West Midlands Cyber

UK Cyber Policy Map

Strategies, legislation, regulators, NCSC programmes and economic policy overlap across the UK’s cyber landscape. This guide maps the major components and explains how they relate.

Contents

Mapping the UK Cyber Policy System: What It Means for the West Midlands

The UK’s cyber policy landscape has become considerably more developed over the past decade. National strategies now sit alongside legislation, regulatory frameworks, technical guidance, workforce research, sectoral analysis, growth policy and programmes concerned with emerging technologies. Taken individually, these documents address different problems. Taken together, they increasingly describe the architecture through which the UK is attempting to manage cyber security as an issue of national resilience, economic growth and organisational capability.

The difficulty is no longer finding cyber policy. It is understanding which parts of an increasingly crowded landscape actually define the system, which provide evidence about its performance, and how national interventions relate to the organisations expected to implement them.

The originating analysis, UK Cyber Policy Ecosystem Mapped: Structure and Evidence, addressed this problem by separating the documents that establish policy, responsibilities and incentives from the research and technical evidence used to understand how that system is performing. That distinction becomes increasingly valuable as cyber policy expands beyond conventional security concerns into economic growth, public-service resilience, skills, operational technology, artificial intelligence and regional development.

For the West Midlands, the purpose of such a map is not simply administrative. National policy increasingly creates consequences for regional businesses, cyber providers, universities and supply chains. Understanding how the components fit together makes it easier to identify where national capability is already strong, where implementation remains difficult, and where regional institutions can add value without duplicating functions that properly belong at national level.

Key Takeaways

  • UK cyber policy now combines national security, economic growth, regulation, organisational resilience, skills and technology policy rather than operating as a single security-policy domain.
  • It is useful to distinguish between system-defining instruments, such as strategies, legislation and regulatory frameworks, and the evidence base used to assess threats, markets, skills and organisational capability.
  • The policy architecture is increasingly sophisticated, but business evidence continues to show substantial implementation gaps, particularly in risk management, incident preparation, supply-chain assurance and technical skills.
  • Cyber growth policy recognises place as an important part of sector development, strengthening the case for regional ecosystems that connect national capability with customers, talent, research and investment.
  • The West Midlands should use the national architecture rather than reproduce it, concentrating regional effort on implementation, industrial demand, skills matching, commercial progression and access to appropriate cyber expertise.

The Cyber Policy Landscape Has Expanded Beyond Security Strategy

The development of UK cyber policy can be understood partly through the changing scope of the problem government is attempting to address. The 2011 UK Cyber Security Strategy established an early national framework at a time when cyber security was still frequently treated as a specialist concern associated with national security, online crime and protection of information systems. Subsequent strategies progressively embedded cyber within government, business and wider economic policy.

The Government Cyber Security Strategy 2022–2030 addressed the resilience of government itself, while the broader policy environment increasingly connected cyber security with digital transformation, critical infrastructure, skills and economic development. More recent interventions have extended this further.

The independent Cyber Growth Action Plan published in September 2025, for example, examined the conditions required to increase supply and demand within the UK cyber market, develop regional strengths and prepare for emerging opportunities in areas including artificial intelligence and quantum technologies. Its structure explicitly included chapters on supply and demand, places, future technologies and strategic alignment. The cyber sector was therefore being considered not simply as a source of defensive capability but as an economic asset whose development depends on relationships between innovation, customers, skills, investment and geography.

The Government Cyber Action Plan, published in January 2026, addressed another part of the system: cyber security and resilience across public services. Backed by more than £210 million, the plan established measurable objectives for government organisations and introduced a Government Cyber Unit intended to strengthen coordination of risk management and incident response.

Alongside these measures sits the Cyber Security and Resilience Bill, which seeks to strengthen and expand the regulatory framework inherited from the Network and Information Systems Regulations.

The result is a policy landscape in which cyber is simultaneously a national-security requirement, a regulatory issue, a public-service resilience problem, a business capability, a technology market and a component of economic policy. A useful map must account for those functions rather than treating every cyber-related government publication as equivalent.

Structure and Evidence Perform Different Functions

One of the most useful distinctions is between the instruments that define the cyber system and those that provide evidence about it.

