Date Posted: Thursday, 10th September 2026
The cyber threat outlook gives business leaders a view of what could disrupt their organisation. The harder question is whether they have the people, expertise and decision-making capacity to respond.
A business can invest in security technology and still struggle to close an exposed system, manage supplier access or restore a critical service. The missing capability may sit in security, engineering, operations or the relationships between them. Understanding where the work stalls is essential to deciding what to strengthen.
This guide connects the threats facing UK businesses with the capabilities they demand. It explores where to develop existing teams, when specialist recruitment can help and how to balance internal knowledge with external support. For established organisations, the aim is to make security capability more effective and sustainable as the business changes.
The evidence gives leaders several different views of cyber exposure. In the UK Government’s Cyber Security Breaches Survey 2025/2026, 43% of businesses reported a breach or attack during the preceding 12 months, unchanged from the previous survey. That includes unsuccessful attacks; it does not mean 43% were successfully compromised.
At the more serious end, the NCSC supported 204 nationally significant incidents in its September 2024 to August 2025 reporting year, compared with 89 previously. This describes the NCSC’s operational caseload, rather than all attacks against UK businesses. Stable overall prevalence and a rise in serious incidents can coexist.
For workforce planning, the useful questions concern how exposure becomes business disruption:
Verizon’s 2026 Data Breach Investigations Report executive summary reports ransomware and third-party involvement in 48% of breaches each. These are overlapping categories in a global dataset, not probabilities for an individual UK company. Their relevance is the breadth of capability needed: protection, supplier assurance and recovery all require attention.
The planning task is to connect that evidence to the organisation’s own services. Which disruption would stop trading, interrupt production or prevent customers from being served? That answer provides a more useful starting point for investment than a general increase in security headcount.
AI affects the threat environment, the systems businesses introduce and the work their security teams perform. Each creates a different capability requirement.
The NCSC’s assessment of AI’s impact on cyber threats to 2027, published in May 2025, anticipates more effective and efficient intrusions, including faster exploitation of known vulnerabilities. This is a forward assessment. For leaders, it strengthens the case for understanding assets, closing exposure promptly and making security part of implementation decisions.
Consider an internal AI assistant that can retrieve business documents and take actions through connected tools. Its usefulness depends on access, but that access needs to match what users and the service are authorised to do.
The work crosses several disciplines:
Recruiting an AI security specialist may provide valuable expertise, but the brief should reflect the technology being deployed and the teams needed to secure it. TRIA’s guide to AI transformation priorities covers the wider decisions around adoption and scale.
Automation also changes where people spend their time. In ISC2’s July 2026 research, based on 856 cyber professionals using AI surveyed that May, 65% said they spent more time deciding whether to trust or act on AI recommendations; 63% spent more time reviewing or validating outputs.
These findings describe reported changes in work, rather than measured productivity gains. Assess the capacity released after checking, correction and exception handling. Developing colleagues also need opportunities to build investigative judgement as routine tasks change.
Job titles describe roles, but they do not always reveal whether the necessary work is covered. A security team may identify an issue while another function controls the systems, budget or maintenance window needed to resolve it.
These six areas connect business exposure to the skills and support needed to address it. Assess each against your critical services and identify who owns the work.
Protecting access requires identity engineering, privileged access controls and service-desk procedures that can withstand impersonation. Give someone clear ownership of identity, supported by people who can investigate suspicious activity and specialists where implementation needs exceed the team’s expertise.
Closing vulnerabilities depends on people who understand the affected systems, can prioritise fixes and have the capacity to make changes. Connect security assessment with engineering delivery, and agree who will maintain improvements when project or contractor support ends.
Recovery needs incident leadership, technical restoration skills, business continuity and clear communications. Combine internal service knowledge with pre-arranged specialist support, and check who is available and authorised to act outside normal working hours.
Someone needs to understand which services depend on suppliers, how access is controlled and how recovery would be coordinated. Keep an internal owner who can challenge supplier evidence and bring providers together when action is needed.
Securing AI services brings together application security, identity, data access and testing. Build that capability within the product and platform teams deploying the technology, using specialist review where designs or integrations are unfamiliar.
Operational environments need security expertise that accounts for safety, availability and the practical limits of making changes. Bring specialists together with operational engineers to plan segmentation and other protections around how the service or facility actually runs.
These are areas to assess, rather than a prescribed team structure. Responsibilities may sit within existing roles, specialist teams or a combination of employees and providers.
The evidence matters as much as the organisation chart. For recovery, ask for the result of a realistic restoration exercise. For access, examine whether review findings were resolved. For remediation, follow an issue from discovery through to a verified fix. Each shows more than a list of assigned responsibilities.
A reduction in advertised roles does not establish that businesses have all the cyber capability they need. Recruitment activity and organisational skills gaps measure different things.
The Government’s Cyber Security Skills in the UK Labour Market 2025 report, corrected in February 2026 and principally reflecting 2024 activity, recorded 32,370 core cyber job postings, a 33% annual decline. It also found basic technical skills gaps in 49% of businesses and advanced gaps in 30%. These figures describe the period studied, rather than current vacancy levels.
