artefact of job descriptions written by people who were not asked to check them.
Certifications are priced as an access ticket and mistaken for a differentiator. Whatever everyone can buy cannot command a premium.
The practical lesson is not that certifications are worthless. It is that they are priced as an access ticket and mistaken for a differentiator. When 6,000 graduates a year and a saturated training market can all produce the same credential, the credential stops carrying signal.
The same research found the top five capabilities hiring managers actually seek: teamwork, problem solving, analytical thinking, data security and cloud security. Three of the five are not technical at all.
AI is compressing the bottom rung, not the ladder
The most recent ISC2 research, conducted in May 2026 across 856 practitioners who use AI in their work, found that 56% believe AI has reduced demand for entry-level roles. That is the number the headlines carried.
The number they did not carry: 53% believe AI is creating new entry-level opportunities, and 62% disagree with the proposition that AI has reduced the need for foundational cybersecurity skills. Only 26% think foundational skills now matter less.
What AI has actually done is shift where practitioner time goes. Some 65% report spending more time deciding whether to trust or act on AI-generated recommendations, and 63% report more time validating AI output. Meanwhile 82% say establishing trust in AI output is very important to their role, and half of organisations hold a human ultimately accountable when an AI recommendation turns out to be wrong.
The work that is disappearing is the work of producing a first-pass answer. The work that is growing is the work of judging one. That is a promotion in disguise, but only for practitioners who can demonstrate judgement rather than throughput.
The Proof Stack
The pattern across all of this data resolves into three layers. Most practitioners over-invest in the first and never build the third.
Layer one: access proof. Certifications, degrees, adjacent IT experience. This gets your application read. It is necessary, cheap, widely held, and therefore commands no premium. Buy the minimum required and stop.
Layer two: capability proof. Evidence that you have personally owned a piece of work end to end. Not “supported the ISO 27001 project” but “wrote the risk assessment methodology, ran the internal audit, closed eleven nonconformities”. Specific, attributable, checkable. This is where the 63% mid-tier demand is actually assessed, and where most CVs collapse into passive verbs.
Layer three: consequence proof. Evidence that your work carried commercial weight. The audit that unblocked a contract. The control that removed a finding holding up a funding round. The detection engineering that cut mean time to respond and let the team stop paying for weekend cover. This is the layer that converts a practitioner into a leadership candidate, and it is the layer almost nobody documents because nobody taught them it counted.
The compression of the wage premium from 33% to 12% is what happens at market scale when a whole profession competes on layer one. The 41% AI and machine learning skills gap is what an unclaimed layer three looks like.
Three questions worth asking yourself
Which of my last three pieces of work could survive a hiring manager phoning the person I reported to? If the answer is fewer than three, the problem is not your CV. It is that you have been contributing to work rather than owning it. Fix the work, then fix the CV.
If my employer bought a capable AI security tool tomorrow, which parts of my week would it take? Whatever it would take is the part of your role the market is already repricing. Move deliberately towards the judgement, escalation and accountability that 82% of practitioners now describe as the core of the job.
Can I name, in figures, one commercial outcome my security work produced in the last year? If not, that is your single highest-return piece of work this quarter, and it costs nothing but attention.
The strategic takeaway
A closing workforce gap and a compressing wage premium look like a worse market. For the median candidate, they are. For a candidate who can evidence specialised capability and commercial consequence, they are the opposite: the noise has thinned, the specific gaps have widened, and the employers with 59% critical skills needs are not competing on volume any more.
The old market rewarded arriving. This one rewards proving. That is a higher standard, and a better one, because it is the first version of this market where the effort you put in is actually legible to the person deciding what to pay you.
Working with Garzon Cyber Solutions
Garzon Cyber Solutions is a young firm. I built it around cybersecurity, compliance and specialist technology recruitment because I have spent my career inside this industry, on the sales, marketing and technical sides of it, and I run the recruitment work personally rather than passing it to a resourcing desk.
If you are a cybersecurity, GRC, cloud or technology professional planning your next move, you are welcome to register your interest with us. We will talk properly about where your capability actually sits against the market, not just what is currently on your CV. Recruitment is delivered on a contingency basis, so nothing is payable by a client until a candidate accepts and starts.
Register your interest
For cybersecurity, GRC, cloud and technology professionals planning their next move. A proper conversation about where your capability sits against the market.
Register Your Interest →Sources: Department for Science, Innovation and Technology, Cyber Security Skills in the UK Labour Market 2025 (findings report, published September 2025) · ISC2, 2025 Cybersecurity Workforce Study (16,029 respondents, fieldwork July to August 2025) · ISC2, Cybersecurity Hiring Trends, June 2025 · ISC2, Rethinking AI’s Impact on Cybersecurity Roles, May 2026 (856 respondents).
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability.