The UK’s Cyber Security & Resilience Bill may fail to achieve its goals unless the Government fundamentally shifts how it addresses the country’s cyber skills crisis, an authoritative new report warns.
Published today by The CSBR, the report – The UK Cyber Skills Gap: Building Capability and Resilience – reveals that, while the UK has built a solid foundation of cyber initiatives, an unstable “hourglass” labour market structure combined with expanding regulatory burdens threaten to undermine genuine digital resilience across critical national infrastructure.
Following royal assent, the Cyber Security & Resilience Bill is expected to expand regulatory powers to managed service providers and introduce strict 24-hour incident reporting.

But the report highlights that this will trigger an unprecedented surge in demand for compliance and assurance skills, inadvertently creating the new risk of the UK trapping scarce technical talent in a cycle of bureaucratic box-ticking.
Drawing on official evidence including the Government Cyber Action Plan, the NCSC Annual Review 2025, the Cyber Security Breaches Survey 2025 and the Cyber Security Skills in the UK Labour Market 2025 report, the report identifies several glaring gaps in the cyber workforce.
About half (49%) of UK businesses and 58% of government organisations already suffering from a basic cyber skills gap.
Without systemic reform, critical personnel will be diverted into compliance management rather than practical threat defence, resulting in legal contestation instead of security.
The report also identified a structural crisis in the UK cyber workforce, which resembles an hourglass: high demand for experienced mid-to-senior level practitioners, but a severe bottleneck at the bottom.
Recommended
In 2024, 65% of core cyber job postings required mid-level experience, whereas entry-level opportunities fell to just 17%.
The CSBR also identified what it dubs to be a ‘leaky bucket’ dynamic, in which trained public sector staff continuously exit to better-paid private sector roles due to rigid pay constraints, recycling the shortage rather than solving it.
“Noone wants a scenario in which the Cyber Security & Resilience Bill becomes a paper tiger,” James Morris, founder of The CSBR, said.
“Unless policy makers systematically connect our fragmented training programs and create viable entry routes for new talent, regulations will overwhelm the very sectors they are meant to protect. We could easily end up with compliance ‘contestation’ instead of genuine resilience.”
Related
