Join our Newsletter — 33% off our NHI Course

Fully Loaded Cost

Fully loaded cost is the total cost of an employee, not just salary. It includes benefits, taxes, equipment, and overhead, and is used to estimate the real expense of security work such as manual triage. This calculation helps teams compare reactive labour with higher-value preventive activities.

Expanded Definition

Fully loaded cost is a budgeting and decision-making lens, not just an accounting figure. It captures the true cost of employing people by adding payroll taxes, benefits, equipment, workspace, management overhead, and the support functions that make labour available. In security teams, that broader view is especially important because the apparent cost of a task, such as manual alert review, is often far lower than the actual cost of staffing it.

The term is commonly used when comparing labour-intensive work against automation, outsourcing, or control improvement. The practical boundary is that fully loaded cost measures the cost of sustaining the role, not the value of the work performed. That distinction matters: a low-salary task can still be expensive once onboarding, supervision, tooling, and escalation time are included.

For that reason, fully loaded cost is most useful when teams need to compare competing uses of scarce security capacity. It helps separate headline compensation from the real resource commitment behind reactive operations.

Examples and Use Cases

Security and operations leaders use fully loaded cost when they need to compare recurring human effort with alternative control investments. It is most useful where the same work could be reduced, delegated, or prevented rather than repeatedly staffed.

  • A SOC lead estimates the true annual cost of analysts who spend part of each shift on repetitive false-positive triage.
  • A security manager compares the loaded cost of manual access reviews with the cost of improving identity governance and workflow automation.
  • A platform team uses the measure to decide whether a recurring onboarding task should remain human-handled or be moved into a self-service process.
  • A finance partner assesses whether a planned headcount increase is cheaper than reducing alert volume through better detection tuning.

The main tradeoff is that the calculation can be sensitive to assumptions. Teams sometimes omit overhead categories or undercount indirect time, which makes reactive work look cheaper than it is.

Security Implications

When fully loaded cost is misunderstood, security programmes tend to underestimate the price of friction. The result is often continued investment in manual work that feels operationally normal but steadily consumes budget, attention, and skilled staff. That can leave less capacity for control hardening, threat hunting, and preventive engineering.

It also creates governance risk. If leaders compare automation projects only against salary line items, they may reject improvements that would reduce analyst burnout, shorten response cycles, or cut repeated low-value work. The hidden consequence is not only cost inefficiency but also slower security maturity, because teams remain trapped in reactive loops.

A common practitioner observation is that the most expensive security labour is often the labour that repeats with little learning effect. Fully loaded cost exposes that pattern by showing how much the organisation really spends to preserve an avoidable workflow.

Domain and Governance Relevance

Fully loaded cost matters in cybersecurity because it changes how organisations evaluate controls, staffing, and operating models. A control that reduces repetitive manual handling can be economically superior even if its direct licence or implementation cost looks higher at first glance. That makes the term useful in business cases for automation, managed services, and process redesign.

It is also relevant to identity and access governance when organisations assess the cost of recurring human approval, review, or exception handling. In those settings, the measure helps decision-makers compare sustained manual oversight with tighter policy design or better workflow controls. The primary question is not whether a task can be done by people, but whether keeping it human-run is the best use of scarce security capacity.

For NHI Management Group, the practical value is in showing where labour is being spent to compensate for weak control design. That insight supports better prioritisation across security operations, identity governance, and preventive engineering.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-03 — Results of Risk Management Activities Supports comparing labour cost to control value in security governance.
Recommendation — Use GV.OV-03 to tie staffing spend to measurable security outcomes.
CIS Controls v8 14 — Security Awareness and Skills Training Relevant where recurring human work reflects avoidable operational burden.
Recommendation — Use Control 14 to reduce repetitive work that depends on constant human intervention.
NIST SP 800-63 6 — Authenticator and Credential Lifecycle Management Applies when loaded cost is used to evaluate recurring identity-related manual effort.
Recommendation — Use Section 6 to shorten manual identity lifecycle effort through stronger lifecycle design.
DORA ICT third-party risk management — ICT third-party risk management Relevant when loaded cost is used to evaluate outsourcing or managed security services.
Recommendation — Assess third-party operating costs against resilience and oversight obligations.