TL;DR
Security capacity is easiest to cut when nothing is visibly on fire, which can make preparedness look like unused labor.
Recent CISA workforce cuts and a later pledge to restore 600 positions make the problem unusually visible: cyber capability doesn’t rebuild at incident speed.
The better leadership test is not utilization. It’s whether the organization can absorb a serious incident without discovering that one exhausted person was the control.

Security capacity looks wasteful when nothing is burning. The incident channel is quiet, the queue is manageable and a senior responder who isn’t actively responding to anything can start to look like expensive empty space on a staffing sheet. That’s usually when somebody gets clever with the math.
The role is consolidated. The second person who knows the ugly part of the identity stack is declared redundant. Regional coverage gets thinner. Training gets pushed because production work is measurable and preparedness mostly isn’t. On a normal Tuesday, the spreadsheet looks cleaner. Then the pager goes off, and the spreadsheet discovers what it removed.
The Spreadsheet Sees Idle
Cybersecurity has a measurement problem that often gets disguised as a staffing problem. We are very good at counting visible work: alerts closed, vulnerabilities patched, tickets handled and assessments completed. We are much worse at pricing the ability to handle the thing that hasn’t happened yet.
That ability can look suspiciously like slack. A senior responder who has enough room to think. Two people who can each perform a critical function even though only one is needed during normal operations. An engineer who remembers why the ugly exception exists because they were there when it was made. A regional advisor whose value sits partly inside relationships thatdon’t not generate tickets.
Put those people into a utilization model and some will look expensive. Put them into a real incident and the arithmetic changes quickly. NIST’s current incident-response guidance treats incident response as part of cybersecurity risk management across the organization, not as a task that begins after detection. If response capability has to exist before the event, some of what leadership is buying will look quiet before it looks valuable.
The hard part is that quiet capacity and useless capacity can look almost identical from far enough away. That’s exactly why a spreadsheet built around ordinary-week utilization is such a weak instrument for deciding what the organization can safely lose.
CISA Is Running the Experiment in Public
The current fight over the Cybersecurity and Infrastructure Security Agency makes the problem unusually visible. In June, Sen. Mark Warner said CISA had lost nearly one-third of its workforce since January 2025, primarily senior career officials. In May, Sen. Maggie Hassan separately wrote that CISA had lost more than a third of its workforce in 2025, including almost all of its senior leaders.
Those are statements from elected officials, not an independent census of the agency, so I wouldn’t treat either percentage as a sacred measurement. The direction is still difficult to miss. CISA lost substantial experienced capacity, and on June 28 Warner publicly welcomed what he described as CISA’s plan to rehire 600 federal employees.
In her May letter to CISA’s acting director, Hassan put it plainly:
In 2025, for example, CISA lost more than a third of its workforce, including almost all its senior leaders, raising questions in the private sector and Congress about the direction of the agency.
There’s a useful detail on the other side of the aisle too. In January, the Republican-led House Homeland Security Committee said its FY2026 DHS appropriations package included $20 million to strengthen the CISA workforce and directed the agency to maintain sufficient staffing, preserve regional field offices and ensure every state and territory had dedicated cybersecurity-advisor support.
The politics are different, but the operational fact underneath them is not: cyber capability has to be standing there before the bad day arrives. That doesn’t mean every cut is reckless or every security role is sacred. It means leadership should understand what a role is buying before deciding that today’s unused capacity is tomorrow’s safe savings.
Capacity Is More Than Headcount
A lazy version of this argument would be “never cut security people.” I don’t buy that. Security organizations can get bloated, teams can keep doing work long after the reason disappeared and a large headcount can still produce a weak program.
Headcount is not capability, but capability is not headcount-free either. When an experienced person leaves, the organization can lose more than one line on an org chart. It may lose the memory of why a control was built a certain way, the person who knows which vendor actually answers after midnight, the responder who can separate familiar noise from the first five minutes of something ugly and the second pair of hands that lets the first responder sleep before hour twenty-six.
Some of that can be documented. Good teams document aggressively. Some of it lives in what people have seen, who they know and what they notice before they can fully explain why it feels wrong.
GAO’s July review of the Federal Rotational Cyber Workforce Program is a useful reminder that building this kind of depth is not automatic. GAO reported that 634 employees applied to the program over its life, while only eight were approved to serve rotations. It also found the program had effectively been halted after low participation and shifting priorities.
