What the new CSBR briefing on the UK cyber skills gap means for organisations building security awareness and culture.

The CSBR has published a briefing called The UK Cyber Skills Gap: Building Capability and Resilience, and it makes an argument that anyone working in security awareness will recognise immediately. The UK’s cyber problem is less about a shortage of specialists than about how unevenly capability is distributed, and about the fact that the thinnest areas rarely show up in a workforce headcount.

The figure in the briefing that deserves the most attention is not the workforce total. Drawing on the Cyber Security Breaches Survey 2025, it reports that 49% of businesses and 58% of government organisations identified a basic cyber skills gap. Almost half of British businesses cannot rely on their own people to carry out foundational cyber tasks with confidence. No amount of specialist recruitment will close that, because the gap is not sitting in the security team. It is sitting everywhere else.

Awareness Is Not a Message, It Is an Operating Condition

The briefing is direct about this. It describes the need to move from awareness as a one-off message towards an embedded culture of everyday cyber responsibility, and it argues that shared responsibility depends on considerably more than training. Role definitions have to specify what cyber action is expected of each function. Performance frameworks have to treat cyber conduct as a dimension of professional behaviour. Leaders have to model good practice somewhere people can actually see it.

That is a useful corrective to how a great deal of awareness budget still gets spent. Annual training completion is a compliance metric, not a capability metric. If a finance team can pass a module on invoice fraud in the morning and process a payment request that afternoon from a spoofed supplier domain, the training worked and the programme did not.

The Case for Defining Baseline Capability

One of the strongest recommendations in the briefing is that the UK should publish a national capability framework distinguishing three levels: a minimum cyber awareness standard expected of all employees and organisations, an operational competence level for people working directly with digital systems, data or security tools, and an advanced specialist level covering security architecture, penetration testing, incident response and governance leadership. The briefing describes the absence of a clear national statement of these tiers as the single most important structural reform the UK could make.

The reasoning is worth restating for anyone building an internal programme, because it applies at organisational scale just as much as at national scale. Without a stated tier structure, employers cannot hire to a standard, training providers cannot align curricula and learners cannot see where they sit on a progression path. Most organisations I work with have the same problem in miniature. They know what their security engineers should be able to do. They have never written down what a procurement manager, a factory shift supervisor or a regional marketing lead should be able to do, which means nobody can say with any confidence whether the awareness programme is working.

Boards Need Translation, Not Simplification

The briefing identifies a persistent gap between cyber language and board level decision making, and it frames the solution carefully. Closing that gap is less about simplifying the issue than about making it governable. It credits the NCSC Cyber Governance Code of Practice and the Cyber Security Toolkit for Boards as genuinely useful, while noting that uptake of this kind of resource remains uneven.

This matches what I see in practice. Boards are not avoiding cyber risk because they find it uninteresting. They avoid it because it arrives in a format they cannot act on. A slide of red vulnerability counts tells a board nothing about which business processes stop, for how long, and at what cost. Translate the same information into operational disruption, financial exposure and contractual consequence and the conversation changes within minutes.

The briefing also makes a point I think is badly under discussed, which is that the translation problem does not only exist at board level. It describes a missing layer of technically informed middle management capable of moving risk between specialist teams and executive decision makers. Where that layer is absent, security teams escalate into a vacuum and boards receive advice that is either too technical or too thin to act on.

Most Cyber Teams Are Very Small

The briefing includes a set of figures that should reframe how consultants and vendors pitch to this market. In 2024, 23% of UK cyber sector businesses had one person in a cyber role, 14% had two and 22% had between three and four. Only 4% had more than 30 people.

If that is the shape of the cyber sector itself, capability inside ordinary organisations is thinner still. Programme design has to start from the assumption that the person receiving it has no team, limited authority and a demanding day job. The briefing makes a related argument about smaller organisations specifically, that they face a usability problem as much as an awareness problem, and that the format, presentation and delivery of support matter alongside its content. Guidance that requires an uninterrupted afternoon will not be absorbed, because nobody has an uninterrupted afternoon.

The briefing’s suggestion here is practical. It points to trusted intermediaries such as trade associations, accountants and local enterprise partnerships as more reliable routes to small businesses than direct government communication, and it highlights the Cyber Resilience Centre model as an illustration of how joined up regional delivery can work.

Widening Who Counts as Cyber Talent

The briefing argues for a broader conception of cyber work, one that includes governance, risk, crisis leadership, operational technology, business continuity, supply chains and behavioural insight alongside deeply technical roles. It then follows that through to its practical consequence. An employer who defines a cyber role as requiring primarily technical or coding skills will systematically miss candidates with strong analytical, communication or governance backgrounds who could contribute a great deal to risk management, business continuity or board level cyber leadership.

It names neurodivergent candidates, mid career entrants and professionals from adjacent analytical disciplines such as data science, intelligence analysis, financial crime and fraud investigation as underused sources of capability. As someone diagnosed autistic and ADHD at 48, after nearly two decades in this industry, I would add that the barrier is very rarely the candidate’s capability. It is recruitment and onboarding processes that filter for interview performance and unnecessary credentials rather than for the reasoning the job actually requires. The briefing is right that widening role definitions and rewriting person specifications could expand the effective talent pool without any new training infrastructure at all.

Where To Start

For organisations that want to act on this briefing rather than file it, four things follow reasonably directly.

Write down your own tiers. State what baseline, operational and specialist capability mean inside your organisation, function by function. Almost everything else becomes measurable once that exists.

Move your reporting away from completion rates. Report on reporting behaviour, time to report, repeat susceptibility and the quality of escalations rather than on how many people clicked through a module.

Give middle management something to work with. Board toolkits exist. Equivalent support for the layer sitting between security teams and executives largely does not, and that is where most escalation failures happen.

Use commercial levers where advice has not worked. The briefing is emphatic that supply chain requirements, procurement conditions and customer standards shift smaller organisations more reliably than guidance ever has, and the Cyber Essentials scheme tied to Procurement Policy Note 014 is offered as the working example.

The briefing’s closing position is that the UK cyber skills gap should be approached as an opportunity to build a more confident and resilient national capability base, and that the country already has many of the right ingredients in place. I agree with that reading. The work that remains is less about invention than about joining things up, and about accepting that resilience gets built in the parts of an organisation that have never thought of themselves as security functions.

Read the Report

The UK Cyber Skills Gap: Building Capability and Resilience is published by The CSBR (Cyber Security and Business Resilience) and was released in July 2026. It is available in full at:

Publication page: https://thecsbr.com/research/the-uk-cyber-skills-gap-report/

Direct PDF: https://thecsbr.com/wp-content/uploads/2026/07/CSBR_Cyber-Skills-Gap_Final-1.0.pdf