Organisations should respond by broadening recruitment, developing younger talent, and adapting to changing skill needs rather than waiting for perfect staffing. The practical challenge is to maintain security quality while building capacity. That means investing in training, using process discipline, and prioritising controls that reduce dependence on scarce specialist intervention for routine identity work.
Closing the talent gap without lowering the bar
The right response is to design security work so that scarce experts spend time on judgement-heavy activities, not on repetitive identity hygiene. That means hiring more broadly, accelerating junior development, and simplifying the operating model so routine access review, credential rotation, and offboarding are process-driven rather than hero-driven. Capacity should expand without expanding exposure.
A useful way to think about the talent gap is as a control-design problem. If a control only works when a handful of specialists are available every time, it is fragile at scale. Teams get better resilience when they reduce dependence on ad hoc expertise and build workflows that are observable, documented, and repeatable across shifts, regions, and business units.
That is especially important where the security work involves identity and secrets handling, because the most common failure mode is not lack of intent but inconsistent execution. NHIMG’s Ultimate Guide to NHIs notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which shows how quickly operational gaps turn into security gaps when the process is manual or poorly owned.
Build capability through process, training, and control design
The practical answer is to shift the organisation from artisanal security operations to disciplined security operations. Training matters, but training alone is not enough unless the work itself is structured so that new staff can execute safely. Good teams pair coaching with checklists, peer review, clear escalation paths, and controls that fail closed when a task is missed.
For identity-heavy work, this usually means standardising provisioning, review, and revocation steps; removing one-off exceptions from normal paths; and using automation where the decision is routine and bounded. The goal is not to automate judgement out of security, but to reserve expert judgement for exceptions, unusual privilege, and ambiguous ownership. That keeps throughput high without making security quality depend on individual memory.
External guidance aligns with that approach. The NIST Cybersecurity Framework 2.0 gives organisations a way to organise work across govern, identify, protect, detect, respond, and recover, which is useful when capacity is constrained. For the control layer itself, NIST SP 800-53 Rev 5 Security and Privacy Controls is helpful because it gives a prescriptive basis for access control, auditing, and configuration discipline that can be operationalised by a broader team.
What good looks like when staffing is thin
When organisations respond well to the talent gap, security outcomes stay stable even as staffing changes. The evidence is in lower variance: fewer missed revocations, fewer stale credentials, faster onboarding to the security team, and less dependency on a small set of senior people for every review or exception.
What to measure: Track how much of the control set is truly repeatable by non-specialists, how quickly new analysts can perform routine tasks correctly, and how often exceptions are needed to complete standard identity work. If quality drops when one experienced person is absent, the process is still too dependent on tacit knowledge.
Common mistake: Treating the talent shortage as a reason to postpone control maturity. Organisations often try to protect themselves by holding tasks in expert hands, but that increases fragility. A better posture is to simplify the work, standardise the decision points, and use automation to absorb volume while people focus on review and exception handling.
Practitioner takeaway: The safest way to address the talent gap is to make secure behaviour easier to execute than insecure shortcuts. Broad hiring and junior development help, but the real win comes from controls that remain effective when skilled staff are scarce, busy, or new.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.GV — Governance | A talent-gap response needs governance that assigns security work and accountability. |
| PR.AC — Identity Management, Authentication, and Access Control | The question highlights routine identity work that should not depend on scarce specialists. | |
| RS.CO — Response Coordination | A thinly staffed security function needs clear escalation and coordination when exceptions arise. | |
| Recommendation — Define ownership and decision rights so security work remains controlled as teams scale. Standardise access control and identity operations so routine tasks are repeatable and low-friction. Set clear escalation paths so exceptions do not stall routine security operations. | ||
| CIS Controls v8 | 5 — Account Management | Broader recruitment should not weaken account lifecycle controls, especially provisioning and revocation. |
| 6 — Access Control Management | Maintaining security outcomes depends on disciplined access governance as staffing varies. | |
| 8 — Audit Log Management | Observable, repeatable controls help teams verify that routine identity work was completed correctly. | |
| Recommendation — Automate account lifecycle tasks to reduce dependence on scarce specialists. Enforce least privilege and periodic review so access decisions remain consistent. Use logging and review evidence to confirm control execution without manual heroics. | ||
Related resources from NHI Mgmt Group
- How should organisations reduce password-related lockouts without weakening security?
- How should organisations reduce access friction for frontline workers without weakening security?
- How should organisations move away from VPN-first remote access without weakening security?
- How should organisations modernise password policy without weakening identity security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org