A hospital consultant chose to become a surgeon, not a compliance officer.
Somewhere in the last few years she started spending real chunks of her week on risk paperwork instead, because someone senior enough has to sign it off and there is nobody else free to do that. It is not really a story about hospitals.
The same thing happens in any profession once the rulebook gets thicker. Only the people qualified to hold the pen are also the ones meant to be doing the actual job, so the senior technical person ends up half buried in governance work nobody hired them for. Nobody plans it that way. It creeps in, one new obligation at a time, and there is never a memo announcing it.
A New Rulebook, and Not Quite Enough People to Run It
Something close to that is about to land across UK IT and cyber security teams.
The Cyber Security and Resilience Bill is moving through parliament now, and once it passes, it pulls a much wider set of organisations, including managed service providers and data centre operators, into far tighter incident reporting duties, with fines running into the millions for getting it wrong. But that part of the story is fairly well covered already.
What gets missed, almost every time, is who actually ends up doing the extra work once the law lands on a real desk. The CSBR published a report in July that put a name to something people in this field already half suspect. Without a workforce fix, it argued, the Bill risks becoming close to toothless in the buildings it should protect.
James Morris, who founded The CSBR, went further. He argued that fragmented training routes and too few realistic entry points into the profession are the real blockers here, not a shortage of legislation. Or put another way, you cannot regulate your way out of a staffing shortage. You can only make the shortage matter more.
The report describes the market as an hourglass, plenty of demand at the experienced end and a narrow neck where new entrants are meant to come through.
In 2024, 65% of core cyber job postings needed someone with existing experience, according to The CSBR's Cyber Skills Gap report, while entry level roles made up just 17% of the total. Nearly half of UK businesses, 49% according to DSIT's Cyber Security Skills in the UK Labour Market 2025 report, already have a basic technical skills gap here. Not a future problem.
A current one, sitting inside businesses that likely have not connected it yet to a law that has not even landed.
Why would tighter cyber rules make hiring harder, not easier?
Because the people qualified for new reporting and governance duties are largely the people already doing the technical work. Once compliance duties rise, the instinct is to pull your most experienced person off the tools and onto the paperwork, since they are the only one senior enough to sign off. That does not create a new hire. It just moves an existing one sideways.
What We're Already Seeing From the Recruiting Side
We have been placing IT managers, security leads and heads of IT for a while now, so this particular squeeze is not news to us. But it is just about to get a legal deadline attached to it. Clients tend to say roughly the same thing in slightly different words each time.
Good, experienced candidates are hard enough to find. And once you do find someone, a good chunk of their week gets eaten by things that were never really the job they were hired for in the first place.
One finance business we worked with earlier this year came to us needing a head of IT, partly because their existing IT manager had, without anyone quite deciding it, become the de facto data protection lead as well.
Nobody sat down and planned that split on purpose. It just happened, the way these things do, and by the time they called us the actual IT work had been quietly piling up for months. Small things first, patching, a couple of overdue upgrades. Then bigger ones, the sort that show up on a board slide with a red icon next to them.
What can employers actually do about a shrinking pool of experienced IT talent?
Start by being honest about what the role actually needs before the job spec gets written.
Technical delivery, governance, or realistically both, because trying to hire one senior person to cover everything is exactly how this squeeze gets worse, not better.
Widening the search matters too. If you need to hire a cybersecurity manager, UK candidates with the strongest track records usually are not browsing job boards, so a recruiter who already knows this market tends to find people the usual channels miss. And where timing is tight, interim cover can buy enough room to make the permanent decision properly instead of under pressure.
Somewhere Between Curiosity and a Plan
We are not about to claim Coburg Banks wrote the Cyber Security and Resilience Bill, or that we have some special line into parliament. What we do have is a decent vantage point on how this plays out for real, because we already work as an IT director recruitment agency UK employers lean on, well before anyone mentioned new legislation.
It is largely the same shortage our clients were fighting anyway, law or no law.
If any of this sounds even slightly familiar, it might be worth a proper look at how to choose a specialist IT recruitment partner, purely so the ground is covered before the new rules make the choice for you. There is no rush attached to any of this. It is less a call-us-today problem and more a worth-knowing-before-it-lands-on-your-desk one.
And for anyone job hunting in this exact corner of IT right now, rather than hiring for it, it is also worth knowing which way the market is actually moving before you commit to anything new. Either way, the pattern behind this particular law is worth remembering long after the headlines about it fade.















