Women in cybersecurity UK roles still make up less than a quarter of the workforce, even though the sector is one of the country’s fastest-growing technology employers. For women founders, career-changers, and employees, cyber security offers strong salaries, flexible working, and rising demand. This article sets out the current UK landscape, highlights women already leading the field, and gives practical steps to enter or advance in the sector.
Women in cybersecurity UK: the 2026 landscape
The UK cyber security sector generated an estimated £11.9 billion in revenue in 2024, according to the Department for Science, Innovation and Technology’s Cyber Sector Economic Estimate. The same report found that the sector employed around 71,000 people full-time, with women making up approximately 24% of the workforce. That is an improvement on the 11% figure cited in the 2017 Global Information Security Workforce Study, but still well below the 50% representation seen across the wider UK labour market. For broader context on women in business, see our Women in Business: Key UK Facts page.
Demand for talent continues to outstrip supply. DCMS research from 2024 found that 50% of UK businesses have a basic cyber security skills gap, rising to 35% for advanced technical skills. This shortage creates openings for women who can combine technical ability with communication, risk management, and leadership skills.
Pay remains competitive. The median cyber security salary in the UK is significantly above the national average, and roles such as security architect, penetration tester, and CISO command six-figure packages in larger organisations. However, the technology sector still reports a wider gender pay gap than the national average. BCS, The Chartered Institute for IT, reported in 2024 that women made up just 20% of IT specialists in the UK, a figure that underlines the pipeline challenge behind senior cyber roles.
UK schemes and organisations supporting women in cyber
Several UK programmes are designed to bring more women into cyber roles and support those already in the field.
- NCSC CyberFirst: The National Cyber Security Centre’s CyberFirst programme offers bursaries, summer courses, and competitions for young women and girls aged 11 to 19. It is one of the largest government-backed routes into the profession.
- UK Cyber Security Council: The professional body for cyber security in the UK sets career pathways, standards, and ethics. It provides guidance on qualifications and chartered status.
- Cyber Runway: Delivered by Plexal and funded by DCMS, Cyber Runway supports cyber startups and scaleups, including women founders, with mentoring, funding introductions, and commercial support.
- Women in Cybersecurity UK (WiCyS UK): The UK affiliate of the global WiCyS network runs conferences, mentoring, and job boards specifically for women in the sector.
- techUK: The technology trade association runs working groups on cyber security and diversity, publishing regular policy papers and event programmes.
Women leading UK cybersecurity today
Role models matter when an industry is rebuilding its culture. The following UK-based women show the range of routes into leadership.
Felicity Oswald, CEO, National Cyber Security Centre
Felicity Oswald became CEO of the NCSC in 2024, having previously led operations and intelligence at the organisation. Her appointment placed a woman at the head of the UK’s primary cyber security authority, responsible for protecting government, critical national infrastructure, and businesses from cyber threats.
Lindy Cameron, former CEO, NCSC
Lindy Cameron led the NCSC from 2020 to 2024 and previously held senior roles in the Foreign, Commonwealth and Development Office and the Department for International Development. She was the first woman to hold the NCSC CEO post and helped raise the profile of ransomware and supply-chain security.
Lisa Forte, Co-founder, Red Goat Cyber Security
Lisa Forte is a UK-based cyber security trainer, speaker, and co-founder of Red Goat Cyber Security, which specialises in social engineering and crisis simulation. She is a regular commentator on BBC News and at industry events, and advocates for more women in technical roles.
Jessica Barker, Co-founder, Cygenta
Dr Jessica Barker is a cyber security expert and co-founder of Cygenta, which advises organisations on cyber risk, culture, and behaviour. She is a chartered security professional and the author of Confident Cyber Security, a book aimed at demystifying the field.
Holly Williams, Founder, Pentest
Holly Williams founded Pentest, a UK penetration testing company, and has built a career in offensive security. She is a vocal advocate for women in technical cyber roles and speaks regularly at conferences including 44CON.
Jane Frankland, Author and Advocate
Jane Frankland is the author of IN Security: Why a Failure to Attract and Retain Women in Cybersecurity Is Making Us All Less Safe and founder of the IN Security Movement. She advises boards and security leaders on diversity and talent retention.
Practical pathways into UK cybersecurity
You do not need a computer science degree to move into cybersecurity. The UK Cyber Security Council recognises multiple entry routes, including apprenticeships, degrees, career transitions, and professional certifications. For more on moving into technology, see our guide to Women in Tech Jobs UK 2026.
- Consider an apprenticeship. The UK government funds cyber security apprenticeships at levels 3 to 7. These combine paid work with study and are open to career-changers as well as school leavers.
- Earn a recognised certification. Entry-level qualifications such as CompTIA Security+, Certified Information Systems Security Professional, and NCSC-certified degrees can help you stand out. The UK Cyber Security Council maintains a list of approved qualifications.
- Join a community. Organisations such as WiCyS UK, the Ladies of London Hacking Society, and CyberGirls provide networking, mentoring, and job opportunities.
- Build practical skills. Free platforms including TryHackMe, Hack The Box, and the NCSC’s Exercise in a Box let you practise incident response, penetration testing, and risk assessment.
- Look for returner programmes. If you are returning after a career break, our guide to Career Change at 40: A Practical Guide for Women sets out structured routes back into professional roles.
What employers can do
Women-led businesses and employers in the sector can accelerate change by reviewing job descriptions for gendered language, offering flexible working from day one, and publishing gender pay gap data even when not legally required. The Gender Pay Gap Reporting 2026 requirements apply to organisations with 250 or more employees, but smaller firms benefit from transparency too.
Mentoring and sponsorship programmes also make a measurable difference. Research by the Alison Rose Review of Female Entrepreneurship consistently shows that access to networks and role models is one of the biggest predictors of success for women founders and senior leaders.
Action steps
- Review the UK Cyber Security Council’s career pathways to identify the route that matches your experience.
- Explore NCSC CyberFirst, apprenticeships, or returner programmes if you are entering or re-entering the sector.
- Join a women-in-cyber community for mentoring and job leads.
- If you employ cyber professionals, audit your recruitment language, pay bands, and progression routes for gender bias.
Women in cybersecurity UK are no longer exceptions. With the sector facing a sustained skills shortage, employers, government programmes, and professional networks are actively recruiting women into technical and leadership roles. Whether you are starting out, switching careers, or scaling a cyber business, the opportunities are growing and the support infrastructure is now in place.






