What regulated organisations, hiring managers and founders should do now.
Spinwell Global × Spinwell Startups · 6 min read · Cyber Security
Fractional cyber security is becoming a key workforce strategy for organisations facing the UK’s growing cyber skills shortage. With more than 11,000 unfilled cyber security roles and increasing regulatory pressure from the proposed Cyber Security and Resilience Bill, employers are combining permanent recruitment with embedded specialists and fixed-scope delivery models to build capability faster.
Last week, we explored what the Cyber Security and Resilience Bill means for regulated organisations, suppliers and cyber professionals. This week, we’re focusing on the practical challenge that follows.
If the Bill expects organisations to have named owners, rehearsed incident reporting, stronger supplier oversight and improved governance, where does that capability come from when traditional recruitment can take months?
Increasingly, organisations are recognising that permanent hiring is only part of the answer. The businesses staying ahead are combining permanent recruitment with fractional cyber security leadership, embedded specialists and fixed-scope delivery so capability exists from day one rather than month six.

The UK’s cyber workforce has grown to around 143,000 professionals, an increase of 5% year on year. On the surface, that appears positive. However, government data still identifies an estimated 11,200 unfilled cyber security roles, with shortages heavily concentrated in specialist disciplines including:
Almost two-thirds of vacancies require professionals with two to six years’ experience. This mid-level talent pool is where competition is fiercest.
For hiring managers, this creates a common problem. Generic job descriptions for a “Cyber Security Manager” or “Cyber Security Specialist” are competing for exactly the same limited group of candidates that every other regulated organisation, MSP and consultancy is trying to attract.
The issue isn’t necessarily a lack of talent. It’s often a lack of precision.
Permanent recruitment remains the foundation of any mature cyber security function.
However, no organisation can recruit its way around a national shortage of more than 11,000 professionals. As organisations prepare for new regulatory requirements, waiting several months for the ideal permanent hire may leave critical capability gaps exposed.
The organisations making the fastest progress are adopting a blended workforce model built around three complementary approaches.
Fractional CISOs, interim incident response leads and supplier assurance specialists can often mobilise within days, providing immediate expertise while permanent recruitment continues.
Statement of Work (SOW) engagements allow organisations to purchase defined outcomes such as:
Rather than paying for headcount, organisations purchase a measurable deliverable with agreed timescales and outcomes.
Permanent hiring continues alongside these engagements, ensuring long-term internal capability continues to grow without delaying immediate operational needs.
The common theme is simple.
An empty vacancy is not a security control.
If the board asks who owns incident escalation today, “We’re still recruiting” is no longer an adequate answer.
For many organisations, purchasing an outcome is now more effective than purchasing headcount.
A fixed-scope engagement—whether mapping essential services, designing an incident reporting process or reviewing critical suppliers—provides:
This approach isn’t designed to replace permanent security teams.
Instead, it ensures critical risks are managed while those long-term teams are being built.
Many recruitment campaigns fail because they’re trying to hire one individual to cover multiple specialist disciplines.
These are distinct areas of expertise, not variations of the same role.
Instead of advertising for “a cyber expert,” define the business outcome first.
Examples include:
Outcome-based recruitment produces stronger shortlists and also translates naturally into embedded or fixed-scope engagements when permanent recruitment isn’t immediately practical.

Fractional cyber security isn’t only for large regulated organisations.
It’s increasingly becoming a practical solution for startups preparing to work with healthcare, government, defence, financial services, transport and critical infrastructure customers.
Many early-stage businesses face extensive cyber security due diligence long before they’re formally regulated.
Investors, procurement teams and enterprise customers increasingly expect mature security governance regardless of company size.
A Fractional CISO gives startups access to senior cyber security leadership without committing to a full-time executive salary.
Typically delivered on a retained or day-rate basis, fractional leadership allows founders to strengthen governance, improve customer confidence and prepare for future regulation while preserving cash flow.
Embedded specialists often receive privileged access to an organisation’s most sensitive systems.
That makes onboarding and offboarding just as important as recruitment.
Before an engagement begins:
Most fractional cyber security engagements operate under clearly defined Statements of Work or day-rate agreements.
When structured correctly, organisations receive certainty over deliverables while contractors gain clarity around tax status, responsibilities and project scope.
Whether you’re leading a regulated organisation, managing recruitment or scaling a startup, the first step is identifying which capability gaps represent today’s operational risks.
Some vacancies can wait for permanent recruitment.
Others can’t.
For those immediate priorities, embedded cyber security specialists, Fractional CISOs and fixed-scope delivery models often provide faster, lower-risk solutions than leaving key positions vacant for months.
The organisations adapting most successfully to the UK’s changing cyber security landscape are no longer choosing between permanent recruitment and flexible expertise.
They’re combining both.
As regulatory expectations continue to increase and specialist talent remains scarce, organisations that embrace fractional cyber security, embedded delivery and permanent recruitment together will be far better positioned to strengthen resilience, reduce operational risk and respond confidently to future compliance requirements.

Spinwell Global recruits permanent, contract, interim and embedded cyber security professionals across governance, risk and compliance (GRC), security architecture, Security Operations Centres (SOC), incident response, IAM, DevSecOps, penetration testing and information security leadership.
For startups, Spinwell Startups provides flat-fee recruitment, Fractional CISO and CTO services, international talent sourcing and six months of structured post-placement support through Spinwell Engage.
Whether your organisation needs a permanent hire, an embedded specialist or a fixed-scope cyber security engagement, our teams can help you build the capability needed to meet today’s operational challenges and tomorrow’s regulatory expectations.
Fractional cyber security gives organisations access to experienced cyber security leaders, such as a Fractional CISO, on a part-time or project basis instead of employing them full time.
An embedded cyber security specialist joins an organisation temporarily to deliver a defined outcome, such as improving governance, supplier assurance or incident response capability.
A Fractional CISO is ideal when an organisation requires senior cyber security leadership but doesn’t yet need a full-time executive or wants specialist expertise while recruiting permanently.
Absolutely. Permanent recruitment remains the best long-term strategy for building internal capability. Many organisations now combine permanent hiring with embedded specialists and fractional leadership to deliver immediate capability while growing their permanent teams.




Sources
Figures were the most recently published at the time of writing and should be checked against the original DSIT release before external use.
We’ve included a selection of additional job search and recruitment blogs below. Each one provides practical advice and deeper insights to support both candidates and employers in today’s evolving job market.
The UK Cyber Security and Resilience Bill: What Organisations, Hiring Managers and Founders Should Do Now The UK is preparing…
Permanent hiring is slowing. Contract hiring is at a three-year high. Here is what that means for your workforce strategy….
The hidden job market is not a myth. It is where most specialist roles are actually filled. Most candidates spend…