Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should organisations respond to the cybersecurity talent…
Identity Beyond IAM

How should organisations respond to the cybersecurity talent gap without weakening security outcomes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

Organisations should respond by broadening recruitment, developing younger talent, and adapting to changing skill needs rather than waiting for perfect staffing. The practical challenge is to maintain security quality while building capacity. That means investing in training, using process discipline, and prioritising controls that reduce dependence on scarce specialist intervention for routine identity work.

Closing the talent gap without lowering the bar

The right response is to design security work so that scarce experts spend time on judgement-heavy activities, not on repetitive identity hygiene. That means hiring more broadly, accelerating junior development, and simplifying the operating model so routine access review, credential rotation, and offboarding are process-driven rather than hero-driven. Capacity should expand without expanding exposure.

A useful way to think about the talent gap is as a control-design problem. If a control only works when a handful of specialists are available every time, it is fragile at scale. Teams get better resilience when they reduce dependence on ad hoc expertise and build workflows that are observable, documented, and repeatable across shifts, regions, and business units.

That is especially important where the security work involves identity and secrets handling, because the most common failure mode is not lack of intent but inconsistent execution. NHIMG’s Ultimate Guide to NHIs notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which shows how quickly operational gaps turn into security gaps when the process is manual or poorly owned.

Build capability through process, training, and control design

The practical answer is to shift the organisation from artisanal security operations to disciplined security operations. Training matters, but training alone is not enough unless the work itself is structured so that new staff can execute safely. Good teams pair coaching with checklists, peer review, clear escalation paths, and controls that fail closed when a task is missed.

For identity-heavy work, this usually means standardising provisioning, review, and revocation steps; removing one-off exceptions from normal paths; and using automation where the decision is routine and bounded. The goal is not to automate judgement out of security, but to reserve expert judgement for exceptions, unusual privilege, and ambiguous ownership. That keeps throughput high without making security quality depend on individual memory.

External guidance aligns with that approach. The NIST Cybersecurity Framework 2.0 gives organisations a way to organise work across govern, identify, protect, detect, respond, and recover, which is useful when capacity is constrained. For the control layer itself, NIST SP 800-53 Rev 5 Security and Privacy Controls is helpful because it gives a prescriptive basis for access control, auditing, and configuration discipline that can be operationalised by a broader team.

What good looks like when staffing is thin

When organisations respond well to the talent gap, security outcomes stay stable even as staffing changes. The evidence is in lower variance: fewer missed revocations, fewer stale credentials, faster onboarding to the security team, and less dependency on a small set of senior people for every review or exception.

What to measure: Track how much of the control set is truly repeatable by non-specialists, how quickly new analysts can perform routine tasks correctly, and how often exceptions are needed to complete standard identity work. If quality drops when one experienced person is absent, the process is still too dependent on tacit knowledge.

Common mistake: Treating the talent shortage as a reason to postpone control maturity. Organisations often try to protect themselves by holding tasks in expert hands, but that increases fragility. A better posture is to simplify the work, standardise the decision points, and use automation to absorb volume while people focus on review and exception handling.

Practitioner takeaway: The safest way to address the talent gap is to make secure behaviour easier to execute than insecure shortcuts. Broad hiring and junior development help, but the real win comes from controls that remain effective when skilled staff are scarce, busy, or new.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.GV — GovernanceA talent-gap response needs governance that assigns security work and accountability.
PR.AC — Identity Management, Authentication, and Access ControlThe question highlights routine identity work that should not depend on scarce specialists.
RS.CO — Response CoordinationA thinly staffed security function needs clear escalation and coordination when exceptions arise.
Recommendation — Define ownership and decision rights so security work remains controlled as teams scale. Standardise access control and identity operations so routine tasks are repeatable and low-friction. Set clear escalation paths so exceptions do not stall routine security operations.
CIS Controls v85 — Account ManagementBroader recruitment should not weaken account lifecycle controls, especially provisioning and revocation.
6 — Access Control ManagementMaintaining security outcomes depends on disciplined access governance as staffing varies.
8 — Audit Log ManagementObservable, repeatable controls help teams verify that routine identity work was completed correctly.
Recommendation — Automate account lifecycle tasks to reduce dependence on scarce specialists. Enforce least privilege and periodic review so access decisions remain consistent. Use logging and review evidence to confirm control execution without manual heroics.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org