The Great Resignation is the broad wave of voluntary employee departures that followed the COVID-19 disruption period. In cybersecurity, it matters because it tightens an already constrained talent market, raises retention risk, and increases the operational load on the people who remain. That combination can weaken resilience and slow security programmes.
What the Great Resignation Means for Cybersecurity Operations
The Great Resignation is not a control failure by itself, but it changes the operating environment that security teams depend on. Fewer experienced people, more churn, and longer hiring cycles mean routine work absorbs more attention, while knowledge transfer, on-call coverage, and review quality can all degrade.
That matters most in functions that rely on continuity, such as identity governance, incident response, security engineering, vulnerability management, and cloud or platform administration. When staff turnover rises, the organisation often loses informal process knowledge before it loses documented process steps, which creates hidden fragility.
How Workforce Churn Changes Security Posture
Security posture weakens when the team cannot keep pace with the same volume of access reviews, alert handling, configuration changes, and remediation tasks. The issue is usually not a single dramatic gap, but accumulated delay, missed handoffs, and reduced scrutiny across many small decisions.
Retention pressure also tends to concentrate risk in a few senior operators. If the remaining staff are carrying too much institutional knowledge, then vacations, resignations, and role changes can create single points of failure in the security function. In practice, this can slow containment, extend recovery, and reduce confidence in control execution.
Operational Pressure Points and Control Friction
The most visible pressure points are usually documentation debt, understaffed review processes, and brittle segregation of duties. Over time, teams under strain may accept exceptions more quickly, defer cleanup work, or rely on a small number of people who know how the environment really works.
That friction is especially risky in environments with many standing privileges, complex approval chains, or manual approval steps. When control ownership is unclear, the organisation may still have the policy on paper but lose the practical ability to execute it consistently.
A useful lens is the broader governance challenge captured in NIST Cybersecurity Framework 2.0, which helps teams connect workforce stability to governance, protection, detection, response, and recovery outcomes.
Why This Matters for Resilience and Recovery
The Great Resignation affects resilience because recovery depends on people as much as process. If the organisation cannot rapidly reassign ownership, replace tribal knowledge, or sustain operations during a transition, then even mature technical controls can underperform.
For teams managing sensitive access and automation, the same workforce pressure can make it harder to keep credentials, review cycles, and offboarding work current. In that context, the operational burden becomes a security issue, not just an HR issue, because delayed action compounds exposure.
Some organisations use the discipline described in NHI Mgmt Group’s Ultimate Guide to Non-Human Identities to understand how concentrated operational ownership and weak lifecycle handling can create broader exposure when teams are already stretched.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC — Organizational Context | Workforce churn changes operating context and security capacity. |
| PR.AT — Awareness and Training | Churn increases the need to preserve process knowledge and role readiness. | |
| RS.RP — Response Planning | High turnover can slow incident execution and handoffs during response. | |
| Recommendation — Reflect turnover risk in governance, ownership, and capacity planning. Refresh training and cross-training so critical security tasks remain covered. Validate response runbooks and backup ownership before staff changes create gaps. | ||
| CIS Controls v8 | 6 — Access Control Management | Churn raises the risk of stale access, weak ownership, and missed revocation. |
| 17 — Incident Response Management | Reduced staffing and knowledge concentration can impair response execution. | |
| Recommendation — Reassign and revoke access promptly when roles change or staff leave. Maintain alternate responders and test incident handoffs regularly. | ||
Practitioner Guidance
Why practitioners should care: Treat workforce churn as a security capacity problem, not only a hiring problem. When experienced staff leave, the first losses are often review quality, escalation speed, and the ability to spot subtle control drift.
Common misunderstanding: Documentation alone does not preserve security capability. If only one or two people can actually run a process, then the control is more fragile than it appears on paper.
Practitioner takeaway: Build redundancy around critical security decisions, because resilience erodes faster when knowledge, approvals, and operational ownership are concentrated in too few hands.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org