UK cyber bill could fail without skills fix, report warns
Fri, 24th Jul 2026 (Today)
The CSBR has warned that the UK's Cyber Security & Resilience Bill may fall short unless the government addresses cyber skills shortages. The warning comes in a new report on gaps in the UK cyber workforce.
The report argues that new legal duties could add pressure to an already stretched labour market, particularly if scarce technical staff are diverted into compliance work rather than frontline defence. That could lead to stronger reporting requirements without a matching improvement in practical resilience across critical national infrastructure.
Under the proposed regime, regulatory oversight would extend to managed service providers, and organisations would face a 24-hour incident reporting requirement. Those changes are likely to drive a sharp rise in demand for compliance and assurance staff at a time when many businesses and public bodies already struggle to recruit and retain cyber workers.
The CSBR based its findings on official material including the Government Cyber Action Plan, the NCSC Annual Review 2025, the Cyber Security Breaches Survey 2025 and the Cyber Security Skills in the UK Labour Market 2025 report. It found that 49% of UK businesses and 58% of government organisations already face a basic cyber skills gap.
Workforce strain
A central theme in the report is what it describes as an "hourglass" labour market. Demand is concentrated among mid-level and senior practitioners, while entry-level routes remain limited.
In 2024, 65% of core cyber job postings required mid-level experience, while entry-level roles accounted for 17%. The report says that imbalance leaves employers competing for a relatively small pool of experienced staff while failing to build a broader base of new recruits.
The public sector faces a separate retention problem. The report describes a "leaky bucket" pattern in which trained staff leave government roles for better-paid private-sector jobs, meaning shortages are recycled instead of resolved.
That matters because the Bill's ambitions depend not just on writing rules, but on having enough people with the right experience to put them into practice. Moving skilled staff into assurance, governance and reporting functions may weaken the operational teams responsible for detecting and responding to threats.
James Morris, founder of The CSBR, put that concern in direct terms. "No-one wants a scenario in which the Cyber Security & Resilience Bill becomes a paper tiger. Unless policy makers systematically connect our fragmented training programs and create viable entry routes for new talent, regulations will overwhelm the very sectors they are meant to protect. We could easily end up with compliance 'contestation' instead of genuine resilience," Morris said.
Policy proposals
The report calls for four interventions. First, it recommends a national cyber capability framework that distinguishes between baseline knowledge for general staff and leaders, practitioner skills for operational roles, and specialist expertise for high-risk functions.
Second, it says policy should focus more closely on transitions into work and progression within work. That includes movement from school into further study, from education into employment, and from adjacent occupations into cyber roles.
Third, the report argues that leadership and shared responsibility should sit more firmly at the centre of cyber policy. It points to existing governance guidance and says cyber literacy should become a more routine part of management and organisational practice.
Fourth, it recommends greater use of procurement requirements, customer standards and light-touch support to improve cyber readiness among smaller firms and across supply chains. Practical incentives may prove more effective than broad messaging for small and medium-sized enterprises.
Morris also framed the issue as one of coordination rather than a lack of policy tools. "The country already has many of the right ingredients: stronger official attention, useful governance tools, visible pipeline programmes and a growing recognition that cyber is a leadership issue as well as a technical one. The task now is to join these elements up more clearly, strengthen pathways and progression, and ensure that capability is built across the economy rather than concentrated in too few places," he said.
Broader debate
The findings come amid a wider debate over how governments should regulate cyber risk without imposing administrative burdens that reduce operational effectiveness. In the UK, that tension is especially sharp in critical sectors, where employers must balance governance, audits and incident reporting with the need for specialist staff who can prevent and manage attacks.
The CSBR's intervention also reflects a long-running concern that the cyber profession has struggled to create enough junior openings. Employers often seek workers with experience, certifications and sector knowledge, but fewer organisations are prepared to invest in training those at the start of their careers.
The problem is compounded when public institutions train staff who are later hired away by private employers with greater flexibility over pay. The report says this drains expertise from government and leaves agencies responsible for national resilience under repeated staffing pressure.
The report was sponsored by recruitment and workforce company RGH. Justin Madgwick, global chief executive officer of RGH, said the issue went beyond formal qualifications. "The CSBR report rightly highlights that the UK's cyber challenge is not simply a shortage of people; it's a shortage of visibility into capability, potential and workforce readiness. Organisations often know who holds cyber qualifications, but they have far less insight into the behavioural, cognitive and transferable skills that determine whether someone can succeed, adapt and progress in increasingly complex cyber environments.
"Through our recruitment and workforce optimisation platform, powered by Epitome, we see significant opportunities to widen talent pools, identify hidden capability and create more effective pathways into cyber careers. Closing the skills gap is not just about attracting more people into the profession; it's about understanding the capability that already exists within organisations and developing it more intelligently.
"The recommendations outlined by The CSBR provide an important framework for doing exactly that, and we welcome the focus on building sustainable capability rather than simply increasing compliance," Madgwick said.