Government must address longstanding cyber skills shortages if the UK’s Cyber Security & Resilience Bill is to achieve its objectives, according to a new report from The CSBR.
The report argues that the legislation, which is expected to receive Royal Assent later this year, will increase demand for cyber governance, compliance and assurance skills as it extends regulatory requirements to managed service providers and introduces mandatory 24-hour cyber incident reporting. Without wider workforce reform, it warns, scarce technical specialists could increasingly be diverted from operational cyber defence into compliance activity.
Drawing on evidence from the Government Cyber Action Plan, the NCSC Annual Review 2025, the Cyber Security Breaches Survey 2025 and the Cyber Security Skills in the UK Labour Market 2025 report, the study highlights that 58 percent of government organisations already have a basic cyber skills gap, compared with 49 percent of UK businesses.
Skills shortage risks undermining resilience
The report argues that increasing regulatory obligations without tackling workforce shortages could result in organisations prioritising compliance over practical cyber defence.
It also identifies what it describes as an “hourglass” cyber labour market, with demand concentrated around experienced practitioners while opportunities for new entrants remain limited. In 2024, 65 percent of core cyber job postings required mid-level experience, while entry-level opportunities accounted for just 17 percent.
The report also points to what it describes as a “leaky bucket” within the public sector, with trained cyber professionals regularly leaving for higher-paid private sector roles because of pay constraints, recycling rather than resolving workforce shortages.
If you liked this content…
James Morris, founder of The CSBR, said: “No-one wants a scenario in which the Cyber Security & Resilience Bill becomes a paper tiger. Unless policy makers systematically connect our fragmented training programs and create viable entry routes for new talent, regulations will overwhelm the very sectors they are meant to protect. We could easily end up with compliance ‘contestation’ instead of genuine resilience.”
Call for coordinated action
Rather than recommending further regulation, the report calls on policymakers to publish a national cyber capability framework, strengthen pathways into cyber careers, embed cyber leadership more widely across organisations and make greater use of procurement and supply chain requirements to improve cyber capability across smaller organisations.
Morris said the UK already had many of the building blocks needed to strengthen cyber resilience but needed a more coordinated approach to developing cyber capability.
“The country already has many of the right ingredients: stronger official attention, useful governance tools, visible pipeline programmes and a growing recognition that cyber is a leadership issue as well as a technical one. The task now is to join these elements up more clearly, strengthen pathways and progression, and ensure that capability is built across the economy rather than concentrated in too few places.”
The report concludes that while the Cyber Security & Resilience Bill has the potential to strengthen the UK’s cyber resilience, its success will ultimately depend on whether organisations can recruit, retain and develop the skilled workforce needed to meet its expanded requirements.
