Skip to content
Go Back
CyberHQ® Executive Notes

Everyone Knows Security Runs Lean, But Why Does Nothing Change?

By Ian Yip 6 min read

Ask most CISOs privately and they’ll tell you exactly where their team runs lean. Nobody’s confused about it. But what’s less clear is why nothing changes, and I don’t think there’s one answer. For some organizations it’s peer benchmarking: everyone else’s team is just as lean and they get on with it. For others it's the budget conversation getting more challenging to win every year. Now we have the AI pitch to do more with fewer people. I’m not going to tell you which is your excuse, that’s for you to own, I’m here to kick off the discussion no one else wants to have.

 

Squad Depth & the bench dilemma

Let's frame this in a comparison. No matter which team sport you follow, football, basketball, rugby, cricket, etc… they all share one thing in common: a roster bigger than the number of players actually on the field at any given moment.

The extras aren't there for show. Injuries happen, suspensions happen, and nobody sustains peak output across a full season or tournament without rotation. A coach who plays the same starting lineup every game isn't being efficient. They're running down the team's ability to perform when the stakes are highest, usually right when it matters most.

Most cybersecurity teams don't get built with that same discipline.

Everyone's lean, but it's not about which layer, it's about how many jobs each person is doing.

Sport does occasionally push a player out of position, an injury crisis forces someone to cover an unfamiliar position for a game or two. But even then, that player isn't also expected to be the team's set-piece analyst, run opposition scouting, and handle strength and conditioning in the same week. The club builds specialist roles around the squad specifically so a player pulled out of position is covering one gap, not absorbing five people's jobs at once.

Security doesn't share that same framework because nobody's position has a boundary anymore. Wearing multiple hats is the standard.

Organizations run specialist roles thin on the calculated bet that they're not needed daily and can be brought in when something happens, on top of the person already maxed out at multitasking.

Though the data doesn't back that bet up.

Senior cybersecurity vacancies take the longest to fill of any role - more than a third of organizations need almost a year or more.

It's not because the people don't exist, it's that budget is now the leading reason these seats stay empty, not talent scarcity.

An organization that assumes it can always “bring someone in” has quietly decided it can absorb a gap at the exact moment it can least afford one. The fix isn't a longer vendor list. It's a relationship that needs to be activated before you actually need it.

Pressure doesn't create the gap, it just exposes the one you already had.

Teams that don't rotate players fade when the stakes rise, in the playoffs or in the finals, because that's when fatigue meets the moment that actually matters. It's the same pattern for security teams, except it's not only fatigue, it's coverage.

Only 11% of CISOs say their team is adequately staffed. The other 89% call their own teams stretched thin or understaffed. According to IANS Research and Artico Search's 2025 CISO benchmark survey, staffing growth slowed to just 7% this year, its lowest level in four years, even as the threat environment grew more complex. That shows that it's a well-known problem, with nine out of ten security leaders describing the exact gap on the record, in their own survey responses.

Overall security budget growth tells a similar story, slowing to 4% in 2025, the lowest rate in five years, down from 8% in 2024. That's not because the industry is shrinking. Gartner's latest forecast has global security spending reaching $248.9 billion in 2026, up 12.7%. The money's still flowing. It's just not landing in the operating budgets of the people running point on incidents, it's landing in tools and platforms, which is exactly the pattern that leaves teams over-tooled and under-staffed.

So let's bring in the AI pitch to solve that gap: do more with fewer people, but untested against what happens when your key specialists aren't there mid-incident. Even Gartner's own 2026 cybersecurity trends frame the AI-driven SOC as something that raises staffing and upskilling pressure, not something that erases it. Cybersecurity leaders must “prioritize people as much as technology,” in Gartner's own words, a distinction that rarely survives the budget meeting.

Questions worth considering

Do we actually have a bench, or is everyone juggling roles that were never meant to sit on one desk and calling it fine?

Most organizations I've worked with, it's the latter. Someone stepped up to cover the gap when it mattered, and the business kept letting them.

When did we last simulate two key people being out during a live incident, and was the outcome acceptable?

Almost nobody tests this and the tabletops assume full staffing and clean escalation. “We haven't tested it” isn't a training gap, it's a resourcing decision your organization made without knowing it made one.

Peer Perspectives

I put these questions to a selected group of senior security leaders: Are you resourced for a normal week, or your worst week in the last three years? Does your specialist bench include a standing arrangement that skips the normal procurement clock, or would you be starting from zero at the worst possible moment? 

Am I resourced for a normal week, or my worst week in the last three years? Honestly, neither. I run a small team wearing many hats, and that is true right across our organisation, not just in security. If I sized the roster for the worst week I have had, it would sit idle for the other fifty one. 
 
What makes that position interesting is who we serve. Our customers are large banks, so the standard we are held to is not the one a company our size would set for itself. Instead, it shows up as continual control assurance. Ultimately, our customers need to understand how we can affect their risk position, and I have come to appreciate why that process exists rather than treat it as pressure. It is the same question I ask of my own suppliers. 
 
