Professionalising Cyber Security in the UK: Regulation, Accreditation and the Future of the Industry

Professionalising Cyber Security in the UK: Regulation, Accreditation and the Future of the Industry

Four years ago I wrote about “the Lemon Market” problem in UK cyber security, the uncomfortable reality that buyers often struggle to tell the difference between genuinely competent professionals and people who’ve done a short course and printed some business cards. 

It turns out we’re not alone.  On 23 January, the Cyber Security Authority in Ghana issued a press release announcing a major crackdown on unlicensed cyber security providers.   

“Starting January 31, 2026, all entities and individuals offering cybersecurity services without proper accreditation will face sanctions, including criminal prosecution and administrative penalties.“ 

Which got me thinking: what would happen if the UK tried something similar? 

What if the Government announced, tomorrow, that it was illegal to offer cyber security services without formal accreditation and actually meant it? 

Short answer: the impact would be huge.  Messy.  Uneven.  And genuinely transformative, not just “disruptive”. 

Here’s why. 

A big, immediate market shock.  The UK cyber security market is large, fragmented and still growing fast.  DSIT’s latest figures put it at £13.2bn in revenue, spread across more than 2,000 firms and around 136,000 people. 

A lot of that ecosystem, especially micro consultancies, sole traders and boutique specialists, operates without any kind of government backed accreditation.  They rely on reputation, experience, commercial certs, or just word of mouth. 

Make accreditation a legal requirement overnight and a few things would happen very quickly: 

  • Some small providers would simply exit the market, not because they’re bad, but because they can’t absorb the cost, time or bureaucracy. 
  • There would be short term shortages, particularly in advisory, vCISO and SME focused work. 
  • Prices would go up as supply tightens and compliance costs get passed on. 

We’ve already seen milder versions of this when things like Cyber Essentials became mandatory in parts of the public sector.  This would be that effect, on steroids. 

Accreditation stops being a “nice to have”.   

Unlike Ghana, the UK already has a dense web of assurance schemes and professional bodies: NCSC assured services; Cyber Essentials; CHECK; CREST; CIISec; UKCSC titles; IASME and The Cyber Scheme; the list goes on.   

Right now, these schemes are merely differentiators.  They help you to stand out.  Under a hard enforcement regime, they’d become something else entirely: a licence to operate. 

The likely consequences? 

  • Buyers would cluster around accredited providers, especially in regulated sectors. 
  • Smaller firms would get bought, merged or absorbed just to “buy in” accreditation. 
  • Midtier and large consultancies that are already formally accredited would strengthen their market position very quickly. 

In other words, assurance would stop being about competitive advantage and start being about survival. 

Independents would feel it hardest.  This is where things get politically and professionally uncomfortable.  The UK already has a cyber skills gap – around 3,800 roles by DSIT’s estimates and we rely heavily on contractors and independents to plug it. 

Mandatory accreditation could easily: 

  • Push independents into umbrella firms or consultancies. 
  • Reduce the diversity of niche skills and specialist experience. 
  • Raise the barrier to entry for careerchangers and returners. 
  • Drive some activity into grey or offshore markets, which rather defeats the point. 

Unless accreditation pathways were genuinely lowcost, modular, rolespecific and business/industry aligned, the policy could end up shrinking capacity rather than improving it. 

If the UK Cyber Security Council is meant to act as the profession’s selfregulatory body, this is where it would really need to step up. 

But quality would improve.  There is a strong upside. 

For SMEs, charities and other buyers who struggle to tell good cyber advice from bad, enforcement would almost certainly raise the baseline.  We already know from Cyber Essentials that even lighttouch assurance improves behaviours and reduces exposure to common attacks.  A tougher regime would likely: 

  • Reduce “snake oil” cyber services and wild marketing claims. 
  • Increase trust in incident response and advisory work. 
  • Make insurers happier and underwriting more consistent. 
  • Push accountability and professional standards in the right direction. 

That’s the core argument for regulation: it makes the market safer for buyers. 

The legal reality is awkward.  This is where the UK differs most sharply from Ghana.  Our cyber market sits inside competition law, commonlaw principles and a long tradition of preferring soft regulation and procurement leverage over criminal sanctions. 

If you tried to criminalise unaccredited cyber services, you’d immediately run into some very tricky questions: 

  • What, legally, counts as “cyber security services”? 
  • Are training, tooling and research in scope? 
  • What about opensource security work? 
  • Would criminal sanctions pass proportionality and judicial review tests? 

None of these are insurmountable, but they’re not trivial either. 

So what’s the net effect?  Handled well, a Ghanastyle approach in the UK would probably lead to professionalisation, not prohibition. 

It would be broadly positive for: 

  • Buyers and insurers 
  • Regulated sectors and critical national infrastructure 
  • Accredited firms and mature consultancies 
  • Longterm trust in the profession 

And negative for: 

  • Microfirms and sole traders 
  • Entrylevel professionals 
  • Innovation at the margins 
  • Shortterm market capacity 

In reality, it would need to be phased and pragmatic, with: 

  • Rolebased accreditation 
  • Long transition periods 
  • Explicit protection for research and open security work 
  • Serious support for SMEs and independents 

Done well, it could accelerate the maturity of the profession.  Done badly, it could entrench incumbents and make an already tight skills market worse. 

My bottom line?  I’ll be honest: having seen what happens when someone does a oneday GDPR course and starts calling themselves a “cyber security expert”, I’m broadly in favour of mandatory skills and certification. 

The Government already regulates hundreds of professions, from architects and barristers to teachers and osteopaths.  Cyber security feels at least as deserving. 

The real question isn’t whether cyber should be professionalised by regulation.   

It’s who could design and run a system that actually improves the market without breaking it. 

Suggestions on a postcard to DSIT or the UKCSC. 

#UKCSC #CIISec #IASME #CREST #CharteredProfessional #CyberProfessional #TheCyberScheme