Cybersecurity Insights, News & Resources | Avertro

Security Runs Lean. Why Nothing Changes | Avertro CyberHQ®

Written by Ian Yip | Sep 9, 2026, 11:24:50 PM

Ask most CISOs privately and they’ll tell you exactly where their team runs lean. Nobody’s confused about it. But what’s less clear is why nothing changes, and I don’t think there’s one answer. For some organizations it’s peer benchmarking: everyone else’s team is just as lean and they get on with it. For others it's the budget conversation getting more challenging to win every year. Now we have the AI pitch to do more with fewer people. I’m not going to tell you which is your excuse, that’s for you to own, I’m here to kick off the discussion no one else wants to have.

 

Squad Depth & the bench dilemma

Let's frame this in a comparison. No matter which team sport you follow, football, basketball, rugby, cricket, etc… they all share one thing in common: a roster bigger than the number of players actually on the field at any given moment.

The extras aren't there for show. Injuries happen, suspensions happen, and nobody sustains peak output across a full season or tournament without rotation. A coach who plays the same starting lineup every game isn't being efficient. They're running down the team's ability to perform when the stakes are highest, usually right when it matters most.

Most cybersecurity teams don't get built with that same discipline.

Everyone's lean, but it's not about which layer, it's about how many jobs each person is doing.

Sport does occasionally push a player out of position, an injury crisis forces someone to cover an unfamiliar position for a game or two. But even then, that player isn't also expected to be the team's set-piece analyst, run opposition scouting, and handle strength and conditioning in the same week. The club builds specialist roles around the squad specifically so a player pulled out of position is covering one gap, not absorbing five people's jobs at once.

Security doesn't share that same framework because nobody's position has a boundary anymore. Wearing multiple hats is the standard.

Organizations run specialist roles thin on the calculated bet that they're not needed daily and can be brought in when something happens, on top of the person already maxed out at multitasking.

Though the data doesn't back that bet up.

Senior cybersecurity vacancies take the longest to fill of any role - more than a third of organizations need almost a year or more.

It's not because the people don't exist, it's that budget is now the leading reason these seats stay empty, not talent scarcity.

An organization that assumes it can always “bring someone in” has quietly decided it can absorb a gap at the exact moment it can least afford one. The fix isn't a longer vendor list. It's a relationship that needs to be activated before you actually need it.

Pressure doesn't create the gap, it just exposes the one you already had.

Teams that don't rotate players fade when the stakes rise, in the playoffs or in the finals, because that's when fatigue meets the moment that actually matters. It's the same pattern for security teams, except it's not only fatigue, it's coverage.

Only 11% of CISOs say their team is adequately staffed. The other 89% call their own teams stretched thin or understaffed. According to IANS Research and Artico Search's 2025 CISO benchmark survey, staffing growth slowed to just 7% this year, its lowest level in four years, even as the threat environment grew more complex. That shows that it's a well-known problem, with nine out of ten security leaders describing the exact gap on the record, in their own survey responses.

Overall security budget growth tells a similar story, slowing to 4% in 2025, the lowest rate in five years, down from 8% in 2024. That's not because the industry is shrinking. Gartner's latest forecast has global security spending reaching $248.9 billion in 2026, up 12.7%. The money's still flowing. It's just not landing in the operating budgets of the people running point on incidents, it's landing in tools and platforms, which is exactly the pattern that leaves teams over-tooled and under-staffed.

So let's bring in the AI pitch to solve that gap: do more with fewer people, but untested against what happens when your key specialists aren't there mid-incident. Even Gartner's own 2026 cybersecurity trends frame the AI-driven SOC as something that raises staffing and upskilling pressure, not something that erases it. Cybersecurity leaders must “prioritize people as much as technology,” in Gartner's own words, a distinction that rarely survives the budget meeting.

Questions worth considering

Do we actually have a bench, or is everyone juggling roles that were never meant to sit on one desk and calling it fine?

Most organizations I've worked with, it's the latter. Someone stepped up to cover the gap when it mattered, and the business kept letting them.

When did we last simulate two key people being out during a live incident, and was the outcome acceptable?

Almost nobody tests this and the tabletops assume full staffing and clean escalation. “We haven't tested it” isn't a training gap, it's a resourcing decision your organization made without knowing it made one.