The point is not that rotations solve the workforce problem. The point is that judgment, cross-agency familiarity and operational depth take deliberate repetition to build. Once that depth leaves, a requisition is not the same thing as replacement.
The Utilization Trap
A security function run at permanent full utilization is a system with no shock absorber. It can look wonderfully efficient right up until something abnormal happens, then every person pulled into response creates another hole behind them. Vulnerability work pauses. Access reviews slip. Engineering projects stall. Someone who already owns two critical systems inherits a third because the one person who knew it best is now living in the incident bridge.
This is where utilization and readiness stop being the same thing. The corporate instinct is to ask whether people are busy enough. Security leadership has to ask something more useful: busy enough for which day?
A normal week and a serious incident are different operating modes. Designing the team entirely around the first and expecting it to absorb the second is like sizing emergency power around average grid demand. It works beautifully until the reason you bought emergency power finally shows up.
That is why I am suspicious of the phrase “extra capacity.” Extra compared with what: the average ticket queue, last quarter’s incident count or the worst event the company has already survived? A spare tire is underutilized right up until the interesting part of the trip.
Run the Incident-Day Test
Before cutting a security team, I would want a different sheet. Not names and salaries first. Capabilities. Take the credible incident you least want next quarter and run the staffing model against it.
Who is on the bridge in the first hour, and who can replace them six hours later? Which critical functions have one person who actually understands the machinery? What normal security work stops while response is underway? Which partner or vendor relationships disappear when one employee leaves?
Then look at the second day, because that is where the fantasy of unlimited human capacity usually gets expensive. Who slept? Who is making consequential decisions after sixteen hours awake? Who can communicate with executives while somebody else stays close enough to the technical detail to know whether the story is drifting away from reality?
There is a difference between redundancy and resilience. Redundancy is two people who can do the same job. Resilience is having enough depth, memory and relationships that the system can take a hit without turning one exhausted person into the architecture.
Resilience is having enough depth, memory and relationships that the system can take a hit without turning one exhausted person into the architecture.
If the cuts still make sense after that test, make them. Security should not be exempt from hard choices merely because the work is scary. But the choice should be explicit: this is the capability we are reducing, this is the failure mode we are accepting and this is what we will not be able to recreate quickly if we guessed wrong.
That is a much cleaner conversation than arguing about benchmark headcount or pretending there is a universal ratio of security people to employees. A board does not need to know whether the team looks lean. It needs to know what the organization can still do when the incident consumes the people normally doing everything else.
That is the capacity number. If the answer depends on calling back the people you cut six months earlier, you did not save capacity. You spent it.
Resources
U.S. Sen. Mark Warner, “Warner Raises Alarm on CISA Workforce and Budget Cuts That Are Leaving Our Country Vulnerable to Threats,” June 16, 2026. https://www.warner.senate.gov/newsroom/press-releases/warner-raises-alarm-on-cisa-workforce-and-budget-cuts-that-are-leaving-our-country-vulnerable-to-threats/
U.S. Sen. Mark Warner, “Senate Intel Vice Chair Warner Statement on Secretary Mullin’s Pledge to Rehire 600 Staffers,” June 28, 2026. https://www.warner.senate.gov/newsroom/press-releases/senate-intel-vice-chair-warner-statement-on-secretary-mullins-pledge-to-rehire-600-staffers/
U.S. Sen. Maggie Hassan, “Senator Hassan Presses for Answers on Major Reported Data Leak at Leading Cybersecurity Agency,” May 19, 2026. https://www.hassan.senate.gov/news/press-releases/senator-hassan-presses-for-answers-on-major-reported-data-leak-at-leading-cybersecurity-agency
U.S. House Committee on Homeland Security, “Chairman Garbarino Celebrates House Passage of the FY2026 Department of Homeland Security Appropriations Bill,” January 22, 2026. https://homeland.house.gov/2026/01/22/chairman-garbarino-celebrates-house-passage-of-the-fy2026-department-of-homeland-security-appropriations-bill/
U.S. GAO, “Cyber Workforce: Agencies Did Not Widely Adopt Rotational Program,” July 16, 2026. https://www.gao.gov/products/gao-26-108736
NIST, “Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile,” SP 800-61 Rev. 3, April 2025. https://csrc.nist.gov/pubs/sp/800/61/r3/final

