Apply an understanding of cyber security to protect from attacks and unauthorised access.
Apprentices develop practical skills across three specialisms: security engineering, cyber risk analysis, or cyber defence and response. Depending on the chosen pathway, they learn to design and build secure networks, conduct risk assessments against recognised standards, develop information security policies, manage encryption systems, and support incident response planning. All three pathways require a firm grounding in security concepts, relevant legislation, and regulatory frameworks. The apprenticeship is designed to produce someone who can work independently on defined security tasks while contributing to a wider technical team.
Depending on the pathway, day-to-day work might involve configuring network infrastructure and testing it against security requirements, carrying out gap analyses against standards such as ISO 27001 or Cyber Essentials, drafting incident response or business continuity plans, or monitoring systems for intrusion indicators. Risk analysts spend time assessing threats and producing written recommendations for stakeholders. Engineers work with hardware and software components, often in lab or computer room environments. Defenders work in security operations functions, reviewing alerts and supporting breach response. All pathways involve communicating findings to both technical and non-technical colleagues.
On completion, typical job titles include SOC Analyst, Cyber Risk Analyst, Information Security Officer, Cyber Security Engineer, and Governance and Compliance Analyst. From there, progression routes lead to roles such as Security Architect, Cyber Operations Manager, or senior consultant positions. Employers span virtually every sector: financial services, defence, government, healthcare, retail, and critical national infrastructure all hire for these roles. Some positions, particularly in defence and government, carry security clearance requirements. The demand for qualified practitioners at this level continues to grow across both large organisations and SMEs.
Sorted by achievement rate.
Blackpool and The Fylde College (B&FC) offers a wide range of technical and professional education o...
Activate Learning is a UK education group that delivers apprenticeships and vocational training thro...
Abingdon & Witney College is a further and higher education college in Oxfordshire offering a wide r...
ANS is a UK-based technology company that delivers an Ofsted-rated ‘Outstanding’ apprenticeship prog...
Achievement Training Limited (ATL) is a private training organisation based in Plymouth city centre,...
Completers typically move into roles such as Cyber Security Analyst, SOC Analyst, Cyber Risk Analyst, Information Security Officer, or Junior Security Engineer, depending on which of the three specialisms they pursued. Those on the engineering pathway may step into network security or infrastructure roles, while risk and compliance-focused completers often enter governance, risk and compliance (GRC) or assurance functions. Defender and responder graduates frequently join security operations centres in monitoring or incident response capacity.
Within three to five years, practitioners commonly progress to Senior Cyber Security Analyst, Security Architect, or Threat Intelligence Analyst. Those who move into management can reach Security Operations Manager or Head of Information Security. The deep-specialist track leads toward roles such as Principal Security Engineer, Penetration Tester, or Forensics Consultant, often supported by professional certifications including CISSP, CISM, or vendor-specific qualifications. At the senior end, roles such as Chief Information Security Officer (CISO) represent the longer-term ceiling for those who combine technical depth with strategic capability.
Demand spans virtually every sector in the UK economy. Financial services, central and local government, defence contractors, NHS trusts, and critical national infrastructure operators are consistent employers, as are managed security service providers (MSSPs) that deliver security functions to multiple clients. Technology firms, retailers with large online operations, and telecoms companies also hire regularly. Roles exist in organisations of all sizes, from SMEs building their first security function to large enterprises running dedicated security operations centres.
Throughout the apprenticeship, learning happens alongside employment, with the apprentice building knowledge and skills directly in their workplace role. Before final assessment, both the employer and training provider confirm the apprentice is ready, a checkpoint commonly called the gateway. At that point, the apprentice must demonstrate competence across the knowledge, skills and behaviours set out in the standard, including whichever specialist option they have followed: Cyber Security Engineer, Cyber Risk Analyst, or Cyber Defender and Responder. Assessment models for many standards are currently being updated as part of wider reforms, so check the standard's gov.uk page for the current specification.
