GCS Talent Briefing
Talent

The Shortage Is Over. The Standard Went Up.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
6 August 2026 · 7 min read
Dark editorial cover graphic with red accent bars top and bottom. Red eyebrow label reads GCS Insights, Cyber Talent. Large white headline reads "The Shortage Is Over. The Standard Went Up." A standfirst below explains that the UK cyber workforce gap has closed by two thirds in three years and the wage premium collapsed with it. Two red-bordered panels on the right show UK shortfall falling from 11,100 to 3,800 and the cyber wage premium falling from 33% to 12%. Footer carries the Garzon Cyber Solutions name and a DSIT source line.
The UK cyber workforce gap has closed by roughly two thirds since 2022. The wage premium fell with it. Source: DSIT, Cyber Security Skills in the UK Labour Market 2025.

The UK cyber workforce gap has closed by two thirds in three years, and the wage premium has collapsed with it. For practitioners, that is not bad news. It is a different game, and the people who understand what actually changed will be paid more, not less.

For most of the last decade, the cybersecurity profession sold itself on a single promise: there are not enough of us, so the market will pay. Every conference keynote, every training provider advert, every careers article repeated the same line. Millions of unfilled roles. A shortage without end.

That promise has quietly expired.

The Department for Science, Innovation and Technology now puts the UK cyber workforce at roughly 143,000 people, growing at about 5% a year. The annual shortfall, the number of professionals the market needs but cannot find, has narrowed to around 3,800. Three years earlier it stood at approximately 11,100. The gap has closed by around two thirds while the workforce itself has continued to grow.

The pricing followed. The wage premium attached to cyber roles over comparable IT roles has fallen to about 12%. In 2022 it was around 33%. The median advertised salary for a core cyber role now sits near £55,000, with London mean earnings at £69,800 against a UK cyber average of £58,800.

Read those two data points together and the conclusion is uncomfortable but useful. Being a cybersecurity professional is no longer, by itself, a scarce asset. The scarcity has moved somewhere more specific, and the practitioners who find it will out-earn the ones still relying on the old story.

What actually changed

The shortage did not end because the problem was solved. It ended because supply caught up at exactly the point where demand was thinnest.

Around 6,000 cyber graduates now enter the UK market each year, a figure that grew by roughly 20% in a single academic year. Add apprenticeships and career changers and the bottom of the pyramid has filled fast. Meanwhile, entry-level positions fell to 17% of core cyber job postings, down from 25% in 2022. Roles requiring two to six years of experience now account for 63% of core postings.

The distribution tells you everything. Employers want people who have already done the work. Some 52% of recruitment into cyber roles comes from the existing cyber talent pool, against 15% from career starters. Cyber graduate unemployment runs at about 9%, against roughly 5% across all graduates.

That is not a shortage of people. It is a shortage of proof.

DSIT’s own framing has shifted accordingly, from increasing supply to matching supply against evolving demand. The policy language has caught up with what hiring managers have been doing for two years.

Dark portrait infographic titled "The gap closed. So did the premium." with the subtitle "Two curves, three years, one event." Two red-bordered panels show the UK annual cyber workforce shortfall falling from 11,100 to 3,800 and the cyber wage premium over IT roles falling from 33% to 12%, both across successive DSIT reports from 2022 to 2025. A lower section headed "Where the demand actually sits" lists four figures: entry-level share of core postings 17%, down from 25% in 2022; roles needing two to six years 63% of core postings, highlighted in red; hiring drawn from career starters 15%, against 52% from the existing pool; cyber graduate unemployment 9%, against 5% across all graduates.
Supply arrived exactly where demand was thinnest. Entry-level postings fell to 17% while the two-to-six-year band took 63% of the market. Source: DSIT, Cyber Security Skills in the UK Labour Market 2025.

The demand did not disappear, it specialised

At the same time, the ISC2 2025 Cybersecurity Workforce Study, covering 16,029 practitioners globally, found that 59% of organisations report critical or significant skills needs, up from 44% the year before. Some 95% report at least one skills need.

Hold those figures against the closing UK workforce gap and the apparent contradiction resolves itself. Organisations are not short of security people. They are short of specific capabilities inside the security people they already have.

The named gaps are precise: AI and machine learning security at 41%, cloud security at 36%, risk assessment at 29%, application security at 28%, and security engineering and governance, risk and compliance at 27%.

Those are not entry points. They are the mid-tier band where 63% of the postings sit, and where the pay premium migrated when it left the profession as a whole.

The certification trap

Here is where most practitioners misallocate their capital, and it is worth naming plainly because the industry profits from the confusion.

ISC2’s hiring managers research found that 90% would consider a candidate whose only relevant background is prior IT work, and 89% would consider a candidate holding only an entry-level cybersecurity certification. In other words, the formal barrier to entry is far lower than the profession advertises.

Yet 38% of those same organisations list CISA as a requirement on entry-level postings, and 34% list CISSP, both of which require five years of documented experience before they can be awarded. The requirement is not a filter. It is an artefact of job descriptions written by people who were not asked to check them.

Certifications are priced as an access ticket and mistaken for a differentiator. Whatever everyone can buy cannot command a premium.

The practical lesson is not that certifications are worthless. It is that they are priced as an access ticket and mistaken for a differentiator. When 6,000 graduates a year and a saturated training market can all produce the same credential, the credential stops carrying signal.

