Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when they cannot hire…
Governance, Ownership & Risk

What should organisations do when they cannot hire enough security specialists in the near term?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

They should spread security knowledge beyond the core team, raise awareness across the business, and build for long-term resilience. Rotating staff into security functions, running phishing education, and making security part of everyday work all reduce bottlenecks. At the same time, leaders should invest in tools and processes that scale with future demand rather than current headcount alone.

How to handle the short-term security talent gap without creating a long-term bottleneck

The practical response is to widen the security operating model, not just the hiring funnel. Organisations need to distribute basic security capability into adjacent teams, standardise repeatable work, and make security decisions easier to execute without waiting on a specialist queue. That usually means clearer ownership, simpler guardrails, and more automation around routine controls.

When the core team is too small, the real constraint is often decision throughput rather than raw knowledge. If every review, exception, or awareness issue must pass through a handful of specialists, security becomes a service desk. A better model is to reserve the specialists for high-risk decisions while pushing common checks, education, and response patterns closer to the teams that already own the systems.

That shift also changes how resilience should be built. Training, secure defaults, and process design matter more when there is no spare capacity to compensate for weak control design. A strong near-term answer is to reduce the number of things that depend on individual heroics, and to make the organisation less sensitive to staffing volatility through documentation, cross-training, and consistent control execution.

Where to spread capability first

Start with the security work that is frequent, repetitive, and easy to standardise. That includes awareness activity, basic policy enforcement, exception handling, phishing resilience, access review support, and routine hygiene checks. These are the areas where a non-specialist can add value quickly if the process is simple and the escalation path is clear.

It also helps to rotate staff into security-adjacent responsibilities rather than trying to isolate security knowledge inside one team. Rotations build familiarity with the business and reduce single points of failure for control ownership. The goal is not to turn every employee into a security operator, but to make security part of ordinary operational practice.

For organisations that are already stretched, scaling the right control set matters more than adding more manual review. NIST Cybersecurity Framework 2.0 is useful here because it reinforces governance, protection, detection, response, and recovery as a coordinated operating model rather than a specialist-only function. Where access decisions are part of the burden, NIST SP 800-53 Rev 5 Security and Privacy Controls gives a stronger control structure for standardising who approves, who reviews, and what evidence should exist.

How to invest for resilience when headcount is constrained

The key design choice is to build security processes that scale with demand instead of staffing. That means using tooling, templates, and workflow automation for repeatable tasks, and reserving human judgment for cases where context or risk is genuinely high. If a control can only work when a specialist is available in real time, it is probably too brittle for a lean organisation.

Leaders should also look for bottlenecks created by unclear ownership. Security work slows down when teams do not know whether the issue belongs to IT, engineering, operations, or a central security function. Clear RACI-style ownership, even if lightweight, is often more valuable than adding more approval layers.

For organisations that depend on digital access, identity and authentication controls deserve attention because they reduce the volume of manual intervention needed from security staff. NIST SP 800-63 Digital Identity Guidelines is relevant for strengthening authentication choices, while NIST Privacy Framework is useful where the business needs a repeatable way to classify and govern sensitive data handling without relying on ad hoc expert review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextThe question is about operating model choices under staffing constraints.
GV.OC-03 — Roles, Responsibilities, and AuthoritiesSpreading security work requires clear accountability across teams.
PR.AT-01 — Awareness and TrainingSecurity knowledge diffusion depends on broader awareness and repeatable training.
Recommendation — Define shared security ownership and embed it into business operating decisions. Assign explicit security responsibilities to adjacent teams and leaders. Deliver role-based security awareness so non-specialists can execute routine controls.

Practitioner Guidance

What to prioritise: Focus first on the tasks that are high-frequency, low-complexity, and currently queue behind the security team, because those are the fastest source of relief. If a task can be taught, templated, or automated, it should be moved out of the specialist bottleneck before you attempt more ambitious redesigns.

Decision rule: If the control depends on one person or one team to keep the organisation safe, redesign it; if the control can be executed consistently by adjacent functions with guardrails, distribute it. The right measure is not whether security owns everything, but whether security can still supervise effectively when demand rises.

What to verify: Check that non-security teams have clear escalation paths, documented playbooks, and enough authority to act on common issues without waiting for specialist approval. Also verify that leadership has committed to reducing manual dependency, not just absorbing the current backlog.

Practitioner takeaway: The best short-term response to a security hiring gap is to reduce dependence on scarce experts while preserving strong oversight, because resilience comes from distributed capability, not from trying to staff every control with specialists.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org