Leaders should treat persistent vacancies as an operating risk, not a recruiting delay. Prioritise the skills tied to incident response, cloud security, and zero trust, then reduce dependence on single experts through cross-training, playbooks, and tighter scoping of high-risk work. When budgets are constrained, focus on the controls that reduce exposure fastest and preserve response capability.
Why unfilled specialist roles become a security issue
Months-long vacancies create real exposure because the organisation still has to operate, respond, and change systems while key expertise is missing. The risk is not only slower delivery, but weaker decisions on incident handling, cloud hardening, and identity or access controls, especially when a small number of people carry too much contextual knowledge.
When a role stays open long enough, teams often compensate by deferring work, simplifying reviews, or handing complex tasks to generalists. That can keep the lights on, but it also increases the chance that high-risk work proceeds without the depth needed to spot weak assumptions, hidden dependencies, or control gaps.
How leaders should prioritise scarce security capacity
The right response is to sort work by exposure reduction, not by organisational habit. The first priority should be the controls and response capabilities that reduce blast radius fastest, especially incident response readiness, cloud guardrails, and zero trust enforcement where privileges, segmentation, or trust boundaries are still too loose.
Leaders should also narrow the scope of work that depends on one specialist. Use cross-training to cover recurring tasks, write playbooks for repeatable decisions, and push routine approval or review work closer to the teams that own the systems. That keeps the most sensitive judgment calls available for the highest-risk cases.
As a practical example, the question is often whether to keep a fragile process running exactly as designed or to reduce its complexity until the team can staff it properly. In a constrained environment, the safer choice is usually the one that preserves containment, detection, and recovery rather than the one that preserves the original division of labour.
What good operating models look like during a vacancy
Healthy teams do not wait for the vacancy to close before making decisions. They document the minimum acceptable operating state, identify which approvals can be delegated, and define what must stop if the missing role is the only one that can safely execute it.
They also keep a short list of controls that must remain staffed at all times. For most organisations, that means knowing who can rotate credentials, who can investigate alerts, who can approve exceptions, and who can restore service when a security change has side effects. If those responsibilities are unclear, the vacancy will be filled informally by whoever is available, which is rarely the safest answer.
Leaders should expect some trade-off between speed and breadth. The aim is not to preserve every current initiative, but to preserve the ability to prevent, detect, and respond while the hiring gap persists.
Risk and Threat Considerations
Extended vacancies matter because they create concentration risk, delayed remediation, and fragile recovery paths. Attackers benefit when one overextended team member becomes the only person who understands a control, a dependency, or an exception that was never documented.
Failure mechanism: Security work becomes dependent on tacit knowledge, so routine changes, incident triage, and exception handling slow down or get simplified. That increases the chance of misconfiguration, overdue remediation, and blind spots in response.
Impact: The organisation can lose time at the exact moment it needs speed, which raises the likelihood of larger incidents, longer dwell time, and more expensive recovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Vacancies create security and operational risk that must be prioritised and governed. |
| PR.AA-05 — Identity Management, Authentication, and Access Control | Staffing gaps raise the need for clear access, delegation, and least-privilege decisions. | |
| RC.RP-01 — Recovery Plan Execution | Vacancies can weaken response and recovery execution when specialist coverage is thin. | |
| Recommendation — Treat persistent specialist vacancies as risk to be prioritised in the enterprise risk program. Tighten access and delegation boundaries so critical duties do not depend on one person. Document and rehearse recovery steps so response capability survives temporary staffing gaps. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Understaffing can delay alert review and incident triage, increasing time to detect and respond. |
| Recommendation — Ensure alert review and escalation remain covered even when specialist roles are vacant. | ||
| NIST Zero Trust (SP 800-207) | SP 800-207 — Zero Trust Architecture | The answer explicitly prioritises zero trust controls to reduce blast radius when expertise is scarce. |
| Recommendation — Use zero trust principles to reduce reliance on scarce experts and shrink trust boundaries. | ||
| CIS Controls v8 | CIS-5 — Account Management | Cross-training and delegation only work when account ownership and access paths are controlled. |
| Recommendation — Keep account ownership and privileged access tightly assigned during staffing gaps. | ||
Practitioner Guidance
What to prioritise: Protect the work that most directly reduces exposure, then push lower-risk tasks into playbooks, shared ownership, or temporary delegation. If a vacant role owns a control that can materially affect production security, treat that as a continuity issue, not a staffing inconvenience.
What to verify: Confirm that at least two people can execute the most critical actions, such as incident escalation, emergency access review, cloud policy changes, and recovery procedures. If you cannot produce that coverage, the vacancy is already degrading control reliability.
Common mistake: Leaders often try to preserve the full original scope with fewer people. A better decision is to trim or pause low-value work so the team can keep the highest-risk protections credible.
Practitioner takeaway: The test is not whether the role is open, but whether the organisation can still make fast, well-governed security decisions without depending on one exhausted expert.
Related resources from NHI Mgmt Group
- How should compliance leaders respond when transaction monitoring cannot be evidenced to regulators?
- How should IAM leaders respond when a large part of the estate sits outside automated governance?
- What should security teams do when some users stay on legacy hashes for months?
- Why do cybersecurity and identity leaders struggle to get board support?