Strategies, legislation, regulatory frameworks and major policy programmes establish objectives, responsibilities, incentives or requirements. They answer questions about what government expects to happen, which organisations are responsible and what mechanisms will be used to influence behaviour.

Research such as the Cyber Security Breaches Survey, Cyber Security Sectoral Analysis and Cyber Security Skills in the UK Labour Market performs a different function. These publications describe aspects of the system as it actually exists. They provide evidence about organisational behaviour, market structure, workforce conditions, security practices and areas of weakness.

The distinction matters because policy ambition should not be confused with policy outcome.

A strategy can state that organisations should become more resilient, while survey evidence can show whether businesses are conducting risk assessments or preparing for incidents. Growth policy can seek to expand the cyber sector, while sectoral analysis can show whether revenue, employment, investment and firm formation are actually changing. Skills programmes can increase the supply of people entering cyber careers, while labour-market research can reveal whether employers need those skills and at what level of experience.

The UK’s increasingly extensive evidence base therefore provides a mechanism for testing the assumptions embedded within its policy architecture.

That relationship should be iterative. Evidence identifies a problem; policy intervenes; subsequent evidence should show whether behaviour or outcomes changed. Where the expected change does not occur, the appropriate response is not necessarily another strategy. It may indicate that the intervention, incentive or delivery mechanism needs to change.

The Evidence Shows That Implementation Remains the Weak Point

The 2025/26 Cyber Security Breaches Survey demonstrates why this distinction between policy and evidence is important. Cyber security has substantial management visibility: 72% of businesses regarded it as a high priority for senior management. Formal organisational capability remains considerably less widespread.

Only 30% of businesses had undertaken a cyber security risk assessment during the previous year, 27% had a formal cyber strategy and 25% maintained a formal incident-response plan. Supplier assurance was weaker still, with 15% reviewing cyber risks associated with immediate suppliers and 6% examining their wider supply chains.

The UK’s skills evidence identifies a related problem. The 2025 cyber security labour-market study estimated that approximately 143,000 people worked in cyber security roles across the UK economy and calculated a net annual workforce shortfall of around 3,800 people. That was substantially below the 11,100 estimated in the 2023 report, reflecting both increased supply and weaker recruitment demand.

A smaller workforce shortfall did not mean that the skills problem had been solved. Approximately 49% of businesses were estimated to have a basic technical cyber security skills gap, equivalent to around 699,000 businesses, while 30% had gaps in more advanced technical skills. Among cyber security businesses themselves, 28% reported technical skills gaps among existing employees, up from 18% in the 2021 report.

This is an important policy tension. The aggregate shortage of people entering the cyber workforce has narrowed at the same time as skills gaps within organisations have persisted or, in parts of the cyber sector, increased.

The labour-market challenge is therefore becoming less amenable to a simple “more people into cyber” solution. The evidence increasingly points towards matching: the right technical and complementary skills, at the right experience level, in organisations able to use them productively.

Growth Policy and Resilience Policy Are Increasingly Interdependent

The cyber policy landscape is sometimes divided between measures intended to improve security and measures intended to grow the cyber industry. In practice, those objectives are increasingly connected.

The UK requires capable cyber suppliers because organisations need products and expertise with which to improve resilience. Cyber companies, in turn, require customers able and willing to purchase security services and technologies. Regulation and assurance can increase that demand, while skills policy affects whether suppliers and customers possess the expertise required to implement security effectively.

The Cyber Growth Action Plan made the interaction between supply and demand explicit. Its recommendations considered not only the creation of cyber technologies but the market conditions in which companies can develop, commercialise and scale them.

That focus is supported by subsequent sector evidence. The 2026 Cyber Security Sectoral Analysis identified 2,603 firms operating in the UK cyber sector, generating approximately £14.7 billion in revenue and £9.1 billion in gross value added. Revenue increased by 11% and GVA by 17%, while employment grew by around 3% to approximately 69,600 full-time-equivalent roles.

The different growth rates are significant. Economic output is increasing considerably faster than employment, suggesting a sector becoming more productive rather than one whose growth can be understood primarily through job creation.

