eCommerceNews UK - Technology news for digital commerce decision-makers
United Kingdom
UK cyber bill risks failing without skills overhaul

UK cyber bill risks failing without skills overhaul

Fri, 24th Jul 2026 (Yesterday)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

The CSBR has warned that the UK's Cyber Security & Resilience Bill may not achieve its aims unless cyber skills gaps are addressed. A new report argues that expanding regulatory duties could deepen existing shortages across business and government.

It says the UK has built a broad base of cyber initiatives but still faces serious weaknesses in workforce capacity. An "hourglass" labour market, with strong demand for experienced staff and limited entry-level openings, risks undermining resilience in critical national infrastructure.

The findings show that 49% of UK businesses and 58% of government organisations already face a basic cyber skills gap. Without broader reform, the report warns, more staff could be pulled into compliance and assurance work rather than operational defence against cyber threats.

The study highlights expected changes under the Bill after royal assent, including wider regulatory powers covering managed service providers and a 24-hour incident reporting requirement. It says those measures are likely to increase demand for compliance and assurance specialists at a time when technical talent is already in short supply.

This creates a risk that scarce cyber professionals will spend more time on administrative obligations than on frontline security work, while legal disputes over compliance could take precedence over practical protection.

Official evidence cited includes the Government Cyber Action Plan, the NCSC Annual Review 2025, the Cyber Security Breaches Survey 2025 and the Cyber Security Skills in the UK Labour Market 2025 report. The analysis says the labour market has become increasingly imbalanced, with 65% of core cyber job postings in 2024 seeking mid-level experience, while entry-level roles accounted for 17%.

The report also describes a "leaky bucket" problem in the public sector, where trained staff continue to leave for higher-paid private sector jobs because of rigid pay constraints. As a result, shortages are recycled rather than resolved.

A central recommendation is for policymakers to set out a national cyber capability framework. This should distinguish between baseline capability for staff and leaders, practitioner capability for operational roles, and advanced specialist capability for high-risk functions.

The report also calls for stronger routes into and through cyber work, with greater focus on transitions from school into further study, from education into employment, and from adjacent professions into cyber roles. In its view, these entry and progression points offer the greatest opportunity to strengthen public sector capability.

Policy focus

Another recommendation centres on leadership and shared responsibility. Cyber literacy, it says, should be embedded more systematically into governance, management and organisational practice, building on existing measures such as the Cyber Governance Code of Practise and National Cyber Security Centre guidance for boards.

For smaller businesses and supply chains, practical incentives are likely to be more effective than broad messaging. The report suggests wider use of procurement rules, customer standards and light-touch support to improve basic cyber practice among smaller organisations.

James Morris, Founder, The CSBR, said: "No-one wants a scenario in which the Cyber Security & Resilience Bill becomes a paper tiger. Unless policymakers systematically connect our fragmented training programs and create viable entry routes for new talent, regulations will overwhelm the very sectors they are meant to protect. We could easily end up with compliance 'contestation' instead of genuine resilience."

Morris said the UK already has many of the elements needed to improve its position, including stronger official focus, governance tools, visible pipeline programmes and growing recognition that cyber is a leadership issue as well as a technical one. He argued that the next step is to connect those elements more clearly and spread capability more widely across the economy.

Recruitment view

The report was sponsored by recruitment and workforce optimisation company RGH Global. It said the cyber labour challenge is not only about the number of people available, but also how organisations assess existing skills and potential.

Justin Madgwick, Global CEO, RGH, said: "The CSBR report rightly highlights that the UK's cyber challenge is not simply a shortage of people; it's a shortage of visibility into capability, potential and workforce readiness. Organisations often know who holds cyber qualifications, but they have far less insight into the behavioural, cognitive and transferable skills that determine whether someone can succeed, adapt and progress in increasingly complex cyber environments."

Madgwick added: "Through our recruitment and workforce optimisation platform, powered by Epitome, we see significant opportunities to widen talent pools, identify hidden capability and create more effective pathways into cyber careers. Closing the skills gap is not just about attracting more people into the profession; it's about understanding the capability that already exists within organisations and developing it more intelligently."

He added: "The recommendations outlined by The CSBR provide an important framework for doing exactly that, and we welcome the focus on building sustainable capability rather than simply increasing compliance."