Security teams should treat the workforce gap as a capacity and resilience problem, not just a recruiting problem. The practical response is to prioritize automation, standardize repeatable controls, and shift scarce staff toward higher-risk work such as triage, remediation, and architecture decisions. Organisations also need better coordination with HR, stronger retention practices, and clearer internal career paths to reduce churn.
Why a workforce gap becomes a security design problem
A widening hiring gap changes the shape of risk. When there are too few people for too many alerts, reviews, and exceptions, the team has to reduce manual work, not just ask staff to work harder. The right response is to remove repetitive effort from the operating model and reserve human judgement for cases that actually need it.
That usually means automating ticket enrichment, evidence collection, baseline checks, and other repeatable work first. It also means standardising control patterns so the team is not re-solving the same problem across every system, and every exception is not treated as a one-off.
A useful lens is capacity: if a task does not need expert interpretation, it should be engineered so the team can execute it consistently at scale. The Workforce Identity Security Guide is relevant here because staffing pressure often shows up first in account recovery, provisioning, and reset workflows, where process friction directly drives operational load.
What work should stay with people, and what should be industrialised?
Security teams usually get into trouble when they try to automate the wrong layer. The goal is not to automate judgement, it is to automate the routine steps that make judgement possible. Human time should be reserved for triage, root-cause analysis, remediation decisions, architecture changes, and the handling of ambiguous cases.
Repeatable controls are the easiest place to gain leverage. Examples include standard access reviews, consistent logging, automated patch verification, and templated incident evidence capture. Those activities reduce queue depth without lowering the quality of the decision because they are primarily procedural, not interpretive.
When the team is short-staffed, the biggest mistake is to preserve bespoke process everywhere. That creates hidden backlog and spreads scarce expertise too thin. Strong teams narrow the number of control variants, document decision criteria, and make escalation paths obvious so the few available specialists can focus where risk is highest.
That operating model also benefits from clearer identity and access guardrails around privileged work, because scarce personnel should not be spending time manually compensating for weak access design. The Ultimate Guide to NHIs, Key Research and Survey Results is useful supporting context for the broader point that scale pressure tends to expose control gaps, especially where repeated credentials, secrets, and access paths multiply operational overhead.
How to reduce churn while keeping coverage stable
Hiring alone will not close the gap if experienced staff keep leaving. Retention becomes a security control because turnover drains institutional knowledge, slows response time, and increases the chance that tribal process knowledge disappears with one person. Teams need visible career paths, sensible on-call expectations, and enough automation to make the job sustainable.
Coordination with HR matters because security work often competes with broader market demand. Better role design, clearer progression, and targeted upskilling can help keep staff longer than a reactive hiring campaign can replace them. If the team is constantly recruiting for the same role, the underlying problem is usually workload design, not just headcount.
Internal mobility also helps. Moving analysts toward engineering, detection, or architecture work gives experienced people a reason to stay while freeing them from the most repetitive tasks. The 52 NHI Breaches Report is a reminder that real-world compromises often exploit weak operational discipline, which is exactly the kind of pressure point that overloaded teams struggle to police consistently.
Risk and Threat Considerations
Capacity gaps create security exposure when routine work is delayed, inconsistent, or skipped. Attackers benefit when teams cannot review access quickly, rotate secrets on time, or investigate alerts before they age out of relevance. Understaffing also increases the chance that exceptions become permanent and that control drift goes unnoticed.
Failure mechanism: The team’s manual queue outgrows its people, so controls that depend on timely human review lose effectiveness. That creates slower detection, weaker remediation, and more room for adversaries to persist through stale access, unreviewed privilege, or delayed response.
Impact: The organisation may not notice compromise early, may take longer to contain it, and may carry more operational risk across identities, systems, and recovery workflows. In practice, the workforce gap becomes an amplifier for every other control weakness already present.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-18 — Penetration Testing | Workforce gaps raise the need for prioritised, repeatable validation of control coverage. |
| Recommendation — Automate control checks and test high-risk processes regularly so scarce staff can focus on findings. | ||
| NIST CSF 2.0 | GV.RR-01 — Roles and Responsibilities | The question is about aligning people, process, and ownership when capacity is constrained. |
| PR.AA-05 — Identity Management, Authentication, and Access Control | Hiring pressure makes repeatable access control and lifecycle hygiene more important. | |
| GV.OV-01 — Oversight of Risk Management Strategy | The answer frames the workforce gap as a capacity and resilience issue requiring governance attention. | |
| Recommendation — Clarify ownership and escalation so limited staff spend time on decisions, not routing. Standardize access workflows so review, provisioning, and recovery stay consistent at scale. Track staffing pressure as an operational risk indicator and adjust control priorities accordingly. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Staff shortages amplify the need for automated and consistent account lifecycle handling. |
| Recommendation — Automate account lifecycle actions and review exceptions so access does not accumulate unchecked. | ||
Practitioner Guidance
What to prioritise: Start with the work that is high-volume, low-judgement, and directly tied to exposure, such as repetitive triage, evidence gathering, access hygiene, and standard remediation steps. If a task can be defined unambiguously, it should usually be the first candidate for automation or standardisation.
What to verify: Make sure automation actually removes toil rather than creating a second layer of review. The right test is whether the team can absorb alerts, exceptions, and lifecycle tasks with fewer handoffs and less context switching, not whether a tool exists in the stack.
What good looks like: The team spends more time on decisions that need expertise and less time on work that follows a script. Staffing pressure is still real, but it no longer determines whether core controls are consistently executed.
Practitioner takeaway: Treat the workforce gap as a control-design problem first, because the safest teams are not the ones that ask people to do more, they are the ones that make the right security work repeatable, measurable, and hard to miss.
Related resources from NHI Mgmt Group
- How should enterprise security teams address the gap between cybersecurity investment and real resilience?
- How should security teams choose cybersecurity podcasts to keep pace with identity and access risks without wasting time on low-value content?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams govern non-human identities at scale?