PHD Discussions Logo

Ask, Learn and Accelerate in your PhD Research

Question Icon Post Your Answer

Question Icon

3 months ago in Cybersecurity By Shreya K

How Many Cybersecurity Staff Do We Actually Need‑ Can I have a Practical Guide ?

We're trying to build a business case for our cybersecurity team's growth. Are there any practical guidelines or benchmarks for estimating how many people and how much budget a company should dedicate to security?

All Answers (3 Answers In All)

By Pranav Answered 2 months ago

There's no one-size-fits-all answer, but good frameworks like the NIST Cybersecurity Framework can help you scope your needs. It boils down to three things: your industry risk, how complex your tech stack is, and what regulations you must follow. A common industry rule of thumb is to allocate 3-6% of your total IT budget to security. For Operational Technology (OT/ICS), the skills gap is huge, so start with at least one dedicated specialist who can work with your IT team. The key is to prioritize based on your top risks first.

Replied 2 months ago

By Shreya K

Hi, thank you Pranav. this was really helpful. I like how you broke it down by risk and complexity instead of just headcount. The OT/ICS note was especially useful for our environment.

By Bindya Answered 2 months ago

From what I’ve seen working with mid-sized organizations, staffing often grows reactively instead of strategically. A practical approach is to map people directly to functions: governance, detection, response, and engineering. In smaller companies, one person may wear multiple hats, but once incidents and compliance reporting start consuming too much time, that’s a clear signal you’re understaffed. In many cases, companies underestimate how much effort monitoring and incident response alone can take on a 24/7 basis.

Replied 2 months ago

By Shreya K

Thanks for sharing your experience Bindya. this makes a lot of sense. The idea of mapping staff to security functions is a really practical way to look at it. Appreciate the real-world insight!

By Puneet Chadha Answered 1 month ago

I usually advise organizations to think beyond just internal headcount. In my consulting work, I’ve seen teams stay lean internally but rely heavily on managed security services for SOC, threat intel, or compliance support. This works well if leadership understands what must remain in-house, like risk ownership and decision-making. Instead of asking “how many people,” I often ask, “what work must be done daily, and who is accountable?” That answer usually defines the staffing model pretty clearly.

Replied 1 month ago

By Shreya K

Hello, thank you for this perspective Puneet. very insightful. The mix of internal staff and managed services is something we’re considering, and your framing around accountability really helps clarify it.

Your Answer