Every CISO says the same thing about hiring. Application volume is high. Shortlist quality isn’t.

UK cyber employment sits at around 143,000 people and rising. The workforce gap is around 3,800 professionals, concentrated in senior and specialist roles. Globally, ISC2 puts the shortfall at 4.8 million.

The demand pressure is real. But security leaders will tell you the harder problem isn’t finding candidates. It’s verifying them.

The certification problem

Cybersecurity leans heavily on certifications. CISSP, CISM, CEH, OSCP, cloud specialisations like AWS Security Specialty. These are useful signals. They filter noise. In enterprise procurement, they’re often mandatory.

But a signal isn’t capability. A candidate with CISSP has demonstrated theoretical knowledge and exam discipline. They haven’t necessarily demonstrated the ability to reason under uncertainty in a live incident, spot a novel attack pattern in log data, or explain a threat model to a non-technical board.

In 2026, hiring managers are routinely seeing candidates with strong academic backgrounds and stacked credentials who can’t complete a basic penetration test, alongside candidates from unconventional paths who can. The reliable signal for practical capability isn’t the credential. It’s the evidence of actual work.

What actually reveals capability

  • Portfolio evidence. CTFs, bug bounties, published disclosures, active TryHackMe or Hack The Box profiles. Its absence in a senior candidate is a data point.
  • A specific incident story. Every senior candidate should have one. What matters is the decision tree, not the outcome.
  • Non-technical fluency. Can they push back on engineering about a risk trade-off? Explain a threat model to a CFO?
  • Curiosity. The best security people read post-mortems and follow disclosure lists even when it isn’t their job.

Four interview questions that work

  • “Walk me through an incident you’ve been part of, from detection to resolution.” Tests real experience versus textbook knowledge.
  • “Here’s an anonymised architecture. Where would you attack first, and what defences would you prioritise?” Tests adversarial thinking.
  • “Tell me about a time you explained a security risk to someone who didn’t want to hear it.” Tests communication and influence.
  • “What’s a widely-used security control you think is over-relied on, and why?” Tests independent judgement.

Red flags

Certifications recently acquired with no supporting depth of experience. Frameworks name-checked without any specific application. Discomfort with “I don’t know.” Reliance on jargon over plain explanation. An inability to describe a specific mistake they’ve learned from. Any one is fine. Together, look harder.

Why the vertical matters

“Cybersecurity” isn’t a single skill set.

In Energy and Utilities, the constraint is OT and ICS experience. Cloud security experience doesn’t automatically translate to protecting critical national infrastructure.

In Financial Services, regulatory literacy matters as much as technical capability. PRA and FCA expectations, third-party risk, operational resilience.

In Healthcare, legacy systems, patient safety implications, and NHS or private governance dynamics all shape the role.

The candidates who thrive in each are rarely interchangeable. And as we set out in our recent look at the true cost of getting hiring wrong, a mis-hire in a specialist security role is one of the most expensive mistakes an organisation can make.

The bottom line

Cybersecurity hiring in 2026 isn’t primarily a volume problem. It’s a verification problem. The candidates you most want to hire are typically employed, don’t respond to generic outreach, and can’t be identified by CV keyword alone.

Getting this right requires interview processes that test thinking, not knowledge. Recruiters who know the discipline deeply enough to vet candidates before they reach your desk. And a willingness to trust unconventional signals when they point to real capability.

If you’re hiring cyber roles for Q3 or Q4, get in touch.