When teams are short-staffed, they usually lose coverage in the places that require manual attention, such as access reviews, secret rotation, and third-party account oversight. That makes it easier for excessive privilege and dormant credentials to persist. In practice, the shortage widens the gap between policy and actual control.
Why This Matters for Security Teams
Skills shortages matter because identity and access controls depend on consistent execution, not just policy. When teams are under-resourced, routine work such as recertification, orphaned account cleanup, privilege elevation approval, and secret hygiene is delayed or skipped. That creates a control gap where excessive access can linger unnoticed, especially in environments with fast-changing cloud services, contractors, and machine identities. Guidance in the NIST Cybersecurity Framework 2.0 treats governance and continuous improvement as core outcomes, but staffing pressure often weakens both.
The risk is not only missed paperwork. Weak coverage can turn identity into a durable attack path, because stale privileges and shared credentials are exactly what attackers look for once they gain an initial foothold. This is especially true where access governance still depends on human review rather than automated policy enforcement, or where non-human identities are growing faster than control maturity. In practice, many security teams encounter privilege creep only after an audit finding, a breach review, or an account compromise has already exposed the control failure.
How It Works in Practice
Skills shortages increase risk in identity and access management because many of the highest-value controls are operational, repetitive, and easy to defer. Mature programmes separate the policy decision from the execution step, but lean teams often merge both into the same small group. That creates bottlenecks in joiner-mover-leaver processing, access certification, privileged account provisioning, and secret rotation. The result is slower remediation and more exceptions that never fully close.
In practice, the failure usually shows up in three places:
- Access reviews are completed late, with reviewers approving entitlements they do not fully understand.
- Privileged access is granted for convenience and left in place longer than intended.
- Service accounts, API keys, and other non-human identities outgrow their owners and become hard to trace.
That last issue is increasingly important. The OWASP Non-Human Identity Top 10 highlights how machine credentials can become unmanaged attack surface when ownership, lifecycle, and rotation are weak. A similar pattern appears in broader control libraries such as NIST SP 800-53 Rev 5 Security and Privacy Controls, which expects organisations to define access authorisation, review, and accountability, not merely issue entitlements.
Operationally, teams reduce risk by standardising approval paths, automating entitlement review where possible, binding every credential to an owner, and using logging to detect privilege drift early. The most effective programmes also reserve human effort for high-risk decisions, while letting automation handle routine renewals, rotations, and orphan detection. These controls tend to break down when identity data is fragmented across SaaS, cloud, and legacy systems because no single team can reliably see who has access to what.
Common Variations and Edge Cases
Tighter identity governance often increases administrative overhead, requiring organisations to balance stronger assurance against limited staff time and operational friction. That tradeoff becomes sharper in businesses with heavy contractor use, rapid cloud adoption, or large volumes of non-human identities, because the control workload grows faster than headcount. In those environments, best practice is evolving toward policy-as-code, automated recertification, and delegated ownership models, but there is no universal standard for this yet.
Some edge cases need special handling. Small security teams may be able to protect a narrow application estate with manual reviews, but that approach rarely scales to multi-cloud or M&A environments. Highly regulated sectors also face a different burden, because access governance may need to satisfy both internal security expectations and external assurance requirements such as PCI DSS v4.0. For organisations trying to improve control coverage without adding headcount, the practical focus should be on reducing discretionary access, improving inventory quality, and making ownership explicit for every account and secret.
Where identity controls intersect with broader security management, the CIS Controls v8 and ISO/IEC 27001:2022 Information Security Management both reinforce the same practical lesson: organisations need repeatable processes, not heroic manual effort. When those processes are understaffed, controls become dependent on memory and goodwill, which is never a reliable access strategy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Skills shortages weaken oversight of access governance and control assurance. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management suffers when staff cannot keep up with lifecycle actions. |
| OWASP Non-Human Identity Top 10 | Machine identities become risky when understaffed teams lose ownership and rotation discipline. | |
| CIS Controls v8 | 5 | Access review and entitlement hygiene are core safeguards against staffing-driven drift. |
Continuously manage accounts and privileges with automated checks and exception handling.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org