ComplianceBack to Blog

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

Precursor Security
28 July 2026
7 min read
1,300 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

The Cyber Security and Resilience Bill (CSRB) will hand thousands of UK organisations a set of hard statutory duties: notification of a significant incident within 24 hours, a full technical report within 72 hours, near-miss reporting for some sectors, and an ongoing obligation to manage cyber risk to a standard a regulator can inspect. Every one of those duties has to be delivered by people. A new report from an independent think tank warns that, for many organisations, the people are not there - and that the Bill risks becoming a "paper tiger" unless the country's cyber skills shortage is addressed alongside it.

For organisations working out how to get ready for the regime, this is not an abstract policy debate. It is the single constraint most likely to determine whether compliance is achievable on the timescale Parliament is setting. This post explains what the warning is, why the skills gap bites hardest for the entities the Bill actually regulates, and what those organisations can do about it now.

The "paper tiger" warning

The report comes from the CSBR, a think tank focused on cyber security and business resilience. (The initials are an easy trap: the CSBR is the commentator, not the Bill, which is the CSRB.) Its founder, James Morris, put the concern bluntly: "No-one wants a scenario in which the Cyber Security and Resilience Bill becomes a paper tiger." His argument is that a new statutory regime is only as strong as the workforce available to operate it, and that expanding regulatory duties across more sectors could deepen a shortage that is already acute.

The scale of that shortage is well established in government data. The report cites the familiar figures: around 49 per cent of UK businesses and 58 per cent of government organisations have a basic cyber skills gap, meaning the people responsible for security lack the confidence or competence to carry out routine tasks such as configuring firewalls or detecting and removing malware. Those are not exotic capabilities. They are the day-to-day foundations the Bill assumes an in-scope organisation already has.

The report describes an "hourglass" labour market - a reasonable supply of entry-level interest and a body of senior expertise, but a squeezed middle of experienced practitioners. It also identifies a "leaky bucket" dynamic in which trained public sector staff continually leave for better-paid private sector roles, so investment in training recycles the shortage rather than closing it. The recommended fix is structural: a national cyber capability framework that distinguishes baseline awareness for general staff and leaders, practitioner skills for operational roles, and specialist expertise for high-risk functions, together with clearer routes into and through cyber careers.

Why the gap bites hardest for entities the Cyber Security and Resilience Bill regulates

A skills shortage is a problem for everyone, but it is a compliance problem for the organisations the Bill brings into scope: operators of essential services, qualifying managed service providers, in-scope data centres, large load controllers and designated critical suppliers. Three of the Bill's features convert a general shortage into a specific staffing requirement.

First, the reporting clock. To make a meaningful notification within 24 hours of becoming aware of a significant incident, an organisation needs people who can triage an event, assess its impact, decide whether it meets the reportable threshold and draft a regulator-facing account - at speed, potentially out of hours, during the disruption itself. That is practitioner and specialist work, precisely the squeezed middle of the hourglass.

Second, the standard of ongoing risk management. Regulators will assess compliance against a risk-based framework built on the Cyber Assessment Framework. Demonstrating that you have identified your risks, protected your systems, and can detect and respond to incidents is not a one-off documentation exercise; it requires people who can maintain that posture and evidence it on request.

Third, near-miss reporting. As we set out in our analysis of the DSIT breaches survey, the near-miss reporting duty goes beyond both the current NIS Regulations and the EU's NIS2. Identifying, classifying and escalating incidents that could have caused significant disruption but did not is monitoring-intensive work that depends on trained security operations resource - the very resource the report says is scarce.

The organisations most exposed are those where in-house security has historically been thin: smaller operators of essential services, and public bodies that sit within supply chains even where the Bill's direct duties largely exempt them. Our public services guidance sets out where those obligations land.

The timing pressure

The skills question is arriving at exactly the point in the Bill's passage where it can still shape the outcome. Following Lords Second Reading on 14 July 2026, Committee Stage begins on 1 September 2026, where scope, delegated powers and the practical workability of the duties are all live issues. Workforce capacity is a natural theme for peers who have already argued the Bill needs to be more ambitious, and the CSBR report gives them evidence to press with.

But organisations should not wait to see whether the point lands in amendments. The legislative timetable already builds in a runway: Royal Assent is expected in late 2026, with the substantive duties phased in through secondary legislation after the DSIT implementation consultation, running towards 2028. That window looks generous until you weigh it against how long it takes to recruit, train or contract for scarce security skills. Hiring a capable incident responder can take months; building an internal capability from a standing start takes longer. The preparation window is a recruitment window, and it is already open.

What in-scope organisations should do now

The report's recommendations are aimed at policymakers. The practical read-across for a regulated organisation is a resourcing plan built around the duties, not around headcount for its own sake.

  1. Map the duties to the roles they require. Work backwards from the 24 and 72-hour reporting obligations, the ongoing risk-management standard and, where relevant, near-miss reporting. Identify which need round-the-clock coverage, which need specialist judgement, and where a single point of failure sits in one person's knowledge.

  2. Distinguish baseline, practitioner and specialist capability. Mirror the report's own framework. General staff and board members need baseline awareness; operational roles need practitioner skills; incident response and threat detection need specialists. You do not need everyone at specialist level, and trying to hire that way in a shortage is self-defeating.

  3. Decide build versus buy, honestly. Given the "leaky bucket" and the cost of the missing middle, many in-scope organisations will find it faster and more reliable to contract for parts of the capability - a managed detection and response service, retained incident response, or independent testing to evidence the risk-management standard - rather than compete for scarce permanent hires. Outsourcing does not transfer the legal duty, so build regulatory notification workflows into any contract and test them.

  4. Invest in retention, not just recruitment. If your plan depends on people you already have, the "leaky bucket" is your risk too. Progression, certification support and realistic pay bands protect the capability you have paid to build.

  5. Cost it into the compliance case now. The staffing and contracting bill is part of the true cost of the regime; our cost recovery explainer covers how regulator charging interacts with that. Building the number into budgets for the next two financial years is more comfortable than discovering it the week a duty commences.

The Bill can only raise the UK's cyber resilience if the organisations it regulates can actually operate the controls it mandates. For a full picture of the obligations and who they fall on, see what the Bill is and what it changes. The skills gap does not change what those duties are. It changes how early you have to start resourcing them.

This article draws on reporting of a July 2026 report by the CSBR (a cyber security and business resilience think tank) and its founder James Morris, covered by Data Centre Review, SecurityBrief UK and IT Brief UK; the 49 per cent and 58 per cent basic-skills-gap figures originate in DSIT's cyber security labour-market research. The Bill's stage (Lords Committee Stage on 1 September 2026) is confirmed on the UK Parliament page for HL Bill 32 (bills.parliament.uk/bills/4035). Position as of 28 July 2026.

Tags:
CSRBcyber securityUK legislationcompliancecyber skills gapcyber skills shortageworkforceHL Bill 32incident reportingmanaged service providersdata centrespublic sectorCyber Assessment Frameworkrecruitmentmanaged detection and responseresourcing
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article
Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

CSRBcyber security+12 more
Read Article
Precursor Security
21 Jun 2026

Cyber Security and Resilience Bill Clears the Commons: Where It Stands in 2026

The Cyber Security and Resilience Bill (CSRB) has cleared every House of Commons stage and passed to the Lords as HL Bill 32. The core architecture survived intact - expanded scope, 24/72-hour reporting, £17m penalties - with one headline change: Ofcom is now the sole regulator for data centres. Here is the confirmed timeline and what to do before Royal Assent, expected late 2026.

CSRBcyber security+12 more
Read Article