Labour market · 2026 · 10 min read

What the UK data says about cyber security pay and cyber security jobs in 2026

Ask what a cyber security job pays in the UK and you will be handed several different numbers, many of them by organisations that earn something when you act on theirs. This report sets the published figures side by side, names who published each one, and prints the period each figure actually describes.

143,000
people in the UK cyber security workforce, up 5% across 2024
DSIT, Cyber security skills in the UK labour market 2025
32,370
core cyber security job postings in 2024, a fall of 33% on 2023
DSIT, Cyber security skills in the UK labour market 2025
£55,000
median advertised salary for a core cyber role, against a £58,800 mean
DSIT, Cyber security skills in the UK labour market 2025

A third fewer adverts, posted into a workforce that grew

Two numbers from the same government release rarely travel together, and these two should. DSIT estimated the UK cyber security workforce at roughly 143,000 people, 5 per cent more than the year before. In the same report it counted 32,370 core cyber security job postings across 2024, an average of 2,698 a month, which is 33 per cent fewer than 2023. More people employed in the field. A third fewer doors advertised into it.

For an individual defender that pairing explains an experience a lot of people have had this year and assumed was personal. Applications take longer to land. The shortlist for a mid-level detection engineering role has forty names on it. Nobody left the profession, so the internal move, the sideways step and the second interview at the firm you already work for carry more weight than they did in 2022. The field kept its people. It advertised for fewer of them.

The fall also sits on top of a genuine expansion. Read the two figures separately and you can write either a boom story or a collapse story, both of them true to one number and false to the other. Read them together and you get the thing a defender can plan against: a large, still-growing profession with a narrower public entrance.

What the published pay figures actually say

Four figures, four owners, four different windows of time. The table below prints each one with the period it describes, because the period is usually where the disagreement lives.

UK cyber security pay, as published by each source. DSIT is a government department analysing 2024 job postings; ITJobsWatch is a commercial job-market tracker reading permanent vacancies to 21 September 2026. All four are advertised salaries, not paid salaries.
Figure What it covers Published by
£55,000 median Core cyber security roles, job postings from 2024 DSIT, Cyber security skills in the UK labour market 2025
£58,800 mean The same 2024 postings, averaged rather than centred DSIT, same release
£60,000 median Cyber security permanent vacancies, six months to 21 Sep 2026, 4,205 salaries quoted ITJobsWatch
£53,000 median Security operations centre analyst, same six months, 109 salaries quoted ITJobsWatch

Note the last row. A security operations centre analyst, the role that carries a great deal of the country’s day-to-day defensive work, sits below the national cyber median in the same dataset, on a sample of 109 quoted salaries. A small sample deserves a light touch. It is still the clearest published signal of what the shift work pays.

Why the number in the advert is not the number in the offer

The gap between £55,000 and £60,000 invites a conspiracy, and it does not need one. DSIT read postings from 2024. ITJobsWatch is reading vacancies from the six months to September 2026, two years further on, in a market where pay has moved. That alone can account for the distance between them.

Three other things widen it. Job titles are not a controlled vocabulary, so one tracker’s cyber security sample holds architects and heads of function that another’s core cyber definition treats separately. London weighting lifts a national median, and a large share of advertised senior roles sit in one city. And a posted range is an asking price written to attract applicants, which is the same reason the top of a range is the number that ends up in the headline.

Recruiters, job boards and training providers all publish salary figures, and most of them earn something when you act on one. That does not make the figures false. It does mean a defender should read who owns a statistic before reading the statistic, and should prefer the release that shows its sample size and its fieldwork dates. DSIT states both: fieldwork ran from 31 July to 18 October 2024, with a recall survey in November 2024.

The floor moved before anything else did

Inside the posting data is a change that matters more than the median. DSIT found that the share of core cyber postings open to candidates with less than one year of experience fell from 25 per cent in 2022, to 22 per cent in 2023, to 17 per cent in 2024. One advert in six now accepts someone who has just arrived, a shift the journal takes up in The first rung is disappearing.

ISC2 looked at the same floor from the practitioner’s side. In May 2026 it surveyed 856 cyber security professionals who use AI in their work, publishing on 14 July 2026. Of those, 56 per cent said AI has somewhat or significantly reduced the need for entry-level positions, and 37 per cent said it has reduced hands-on learning opportunities, though 36 per cent said it has not.

The same survey carries its own counterweight, and it belongs in the record. 53 per cent of those professionals said AI is creating new kinds of entry-level role, and 62 per cent said it has not reduced the need for foundational cyber security skills. Read together, the ISC2 figures describe people reshaping the bottom of the ladder while they climb it. That is a harder thing to plan a first job around than either a boom or a bust, and it is what the practitioners themselves reported.

