The Cyber Security and Resilience Bill: What It Means for Cyber Hiring

New cyber rules are on the way for managed service providers, data centres and their suppliers. With cyber skills already short, the harder part may be finding the people to meet them.

By Harry Twynham, IT Resourcing Consultant · Updated 29 September 2026

Security engineer with an ID badge working at a laptop in an office
SVG Image

Key points

  • The Bill brings managed service providers and data centres into UK cyber regulation.
  • Incidents must be reported within 24 hours, with a fuller report within 72.
  • Cyber skills are already short, so plan hiring and training early.

What the Bill does

The Cyber Security and Resilience (Network and Information Systems) Bill updates the UK's 2018 NIS Regulations, which cover essential services such as energy, transport, water, health and digital infrastructure. It has passed the House of Commons and is now going through the House of Lords. Much of the detail will follow in regulations once it becomes law.

The main changes are:

  • Medium and large managed service providers come into scope for the first time, regulated by the Information Commissioner's Office.
  • Medium and large data centres are treated as essential services, regulated by Ofcom.
  • Regulators can designate critical suppliers to essential and digital services, so a key supplier can be brought into the regime even if it would not otherwise qualify.
  • Significant incidents must be reported within 24 hours, with a fuller report within 72 hours. Data centres and managed service providers must also tell affected customers.
  • Regulators get stronger enforcement powers, with penalties brought more closely into line with data protection law.

Why this is really a skills question

New duties need people to meet them. Since the Bill was introduced, industry reports have warned that it could struggle without a bigger cyber workforce, and the government's own figures show why.

The latest DSIT research on the cyber labour market found that 49% of UK businesses have a basic cyber skills gap, in tasks such as setting up firewalls or detecting malware, and 30% have gaps in advanced skills such as penetration testing and forensics. It put the annual shortfall of cyber professionals at around 3,800. Women make up 17% of the cyber workforce, and 12% of senior roles.

Meanwhile, jobs in the cyber security sector grew by just 3% in the latest year, the slowest rate since the government started measuring the sector in 2018. Once the new duties start, demand for experienced people is likely to grow faster than supply.

Who will be hiring

  • Managed service providers, which will need governance, security operations and incident response they can evidence to a regulator.
  • Data centre operators, particularly in security operations, risk and compliance.
  • Suppliers that could be designated as critical, which are likely to face tougher questions from their customers first.
  • Organisations already covered by the NIS Regulations, which will need to meet the 24-hour reporting window and closer oversight.

The roles most likely to be in demand are security operations analysts, incident responders, governance, risk and compliance specialists, security architects and cloud security engineers. People who can explain cyber risk clearly to a board will be especially valuable.

How to prepare your team

  1. Work out whether you, or your key customers, are likely to be in scope.
  2. Map the skills you need against the team you have, including out-of-hours cover for the 24-hour reporting window.
  3. Upskill existing IT and infrastructure staff where you can. Many strong security professionals started in networking, systems or support.
  4. Start early on hard-to-fill roles. Senior incident response and governance, risk and compliance roles can take months to fill.
  5. Consider contractors for the initial gap analysis and set-up, alongside permanent hires for the long term.
  6. Widen your search. With women making up 17% of the cyber workforce, adverts, requirements and interview panels that put people off are a real cost.

If you work in IT or cyber

Experience in incident response, governance and cloud security is likely to be in demand as the Bill comes into force. If you work in IT support, networking or infrastructure, this is a good time to build security skills and certifications, because employers will be looking for people they can develop.

How we can help

We recruit cyber security professionals on a permanent and contract basis, from analysts to heads of security. If the Bill is likely to affect your team, send us the role and we will tell you what the market looks like.

Sources: GOV.UK, Cyber Security and Resilience Bill summary; DSIT, Cyber security skills in the UK labour market 2025; DSIT, Cyber security sectoral analysis 2026; THINK Digital Partners on the skills warning.

49%

of UK businesses have a basic cyber security skills gap (DSIT, 2025)

24 hours

to make an initial report of a significant incident under the Bill (GOV.UK)

Hiring for cyber?

We recruit security professionals from analysts to heads of security, on a permanent and contract basis.

Harry Twynham, IT Resourcing Consultant at Deerfoot Recruitment Solutions

About the author

Harry Twynham, IT Resourcing Consultant

Harry joined Deerfoot in 2021 as an IT Resourcing Consultant, working with candidates across the UK tech market.

Connect with Harry on LinkedIn

More insights

Hiring manager reviewing a document with a colleague at a laptop

Hiring advice

Salary Ranges in Job Adverts

What the UK pay transparency plans mean for tech employers, and how to get ready now.

Peter Hirst, Associate Director · 29 September 2026

Manager and employee in a one-to-one meeting at a table in an office

Hiring advice

Employment Rights Act: What Changes from October 2026

Tribunal time limits, the new harassment duty and why probation matters more from January.

Marie Bundy, Lead IT Recruitment Partner · 29 September 2026

Two junior developers working through code together on a laptop

Hiring advice

AI and Junior Tech Hiring

Why cutting your junior pipeline could leave you short of mid-level talent.

Ben Gordon, IT Recruitment Delivery · 29 September 2026

Planning a tech hire?

Send us the brief and a consultant who specialises in that area of technology will call you back within one working day.