Investment provides a further qualification. Dedicated cyber firms raised £184 million across 47 investment deals in 2025, down from £206 million across 59 deals in 2024 and continuing the decline from the investment peak recorded in 2022.

A cyber growth strategy therefore has to operate within a market where revenue and productivity are increasing but investment has become more constrained. Commercial validation, procurement and customer access become correspondingly important because venture capital cannot be assumed to provide the principal route through which promising companies progress.

For regional ecosystems, that changes the emphasis from simply creating more startups towards helping capable businesses acquire customers and develop sustainable market positions.

Place Has Become Part of the National Cyber Growth Question

The inclusion of “places” within the Cyber Growth Action Plan is important because UK cyber activity is geographically distributed even though particular concentrations remain strong.

The 2026 sectoral analysis estimates that 51% of UK cyber office locations are now outside London and the South East. The West Midlands accounts for approximately 6% of UK cyber offices but an estimated 8% of cyber employment. The difference suggests that the region’s cyber economic footprint cannot be understood solely by counting registered headquarters or office locations.

The regional employment estimate should nevertheless be treated carefully. DSIT’s methodology combines information on major employers, office locations, vacancies, labour-market evidence and other regional intelligence because company-registration data alone cannot reliably allocate employment within firms operating across multiple regions.

The important point is therefore not an exact regional league-table position. It is that national cyber capability is distributed across places whose economic structures differ substantially.

London’s cyber market is influenced heavily by finance, professional services, headquarters functions and major technology companies. Other locations have developed strengths associated with defence, intelligence, research or particular technology clusters. The West Midlands has a different economic context, with substantial advanced-manufacturing, engineering and supply-chain activity.

Regional cyber development becomes more credible when it builds upon those economic differences rather than attempting to reproduce a generic technology-cluster model in every location.

For the West Midlands, this points towards cyber capability connected with industrial resilience, operational technology, supply-chain assurance, secure adoption of emerging technology and the cyber requirements of manufacturing-intensive environments.

Regulation Is Changing the Relationship Between Cyber Policy and Businesses

The Cyber Security and Resilience Bill adds another mechanism through which national policy reaches organisations. Its purpose is to strengthen the UK’s regulatory framework for essential and digital services, including through expanded coverage, stronger regulatory powers and revised incident-reporting requirements.

The significance extends beyond the organisations directly regulated. Higher expectations placed upon important operators and technology providers can move through commercial relationships as regulated organisations seek assurance from suppliers on which they depend.

This makes supply-chain security one of the points at which national policy, organisational resilience and economic participation intersect.

The Breaches Survey suggests that formal supplier-risk management remains relatively immature. Fifteen per cent of businesses reviewed immediate supplier cyber risks, but the figure increased to 48% among large businesses. As larger organisations develop more systematic approaches, their smaller suppliers are likely to encounter increasing requirements for security evidence.

Cyber Essentials provides one established mechanism through which that evidence can be demonstrated. Certification remained limited across the overall business population in 2025/26, at 5%, but adoption increased from 3% in the previous year. Among small businesses, certification rose from 5% to 12%, while 35% of large businesses reported certification, compared with 21% previously.

The implication is that regulation should not be examined only through the number of companies directly within statutory scope. National policy can influence a much larger population through procurement, contracts and supply-chain assurance.

For an economy containing extensive SME supply chains, that indirect transmission can be particularly consequential.

Skills Policy Needs to Respond to a Changing Labour Market

The cyber policy map also demonstrates why skills cannot be treated as a separate pipeline problem.

The 2025 labour-market research estimated that approximately 6,000 cyber security graduates were entering the potential labour market annually, alongside around 2,500 people from certification and private training and approximately 600 apprenticeship starts. At the same time, core cyber job postings fell by 33% during 2024.

Demand for genuinely entry-level candidates also weakened. The proportion of core cyber job postings seeking candidates with less than one year of experience fell from 25% in 2022 to 22% in 2023 and 17% in 2024. Almost two-thirds, 63%, required between two and six years of experience.