The same research found the top five capabilities hiring managers actually seek: teamwork, problem solving, analytical thinking, data security and cloud security. Three of the five are not technical at all.

AI is compressing the bottom rung, not the ladder

The most recent ISC2 research, conducted in May 2026 across 856 practitioners who use AI in their work, found that 56% believe AI has reduced demand for entry-level roles. That is the number the headlines carried.

The number they did not carry: 53% believe AI is creating new entry-level opportunities, and 62% disagree with the proposition that AI has reduced the need for foundational cybersecurity skills. Only 26% think foundational skills now matter less.

What AI has actually done is shift where practitioner time goes. Some 65% report spending more time deciding whether to trust or act on AI-generated recommendations, and 63% report more time validating AI output. Meanwhile 82% say establishing trust in AI output is very important to their role, and half of organisations hold a human ultimately accountable when an AI recommendation turns out to be wrong.

The work that is disappearing is the work of producing a first-pass answer. The work that is growing is the work of judging one. That is a promotion in disguise, but only for practitioners who can demonstrate judgement rather than throughput.

The Proof Stack

The pattern across all of this data resolves into three layers. Most practitioners over-invest in the first and never build the third.

Layer one: access proof. Certifications, degrees, adjacent IT experience. This gets your application read. It is necessary, cheap, widely held, and therefore commands no premium. Buy the minimum required and stop.

Layer two: capability proof. Evidence that you have personally owned a piece of work end to end. Not “supported the ISO 27001 project” but “wrote the risk assessment methodology, ran the internal audit, closed eleven nonconformities”. Specific, attributable, checkable. This is where the 63% mid-tier demand is actually assessed, and where most CVs collapse into passive verbs.

Layer three: consequence proof. Evidence that your work carried commercial weight. The audit that unblocked a contract. The control that removed a finding holding up a funding round. The detection engineering that cut mean time to respond and let the team stop paying for weekend cover. This is the layer that converts a practitioner into a leadership candidate, and it is the layer almost nobody documents because nobody taught them it counted.

The compression of the wage premium from 33% to 12% is what happens at market scale when a whole profession competes on layer one. The 41% AI and machine learning skills gap is what an unclaimed layer three looks like.

Dark portrait infographic titled "The Proof Stack" with the subtitle "Most build layer one, then wonder why the market went quiet." Three stacked panels read from top: 03 Consequence Proof, the contract it unblocked and the finding it cleared, gets you paid, marked with a red border and red left bar; 02 Capability Proof, work you owned end to end, specific and checkable, gets you interviewed; 01 Access Proof, certifications, degrees and adjacent IT experience, gets you read. A lower section headed "Where the premium went" shows red horizontal bars for reported skills needs: AI and machine learning security 41%, cloud security 36%, risk assessment 29%, application security 28%, security engineering and GRC 27%.
Three layers of proof. A wage premium falling from 33% to 12% is what happens when a whole profession competes on layer one. Source: ISC2 2025 Cybersecurity Workforce Study, 16,029 respondents.

Three questions worth asking yourself

Which of my last three pieces of work could survive a hiring manager phoning the person I reported to? If the answer is fewer than three, the problem is not your CV. It is that you have been contributing to work rather than owning it. Fix the work, then fix the CV.

If my employer bought a capable AI security tool tomorrow, which parts of my week would it take? Whatever it would take is the part of your role the market is already repricing. Move deliberately towards the judgement, escalation and accountability that 82% of practitioners now describe as the core of the job.

Can I name, in figures, one commercial outcome my security work produced in the last year? If not, that is your single highest-return piece of work this quarter, and it costs nothing but attention.

The strategic takeaway

A closing workforce gap and a compressing wage premium look like a worse market. For the median candidate, they are. For a candidate who can evidence specialised capability and commercial consequence, they are the opposite: the noise has thinned, the specific gaps have widened, and the employers with 59% critical skills needs are not competing on volume any more.

The old market rewarded arriving. This one rewards proving. That is a higher standard, and a better one, because it is the first version of this market where the effort you put in is actually legible to the person deciding what to pay you.

Working with Garzon Cyber Solutions

Garzon Cyber Solutions is a young firm. I built it around cybersecurity, compliance and specialist technology recruitment because I have spent my career inside this industry, on the sales, marketing and technical sides of it, and I run the recruitment work personally rather than passing it to a resourcing desk.

If you are a cybersecurity, GRC, cloud or technology professional planning your next move, you are welcome to register your interest with us. We will talk properly about where your capability actually sits against the market, not just what is currently on your CV. Recruitment is delivered on a contingency basis, so nothing is payable by a client until a candidate accepts and starts.

Register your interest

For cybersecurity, GRC, cloud and technology professionals planning their next move. A proper conversation about where your capability sits against the market.

Register Your Interest →

Sources: Department for Science, Innovation and Technology, Cyber Security Skills in the UK Labour Market 2025 (findings report, published September 2025) · ISC2, 2025 Cybersecurity Workforce Study (16,029 respondents, fieldwork July to August 2025) · ISC2, Cybersecurity Hiring Trends, June 2025 · ISC2, Rethinking AI’s Impact on Cybersecurity Roles, May 2026 (856 respondents).

#CyberCareers #Talent #GRC #CloudSecurity #Skills #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability.