Join our Newsletter — 33% off our NHI Course

Should organisations promote internal growth or hire only people who already know cloud security?

Organisations should balance both, but they should not wait for a perfect expert if a promising internal person is nearly ready. People who already do the role can become bored or leave, while people who are close to ready can grow into durable contributors. Development opportunities also improve retention and make the team easier to sustain.

Why this is really a hiring and capability-building question

The real choice is not between “train” and “hire” in the abstract, but between speed to capability and long-term team resilience. Cloud security work changes quickly, so a team made only of external experts can be expensive, hard to retain, and narrow in perspective. A team that never hires proven practitioners, however, can move too slowly on high-stakes work.

The better question is which parts of the role need immediate depth and which parts can be developed safely. Organisations usually need both: a stable core of people who understand the environment and a few experienced hires who can set direction, coach others, and raise the team’s baseline.

That balance matters because cloud security is not a single skill. It spans identity, configuration, logging, detection, engineering, and governance, and few candidates arrive strong in all of them. If you insist on perfect prior experience, you may shrink the talent pool so much that the team never scales.

When internal growth beats waiting for a perfect hire

Internal growth is strongest when the person already understands the business, the platform, or the operating model and only needs cloud security depth added. That path often produces better judgement than hiring a generic “cloud security expert” who still has to learn how your systems actually work.

It is also the better answer when the role needs continuity. Security teams often depend on context that is hard to document fully, such as application ownership, change patterns, exception history, and which controls the business will realistically adopt. Developing someone inside the organisation helps preserve that context while building security capability around it.

Promoting growth also improves retention when the job market is competitive. People who can see a progression path are more likely to stay long enough to become effective, and that is especially important in cloud security because turnover can leave gaps in review, architecture decisions, and incident response judgement.

When hiring experienced cloud security people is the better move

Hiring is the right move when the organisation has a real capability gap that cannot wait, such as a major cloud migration, a serious control weakness, or a need to redesign guardrails quickly. In those cases, the team needs someone who can make good decisions immediately, not just someone with potential.

It is also appropriate when internal candidates would be asked to do work that is too new, too broad, or too exposed for a first stretch role. Cloud security leaders often need to make trade-offs across access, segmentation, policy design, and operational friction, so some roles benefit from a person who has already made those calls in another environment.

The practical risk of hiring only externally is that you can create a brittle team. External hires may be very capable, but they still need time to learn the organisation’s cloud estate, governance habits, and delivery pace. Without internal talent alongside them, knowledge can concentrate in a few individuals and become hard to replace.

What a sustainable mix looks like in practice

A sustainable approach is usually layered. Use experienced hires for roles where judgement must be right quickly, then build a pipeline of internal staff who can absorb the methods, tools, and decision standards. That gives you both immediate competence and future depth.

For cloud security specifically, the best teams tend to treat capability as a portfolio. Some people bring architecture or risk judgement, some bring engineering depth, and some grow into operational security through structured exposure. The organisation does not need every person to arrive fully formed, but it does need a deliberate way to move promising staff into higher-trust work.

ISO/IEC 27001:2022 Information Security Management is useful here because it frames competence, awareness, and control ownership as part of an operating system, not an afterthought. For cloud-specific control design, the CSA Cloud Controls Matrix gives a more direct way to think about which skills and responsibilities must be covered across cloud governance, IAM, and infrastructure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.6.3 — Information security awareness, education and training Cloud security staffing depends on building competence, not only hiring it.
A.5.2 — Information security roles and responsibilities The question is about who should own cloud security work and how capability should be distributed.
Recommendation — Build role-specific security training and progression paths for internal cloud talent. Define cloud security ownership, escalation, and role expectations clearly.
CSA Cloud Controls Matrix IAM — Identity and Access Management Cloud security staffing decisions materially affect access control and cloud governance capability.
Recommendation — Staff IAM and cloud governance roles with both experienced hires and developed internal talent.

Practitioner Guidance

What to prioritise: Hire for the gaps that would create near-term exposure if left open, but build internal succession for the roles that depend on environment knowledge, control ownership, and steady judgement. If a candidate is close to ready, the cost of growing them is often lower than the long-term cost of constant external replacement.

What to verify: Before deciding that a role must be external-only, check whether the real requirement is cloud security expertise or simply the ability to make decisions under pressure. If the latter, a strong internal operator with structured coaching may outperform a specialist who still lacks organisational context.

Practitioner takeaway: The best cloud security team is usually not the one with the most imported expertise, it is the one that can keep critical judgement in-house while still bringing in outside depth when the work genuinely demands it.