The median UK contract day rate for a cyber security consultant is £599, up from £492 a year ago. That is a rise of 21.75%, the largest movement of any consulting specialism we benchmark, in a year when management consulting fell 12%.

The usual explanation is a skills shortage. That is only half right, and the weaker half.

Cyber security rates, August 2026

£599 median UK cyber security consultant day rate IT Jobs Watch, Aug 2026
+21.75% year on year, from £492 IT Jobs Watch
43 quoted day rates in the sample IT Jobs Watch
$120–$194 US federal ceiling rates for cyber roles, per hour (middle half) GSA CALC+, Sep 2026
Methodology Data as of 21 August 2026

Median advertised daily rates on the UK contract and interim market for cyber security consulting roles.

Source
IT Jobs Watch, which derives medians from daily rates quoted in advertised UK contract vacancies.
Sample
43 quoted day rates in the six months to 21 August 2026. This is a small sample and the figure should be read as directional.
Window
Six months ending 21 August 2026, compared against the six months ending 21 August 2025.
What this measures
What an individual contractor is paid. US figures quoted for comparison are federal ceiling rates from GSA CALC+, pulled 28 September 2026: the most a contractor may charge a US federal agency for that labour category, not contractor pay.
Review cycle
Reviewed quarterly against the same source.
Cite this page

ConsultingDemand, “Cyber Security Consulting Rates in 2026”, data as of 21 August 2026. https://consultingdemand.com/blog/cybersecurity-consulting-rates/

Start with the caveat, because it matters

Forty-three quoted rates is a thin sample. It is the second-thinnest in our benchmark, and it produced the largest movement in the benchmark. Those two facts are related.

A 22% jump on 43 observations can be produced by a handful of well-paid incident response or regulatory remediation contracts landing inside the window. It does not take a structural shift. Anyone citing this number should cite the sample alongside it, and we would rather say so than let a headline travel further than the evidence supports.

What makes the direction credible is corroboration. Cyber did not rise alone. Data science rose 12.94% and change management rose 10%, while generalist advisory fell. The specific magnitude is soft. The pattern is not.

The full picture

SpecialismMedian day rateYear agoChangeSample
Cyber Security Consultant£599£492+21.75%43
Data Scientist£600£531+12.94%217
Change Manager£550£500+10.00%155
Machine Learning (skill)£575£556+3.42%1,018
Project Manager£540£525+2.86%1,287
IT Consultant£525£516+1.69%45
Artificial Intelligence (skill)£559£550+1.64%3,018
Business Analyst£500£500not published1,376
SAP Consultant£550£560−1.79%240
Cloud Architect£600£633−5.14%229
Management Consultant£550£625−12.00%67

Artificial Intelligence and Machine Learning are skill markers, not job titles: IT Jobs Watch counts vacancies citing the skill across every contract role, so they overlap the job titles above and cannot be added to them.

Median UK contract day rates, security and adjacent roles

Data Scientist
£600/day
Cloud Architect
£600/day
Cyber Security Consultant
£599/day
Machine Learning
£575/day
Artificial Intelligence
£559/day
Management Consultant
£550/day
IT Consultant
£525/day

Six months to 21 August 2026. Source: IT Jobs Watch.

It is priced as liability, not as labour

Here is the part the skills-shortage story misses. Cyber security work is bought by people managing an exposure, and exposure has a number attached to it.

When a board approves a penetration test or a regulatory remediation programme, the comparison is not “what does a consultant cost.” It is “what does a breach cost.” Fines, notification obligations, customer attrition, the cost of a forensic investigation, the cost of being the subject of a news cycle. Against that denominator, a £599 day rate is a rounding error, and procurement behaves accordingly.

Compare that with generalist strategy advice. Good advice creates value, but bad advice does not create a fine. There is no regulator issuing penalties for a mediocre operating model review. The buyer is spending from a discretionary budget rather than defending against a quantified downside, and discretionary budgets get benchmarked harder.

Where the specific premiums sit

Not all security work prices the same. The pattern in the advertised market is that the closer the work sits to a named obligation, the better it pays.

Regulatory and assurance work commands the top of the range. If the deliverable is evidence that satisfies an auditor or a regulator, the buyer has a deadline they cannot move and a consequence they cannot absorb. That is the strongest negotiating position a supplier can have, and it shows.

Incident response prices on urgency. Nobody negotiates hard at two in the morning. Retainer arrangements exist precisely because buyers know this and would rather fix the rate in advance.

Architecture and engineering sits closer to ordinary technical contracting. Valuable, less leveraged, and priced nearer the cloud and IT consulting benchmark.

Awareness and training sits lowest, and is the part most exposed to being replaced by a platform subscription.

Warning
What the rise does not tell you

A rising day rate is a signal about market pricing, not about supplier quality. The certification boom has produced a large number of people who can pass a security interview and a much smaller number who have run a real incident. Rate is a poor proxy for either. Ask for specific engagements, named outcomes, and references you can actually call.

Buying at these rates

If you are on the buying side, the leverage is in scope, not in the rate.

Separate assessment from remediation. Bundling them gives the supplier an incentive to find a lot of work. Two contracts, ideally two suppliers, keeps the diagnosis honest.

Fix the retainer before you need it. An incident response retainer bought calmly costs a fraction of the same capability bought during an incident. This is one of the few places in consulting where buying in advance is straightforwardly cheaper.

Ask what happens after the report. A findings document is not a security improvement. The engagements that deliver value include the remediation plan, the retest, and someone accountable for closing the gap.

Our broader guide to hiring a consultant covers the general vetting framework. For US comparison, consulting fees by industry sets out federal ceiling rates, the most a contractor may charge a US federal agency: $120 to $194 an hour for cyber roles (the middle half), median $152, across 10,723 rates in GSA CALC+ in September 2026. Clearance moves that less than the market suggests. Of 949 cleared cyber rates, six are $400 an hour or more, and those requiring 15 years’ experience top out at $318.73. For incident response, one public price: in April 2024 Tulsa County, Oklahoma, approved a $19,800 initial engagement, 30 hours at $660 an hour (county procurement memo).

What to watch

If the sample grows and the rate holds near £600, this is a genuine structural repricing and it will pull permanent salaries up behind it. If the sample stays thin and the rate reverts toward £520, the 22% was noise in a small market.

The more interesting question is whether the divergence continues. The gap between cyber and management consulting was £133 a day a year ago. It is now £49 in the other direction, a swing of £182. If regulated AI assurance work matures into its own specialism, expect it to price like security rather than like strategy, for exactly the same reason.

Key Takeaways
  • UK cyber security consulting day rates rose 21.75% to a £599 median, the fastest movement of any specialism tracked
  • The figure rests on 43 quoted rates, so treat the direction as reliable and the magnitude as soft
  • The premium comes from liability rather than scarcity: buyers compare the fee against the cost of a breach, not against other consultants
  • Regulatory, assurance and incident response work prices highest; architecture and awareness training price lowest
  • Buyer leverage sits in scope, not rate — separate assessment from remediation, and fix incident retainers before you need them
  • The cyber-to-management-consulting gap swung by £182 a day in twelve months, from £133 behind to £49 ahead
Nadia Lindqvist Technology Editor, ConsultingDemand

Covers IT, AI, cyber, ERP and data consulting rates, and the statement-of-work clauses that decide whether the rate is the least of your costs.

Last updated: 28 September 2026