Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do organisations get wrong when they think…
Cyber Security

What do organisations get wrong when they think cybersecurity hiring will solve talent shortages on its own?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Cyber Security

Hiring alone rarely fixes a security talent gap because demand is broad and competition is intense. Organisations also need internal development, tuition support, and clearer pathways into specialist roles. When they rely only on external recruitment, they miss candidates who can grow into the work and struggle to build durable capability across the security function.

Why This Matters for Security Teams

Hiring is only one part of security capacity, and it is often the slowest path to impact. Organisations underestimate how much of the shortage is really a pipeline problem: too few candidates with hands-on experience, too much competition for the same profiles, and too little internal mobility into specialist roles. The result is a persistent gap between open reqs and operational coverage, even when budgets increase.

For NHI-heavy environments, the issue is sharper because the work is tied to service accounts, secrets, rotation, and workload visibility rather than just headcount. NHIs outnumber human identities by 25x to 50x in modern enterprises, and only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs — Why NHI Security Matters Now. That means a new hire cannot compensate for weak process, weak tooling, or unclear ownership.

Security teams also get trapped by the assumption that external recruitment will automatically create durable capability. In practice, many organisations discover the shortage only after incident response, audit findings, or a privileged access review has already exposed the gap, rather than through intentional workforce planning.

How It Works in Practice

Effective talent strategy treats hiring as an input, not the solution. The strongest programmes combine external recruiting with apprenticeship-style development, cross-training from adjacent IT and engineering functions, and role ladders that let practitioners move from generalist work into IAM, cloud security, detection engineering, or NHI operations. That matters because security work is increasingly specialised, and the operational skills required to manage secrets, identity lifecycle, and access policy rarely appear fully formed in the market.

This is especially true where identity and workload security intersect. Current guidance suggests teams should pair staffing decisions with concrete operating controls: inventory the identities that matter, assign clear ownership, and make rotation, offboarding, and exception handling routine. For broader context, see Top 10 NHI Issues and the CISA cyber threat advisories for the kinds of identity-driven attack patterns that keep recurring.

  • Use hiring to fill near-term gaps, but build internal progression paths for analysts, administrators, and developers who already understand the business.
  • Fund certifications, lab time, and tuition support so employees can move into specialist work without leaving the organisation.
  • Map each role to a small set of operational outcomes, such as secrets rotation, access reviews, or alert triage, instead of vague “security support.”
  • Measure time-to-productivity, not just time-to-fill, because a fast hire without domain context can still leave controls weak.

For NHI security specifically, the operational goal is to reduce dependence on individual heroics by building repeatable controls around credential inventory, rotation, and access governance, as described in the Ultimate Guide to NHIs — Key Challenges and Risks. These controls tend to break down when teams hire into a fragmented operating model because no one owns the full lifecycle of identities and secrets.

Common Variations and Edge Cases

Tighter hiring plans often increase short-term cost and manager overhead, requiring organisations to balance speed against capability-building. That tradeoff becomes more visible in smaller teams, regulated environments, and distributed enterprises where the same person may cover IAM, cloud, and compliance work at once.

There is no universal standard for how much should be solved by hiring versus development, but current guidance suggests the right mix depends on how specialised the work is and how much institutional knowledge is embedded in the stack. In some organisations, the bottleneck is not talent availability but the absence of a training path that turns junior staff into effective operators. In others, external recruitment is necessary for niche roles, but it must be paired with documentation, mentorship, and backfill planning so knowledge does not sit with one person.

The edge case to watch is a team that keeps adding specialists without fixing operational clarity. If secrets live in code, ownership is ambiguous, or access reviews are manual, new hires spend their time compensating for process debt instead of reducing risk. That is why workforce planning and control design have to move together, not in sequence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Identity inventory and ownership are central to building repeatable NHI capability.
OWASP Agentic AI Top 10Autonomous workloads need operational governance, not just extra headcount.
CSA MAESTROMAESTRO aligns workforce design with secure operating models for AI systems.
NIST CSF 2.0GV.OC-01Cybersecurity talent strategy should support organisational roles and responsibilities.
NIST AI RMFGOVERNAI RMF governance emphasizes capability, accountability, and role clarity for complex systems.

Staff to support runtime identity control, policy enforcement, and incident response for agentic systems.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org