Before deciding to recruit, distinguish four problems that can look similar:
Each points towards a different response. More analysts might help an overloaded team, while a specialist engagement could resolve an unfamiliar technical challenge. Unclear authority needs management attention, and dependence on one experienced employee may require cross-training and succession planning.
This distinction makes a hiring brief more precise. It also helps explain why an apparently well-staffed team can still struggle to deliver. The wider assessment approach is covered in TRIA’s guide to identifying the capabilities your business needs.
Talent balance covers more than permanent employees and contractors. It includes technical depth, business knowledge, senior judgement, developing talent and the ability to maintain services through absence or change.
Choose the delivery model around the duration of the work, its urgency and the knowledge that needs to remain within the organisation. Several approaches may contribute to the same capability.
Development is a useful option where the work is recurring, adjacent expertise exists and there is time to learn. Infrastructure engineers may bring valuable system knowledge to security work; risk and service-management colleagues may contribute relevant analytical and coordination skills.
Make the commitment practical:
Course completion can support development, but capability needs to be demonstrated in the work itself. The plan should also account for the senior time required to review decisions and support learning.
A permanent appointment is appropriate where the business needs continuing ownership, specialist depth or someone to develop a team over time. Define the outcomes and working relationships before settling on the title.
A credible brief should establish:
Once those decisions are clear, TRIA’s practical guide to technology hiring covers the wider recruitment process.
Specialist contractors can provide expertise or capacity for an implementation, migration, remediation programme or temporary workload. Their contribution is easier to assess when the required outcome and boundaries are explicit.
Agree deliverables, access to decision-makers, acceptance criteria and knowledge transfer before work begins. If a contractor improves privileged access, for example, an internal owner still needs to maintain the controls, manage exceptions and understand the configuration afterwards.
An interim leader may help during a transition, while a fractional appointment can provide senior judgement where a part-time commitment fits the requirement. Availability and authority need to reflect the actual work, including incident expectations.
Consider the time needed for team leadership, executive engagement and delivery follow-through. TRIA’s CISO leadership and hiring guide explores leadership scope, appointment decisions and fractional roles in greater depth.
External security providers can offer monitoring, specialist testing or response services. The organisation needs enough internal understanding to judge the service, act on its findings and connect it to business priorities.
Before relying on that support, establish:
Security provision and recruitment support serve different purposes. TRIA’s role in this picture concerns defining and sourcing technology talent; the operating scope of a security provider requires its own assessment.
The CISO or security lead can coordinate priorities, but delivery depends on colleagues who control systems, operations, investment and people. A workforce plan should make those dependencies visible.
The Cyber Governance Code of Practice emphasises senior ownership, resources and assurance. In practical planning, that means establishing how responsibilities connect:
For example, a remediation plan should identify who will carry out the change and who can approve the operating disruption it requires. Escalation also needs an owner when teams cannot agree a workable timetable.
TRIA’s article on taking information security seriously explores the wider organisational commitment. Here, the test is whether that commitment gives people the time, authority and support to deliver.
A useful cyber workforce plan starts with a business service and ends with evidence that the required capability works. This keeps investment connected to identifiable exposure and gives leaders a basis for reviewing progress.
Use the following sequence for each priority service:
Suppose a restoration exercise identifies that only one engineer understands how to recover a critical platform. Recruiting another security analyst would leave that dependency unresolved. A more relevant response could combine documentation, supervised cross-training and specialist help to validate the recovery process.
Review the plan when business conditions change. An acquisition, new supplier, AI deployment or move into extended operating hours may alter the capability needed even if the security team’s headcount stays the same. Progress should be visible in outcomes such as completed fixes, demonstrated recovery and dependable coverage.
Start with the services and information whose compromise would matter most, then assess the work needed to protect and recover them. Identity, remediation, incident response and recovery are useful areas to examine, with cloud, application, AI or operational technology expertise considered against your environment. Include the engineering and business skills needed to turn security findings into action.
A permanent hire can suit an enduring need for ownership or specialist capability. Development works where relevant foundations and sufficient learning time exist. Contractors can address defined delivery needs, while providers can supply agreed ongoing services. Urgency, internal knowledge and the capacity to supervise or manage the work should guide the combination.
AI may reduce effort on particular tasks, but its effect on staffing depends on the workload remaining after validation, correction and escalation. Assess demonstrated capacity gains before changing headcount assumptions. Preserve experienced judgement and opportunities for junior colleagues to learn as tasks change.
Cyber security planning is most useful when leaders can connect business exposure to specific work, clear ownership and a credible resourcing decision. That creates a stronger basis for investment and a clearer brief when recruitment is needed.
TRIA helps organisations recruit technology talent, from individual specialists to teams. If your next step involves a permanent appointment or specialist contractor, start with the expertise, outcomes and delivery capacity your programme needs.
Planning your cyber security team?
As a founder of TRIA, Harriet is proud of the company's impact in transforming recruitment through strategic insight and deep market understanding. Her leadership style is characterised by a focus on sustainable growth and the development of long-term client relationships.
Connect on LinkedIn