Key takeaways
Industry overview and recent performance
The cyber security industry comprises businesses supplying products and services to help organisations and individuals reduce the risk and impact of cyber attacks, protecting networks, information systems, connected devices, software and data from unauthorised access, disruption, theft or damage. Its activities span software, professional services, telecommunications, managed services, hardware, and artificial intelligence.
Data assembled by the Department for Science, Innovation & Technology (DSIT) show that the industry has grown significantly in recent years. An estimated 2,603 firms were active in the sector as of December 2025, compared with 1,483 in 2020. Over the period 2020–2025, annual revenue rose from £8.9bn to £14.7bn, with employment up from 46,683 to 69,589 full-time-equivalent jobs. Meanwhile, sector GVA more than doubled from £4.0bn in 2020 to £9.1bn in 2025, growing considerably faster than employment and indicating higher value added per worker. Exports reached £8.6bn in 2024, more than twice their 2020 level.
According to DSIT's Cyber Security Sectoral Analysis 2026, most of the firms operating in the sector are micro (58%) or small (19%) in size. However, 22% are medium or large, compared with around 3% of the wider UK business population. Thus, a "long tail" of specialist cyber security providers co-exists with a smaller but highly significant group of major platforms, consultancies and managed service businesses. In 2025, the 240 large firms operating in the sector together generated £10.4bn in revenue (70% of the industry total) and employed 43,310 FTE workers.
In its Digital and Technologies Sector Plan (June 2025), the government identifies cyber security as one of six priority “frontier technologies”. The plan outlines a package of support for the industry, focused on commercialising research, scaling start-ups, developing skills and advancing secure-by-design technologies. For example, the Cyber Academic Startup Accelerator Programme (CyberASAP) aims to help start-ups to spin out of academia.
That said, many early-stage cyber companies continue to face distinctive scale-up barriers — as is discussed in greater detail below. Notably, private funding has fallen sharply from its 2021 peak — dedicated UK cyber security firms raised £184m across 47 deals in 2025, down from £206m in 2024 and far below the £1bn raised in 2021.
However, the underlying demand outlook appears favourable. High-profile cyber incidents, an evolving landscape of threats, and tighter regulation look likely to reinforce demand for stronger resilience, incident response and supply-chain assurance. In January 2026 KPMG reported that 57% of the UK organisations it surveyed planned to increase cyber security budgets by more than 10% over the next 12 months, compared with 41% globally.
Market segmentation
DSIT's 2026 sectoral analysis points to several key ways in which the UK cyber security market may be segmented.
Service-led vs. product-led
Perhaps the clearest differentiator is business model. As of 2025 the sector contained 1,216 service-led firms, 743 product-led firms and 644 firms primarily classified as managed security service providers. Overall, around 72% of businesses were mainly service-focused (including managed services), compared with just under 29% that were primarily engaged in product development.
Revenue is similarly weighted towards services, with service-led firms generating approximately £8.4bn in 2025, compared with £6.4bn for product-led businesses.
Service providers operate across areas including consultancy, risk assessment, penetration testing, incident response, managed detection and response, and security operations centres. Product-led firms supply technologies such as endpoint protection software, network detection and response platforms, anti-phishing systems, identity and access management systems, and so on.
Dedicated vs. diversified
A further distinction can be drawn between dedicated cyber security businesses and diversified companies that offer cyber services as part of a broader portfolio. Dedicated, or ‘pure-play’, firms account for 69% of the sector by number, while diversified businesses represent 31%.
Micro and small businesses are more likely to be dedicated specialist cyber providers, whereas most large firms are diversified. This reflects the presence of major telecommunications groups, consultancies, defence contractors and technology companies with substantial cyber security divisions.
Solution category
The market can also be divided by solution category. Information risk assessment and management and cyber professional services are the most widely represented areas, each offered by 80% of firms. These are followed by network security (52%), threat intelligence, monitoring, detection and analysis (45%), training and awareness (43%), and incident response and management (38%).
More specialised operational areas have fewer suppliers but remain strategically important. These include identity and access management (29%), endpoint security (25%), internet of things security (10%), and security for supervisory control and data acquisition and industrial control systems (7%).
Trends, challenges, and opportunities
1. Persistent cyber risk is supporting demand
Cyber security has lately come to the fore as a key business resilience issue, as organisations have sought to manage a persistent, complex and growing set of cyber risks.
Recently, there have been a number of particularly high-profile cyber attacks across retail, public services and other sectors. The National Cyber Security Centre (NCSC) recorded 204 nationally significant incidents in the year to September 2025, including 18 classed as highly significant, compared with 89 nationally significant incidents in the previous year.
Meanwhile, many other organisations have been affected by cyber incidents of various kinds. DSIT’s 2025/26 Cyber Security Breaches Survey found that 43% of businesses and 28% of charities had experienced an attack during the preceding 12 months.
