News & Views

Beyond the Balance Sheet: The UK Cyber Sector Must Choose Maturity Over Mere Growth

Beyond the Balance Sheet: The UK Cyber Sector Must Choose Maturity Over Mere Growth

Author: Jon Holden, CyberNorth CEO

There is plenty of reason for optimism in the UK’s latest cyber security sectoral figures. On paper, the 2026 Analysis paints a picture of a flourishing industry: £14.7 billion in revenue, a workforce nearing 70,000, and a steady climb to over 2,600 active firms. These aren’t just vanity metrics. Coupled with the government’s direct communication to FTSE 250 companies, emphasising cyber security as a boardroom issue rather than merely an IT one, these metrics signal that the sector has finally transitioned from a “niche IT concern” into a cornerstone of our national economic strategy.

However, statistics only tell part of the story. In my dual roles as a fractional CISO and as CEO of CyberNorth, I spend my days navigating the tension between high-level corporate risk and the ground-level reality of our talent pipelines. Interacting daily with organisations and practitioners across the UK provides a unique and sometimes sobering perspective that a spreadsheet simply cannot capture. 

From the boardroom to the regional meetup, I see a sector that is becoming bigger, certainly, but one that is still struggling to become truly resilient. This isn’t a critique for the sake of it; it is an observation from the front lines: growth is an inevitable byproduct of a dangerous world, but real maturity is a deliberate choice we have yet to fully make.

The growth figures are just a distraction. It makes me wonder if we are measuring the wrong things.

 We are becoming bigger, certainly, but are we becoming more resilient?

Leveraging our Technical Heritage

We must acknowledge that the UK starts from a position of enviable strength. The National Cyber Security Centre (NCSC) remains a global benchmark for how a state should coordinate incident response and threat intelligence. This isn’t accidental; it is built upon the deep technical heritage of GCHQ, a pedigree that remains the “gold standard” for international partners.

From our world-class universities to our high-calibre practitioners, the raw ingredients of excellence are already in the pot. We are excellent at the “sharp end” of cyber: the intelligence, the defence, and the initial spark of innovation.

The Agentic Shift

The landscape is shifting under our feet at a rate that traditional policy often struggles to track. Attending Google Cloud Next this year, the atmosphere was one of quiet but definitive revolution. We are moving beyond the era of the ‘AI Co-pilot,’ which still requires heavy human steering, and into the age of agentic AI.

We are no longer just talking about sophisticated chatbots; we are looking at autonomous systems capable of investigating threats, correlating disparate intelligence, and executing response workflows in real-time. 

For the modern Security Operations Centre (SOC), this represents a fundamental paradigm shift. As a CISO, I see teams every day who are drowning in alert fatigue and hampered by a persistent skills gap. Agentic systems offer a way out of that manual grind, but they also demand a new kind of practitioner, one who can oversee and govern autonomous agents rather than just ‘driving’ a software tool.

Critically, we must recognise that the agentic shift represents not just a distant “future state,” but a very near reality that draws closer every day. A refusal to address our current growth model now will actively disadvantage the UK. By clinging to outdated scaling strategies and fragmented support systems, we risk dragging ourselves further behind global competitors and, crucially, weakening our position of strength. 

Our technical heritage is a platform to build upon, not a cushion to rest on. The nations that successfully integrate agentic workflows won’t just move faster; they will fundamentally redefine what operational resilience looks like, leaving behind those who hesitated to catch up.

The question for the UK is whether our current growth model allows us to pivot this quickly, or if we are too bogged down in legacy structures.”

The Fragility of the “Quiet Work”

This is where we need to be honest about our weaknesses. While the UK is fantastic at “Level 1” innovation, starting a company, or writing a paper, we historically struggle to scale the ecosystems that sustain them.

Growth is about numbers; maturity is about the connective tissue.

I have spent years working across the intersection of industry, government, and academia, and I’ve seen that the most vital work happens in the shadows of the big conferences. It happens in regional clusters like CyberNorth, in university mentorship programmes, and in local practitioner meetups. These are the places where talent is actually found and where long term trust is forged.

Yet, these communities often survive on little more than volunteer goodwill and precarious, short-term grants. We must be clear: a lack of financial stability and a reliance on “goodwill” is a direct detriment to the whole ecosystem. It creates an environment of transience that hampers an organisation’s ability to work to the highest professional standards, ultimately weakening the very organisational security we are trying to bolster. If we truly consider cyber security to be critical national infrastructure, and I believe it is, then we must treat the ecosystems that produce our talent as strategic assets, not as afterthoughts. Currently, they feel far too fragile.

At CyberNorth, we are working daily to bridge these gaps, actively supporting these regional ecosystems and providing the insight needed to connect disparate teams across the UK. However, the responsibility cannot rest on the shoulders of a few organisations alone. While we are proud of the progress we have made, there is far more to be done. The current framework for cyber ecosystem support requires a fundamental overhaul; we need a strategic shift in how we fund and value these communities including my own if we are to move from a sector that is merely “growing” to one that is genuinely mature.

Closing the Gap

Compared to the aggressive scaling models of the US or the tight-knit commercialisation pipelines in Israel, the UK still feels fragmented. We struggle with procurement speed, regional investment, and the “Valley of Death” between academic research and commercial viability.

We don’t lack brilliance; we lack coordination and continuity.

The future of cyber won’t be won by the nation with the most tools, but by the nation with the most resilient ecosystem. We need to stop asking “How fast are we growing?” and start asking:

  • Are we building sustainable talent pipelines that reach beyond London and the South East?
  • Are we investing in the communities that support our practitioners?
  • Is our growth supported by an ecosystem that can survive a market downturn?

The UK has the foundations to be the global leader in the AI-driven cyber era. But to get there, we must stop measuring our success solely by the balance sheet and start measuring it by the strength of the foundations we are building.

What are you doing to sustain the ecosystem in your area?

Are you supporting your cluster network to grow your region’s talent? 

It is no longer commercially viable to consider only ourselves. We must engage with our local support systems and community because without them, the focus of building, growing and nurturing the next generation leaves us too.