The Register Home Page

back to article Cybersec is a thankless job: expanding workload and shrinking pay packet

Cybersecurity professionals were the most overlooked workers in IT when it came to pay rises in 2025, according to new figures from recruiter Harvey Nash. The trend was especially stark in the UK, where 77 percent of all security staff saw no salary increase, although the pattern was observed globally too with 71 percent of …

  1. Like a badger Silver badge

    I beg to differ

    Cybersecurity has become a victim of its own effectiveness

    So, apart from the months of disruption and lost sales at Co-op, M&S, JLR, it's been a superb year for ITSec?

    1. Ken G Silver badge

      Re: I beg to differ

      I'm sure the three companies you name will be offering big salaries for the right profiles.

      1. druck Silver badge

        Re: I beg to differ

        Only the titles that begin with a C, the actual security workers will be the cheapest bodies they can find that are still warm.

        1. Anonymous Coward
          Anonymous Coward

          Re: I beg to differ

          A bit of AI, and a steam cleaner, and that limitation is history.

    2. doublelayer Silver badge

      Re: I beg to differ

      Consider that part of the problem might be local effectiveness. If one company has not experienced any incidents, they may not be too worried about someone else that has unless someone comes along to scare them. Corporate leadership don't tend to spend much time reading about security incidents that happened to someone else, especially when compared to IT people who read IT news, so they no little about those incidents, and if they do, they probably assume there's a reason why those companies were attacked and their one wasn't, a reason other than scale and luck. Security teams usually don't think they need to bring scare stories to management because they have the same context as you do and assume management is aware of that. In my experience, it's also seen as unethical to exaggerate threats or speculate about what an attack on this company might look like, the approaches most likely to increase support for adding resources to security.

  2. Dinanziame Silver badge
    Devil

    Security is not profitable

    It only costs money, brings no profit whatsoever

    1. ecofeco Silver badge

      Re: Security is not profitable

      That's exactly how they think.

      There's an old saying, "It's good to save money in business, but go too far and you CAN save yourself right out of business."

    2. Taliesinawen Bronze badge

      Re: Security is not profitable

      It is if you're a lawyer .. have I've been in the wrong profession all these years :o

      Rigbyfinancial.co.uk: “As we head into 2026, cyber threats look set to continue dominating the risk landscape, with the need for robust cover switching from ‘nice-to-have’ to ‘must-have’. In response, insurers are tightening terms, raising premiums, and demanding proof of strong cybersecurity practices before offering cover. Policies are also evolving to tackle new threats like deepfakes, AI-enhanced phishing and supply chain vulnerabilities.”

  3. MattieD

    Successful teams get overlooked, same as it ever was

    If there's one thing that anyone who's worked in the IT field for a while will know to be true is that the team that's constantly firefighting - most often due to their lack of ability - are the ones that are praised. Because they're always running around, doing this, doing that, sending emails about downtime and patching, and the other busywork, they're the ones the business sees as 'working hard'.

    Whereas the team that's got everything running properly, has scheduled maintenance windows and staff who actually know and understand what they're doing at the micro and macro levels, they're getting ignored because they're essentially invisible.

    Honestly, it's a disgrace. It's a failure of management to see and recognise where the work and effort is going and what it is achieving - but then again, when have management ever had vision or brought about success?

    IT nowadays is akin to a utility - water, gas, electricity - everyone just expects it to work. Would you praise your electricity supplier if they had to turn the power off every second Tuesday or your water supplier if the water pressure varied from day to day between a trickle and gush?

    1. Ken G Silver badge

      Re: Successful teams get overlooked, same as it ever was

      Yes, worse, that 2nd team will have it's budget cut and leavers from it won't be replaced until it gets down to a size too small to properly support the system and becomes like the 1st team.

    2. Bebu sa Ware Silver badge
      IT Angle

      Re: Successful teams get overlooked, same as it ever was

      water, gas, electricity - everyone just expects it to work.

      In a few place those historic expectations are not always being met. Not infrequently from the same root causes of the dismal reliabilty and resilience historically exhibited by IT.

      I have certainly seen successful teams retrenched with the roles/work out·sourced on the unspoken assumption that those teams couldn't have been doing much if they weren't being noticed. The out·sourced replacement are invariably very soon "noticed" and very frequently thereafter.

    3. BBRush

      Re: Successful teams get overlooked, same as it ever was

      There is no doubt that communicating metrics to management in this field helps lift the profile of these teams, but only if done properly and only if the higher levels are actually receptive and supportive of the work. If you have a good manager that communicates well and is trusted by the C-suite, that also understand risk, threats, etc, then it's all good (mostly). If you have a poor management chain (like a CISO that claims every nmap scan or ping-sweep as an attack, then you're on a hiding to nothing.

      I spent a long time as a meat-shield for a large software/hardware supplier in the US. I was good enough at it that no researcher broke the responsibile disclosure timescales. One of the products was, and still is, a dumpster fire of security nastiness. In part due to me and tthe team, the leadership just deprioritised fixing security. It burned me out. It's still a dumpster fire. I still won't have it in my new company.

  4. Anonymous Coward
    Anonymous Coward

    Aren't cyber incidents rising massively though?

    Yes, we're doing well to protect, but incidents are still on the rise, and recent NCSC, Microsoft, Government security alerts, as well as our own experiences are showing a rise...

    Maybe we're at 'peak' Cyber protection - and the attackers are winning whatever we do from now on... ?

    1. NickHolland

      Re: Aren't cyber incidents rising massively though?

      are they rising? yes.

      It isn't due to lack of cybersec people. It is due to lack of /good/ cybersec people, and deliberate management decisions. But mostly, management.

      Security problems come from the C level. Cybersecurity people try to change that, but they will fail, as long as high-level managers are making stupid decisions with security being literally the last priority (look at actions, not words -- last. absolute...last).

      You know the saying, "security isn't a product"? Well, security also isn't a team. You can't buy a product and become secure, you can't hire a team and become secure.

      We are not at "peak cyber protection" -- we are in a valley, and we keep digging.

  5. QET

    I'm not at all surprised that management neglects roles that essentially are about prevention.

    As the late Trevor Kletz often said regarding the chemical industry: "if you think safety is expensive, try having an accident", which IMO should be chiseled into the forehead of everyone in a management position.

    1. NickHolland

      the problem in IT is that security problems AREN'T expensive enough.

      Managers keep their jobs -- even the ones that directly CAUSED the problem in the first place.

      Customers complain, but keep buying from the same vendors.

      The media portrays the attackers as the bad guys, and the company as the victim.

      Business insurance pays damages.

      Zero accountability.

      There are some companies that violate every security standard and just shouldn't be allowed to continue to exist. But instead, those companies are generally the lowest bidder. Doing the job right is too expensive.

      Unfortunately, I think there needs to be a "corporate death penalty" -- where companies are just instantly shutdown. Stockholders lose 100% of their value. C-level managers are required to repay the previous year's bonuses and have a lifetime ban from taking a similar role at any future employer. Customers and vendors are screwed without compensation, as they should have been doing the "due diligence" thing, they weren't, share the pain. It is something that should be used rarely, but its possibility should be on every manager's mind during at every decision they make.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon