Summary
- The UK cyber workforce reached an estimated 145,900 people at the end of 2025, up 2%, while core cyber job postings recovered 7% from their 2024 low.
- Seventy per cent of cyber businesses now report staff using AI in day-to-day work, up from 53%, while automation appeared in 15% of core cyber job postings.
- Graduate supply is growing, but apprenticeship enrolment fell 15% and employers told researchers that automation may further narrow entry-level routes needed to develop future senior specialists.
Artificial intelligence is spreading through the UK cybersecurity workforce faster than the workforce itself is growing, creating a labour market in which automation skills are becoming more valuable while the traditional route from junior roles into experienced security work is becoming harder to navigate.
New research published by the Department for Digital, Culture, Media and Sport estimates that 145,900 people were working in cybersecurity roles across the UK economy at the end of 2025, an increase of 2% from the previous study.
At the same time, 70% of cybersecurity businesses told researchers that employees were using AI in their day-to-day work, up sharply from 53% in the previous report. Demand for automation skills has also risen in job advertisements, appearing in 15% of core cybersecurity postings in 2025 compared with 11% in 2024 and 9% in 2023.
The eighth annual labour-market study, carried out by Ipsos and Perspective Economics, combines representative surveys, interviews, job-advertisement data, and education statistics. Most of the survey fieldwork was conducted in the second half of 2025, so the findings describe a labour market that predates publication by several months rather than a live count of current vacancies.
Vacancies have recovered from a low base
Core cybersecurity job postings increased by 7% in 2025 compared with 2024, while the broader category of jobs requiring cyber skills rose 10%. The improvement follows two years of substantial contraction, meaning demand may be recovering from a low base rather than returning immediately to the recruitment conditions seen earlier in the decade.
The report recorded an average of 2,911 core cybersecurity vacancies a month during 2025, alongside another 2,669 postings for wider roles requiring security skills. Greater London, Manchester, Birmingham, and Bristol remained the four largest locations for core vacancies, with Edinburgh moving into fifth place.
Recruitment expectations among cybersecurity suppliers have nevertheless softened. Fifty-three per cent expect their workforce to grow during 2026, down from 67% in the previous study, while 46% expect staffing to remain unchanged. Employers also told researchers that they were receiving large numbers of applications, including AI-generated CVs from candidates who sometimes overstated their skills.
That combination complicates the familiar claim that cybersecurity simply suffers from a universal shortage of people. Businesses can receive too many junior applications while still struggling to hire experienced specialists in particular disciplines, and the government has stopped publishing a single workforce-gap estimate because changing demand and methodological limitations made that number increasingly difficult to interpret.
The entry-level pipeline is narrowing
Education is supplying more potential recruits. The number of cybersecurity graduates increased 14% between the 2022/23 and 2023/24 academic years to 7,950, while the study estimates around 8,600 people entered the cyber workforce through formal education and training pathways during 2025.
Yet the routes from study into professional work are less straightforward. Enrolment in cybersecurity-specific apprenticeships fell 15% between 2023/24 and 2024/25, while graduate-outcomes data showed an 11% unemployment rate for cybersecurity graduates from the 2022/23 academic year compared with 6% across graduates overall.
Employers interviewed for the research described the junior recruitment market as saturated, with some entry-level vacancies attracting large numbers of candidates who did not have the practical experience being sought. Several also reported that nominally junior cyber roles increasingly require broader IT experience, such as previous work on a help desk.
AI introduces another pressure. Interviewees expected automation to absorb some junior analytical and operational tasks while increasing demand for people able to interpret AI-generated findings, secure models, design controls, and exercise judgement when automated systems produce ambiguous results.
That creates a long-term workforce problem rather than simply a short-term headcount question. Experienced security engineers, architects, incident responders, and managers generally develop through years of operational work, so removing too many junior tasks can reduce the places where people acquire the judgement required for more senior roles later.
AI use is rising faster than confidence
Greater AI adoption also sits beside worsening gaps in more basic cybersecurity capability across the wider economy. Fifty-seven per cent of UK businesses were assessed as having a basic technical cyber skills gap, up from 49% in the previous report, based on whether people responsible for security were confident carrying out a range of common tasks.
Almost half of the individuals responsible for cybersecurity in businesses and charities — 47% in each group — lacked confidence in their ability to deal with a breach or attack and had not outsourced that responsibility. The finding indicates that introducing AI-assisted security products does not automatically supply the organisational knowledge needed to respond when an incident occurs.
Specialist employers face a different shortage. More than half of cyber companies trying to recruit reported hard-to-fill vacancies, while principal-level roles requiring roughly six to nine years of experience became markedly more difficult to fill. Technical capability remains scarce in areas where experience cannot easily be produced through a short training course.
Meanwhile, AI is changing what employers ask existing security teams to do. Cyber professionals increasingly need to secure AI systems themselves, assess AI-generated analysis, understand how automation can fail, and distinguish credible output from plausible mistakes while attackers also use the same technology to scale reconnaissance, phishing, and software development.
Workforce growth is only one measure
The government estimates that around 4% of the existing cyber workforce may leave in a typical year through retirement or career change, equivalent to roughly 5,800 people based on the current workforce estimate. Its modelling suggests the labour market would need about 10,200 new entrants during 2026 to cover both new demand and replacement needs.
Those estimates carry substantial uncertainty, which is one reason the report has dropped the headline annual workforce-gap number used in earlier editions. The more useful picture now lies in the mismatch between levels of experience, the type of skills employers need, and the opportunities available for newcomers to acquire them.
AI can improve the productivity of experienced cybersecurity teams by automating repetitive investigation, summarising alerts, analysing code, or assisting with documentation. Used badly, it can also remove the routine work through which less experienced employees learn how systems behave before they are expected to make higher-risk decisions.
The UK labour market is therefore moving into a more difficult phase than a simple shortage narrative suggests. Cyber employment is still growing, vacancies have begun recovering, and graduate numbers are rising, yet skills gaps persist while organisations automate parts of the work that once formed an entry point into the profession.
With seven in ten cyber businesses already using AI in daily work, the technology is no longer a future workforce scenario for the sector. The harder question is whether companies can capture the productivity benefits without weakening the apprenticeship, junior, and operational routes through which the next generation of experienced security staff is built.












