Your First Security Hire Should Not Be Full-Time
SME takeaway
A security hire does not create security capacity. It consumes everyone else's.
Small companies that handle sensitive data are right to take security seriously. They are usually wrong about the first move.
Four people in IT. Turnover high enough that one of them is always new. Nothing written down, because nobody has had a quiet week in which to write it.
Then the CEO decides the company should be secure, and hires a cybersecurity specialist.
The specialist is placed inside IT, at the same level as the technicians. There is no standing route to the management floor, because management has already decided what security is: an IT problem, and now a solved one, because someone in IT finally has security in their job title. Meanwhile IT is exactly as busy as it was the week before.
Nothing moves. Not because anyone is incompetent or unwilling, but because the decision was right and everything arranged around it was wrong. I know the shape of this closely. It is roughly the position I was once hired into.
The companies that get stuck here
You might reasonably ask why a company of 150 or 200 people needs a dedicated security specialist at all. Most do not.
But some small companies handle material that does not care how small they are. Defence-adjacent engineering. Healthcare. Law firms. Small public-sector bodies. Operators of critical infrastructure. These businesses process information whose loss is a serious event regardless of headcount, and the people running them usually know it.
That produces an odd gap. These companies value security highly enough to fund it, and are too small to absorb the person they just funded. They are underserved from both directions: too serious for the buy-an-antivirus-and-hope advice aimed at small businesses, too small for the enterprise playbook that quietly assumes a security function with a team, a budget line and a seat at the table.
What happened when I took the job
I was hired full-time by a regulated operator of critical infrastructure. Roughly 200 people, most of them in operations, with a lot of field engineering and monitoring work. As critical infrastructure they took security seriously, and the brief was open-ended: help us implement cybersecurity properly, over a long period. Real need, real mandate, no bad faith anywhere.
Within a few weeks the blockers were clear.
- The four-person IT team had high turnover and no documentation. Every question started from scratch, and the answers left with people.
- The role sat inside IT at technician level, so there was no reliable route to the people who set priorities, approve process changes and release budget.
- Management treated security as an IT matter, which meant the governance half of the work had no owner, no forum and no agenda slot.
- IT was fully loaded with daily operations, so even the technical half of the work moved only when somebody else’s week allowed it.
None of that is unusual. All of it is fatal to a full-time security role. We agreed to change the shape of the engagement rather than spend a year demonstrating the obvious.
A four-person IT team has no spare utilisation
Picture the standard team. One person is helpdesk and firefighting, the one who fixes what broke this morning. One person owns the network. One person owns the servers, if you are lucky and it is not the same person. Somewhere in there is a lead who is also doing one of those three jobs.
By small-company standards that is a strong team. It is also a fully consumed one. The capacity is not missing, it is already booked. Daily operations expand to fill it, and they have a habit of winning, because a broken laptop is visible today and an unpatched server is only visible later.
Two things make it worse. Turnover means the team is permanently relearning its own estate. No documentation means every security question is answered from memory, by whoever is still there to remember. A security hire fixes neither. It queues behind both.
A security person cannot implement security alone
This is the part that gets missed, and it is the whole argument.
A security specialist almost never implements security personally. They decide what matters, in what order, and then depend on other people to do it. That dependency is not a weakness in the role, it is the role. Which means the work stops wherever the company is already saturated:
- Governance stalls when management has no time to make decisions.
- Vulnerability management stalls when the one server administrator is busy.
- Incident response cannot be defined or exercised when the whole of IT is busy, because a tabletop needs the same four people who are fixing today’s outage.
- Patching cannot be planned when the asset register is unclear, and nobody has hours to spare to make it clear.
- Data protection obligations cannot be met when nobody can say where personal data actually lives. In a company this size, HR is often one person with shared responsibilities keeping most of it in email. If that person is busy, GDPR records of processing are busy too.
You see the pattern. A real security function reaches into every layer of the company, not only IT. Put it somewhere it cannot reach, or somewhere every dependency is already at capacity, and you have bought a very expensive person the right to wait.
The point
A security hire does not add capacity. It creates demand on capacity you do not have.
Security at technician level is the expensive mistake
Placing a senior security person inside IT alongside the technicians fails for three reasons, and only one of them is money.
It is expensive: a senior salary spent on a role scoped like a junior one. It is wasteful: the reach across the business is precisely what you were paying for, and the org chart removes it on day one. And it is self-confirming: putting security under IT tells management, in the clearest possible language, that security is IT’s problem. That is the belief you needed to change.
Position is not an administrative detail here. It decides which half of the job is even attempted.
Security runs top-down, not bottom-up
The logic runs in one direction only.
You have a business, and it has to keep running. Keeping it running depends on assets: systems, data, people, suppliers, physical sites. You protect the assets that actually matter to the business, in the order they matter. IT is among them. It is not all of them.
Work that way and maturity accumulates naturally. Priorities have a reason a director can repeat. Risk decisions get made by people who own the risk. Governance is not a document exercise, because it started as a business conversation.
Work from the bottom of IT and you can only ever fix IT problems. Most of the expensive ones did not start there.
When a full-time hire is the right call
I am not arguing that nobody should hire a security person. I am arguing about sequence. Hire full-time when most of these are already true:
Hire full-time when
- IT has genuine slack, or you are funding extra IT capacity alongside the hire
- A named executive sponsor has real calendar time, not just approval rights
- The role reports outside IT, or has a standing route to whoever sets priorities
- IT is stable enough to hand over knowledge, not rehiring the same roles yearly
- There is an implementation budget, not only a salary budget
- There is enough security work to fill a week, every week, for a year
- Law or contract requires a named, in-house accountable person
- Security is part of the product, not only an internal function
When most of that is true, hire, and hire well. A retainer is the wrong answer for a company in that position.
The right dose
If it is not true yet, the honest answer is a smaller amount of senior expertise, applied continuously.
Too little security attention and the risk is simply ignored. Too much and you have a senior person on a full salary, blocked on other people’s calendars, slowly becoming the most expensive documentation project in the company. For reference, a full-time CISO in Central Europe costs €80,000 to €150,000 a year in salary alone, before you have funded a single control.
The useful measure is not how much security you need in theory. It is how much your company can currently absorb: how much IT time, management attention and implementation budget you can genuinely put behind the recommendations. Buy expertise to match that, and increase it as your absorption capacity grows.
That is what the Retained Security Partner engagement is built around, and it is the same argument I made about why a retainer beats a one-off pentest for a growing company. If you want to work out what your own situation actually calls for, the Discovery Calculator is the fastest way to map it.
The bottom line
Hiring a full-time security expert as the first step is not too ambitious. It is the wrong shape. It puts the cost of your security programme onto four IT people and one HR person who are already at capacity, and it usually buries the person you hired at exactly the level where they cannot reach the decisions that matter.
Start with the smallest amount of senior security expertise your company can actually absorb, placed high enough to be useful, and grow it as your capacity to absorb it grows.
Found this useful?