Who the 143,000 are

DSIT prints the composition of the workforce as plainly as it prints its size, and those sentences deserve to be quoted rather than summarised. 17 per cent of the cyber security workforce is female, against 30 per cent of the digital workforce and 48 per cent of the UK workforce as a whole. 19 per cent come from ethnic minorities, above the UK workforce average of 15 per cent, and only 8 per cent are in senior roles. 8 per cent are disabled, against 17 per cent of the UK workforce. The report also notes that the senior workforce, those with six or more years of experience, is less diverse on gender, disability and ethnicity than the wider cyber security workforce.

There is movement in the pipeline. The proportion of female students on postgraduate cyber courses rose from 21 per cent in 2020/21 to 24 per cent in 2021/22 and 27 per cent in 2022/23, and employers reported neurodivergent staff at 16 per cent in the 2025 report, up from 9 per cent in 2020. The entry point is widening faster than the senior tier is changing, which is exactly the pattern you would expect when the barrier sits at promotion rather than at hiring.

Employers are still reporting the gap they are advertising less for

The demand side has not gone quiet. In the same DSIT release, 49 per cent of businesses reported a basic cyber security skills gap and around 30 per cent reported an advanced one. Those employers are describing work they cannot get done, at the same time as the advert count fell by a third.

Both things can hold at once. A skills gap is a statement about the people already inside an organisation; a posting count is a statement about budget and hiring confidence. When the second contracts and the first does not, the pressure lands on the people who are already there, and it lands hardest on the ones who quietly absorb the work nobody has been hired for.

What a checkable record is worth when the adverts thin out

When a third fewer roles are advertised, a defender’s standing in the field stops being decided by a job title and starts being decided by what a stranger can verify about their work. That is the whole reason an independent panel reads nominations against published criteria and publishes the outcome. The Hall of Fame is a public record of judged work, scored on merit and never bought, and it stays checkable long after the advert that once described someone’s job has expired.

The people in that record did not get there by having the best year in the market. They got there by doing work someone else could point at.

About this report: every figure belongs to the organisation named in the sentence that carries it. Workforce, postings, advertised pay, experience thresholds, diversity and skills-gap figures are from the Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025 (fieldwork 31 July to 18 October 2024, with a recall survey in November 2024; page last updated 2 February 2026). Median salaries for cyber security and for security operations centre analysts are from ITJobsWatch, covering permanent vacancies in the six months to 21 September 2026. The entry-level and AI figures are from ISC2, Rethinking AI’s Impact on Cybersecurity Roles, fieldwork May 2026 among 856 professionals who use AI, published 14 July 2026. The Cyber Security Awards runs no pay survey and publishes no salary data of its own. One figure was dropped during checking: a widely repeated claim that women hold 12 per cent of senior UK cyber roles does not appear in the DSIT release, so the senior-tier figure printed here is the one the report does carry, 8 per cent of the ethnic-minority workforce in senior roles. Read the judged record in the Hall of Fame, or see Skills and Careers 2026 and Who Defends the World 2026.

FAQ

Questions about UK cyber security pay and jobs

What is the average cyber security salary in the UK?

There is no single figure, and the published ones disagree for honest reasons. DSIT reported a median advertised salary of £55,000, and a mean of £58,800, for core cyber security roles in job postings from 2024. ITJobsWatch, reading permanent vacancies in the six months to 21 September 2026, puts the cyber security median at £60,000 from 4,205 quoted salaries. All are advertised salaries.

Are there fewer cyber security jobs in the UK?

Fewer were advertised. DSIT counted 32,370 core cyber security job postings in 2024, a fall of 33 per cent on 2023, while the workforce grew 5 per cent to roughly 143,000 people. Advertised demand and employment moved in opposite directions, which is a different situation from a shrinking profession.

Why is the recruiter’s salary figure usually higher than the government one?

Because the two measure different things. DSIT analysed 2024 postings; ITJobsWatch reads vacancies in the six months to September 2026. Samples differ by role and seniority, London weighting lifts a national median, and a posted range is an asking price. Nobody has to be behaving badly for two honest numbers to disagree.

Is it harder to get an entry-level cyber security job in the UK?

The published data points that way. DSIT found the share of core cyber postings open to candidates with under a year of experience fell from 25 per cent in 2022 to 17 per cent in 2024. ISC2, surveying 856 AI-using professionals in May 2026, reported 56 per cent saying AI has reduced the need for entry-level positions and 53 per cent saying it is creating new kinds of entry-level role.

Does the Cyber Security Awards hold its own salary data?

No. The programme judges nominations and runs no pay survey. Every figure here belongs to the organisation named in the sentence that carries it, and any number that could not be checked against its original release was left out.