The UK’s Cyber Security & Resilience Bill may fail to improve the security of critical national infrastructure unless the Government takes more decisive action to tackle the country’s cyber skills shortage, a new report has warned.
The new report was released by The CSBR and argues that the UK has already established a number of useful cyber security initiatives, but has failed to connect them into a coherent system for training and retaining workers.
This could become increasingly problematic as the Cyber Security & Resilience Bill expands regulatory requirements across the UK economy.
Following royal assent, the legislation is expected to extend regulatory powers to managed service providers and introduce stricter incident reporting requirements, including a 24-hour reporting deadline.
While those changes are intended to strengthen the UK’s response to cyber attacks, The CSBR has warned that they could also create a sudden rise in demand for workers with compliance and assurance expertise.
The concern is that organisations will be forced to divert already scarce cyber security personnel away from practical threat detection and defence, leaving them to focus instead on demonstrating regulatory compliance.
James Morris, Founder of The CSBR, noted, “No-one wants a scenario in which the Cyber Security & Resilience Bill becomes a paper tiger. Unless policy makers systematically connect our fragmented training programs and create viable entry routes for new talent, regulations will overwhelm the very sectors they are meant to protect. We could easily end up with compliance ‘contestation’ instead of genuine resilience.”
An ‘hourglass’ cyber workforce
The report draws on evidence from the Government Cyber Action Plan, the NCSC Annual Review 2025 and the Cyber Security Breaches Survey 2025, as well as official research into the UK cyber security labour market.
According to the findings, 49% of UK businesses and 58% of government organisations are already affected by a basic cyber skills gap.
However, the problem is not simply that too few people are interested in working in cyber security. The report describes the current labour market as an ‘hourglass’, with high demand for experienced mid-to-senior professionals but relatively few opportunities for new entrants to gain the experience those roles require.
In 2024, 65% of core cyber job postings required applicants to have mid-level experience, while entry-level roles accounted for just 17%.
That leaves the sector with an obvious problem. Employers say they can’t find enough experienced cyber security workers, but are offering too few junior positions for people to develop that experience in the first place.
The public sector also faces what the report calls a ‘leaky bucket’ problem, where employees who have received training move into better-paid private sector positions. Rigid public sector pay structures then make it difficult to replace them, meaning investment in training does not necessarily result in a lasting increase in government capability.
What needs to change?
The CSBR is calling on the Government to establish a national cyber capability framework that distinguishes between the basic knowledge expected of employees and business leaders, the operational skills required by practitioners, and the advanced expertise needed for higher-risk roles.
It also wants ministers to place a greater focus on the transition between education and employment, as well as creating clearer routes for people moving into cyber security from other professions.
Leadership is another key part of the report’s recommendations. While initiatives such as the Cyber Governance Code of Practice have begun to place greater responsibility on company boards, The CSBR believes cyber literacy should become a more established part of organisational governance and management.
The report also recommends using procurement rules, customer standards and practical support to improve cyber security across small and medium-sized businesses and supply chains.
This is particularly important given that smaller organisations may lack the resources to recruit dedicated cyber security teams, despite potentially providing services to operators of critical national infrastructure.
“The country already has many of the right ingredients: stronger official attention, useful governance tools, visible pipeline programmes and a growing recognition that cyber is a leadership issue as well as a technical one. The task now is to join these elements up more clearly, strengthen pathways and progression, and ensure that capability is built across the economy rather than concentrated in too few places,” concluded Morris.

