Only 16 percent of the UK’s cybersecurity workforce now identifies as women — the lowest share since 2021 and a sharp contrast with the UK-wide female workforce average of 48 percent.
Women in UK cybersecurity: the numbers
The figures published in the government’s industry review show a steep drop in female representation at every level of the UK cyber sector. While 16 percent of cybersecurity workers overall identify as women, the share falls to 12 percent among senior staff with six or more years’ experience — a level that “has remained broadly consistent since records began,” the report notes. By comparison, last year’s digital-sector average was 30 percent.
Structural barriers and hiring bias cited by stakeholders
The government’s interviews with employers, recruiters and education providers attribute much of the shortfall to structural barriers inside organisations. Recruiters reported that hiring decisions were influenced by assumptions about women’s future family plans: “When I’ve spoken to a business and said to them ‘why don’t you hire a more diverse workforce?’ You’ll get the normal common ones of ‘well if we hire a female, she’ll get pregnant, she’ll be off for 12 months,’ which isn’t right,” a recruitment agent told the review.
The report explicitly links such assumptions to unlawful behaviour, noting that refusing to hire women on the basis of anticipated pregnancy constitutes illegal gender discrimination under the UK’s Equality Act 2010. The review also documents persistent stereotyping about women’s technical abilities and a lingering culture that some described as “an old boys’ club.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleEducation, stereotyping and early attrition
Interviewed employers and a cybersecurity firm reported examples from the classroom that reinforce the problem: during a careers talk about cybersecurity, “a group of girls walked out of the talk, and the careers teacher reinforced the perception that the sector did not appeal to women,” the report quoted the business as saying. The careers teacher reportedly responded, “Oh, cyber security is not really a girl’s job.”
The review highlights that the pipeline itself is weak: fewer girls choose cybersecurity courses than computer science, despite evidence that girls perform well in school STEM subjects when they take part. Those early signals — from teachers and career guidance — feed the structural barriers employers later cite for failing to promote women into senior roles.
Neurodiversity, ethnicity and disability: uneven progress
Not all diversity indicators moved in the same direction. Neurodivergent workers reached a new high of 22 percent of the cybersecurity workforce, up from 16 percent the year before and from 9 percent in 2020 — a steady rise the report attributes partly to growing employer awareness. “Cybersecurity is the most neurodiverse sector I have ever seen, and I think personally it’s celebrated, especially internally within the sector,” one respondent from a small cybersecurity business told the report’s authors.
Ethnic-minority representation held at 19 percent — the same level as in 2025 and up from 13 percent in 2024 — roughly in line with the wider digital-sector average of 20 percent and above the UK pan-industry average of 16 percent. But minority representation thins at senior levels: only 9 percent of senior cybersecurity roles are held by people from ethnic minorities, a low figure that has “persisted for the third year running” and is well down from a 15 percent high in 2021.
Disabled people are notably underrepresented, making up 9 percent of the cybersecurity workforce and only 5 percent of senior staff — both below the digital-sector averages (15 percent) and the UK pan-industry average (18 percent).
What this means for employers, educators, and policymakers
- Employers: The report and industry voices place the onus on firms to dismantle stereotypes and change hiring and promotion practices. Jill Broom, head of cyber resilience at techUK, warned that “a lack of gender diversity not only limits opportunities for women … but also risks narrowing the range of perspectives and ideas that are essential to tackling increasingly complex cyber threats.”
- Educators and careers advisers: Classroom interactions that steer girls away from cybersecurity were explicitly named as part of the problem. The review includes instances where career guidance reinforced the message that cyber “is not really a girl’s job,” suggesting a need for more inclusive outreach.
- Policymakers and regulators: The report documents illegal hiring biases under the Equality Act 2010 and highlights persistent senior-level shortfalls for women, ethnic minorities and disabled people — gaps where government interventions, incentives or guidance could be targeted.
The review paints a sector with mixed progress: strong gains in neurodiversity and modest improvements in ethnic representation overall, but stubborn, structural exclusion of women and disadvantaged groups from leadership. The report’s own interviews place responsibility squarely on employers and educators — a diagnosis that leaves a pointed question as the sector expands: will organisations act to break the “old boys’ club” and the classroom signals that feed it, or will the senior ranks remain a self-perpetuating barrier to change?




