Every unfilled cyber security role in CNI carries compounding operational, compliance, and financial risk. The salary you are saving is a fraction of the exposure you are carrying.
← Back to Insights
Every unfilled cyber security role is an open door. In critical national infrastructure, that door leads somewhere you cannot afford to leave unguarded.
The UK cyber threat landscape is not slowing down. 43% of UK businesses reported a cyber security breach or attack in the past year. That is 612,000 companies. Cyber attacks on UK utility companies surged 586% between 2022 and 2023. The total cost of cyber crime to the UK economy now exceeds £27 billion per year.
Against that backdrop, 4.8 million cyber security jobs sit unfilled globally. The question is not whether your organisation has a vacancy. It is what that vacancy is costing you right now.
Most organisations calculate the cost of an unfilled role in salary savings. That is the wrong lens.
The average cost of a significant cyber attack for a UK business is nearly £195,000. Globally, the average cost of a data breach reached $4.88 million in 2026. These figures account for direct remediation, legal fees, regulatory penalties, and reputational damage. They do not account for the slow erosion that happens when a critical role sits empty for months.
Every week without a dedicated threat analyst, incident responder, or compliance lead creates compounding exposure. Alerts go untriaged. Vulnerability assessments fall behind schedule. Regulatory submissions slip. Board reporting loses depth. Insurance renewals become harder to justify.
The salary you are saving is a fraction of the risk you are carrying.
95% of organisations say regulation now drives hiring decisions. In CNI sectors, this pressure is acute. NIS2 obligations, the Telecommunications Security Act, and evolving Ofgem and CAA frameworks demand named, qualified individuals in defined roles. An empty seat is not just a resourcing gap. It is a compliance gap.
Regulators are not interested in your recruitment timeline. They want evidence of capability, governance, and accountability. When audit season arrives, a vacancy on your org chart is a finding waiting to happen.
Unfilled cyber roles do not exist in isolation. They create pressure across the entire security function.
Remaining team members absorb additional workload. Incident response times stretch. Projects stall. Burnout accelerates. Retention risk increases. One vacancy can quickly become two.
Staffing and compensation already consume 37% of the average security budget, the largest single expense category. When attrition compounds, that budget comes under even greater strain. The cost of backfilling two roles simultaneously, often at inflated market rates, dwarfs the investment in filling the first role quickly.
Cyber security is no longer a technology issue. It is a governance issue. Directors of CNI organisations carry personal accountability for operational resilience. An unfilled CISO, Head of Security, or compliance lead role is not just an HR metric. It is a board-level risk exposure.
Insurers are paying attention too. Cyber liability policies increasingly require evidence of adequate staffing, qualified leadership, and documented response capability. A prolonged vacancy in a critical security role can affect coverage terms, premium calculations, and claims outcomes.
The financial case for faster hiring is not theoretical. It is measurable in incident costs avoided, compliance penalties mitigated, insurance terms maintained, and operational continuity preserved.
The traditional recruitment process is too slow for this market. Lengthy shortlists, unfocused briefs, and drawn-out interview cycles leave roles open for months. In cyber security recruitment for CNI, that delay carries real operational consequence.
At Foundations Search, we built our model specifically for this problem. We send 98% fewer CVs than generalist recruiters. 80% of the candidates we present reach interview. Our average time to hire is four weeks. We achieve this by combining deep sector knowledge with a focused, search-led methodology. We know the market because we work inside it every day.
Filling a critical cyber role is not about volume. It is about identifying the right individual, fast, and managing the process with the urgency the threat landscape demands.
The cost of an unfilled cyber role in CNI is not the salary you are not paying. It is the incident you are not prepared for. The compliance gap you have not closed. The insurance claim that will not be honoured. The board liability that has not been addressed.
Every month a critical role sits empty, your organisation carries unmitigated risk. The business case for faster, more focused hiring is clear. The only question is how long you are prepared to wait.
Trusted by security leaders at



"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."
Manager of EMEA & APAC Network Engineering, Equinix