Certain well-known incidents have clearly demonstrated the operational and financial consequences of inadequate preparation. As noted in recent analysis from ICAEW, the ransomware attack suffered by M&S in April 2025 (which resulted in £131.3m of incident-related costs) underlined the importance of robust backups and contingency planning, whilst the October 2023 attack on the British Library highlighted the need to invest in up-to-date systems and strong forensic preparedness. Meanwhile, the experiences of TfL and the Co-op point, respectively, to the importance of capable incident-response providers and the value of network segmentation, effective backups and rapid containment.
In this context, demand for cyber security products and services is growing. In January 2026, KPMG reported that 83% of the UK organisations responding to their survey expected to increase cyber-security investment during the coming year, with 57% planning an increase of more than 10%.
2. Regulation is increasingly making cyber security a compliance requirement
Regulation is becoming an increasingly important driver of demand for UK cyber security products and services.
Here, the central development is the Cyber Security and Resilience (Network and Information Systems) Bill, which was before the House of Lords as of July 2026. The Bill would extend the existing NIS regime to cover areas including data centres, large load controllers, medium and large managed service providers, and designated critical suppliers. Proposed measures include stronger risk-management duties, stronger enforcement mechanisms, customer notification requirements for some providers, and a two-stage incident-reporting process, requiring initial notification within 24 hours and a fuller report within 72 hours.
Trowers & Hamlins describe the legislation as "the most significant overhaul of the UK's cybersecurity regulatory framework since [...] 2018". It is likely to stimulate demand for compliance advice, incident-response retainers, security monitoring, supply-chain assurance, forensic readiness and resilience planning — though a notable complicating factor is that some cyber security and managed IT providers may themselves become directly regulated.
Further proposals covering ransomware payments and reporting could reinforce this trend if implemented. Meanwhile, the Data (Use and Access) Act 2025 may generate security-related work around digital identity, privacy engineering and secure data sharing.
3. Significant growth opportunities are emerging in key areas
Certain sub-fields and technological frontiers currently present particularly notable opportunities for growth. AI, quantum, cyber-physical systems and secure-by-design technologies are perhaps the most significant in this regard.
The DSIT's Cyber Security Sectoral Analysis 2026 identified 111 UK-registered firms offering security for AI systems — 68% more than in its previous baseline — including 32 specialist providers. Assurance services covering models, data, prompts, agents and AI-supported workflows, for example, appear to be increasingly sought-after. In addition, growing risks from AI-enabled phishing, deepfakes, automated exploitation and prompt injection are supporting demand for governance, monitoring and incident-response services. Crucially, cyber security firms may themselves utilise AI to enhance their products or services.
Post-quantum cryptography (PQC) is likewise developing into a substantial market, albeit at a somewhat slower pace. The NCSC has set an indicative UK timeline for migration to PQC, and expects organisations to complete cryptographic discovery and initial planning by 2028, undertake priority migrations by 2031 and finish the transition by 2035. This should generate demand for specialist assessment, engineering, implementation and assurance expertise.
Meanwhile, the government’s Cyber Growth Action Plan identifies significant opportunities in securing cyber-physical systems, with cyber resilience for operational technology being a growing challenge for many organisations. Alongside this, increasingly prominent secure-by-design principles — as exemplified in the work of the £70m Digital Security by Design (DSbD) programme — should favour suppliers able to embed protection within products and systems from their earliest development stages.
4. Early-stage cyber companies face scale-up barriers
Despite the sector enjoying strong demand overall, early-stage cyber companies often face challenges as they seek to scale.
The UK Cyber Growth Action Plan identifies difficulties in testing products in realistic environments, securing early customers and accessing investors with sufficient sector knowledge. In addition, technically strong founders may underestimate CISOs’ budget, integration and operational constraints, whilst risk-averse buyers often favour established suppliers. Fragmented public funding mechanisms, complex government procurement and shortages of growth-stage capital and go-to-market expertise add to these challenges.
Investment conditions also remain relatively subdued. DSIT’s Cyber Security Sectoral Analysis 2026 reports that dedicated UK cyber firms raised £184m across 47 deals in 2025, compared with £206m across 59 deals in 2024 and £1bn in 2021. However, smaller businesses attracted most investment by value, suggesting growing appetite for emerging fields such as AI security and post-quantum cryptography.
Several initiatives aim to strengthen commercialisation. CyberASAP, for example, helps UK academics turn cyber security research into commercially viable products and services, whilst Cyber Runway supports businesses from start-up to scale-up. Regional initiatives such as Cardiff's Cyber Innovation Hub also provide market validation, mentoring and realistic test environments.
5. Low uptake among SMEs represents both a challenge and a major opportunity
The Association of British Insurers (ABI) has identified a substantial cyber protection gap among SMEs, partly reflecting limited awareness of cyber risks. Many SMEs still lack basic cyber resilience mechanisms and tested incident-response plans.
