The 2026 DSIT/Ipsos report finds 808,000 UK businesses lack confidence in fundamental cybersecurity technical skills, up from 49% in 2025.
DEAFLETTER // WEEKLY BRIEF
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The UK is measuring its black hole more precisely: 57% of businesses don't trust their basic cybersecurity skills, an eight-percentage-point jump in a single year. The figure comes from the government's Cyber Security Skills in the UK Labour Market 2026 report, published September 30, 2026 by the Department for Science, Innovation and Technology (DSIT) in collaboration with Ipsos. Roughly 808,000 UK businesses — nearly six in ten — admit they lack confidence in performing at least one of nine fundamental digital defense tasks, up from 699,000 in 2025.
Key Takeaways
- 57% of UK businesses have a basic technical skills gap in 2026, up from 49% in 2025: about 808,000 businesses versus 699,000 last year.
- Malware detection and removal is the task with the largest skills deficit: 38% of businesses and 47% of charities don't feel capable.
- 47% of cybersecurity leads in businesses and charities lack confidence in handling breaches or attacks and have not outsourced the function.
- The UK cybersecurity workforce stands at roughly 145,900 people, growing just 2% year over year.
The Awareness Paradox: Measuring More, But Not Fixing More
The eight-point increase doesn't necessarily signal an objective decline in capabilities. DSIT/Ipsos researchers, as reported by The Register, explicitly cautioned that the jump from 49% to 57% "might reflect greater awareness of organizations' security posture rather than an actual deterioration in their capabilities." In other words, the UK is getting better at recognizing its own weaknesses — diagnostically useful, but therapeutically neutral. The survey methodology — a representative telephone sample with fieldwork between August and October 2025 — gives the data statistical robustness. The problem isn't the measurement; it's what government and the market do with it.Nine Tasks, One Black Hole: Malware Detection as Achilles' Heel
The DSIT report breaks the basic technical skills gap into nine fundamental tasks. Above all, malware detection and removal emerges as the most critical weak point: 38% of private businesses, 47% of charities, and 23% of the public sector say they can't perform it. The gap between business and the public sector is significant, but the latter shows accelerated deterioration: its skills gap nearly doubled, rising from 14% in 2025 to 27% in 2026. The technology context compounds the pressure. Sam Thornton, COO of Bridewell, notes that "malware is evolving quickly, and AI is increasingly helping attackers produce faster variants which are harder to spot." In this scenario, AI isn't the cause of the gap but a threat multiplier: it lowers the cost of producing polymorphic variants and increases how often basic defenses are tested.The 47% Without a Net: Those Who Don't Know and Don't Buy Help
The most unsettling finding in the government report concerns the overlap between incompetence and isolation. 47% of individuals responsible for cybersecurity in businesses and charities lack confidence in managing breaches or attacks and have not outsourced the function. These aren't organizations delegating to a managed security provider; they are organizations that currently possess neither internal nor external expertise. This 47% represents a systemic risk to the UK supply chain. A small business without effective defensive capabilities becomes the path of least resistance for attackers targeting larger partners. The mechanism is familiar: compromise of weak third parties, lateral movement, access to higher-value targets.The Workforce That Isn't Growing: 145,900 People for 808,000 Businesses
The UK's specialized cybersecurity workforce numbers roughly 145,900 individuals, growing just 2% year over year according to the DSIT/Ipsos report. The arithmetic is unforgiving: even assuming uniform distribution, each professional would need to cover more than five struggling businesses. Distribution isn't uniform, and smaller businesses — those without budgets to attract talent — face the greatest pressure. One data point from the same report: 70% of cybersecurity firms report staff using AI in daily work, up from 53% the previous year. But defenders' adoption of AI tools doesn't automatically close the basic skills gap. Tools require operators who can interpret output, configure parameters, and recognize limits."When more than half of UK businesses lack confidence in basic skills, and nearly half of those responsible for security don't feel equipped to handle an attack, you have an economy that's easier to breach and slower to recover" — Sam Thornton, COO Bridewell
What to Do Now
UK businesses affected by the basic technical skills gap have three operational levers documented in the brief. First, an internal audit of the nine fundamental tasks in the DSIT/Ipsos report, with absolute priority on malware detection and removal — the task with the largest deficit (38% of businesses, 47% of charities). Second, an evaluation of outsourcing the cybersecurity function: the 47% of leads without confidence and without outsourcing represent the most exposed segment. Third, monitoring the Cyber Security and Resilience Bill under discussion in the House of Lords, which imposes stricter standards but, in available sources, provides no direct operational support for the skills gap. The DSIT/Ipsos report does not measure the effectiveness of the £210 million Cyber Action Plan in mitigating the skills deficit. Businesses cannot rely on this instrument as a verified solution to the problem. The specialized workforce's 2% year-over-year growth offers no prospect of near-term relief: demand for skills far outstrips measured supply.The Bald Tire Metaphor: When Tech Investment Doesn't Cover Missing Fundamentals
Matt Hull of NCC Group captures the problem with a mechanical metaphor: "It's a bit like maintaining your car. You can spend a fortune on the latest safety features and a brilliant stereo, but none of that helps much if your tires are bald or you can't see through the windshield." UK cybersecurity in 2026 looks like a vehicle with excellent options and neglected routine maintenance. The concrete risk to the UK economy is twofold. From a microeconomic perspective, businesses without basic skills are more vulnerable to operational disruption, recovery costs, and reputational damage. From a macroeconomic perspective, the concentration of risk across such a broad swath of the productive fabric exposes the entire system to supply-chain shocks that individual businesses, even mature ones, cannot manage alone.Information verified against cited sources and current as of publication.
Sources
- https://www.theregister.com/security/2026/09/30/more-than-half-of-uk-businesses-lack-confidence-in-basic-cyber-skills/5299991
- https://www.gov.uk/government/publications/cyber-security-skills-in-the-uk-labour-market-2026/cyber-security-skills-in-the-uk-labour-market-2026
- https://www.digit.fyi/comment-building-cyber-talent-takes-more-than-a-degree/
- https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
- https://www.cloudswitched.com/news/cyber-breaches-survey-2026-612k-uk-businesses-hit-it-support-proactive-plan
- https://iseoblue.com/post/cyber-security-breaches-survey-2026-small-business/
- https://www.pwc.com/gx/en/1/issues/c-suite-insights/ceo-survey.html
- https://www.theregister.com/security/2025/12/19/ministers-confirm-breach-at-uk-foreign-office/2566042
DEAFLETTER // WEEKLY BRIEF
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.