This creates a different problem from a straightforward shortage of graduates. Increasing the number of people completing cyber courses does not necessarily solve employer demand for practitioners with several years of applied experience.

There is also a regional dimension. Training provision becomes more economically useful when it connects with the types of cyber capability required by employers in the surrounding economy. A region with substantial industrial activity may need combinations of cyber knowledge, engineering understanding, operational technology experience and risk-management capability that are not visible in generic measures of cyber vacancies.

Better feedback between employers, universities, training providers and practitioners is therefore part of the policy infrastructure required to improve matching.

Emerging Technology Is Expanding the Evidence Layer

The supporting evidence base is also changing as the technologies requiring security evolve.

Government and NCSC research now includes work on post-quantum cryptography, enterprise Internet of Things security and operational-technology vulnerabilities. AI has simultaneously become part of both cyber defence and cyber risk.

This illustrates why separating structural policy from supporting evidence is useful. Government does not necessarily require a new overarching cyber strategy every time a technology changes. It requires mechanisms through which emerging evidence can modify technical guidance, assurance expectations, investment decisions and organisational practice within an existing strategic framework.

The 2026 sectoral analysis demonstrates how quickly markets can respond. It identified 111 firms explicitly offering cyber security for AI, an increase of 68% from 66 in the previous baseline, including 32 specialist providers.

Business adoption creates the corresponding demand-side challenge. The 2025/26 Breaches Survey found that 31% of businesses were using AI, adopting it or considering doing so, but only 24% of that group reported cyber security practices or processes specifically addressing AI-related risk.

The mismatch between adoption and explicit security governance is precisely the type of issue that an effective evidence layer should reveal early enough to influence policy and practice.

The West Midlands Should Connect to the National System Rather Than Duplicate It

Mapping the national architecture clarifies where regional cyber organisations can contribute and, equally importantly, where they should not.

There is little value in creating regional substitutes for authoritative national threat intelligence, NCSC technical guidance, national certification standards or statutory regulation. Those mechanisms benefit from consistency and scale.

The stronger regional role lies where national mechanisms encounter organisational reality.

Businesses may need help interpreting which standards apply to them. Smaller suppliers may need practical routes towards assurance demanded by larger customers. Manufacturers may need access to specialist industrial cyber expertise. Cyber companies need environments in which products can be validated and customers willing to procure them. Universities and training providers need better information about changing employer requirements.

These are coordination and implementation problems rather than deficiencies in national strategy.

The West Midlands Cyber Cluster can therefore contribute most effectively by strengthening the connections between national policy and the regional economy: interpreting developments through the region’s sectoral structure, identifying capability gaps, bringing demand and supply together, and ensuring that regional evidence reaches policymakers where national assumptions do not reflect operational experience.

That is a more disciplined role than attempting to become a miniature version of the entire UK cyber ecosystem.

A Policy Map Is Useful Only If It Reveals the Gaps

The growing volume of UK cyber policy can create an impression of comprehensiveness. Strategies address national security and government resilience; legislation strengthens regulation; the NCSC provides technical guidance; growth policy addresses the commercial sector; skills research examines the workforce; and increasingly detailed evidence describes business behaviour and emerging technology.

The presence of those components does not establish that the system is complete.

The evidence continues to reveal significant gaps between management priority and formal risk management, between the supply of new cyber talent and employer demand for experienced practitioners, between basic technical controls and mature incident preparation, and between increasingly sophisticated supply-chain expectations and the ability of smaller organisations to satisfy them efficiently.

Those gaps are where policy architecture becomes an implementation problem.

For the West Midlands, mapping the national cyber system is therefore valuable not because the region needs another catalogue of strategies and programmes, but because it establishes a division of labour. National institutions should continue to provide common standards, regulation, threat intelligence and strategic direction. Regional capability should concentrate on the areas where proximity to businesses, sectors, universities and supply chains can materially improve execution.

The test is whether those connections produce measurable results: stronger organisational resilience, better matching of cyber skills to economic demand, more effective supplier assurance, greater access to specialist capability and stronger commercial progression for cyber firms.

A coherent national cyber policy system provides the architecture. Its economic and security value ultimately depends on whether organisations throughout the country can use it.