The Cyber Security Breaches Survey 2025/26 found that 42% of micro businesses and 46% of small businesses had identified a breach or attack during the previous year. Despite this exposure, small-business preparedness declined. The proportion undertaking cyber risk assessments fell from 48% to 41%, while those with a formal cyber security policy dropped from 59% to 52%. Smaller firms were also much less likely than larger businesses to assess supplier-related cyber risks.
This situation presents opportunities for businesses offering affordable, easily-adoptable products and managed services, including Cyber Essentials support, staff training, compliance automation and managed detection and response. SME-focused providers such as CyberSmart are already targeting this under-served market.
Tax landscape
The tax treatment of the UK cyber security industry is complex, and a full explication of its nuances is beyond the scope of this profile.
That said, elements of the UK tax system which may be of particular interest include:
- Research & Development (R&D) tax relief — cyber security firms undertaking work aimed at an advance in science or technology may need to consider R&D relief.
- Patent Box — product-led cyber security companies may be able to benefit from the Patent Box, which allows profits attributable to qualifying patented inventions to be taxed at a reduced corporation tax rate of 10%.
- Capital allowances and full expensing — firms investing in qualifying plant and machinery (which might include servers, lab equipment, or test rigs) should consider capital allowances.
- SEIS and EIS — early-stage and growth companies may secure investment through the use of venture capital tax relief schemes.
- Employee share schemes — tax-advantaged share option schemes, particularly Enterprise Management Incentives (EMI), may help early-stage and scale-up cyber security companies recruit and retain technical, commercial and scientific talent where cash remuneration is constrained.
Notable players
The size and diversity of the UK cyber security industry means that any list of notable players will not be fully representative or comprehensive.
That said, some examples of noteworthy players are set out below.
- BAE Systems Digital Intelligence — large UK defence and security player whose cyber business is aligned with government, national security, and critical-infrastructure demand.
- Bridewell — cyber security services company focused on protecting critical national infrastructure and essential-service organisations through consultancy, managed security, penetration testing, incident response and cyber resilience support.
- BT Business — major telecom-integrated provider of cyber security consulting, managed security services, threat management, secure connectivity, endpoint/device protection and small-business cyber products.
- CyberSmart — cyber security platform provider focused on helping SMEs achieve Cyber Essentials certification and improve everyday cyber resilience through vulnerability scanning, device monitoring, policy management, staff training and cyber insurance support.
- Darktrace — AI cyber security platform vendor focused on detecting, investigating and autonomously responding to threats across network, email, cloud, endpoint, identity and operational-technology environments.
- Immersive — cyber resilience platform provider using realistic labs, drills, cyber ranges and crisis simulations to test and improve organisations’ readiness across people, teams, leadership and AI-era threats.
- Maze – provider of an AI-led cyber security platform that investigates vulnerabilities across code and cloud environments, prioritises those that are genuinely exploitable, and supports remediation.
- NCC Group — UK-headquartered global cyber security and software escrow business providing technical assurance, consulting, managed services, threat intelligence and incident response to help organisations assess, develop and manage cyber threats.
- Netcraft — specialist provider of digital risk protection, phishing and scam detection, domain takedown, brand protection, threat intelligence and deep/dark web monitoring services for major brands, technology firms and public-sector organisations.
- PQShield — post-quantum cryptography specialist developing quantum-safe security for chips, applications and cloud environments, helping enterprises, governments and technology suppliers prepare systems for future quantum-era threats.
- Sophos — cyber security vendor providing AI-powered security products and managed services across endpoint, firewall, email, cloud, mobile, XDR and MDR.
ICAEW’s Library & Information Service can provide information on UK and Irish participants in the cyber security industry via its wide range of company information services. For more information, please contact our enquiry team on +44 (0)20 7920 8620 or at library@icaew.com to discuss your requirements.
Professional organisations and trade bodies
UK
International
UK Industrial Strategy
Drawing on members expertise and our research into business confidence, ICAEW offers policymakers advice on how to tackle the barriers to growth.
Can't find what you're looking for?
The ICAEW Library can give you the right information from trustworthy, professional sources that aren't freely available online. Contact us for expert help with your enquiries and research.
Every effort has been made to ensure that the information given in this industry profile is correct. However, the content of websites changes frequently and users should satisfy themselves that the information they contain is suitable for the purposes for which they wish to use it. We would be grateful to receive notification of any broken links at library@icaew.com.
ICAEW accepts no responsibility for the content on any site to which a hypertext link from this site exists. The links are provided ‘as is’ with no warranty, express or implied, for the information provided within them. Please see the full copyright and disclaimer notice.
-
Update History
- 28 Jul 2026 (04: 26 PM BST)
- First written and published by ICAEW's Library & Information Service.
Further support
Explore the full range of industry and company information available from the Library.
Browse all industry profilesCompany research services