My hardest week did not come from something we did. Like many organizations, it came from third party exposure with the potential to reach us. The work was not technical heroics. It was answering quickly and credibly what it meant for us, and therefore what it meant for our customers. Doing that properly takes people who already understand our environment, and it takes them to be able to respond on the day, not next week. 
 
So my bench is contracted rather than hired. Incident response, detection and response, and specialist testing all sit behind standing arrangements, scoped and signed while nothing is on fire. Just as importantly, I sit on the executive team, which means the decision to commit money mid-incident is mine to make on the spot. That does more to compress the clock than any clause in a retainer. If you are CISO without that delegation, it is worth arguing for as hard as you argue for headcount. A retainer you cannot activate until a purchase order clears is no much help in the first few hours. 
 
Additionally, depth is worthless if the knowledge resides in only one person’s head, or worse in a vendor’s “playbook”. I put deliberate effort into keeping our documented and easily accessible, so someone else can pick it up mid-crisis without me in the room. 
 
For me, squad depth is less about the number on the roster and more about how long it takes for a competent, authorised second pair of hands to start work. That is the measure I use when I ask myself whether we are ready. 

A lean cybersecurity team can be effective if the organisation has a strong risk management foundation. Responsibility is critical: asset and service owners must protect their domains and manage their own risks. Problems occur when security teams are assigned responsibilities outside their scope, making workloads unmanageable. Organisations with small security teams must embed risk management into daily operations and use it as a key performance metric for managers and risk owners. Sustainable protection is achieved only when the entire organisation, not just the security team, remains vigilant and accountable.

Security is an expense and an investment in prevention rather than profit. It is understandable that businesses limit the size of non-revenue-generating teams; this approach is both economical and rational. While revenue sustains the organisation, risk management guides decision-making and helps identify threats early. Effective risk management, supported by a strong incident response plan and a prepared team (Many IR members sit outside of security), enables the organisation to withstand adversity and maintain order.
 
Neglecting this exposes the business to significant risk. Even the largest cybersecurity team cannot succeed without cooperation from the broader organisation. The key is cultural: the business must prioritise protection by improving processes, implementing checks and balances, and investing in higher-quality systems. True security results from a culture where individuals understand how to manage conditions to create a secure environment. When this is achieved, protection becomes a shared pursuit of order rather than a burden.

The size of the team is irrelevant if we consider the operational burden that comes with poor risk management and cooperation in the organisation.

The View From Here

Squad size is a strategy decision and teams don't carry a bench because they enjoy paying for the players who don't start. They carry it because the season is long, the stakes escalate, and the cost of finding out you were too thin lands exactly when you can least afford it.

AI can genuinely take on work and ease the load from your team and should be used. But just don’t let it sit in the same budget line as headcount.

I’m not saying we all need to be resourced for our worst week, that’s not reality nor sustainable. But we do need to know how prepared we are when things go wrong, who can be hands on and how quickly. That’s an honest check we should all be having.

Security teams are not playing a completely different game, they're just less willing to fight for a change when we all know that everyone on the roster is already covering for someone else.

Board-Ready Risk Reporting, Every Time You Need It

CyberHQ® turns fragmented tool outputs into one continuously maintained, evidence-based view of financial risk exposure, defensible to your board, regulator, and insurer, regardless of which specialist is available to produce it.

Ian Yip

Ian Yip

Ian is the Founder and CEO of Avertro, a cybersecurity software company helping organizations validate their defense, justify spend, or prove a state of resilience with confidence. Ian has 25+ years of cybersecurity, business, and leadership experience in a variety of global roles spanning advisory, strategy, sales, marketing, product, services, and technology functions in some of the world’s leading companies including McAfee, EY, and IBM. Avertro's flagship product, CyberHQ® is the Resilience Command Platform that directs your defense. It translates technical signals into quantifiable, governance-ready intelligence, empowering you to validate cyber effectiveness, prove defensible resilience, and optimize security-per-dollar with absolute confidence.

Share: LinkedIn

Board-Ready Risk Exposure, Continuously

CyberHQ® quantifies cyber risk in financial terms. Get the evidence your board, regulator, and insurer can rely on.

Latest Articles

Everyone Knows Security Runs Lean, But Why Does Nothing Change?
CyberHQ® Executive Notes

Everyone Knows Security Runs Lean, But Why Does Nothing Change?

Most CISOs already know their team is running lean. Three security leaders explain why staffing keeps falling and what it takes to build a real bench.

September 09, 2026

Building Resilience Beyond Compliance: UK Cyber Security & Resilience Bill
Insights

Building Resilience Beyond Compliance: UK Cyber Security & Resilience Bill

How to prepare for the UK Cyber Security and Resilience Bill by building resilience readiness beyond compliance, before requirements become mandatory.

July 26, 2026

The UK Governance Blind Spot: Framework Alignment Doesn't Prove Resilience
Insights

The UK Governance Blind Spot: Framework Alignment Doesn't Prove Resilience

Framework alignment no longer proves cyber resilience. See why UK boards and regulators now expect evidence of operational continuity, not just compliance.

July 26, 2026