Gathering evidence as work happens is far easier than reconstructing it later. Apprentices should keep records of real tasks throughout, whether that is a risk assessment, a network build, an incident response plan, or a security audit contribution, because this evidence forms the basis of demonstrating competence at the end. Working closely with both the employer and training provider from an early stage helps identify any gaps in coverage before the gateway, giving time to address them without pressure.
Look for providers with an achievement rate above 65% on their FATP profile, and ideally above 75% given the technical complexity of this standard. Because apprentices complete one of three pathways (engineer, risk analyst, or defender and responder), a good provider will be clear upfront about which pathways they deliver and how they structure the split. Check that training covers current frameworks such as NCSC guidance, ISO 27001 and NIST, and that apprentices get hands-on exposure to tools used in live security environments, including SIEM platforms, vulnerability scanners and network analysis tools, not just classroom theory. Strong employer satisfaction scores and learner reviews that mention real-world application are worth weighting heavily here.
Be cautious if a provider cannot tell you clearly which of the three pathways they specialise in, or if they teach all three with equal confidence but have thin cohort sizes across each. Outdated tool coverage is a concrete risk in this standard; if a provider's curriculum still centres on legacy platforms or avoids cloud security entirely, that is a problem. A high volume of starts combined with a declining achievement rate deserves scrutiny. Also probe any provider that cannot show where alumni have ended up, since SOC analyst, GRC analyst and security engineer roles are specific enough to verify.
There are no nationally set entry requirements for this standard, so individual employers and training providers set their own criteria. Candidates typically need a good level of digital literacy and often hold GCSEs in maths and English, or equivalent qualifications. Some employers ask for A levels or a relevant Level 3 qualification. Employers with security clearance requirements may also impose nationality or residency conditions, so check those early in the recruitment process.
The typical duration is 24 months, though the current off-the-job training requirements are subject to revision under ongoing Skills England reforms. Check the current specification on the Institute for Apprenticeships and Technical Education pages at gov.uk for the latest requirements. Throughout the programme, apprentices remain employed and apply their learning directly in the workplace, gaining practical experience across cyber security tasks alongside structured off-the-job training.
Before reaching end-point assessment, the apprentice must pass through gateway, where the employer and training provider confirm the apprentice has developed the required knowledge and skills. Assessment models for many standards are currently being reviewed, so check the current endpoint assessment plan on gov.uk for precise details. The assessment will require the apprentice to demonstrate competence in their chosen pathway, whether that is Cyber Security Engineer, Cyber Risk Analyst, or Cyber Defender and Responder.
The funding band for this standard is £18,000, which is the maximum that can be drawn from the apprenticeship levy or co-investment funding. Larger employers with a levy account use funds from that account. Smaller employers without a levy account pay 5% of the training cost, with the government covering the remaining 95%. Employers with fewer than 50 staff who take on an apprentice aged 16 to 18 pay nothing; the government funds the full cost.
The day-to-day work depends on which of the three pathways the apprentice follows. Engineers design, build and test secure networks and systems. Risk analysts conduct cyber risk assessments, carry out security audits, and develop information security policies. Defenders and responders configure security systems and monitor them for breaches, developing incident response and business continuity plans. All three pathways involve working with both technical and non-technical colleagues, and handling real security challenges in live organisational environments.
Completing this apprenticeship opens routes into senior technical and analytical roles such as security architect, cyber operations manager, security analyst, or intelligence researcher. Some graduates move into management positions with responsibility for teams or budgets. Others pursue further qualifications, including degree apprenticeships or professional certifications in cyber security. Because the skills are applicable across almost every sector, career paths are available in finance, government, defence, health, retail, and many other areas.
Tell us a bit about your team and we'll send a shortlist.
Tell us your requirements and we'll match you with the right training providers.
Curated by Alex Lockey, FATP founder and editor. Last reviewed: .
Sources include the apprenticeship's official specification on apprenticeships.gov.uk, Skills England guidance, IfATE archive records, DWP funding bands, and provider data sourced directly from the public Apprenticeship Provider and Assessment Register (APAR). Standard reference: 619.
Some sections on this page were drafted with AI assistance from published source data and reviewed by a human editor before publication. See our editorial methodology for how we maintain this content. Spotted something out of date? Tell us.