Join our Newsletter — 33% off our NHI Course

What should organisations do first when cybersecurity staff shortages are making operations unsustainable?

Organisations should first map the highest-volume, most repetitive response tasks and identify which ones can be standardised or automated. That gives scarce staff capacity back to higher-value investigations and reduces dependence on manual processing. The first move is not simply hiring more people, but redesigning the work so qualified analysts focus on decisions that require judgement and context.

Start With the Work, Not the Headcount

When cybersecurity operations become unsustainable, the first move is to identify where staff time is being consumed by repeatable, low-judgement work. That means separating high-volume response activity from the tasks that genuinely need analyst context, then standardising or automating the former so scarce people can stay focused on triage, investigation, and escalation decisions that matter.

The practical test is whether a task follows a stable pattern, has clear inputs and outputs, and can be executed with low variation. If it does, it is usually a candidate for workflow redesign before it is a candidate for more manual staffing.

For teams trying to stabilise operations quickly, the priority is to reduce queue pressure, not to perfect the entire operating model at once. That often means starting with the most repetitive tickets, alerts, or approvals and measuring how much analyst time they consume before and after standardisation.

Which Tasks Are Most Worth Automating First?

The best first candidates are the tasks that are frequent, bounded, and easy to verify. In practice, that often includes alert enrichment, routine triage, simple access reviews, evidence collection, ticket routing, and other responses that follow a predictable playbook. These are the jobs where consistency matters more than deep investigation.

Tasks that involve ambiguity, sensitive business judgement, or irreversible action should stay human-led longer. The goal is not to automate everything, but to remove the work that absorbs time without adding much decision value. A good shortlist is usually the set of activities that your strongest analysts do well, but do not need to do personally every time.

SANS Security Resources is useful here because the operational patterns behind triage and incident handling show which activities can be turned into playbooks and which still require judgment.

NIST Cybersecurity Framework 2.0 also helps teams separate repetitive protect, detect, respond, and recover work from higher-value governance and escalation decisions.

How to Redesign Operations So Shortages Stop Dominating the Team

Once the repetitive work is visible, the next step is to redesign the operating model around it. That usually means standardising handoffs, defining clear decision thresholds, consolidating duplicated queues, and using automation to handle the predictable first pass. Staff shortages become much less destabilising when every alert or request does not need a fresh manual start.

Good redesign also depends on measuring whether the change actually reduces load. Look at mean time spent per case, backlog growth, false-positive handling, and how often analysts are forced into routine processing instead of meaningful analysis. If those signals do not improve, the automation is probably cosmetic rather than operationally useful.

CISA cyber threat advisories can support the response side of that redesign by helping teams prioritise what needs attention first when capacity is thin.

FIRST EPSS is helpful when the issue is triage volume, because it supports prioritisation when you cannot treat every finding or alert with the same urgency.

Risk and Threat Considerations

Staff shortages do not just create inconvenience, they create operational exposure. When teams are overloaded, repetitive work tends to get queued, exceptions get missed, and the organisation becomes slower at noticing genuine incidents. That can widen the window for attacker activity, but it also increases the chance of self-inflicted failure through backlog and process drift.

Failure mechanism: Excess manual work, combined with limited analyst capacity, causes delayed triage, inconsistent handling, and reduced visibility into what is actually urgent.

Impact: The organisation can miss early signs of compromise, accumulate response debt, and keep critical decisions tied to people instead of repeatable controls.

CISA Known Exploited Vulnerabilities Catalog is a practical reminder that prioritisation matters most when capacity is constrained, because known active exploitation changes the cost of delay.

MITRE ATT&CK Enterprise Matrix is useful when you need to understand how delayed detection and response can help attackers move from initial access to persistence or lateral movement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-8 — Audit Log Management Automating repetitive monitoring and response depends on reliable log visibility.
Recommendation — Standardize log collection and review so automation can safely handle routine response.
NIST CSF 2.0 PR.IR-03 — Mechanisms are established to achieve resilience and recover from incidents Reducing manual workload improves operational resilience when staff are scarce.
PR.AA-05 — Identities are authenticated and linked to assets and services Operational automation often relies on controlled access for tools and responders.
DE.CM-01 — Networks and network services are monitored to find potentially adverse events Triage automation is most valuable where monitoring creates high event volume.
Recommendation — Redesign routine response work to maintain resilience under constrained staffing. Ensure automated workflows have tightly controlled, attributable access. Use monitoring coverage to identify repetitive events suitable for automation.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting High-volume response work often begins with reviewing and prioritizing audit evidence.
Recommendation — Automate routine audit review so analysts focus on exceptions and escalation.

Practitioner Guidance

What to prioritise: Start with the top few workflows that consume the most analyst hours and have the clearest rules for handling. If a task can be described as “same input, same decision, same output,” it belongs near the front of the automation queue.

What to verify: Before automating, confirm that the task has a stable decision threshold, a clear exception path, and an auditable output. If you cannot explain how the automated result will be reviewed when it fails, the control is not ready for production use.

Practitioner takeaway: The right first move is to reduce manual load at the source, because staffing problems are usually made worse by process design that forces experts to spend time on work that does not need expert judgement.