Last week, I watched a senior threat analyst walk away from a £20K salary bump because he didn't understand the equity package on offer at the competing firm. Painful.
It's 2026 and I'm still seeing cybersecurity professionals, even highly technical ones, make career decisions based on base salary alone. But here's the thing: in today's market, particularly with the surge of UK cyber startups since the NCSC's accelerator programme expanded last year, your total compensation package matters far more than that headline number.
The Equity Blind Spot
I spent seven years as a SOC analyst before moving to the recruitment side, and I can tell you: most security professionals are brilliant at detecting threats but rubbish at detecting value in their compensation packages.
Make no mistake, equity isn't just for fintech hotshots and AI whiz kids. The cybersecurity sector has evolved. Post-2025 investment rounds have transformed how UK security firms structure their compensation, particularly for senior threat intelligence, cloud security, and OT security specialists.
But what does that mean for you?
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
Share Options vs RSUs: Know Your Equity
There are fundamentally different types of equity compensation, and they're not created equal:
EMI Share Options
These remain the darling of UK cybersecurity startups. They give you the right to purchase shares at a predetermined price. The tax treatment is favourable, 10% capital gains rather than income tax rates if structured properly.
What nobody tells you: the strike price matters enormously. A £0.01 option in a pre-Series A security consultancy might be worth more than a £5 option in an over-valued, later-stage company that's already peaked.
Restricted Stock Units (RSUs)
More common in established firms or those with US parents. RSUs are actual shares granted to you after a vesting period. They're taxed as income when they vest, which can be painful if you're not prepared.
I've seen cleared SOC managers at defence contractors get walloped with unexpected tax bills because nobody explained how RSUs work at grant time.
The Questions You Should Actually Ask
When evaluating an offer with equity, don't waste time with vague questions. Get specific:
- What percentage of the fully diluted company do these shares represent? (Not just raw numbers)
- What was the last valuation, and when?
- What's the vesting schedule? (The standard 4-year vest with 1-year cliff isn't universal anymore)
- What happens to my options if I leave? (The exercise window can be as short as 90 days)
- Is there accelerated vesting on acquisition? (Critical in the current consolidation market)
The most important question? Ask about liquidation preferences. These determine who gets paid first if the company sells, and trust me, in the 2026 cyber market, preferences can make your equity worth absolutely nothing even in a "successful" exit.
Bonus Structures: The Good, the Bad, the Delusional
Bonuses in cybersecurity fall into roughly three categories:
-
Performance-based individual bonuses: Increasingly tied to specific metrics rather than vague "exceeding expectations" language. The best ones have clear, documented thresholds.
-
Team or company bonuses: Often linked to client acquisition or retention. Watch for the percentage that's in your control versus dependent on others.
-
On-call or incident response bonuses: A growing trend, particularly after the Commercial Incident Response Standards (CIRS) framework rolled out. These can substantially boost compensation but destroy your work-life balance.
My advice? If a bonus makes up more than 20% of your expected compensation, assume you'll get half of it at best, and decide if you're still happy with the package.
Comparing Apples to Oranges (or SOCs to MSSPs)
The hardest part is comparing different types of packages. How do you weigh a £75K base with modest equity at a promising startup against a £95K corporate role with a structured bonus but no equity?
My approach, which I've used when placing senior security analysts and SOC leads, is to create three compensation scenarios:
- Conservative (what you'll definitely get)
- Expected (what's reasonably likely)
- Optimistic (what's possible but not guaranteed)
This forces you to assign realistic probabilities to equity and bonus components.
A Real-world Example
I just placed a threat intel specialist who had two offers:
- A bank offering £110K base, 15% bonus, standard benefits
- A Series B security firm offering £85K, options worth roughly 0.08% of the company, and a 10% bonus
The bank offer looked £25K better on paper. But after examining recent exits in the space and applying a conservative valuation multiple, the equity could reasonably be worth £50-120K over four years if the company continued its trajectory.
She took the startup role. Why? Not just money, but because she'd have skin in the game and could directly impact the company's success.
The Tax Trap
But taxes. God, the taxes.
The 2025 changes to EMI schemes altered the landscape significantly. The advanced clearance requirement has slowed down many equity grants. And with the April budget adjustments to capital gains rates for amounts over £40K, your tax liability may be significantly higher than you've calculated.
Talk to a proper accountant, not just the company's finance team. I've seen too many security professionals get burned by tax surprises, especially those coming from contractor roles into their first equity-offering permanent position.
Beyond the Numbers
What's your actual goal? If it's short-term cash to buy a house, equity that might pay off in 5 years is nearly useless to you. If you want to retire by 45, guaranteed income might matter less than high-risk, high-reward equity.
Compensation isn't just about maximising a number, it's about matching your personal priorities.
The best security professionals I know have clear financial goals. The ones who bounce between roles chasing small base salary increases often end up worse off than those who strategically build wealth through well-structured compensation packages.
Trust me, after sitting on both sides of the hiring table, understanding your total package isn't optional. It's essential.
If you're considering a move and want to understand the current market rates for security roles with particular skill sets, The OHub's insights section tracks compensation trends specific to cybersecurity specialisations. Their data on equity compensation in UK security firms is particularly useful for benchmark comparisons.
And remember, you wouldn't accept a vulnerability scan that only checked 60% of your attack surface. Don't evaluate job offers that way either.
