Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should cybersecurity leaders respond when specialist roles…
Governance, Ownership & Risk

How should cybersecurity leaders respond when specialist roles stay unfilled for months?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Leaders should treat persistent vacancies as an operating risk, not a recruiting delay. Prioritise the skills tied to incident response, cloud security, and zero trust, then reduce dependence on single experts through cross-training, playbooks, and tighter scoping of high-risk work. When budgets are constrained, focus on the controls that reduce exposure fastest and preserve response capability.

Why unfilled specialist roles become a security issue

Months-long vacancies create real exposure because the organisation still has to operate, respond, and change systems while key expertise is missing. The risk is not only slower delivery, but weaker decisions on incident handling, cloud hardening, and identity or access controls, especially when a small number of people carry too much contextual knowledge.

When a role stays open long enough, teams often compensate by deferring work, simplifying reviews, or handing complex tasks to generalists. That can keep the lights on, but it also increases the chance that high-risk work proceeds without the depth needed to spot weak assumptions, hidden dependencies, or control gaps.

How leaders should prioritise scarce security capacity

The right response is to sort work by exposure reduction, not by organisational habit. The first priority should be the controls and response capabilities that reduce blast radius fastest, especially incident response readiness, cloud guardrails, and zero trust enforcement where privileges, segmentation, or trust boundaries are still too loose.

Leaders should also narrow the scope of work that depends on one specialist. Use cross-training to cover recurring tasks, write playbooks for repeatable decisions, and push routine approval or review work closer to the teams that own the systems. That keeps the most sensitive judgment calls available for the highest-risk cases.

As a practical example, the question is often whether to keep a fragile process running exactly as designed or to reduce its complexity until the team can staff it properly. In a constrained environment, the safer choice is usually the one that preserves containment, detection, and recovery rather than the one that preserves the original division of labour.

What good operating models look like during a vacancy

Healthy teams do not wait for the vacancy to close before making decisions. They document the minimum acceptable operating state, identify which approvals can be delegated, and define what must stop if the missing role is the only one that can safely execute it.

They also keep a short list of controls that must remain staffed at all times. For most organisations, that means knowing who can rotate credentials, who can investigate alerts, who can approve exceptions, and who can restore service when a security change has side effects. If those responsibilities are unclear, the vacancy will be filled informally by whoever is available, which is rarely the safest answer.

Leaders should expect some trade-off between speed and breadth. The aim is not to preserve every current initiative, but to preserve the ability to prevent, detect, and respond while the hiring gap persists.

Risk and Threat Considerations

Extended vacancies matter because they create concentration risk, delayed remediation, and fragile recovery paths. Attackers benefit when one overextended team member becomes the only person who understands a control, a dependency, or an exception that was never documented.

Failure mechanism: Security work becomes dependent on tacit knowledge, so routine changes, incident triage, and exception handling slow down or get simplified. That increases the chance of misconfiguration, overdue remediation, and blind spots in response.

Impact: The organisation can lose time at the exact moment it needs speed, which raises the likelihood of larger incidents, longer dwell time, and more expensive recovery.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyVacancies create security and operational risk that must be prioritised and governed.
PR.AA-05 — Identity Management, Authentication, and Access ControlStaffing gaps raise the need for clear access, delegation, and least-privilege decisions.
RC.RP-01 — Recovery Plan ExecutionVacancies can weaken response and recovery execution when specialist coverage is thin.
Recommendation — Treat persistent specialist vacancies as risk to be prioritised in the enterprise risk program. Tighten access and delegation boundaries so critical duties do not depend on one person. Document and rehearse recovery steps so response capability survives temporary staffing gaps.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingUnderstaffing can delay alert review and incident triage, increasing time to detect and respond.
Recommendation — Ensure alert review and escalation remain covered even when specialist roles are vacant.
NIST Zero Trust (SP 800-207)SP 800-207 — Zero Trust ArchitectureThe answer explicitly prioritises zero trust controls to reduce blast radius when expertise is scarce.
Recommendation — Use zero trust principles to reduce reliance on scarce experts and shrink trust boundaries.
CIS Controls v8CIS-5 — Account ManagementCross-training and delegation only work when account ownership and access paths are controlled.
Recommendation — Keep account ownership and privileged access tightly assigned during staffing gaps.

Practitioner Guidance

What to prioritise: Protect the work that most directly reduces exposure, then push lower-risk tasks into playbooks, shared ownership, or temporary delegation. If a vacant role owns a control that can materially affect production security, treat that as a continuity issue, not a staffing inconvenience.

What to verify: Confirm that at least two people can execute the most critical actions, such as incident escalation, emergency access review, cloud policy changes, and recovery procedures. If you cannot produce that coverage, the vacancy is already degrading control reliability.

Common mistake: Leaders often try to preserve the full original scope with fewer people. A better decision is to trim or pause low-value work so the team can keep the highest-risk protections credible.

Practitioner takeaway: The test is not whether the role is open, but whether the organisation can still make fast, well-governed security decisions without depending on one exhausted expert.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org