The median UK contract day rate for a cyber security consultant is £599, up from £492 a year ago. That is a rise of 21.75%, the largest movement of any consulting specialism we benchmark, in a year when management consulting fell 12%.
The usual explanation is a skills shortage. That is only half right, and the weaker half.
Cyber security rates, August 2026
Median advertised daily rates on the UK contract and interim market for cyber security consulting roles.
- Source
- IT Jobs Watch, which derives medians from daily rates quoted in advertised UK contract vacancies.
- Sample
- 43 quoted day rates in the six months to 21 August 2026. This is a small sample and the figure should be read as directional.
- Window
- Six months ending 21 August 2026, compared against the six months ending 21 August 2025.
- What this measures
- What an individual contractor is paid. US figures quoted for comparison are federal ceiling rates from GSA CALC+, pulled 28 September 2026: the most a contractor may charge a US federal agency for that labour category, not contractor pay.
- Review cycle
- Reviewed quarterly against the same source.
ConsultingDemand, “Cyber Security Consulting Rates in 2026”, data as of 21 August 2026. https://consultingdemand.com/blog/cybersecurity-consulting-rates/
Start with the caveat, because it matters
Forty-three quoted rates is a thin sample. It is the second-thinnest in our benchmark, and it produced the largest movement in the benchmark. Those two facts are related.
A 22% jump on 43 observations can be produced by a handful of well-paid incident response or regulatory remediation contracts landing inside the window. It does not take a structural shift. Anyone citing this number should cite the sample alongside it, and we would rather say so than let a headline travel further than the evidence supports.
What makes the direction credible is corroboration. Cyber did not rise alone. Data science rose 12.94% and change management rose 10%, while generalist advisory fell. The specific magnitude is soft. The pattern is not.
The full picture
| Specialism | Median day rate | Year ago | Change | Sample |
|---|---|---|---|---|
| Cyber Security Consultant | £599 | £492 | +21.75% | 43 |
| Data Scientist | £600 | £531 | +12.94% | 217 |
| Change Manager | £550 | £500 | +10.00% | 155 |
| Machine Learning (skill) | £575 | £556 | +3.42% | 1,018 |
| Project Manager | £540 | £525 | +2.86% | 1,287 |
| IT Consultant | £525 | £516 | +1.69% | 45 |
| Artificial Intelligence (skill) | £559 | £550 | +1.64% | 3,018 |
| Business Analyst | £500 | £500 | not published | 1,376 |
| SAP Consultant | £550 | £560 | −1.79% | 240 |
| Cloud Architect | £600 | £633 | −5.14% | 229 |
| Management Consultant | £550 | £625 | −12.00% | 67 |
Artificial Intelligence and Machine Learning are skill markers, not job titles: IT Jobs Watch counts vacancies citing the skill across every contract role, so they overlap the job titles above and cannot be added to them.
It is priced as liability, not as labour
Here is the part the skills-shortage story misses. Cyber security work is bought by people managing an exposure, and exposure has a number attached to it.
When a board approves a penetration test or a regulatory remediation programme, the comparison is not “what does a consultant cost.” It is “what does a breach cost.” Fines, notification obligations, customer attrition, the cost of a forensic investigation, the cost of being the subject of a news cycle. Against that denominator, a £599 day rate is a rounding error, and procurement behaves accordingly.
Compare that with generalist strategy advice. Good advice creates value, but bad advice does not create a fine. There is no regulator issuing penalties for a mediocre operating model review. The buyer is spending from a discretionary budget rather than defending against a quantified downside, and discretionary budgets get benchmarked harder.
Where the specific premiums sit
Not all security work prices the same. The pattern in the advertised market is that the closer the work sits to a named obligation, the better it pays.
Regulatory and assurance work commands the top of the range. If the deliverable is evidence that satisfies an auditor or a regulator, the buyer has a deadline they cannot move and a consequence they cannot absorb. That is the strongest negotiating position a supplier can have, and it shows.
Incident response prices on urgency. Nobody negotiates hard at two in the morning. Retainer arrangements exist precisely because buyers know this and would rather fix the rate in advance.
Architecture and engineering sits closer to ordinary technical contracting. Valuable, less leveraged, and priced nearer the cloud and IT consulting benchmark.
Awareness and training sits lowest, and is the part most exposed to being replaced by a platform subscription.
A rising day rate is a signal about market pricing, not about supplier quality. The certification boom has produced a large number of people who can pass a security interview and a much smaller number who have run a real incident. Rate is a poor proxy for either. Ask for specific engagements, named outcomes, and references you can actually call.
Buying at these rates
If you are on the buying side, the leverage is in scope, not in the rate.
Separate assessment from remediation. Bundling them gives the supplier an incentive to find a lot of work. Two contracts, ideally two suppliers, keeps the diagnosis honest.
Fix the retainer before you need it. An incident response retainer bought calmly costs a fraction of the same capability bought during an incident. This is one of the few places in consulting where buying in advance is straightforwardly cheaper.
Ask what happens after the report. A findings document is not a security improvement. The engagements that deliver value include the remediation plan, the retest, and someone accountable for closing the gap.
Our broader guide to hiring a consultant covers the general vetting framework. For US comparison, consulting fees by industry sets out federal ceiling rates, the most a contractor may charge a US federal agency: $120 to $194 an hour for cyber roles (the middle half), median $152, across 10,723 rates in GSA CALC+ in September 2026. Clearance moves that less than the market suggests. Of 949 cleared cyber rates, six are $400 an hour or more, and those requiring 15 years’ experience top out at $318.73. For incident response, one public price: in April 2024 Tulsa County, Oklahoma, approved a $19,800 initial engagement, 30 hours at $660 an hour (county procurement memo).
What to watch
If the sample grows and the rate holds near £600, this is a genuine structural repricing and it will pull permanent salaries up behind it. If the sample stays thin and the rate reverts toward £520, the 22% was noise in a small market.
The more interesting question is whether the divergence continues. The gap between cyber and management consulting was £133 a day a year ago. It is now £49 in the other direction, a swing of £182. If regulated AI assurance work matures into its own specialism, expect it to price like security rather than like strategy, for exactly the same reason.
- UK cyber security consulting day rates rose 21.75% to a £599 median, the fastest movement of any specialism tracked
- The figure rests on 43 quoted rates, so treat the direction as reliable and the magnitude as soft
- The premium comes from liability rather than scarcity: buyers compare the fee against the cost of a breach, not against other consultants
- Regulatory, assurance and incident response work prices highest; architecture and awareness training price lowest
- Buyer leverage sits in scope, not rate — separate assessment from remediation, and fix incident retainers before you need them
- The cyber-to-management-consulting gap swung by £182 a day in twelve months, from £133 behind to £49 ahead
Last updated: 28 September 2026