I was on a call with the CISO of a major London fintech last week. Their security team had been running two analysts short for nearly four months. "We're saving on headcount costs," he said, without a hint of irony. I nearly choked on my coffee.
Look, I get it. Hiring budgets are tight in mid-2026. The post-recession hangover is real. But this kind of short-term thinking is costing organisations obscene amounts of money - and most have no idea how bad the maths actually is.
After six years placing cybersecurity professionals across New York and London, I've watched dozens of companies drag their feet on critical hires while bleeding money invisibly. The bean counters see an unfilled role as a temporary saving. The reality? It's a financial haemorrhage that rarely shows up on the quarterly statements.
The Real Cost Formula Most Companies Miss
Forget the basic salary calculations. When I audit the true cost of vacancy for clients, the numbers get alarming fast. The formula is deceptively simple:
True Cost = Direct Revenue Impact + Productivity Loss + Team Burnout Cost + Compensation Premium
But the devil's in the execution. Most hiring managers I work with can't accurately measure even one of these components. They're flying blind while their budget burns.
Direct Revenue Impact: The Opportunity Cost Killer
In cyber, this is particularly vicious. A missing detection engineer means threats slip through. A vacant AppSec role means vulnerable code goes to production. A CISO search that drags on for months creates governance blind spots that compliance auditors will crucify you for.
I placed a threat hunter at a payment processor in April after a 7-month vacancy. During that period, they suffered a minor breach that wouldn't have happened with proper staffing. The clean-up cost? Just north of £370,000 - roughly 4× the annual salary they "saved" by dragging their feet.
And this isn't rare. The UK's National Cyber Security Centre has been warning about precisely this pattern in their guidance updates. The risk/cost equation fundamentally changes when your defensive posture is compromised by missing personnel.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
Productivity Tax: The Ripple Effect Nobody Measures
What happens when you're down a key security architect? Everyone else picks up the slack. The cascade is predictable:
- Existing staff get stretched across more projects
- Quality suffers as attention gets divided
- Technical debt accumulates as corners get cut
- Decision bottlenecks form as fewer people hold authority
This invisible "productivity tax" compounds daily. The longer the vacancy, the worse it gets. One client I worked with in Manchester had a vacancy rate of 22% in their security operations team. Their incident response times doubled, their false positive rate increased 3×, and their after-hours call rotation became unbearable.
The productivity hit didn't just affect security - it cascaded to development teams who waited longer for security reviews, to compliance teams who couldn't get timely audit support, and to the business units whose projects faced delays.
When calculating this cost, I start with the simple maths: take the missing person's expected output value and multiply by vacancy duration. But then add the degradation factor for everyone impacted by their absence. It's rarely less than 2-3× the base salary of the missing role.
The Burnout Premium: Your Team Is Watching
This is where things get really expensive.
When teams run understaffed for extended periods, people break. Not all at once, and not always visibly, but the damage accumulates like radiation exposure. By the time someone hands in their notice citing burnout, the damage has already spread to others.
I've seen security teams collapse like dominoes after running 20% understaffed for more than six months. One resignation triggers another, then another. Soon you're not filling one role - you're desperately trying to replace half your team while institutional knowledge walks out the door.
The financial impact? Catastrophic. When a senior security engineer with three years of system knowledge quits, you're not just losing a salary slot - you're losing years of accumulated context that will take a new hire 6-12 months to rebuild.
Staff who stay become flight risks too. The ones you most want to keep - your high performers - are precisely the ones receiving LinkedIn messages from recruiters like me daily. The moment they feel exploited by vacancy-driven workload increases, their loyalty evaporates.
The Talent Premium Tax: Delayed Hires Cost More
Here's a pattern I've observed consistently across both UK and US markets since 2025: The longer you wait to fill critical security roles, the more you'll pay for the same talent.
In cybersecurity specifically, we're seeing 7-12% year-on-year salary inflation for specialist roles, particularly in cloud security, OT security, and AI safeguarding. That means a role you couldn't justify filling at £95K in January might cost you £102K by summer's end. The budget you thought you were saving? It's already been eaten by market inflation.
But it gets worse. Extended vacancies create desperate employers. Desperate employers make premium offers to candidates. I've watched companies reject perfectly qualified candidates at £105K only to hire someone with identical skills at £125K six months later out of sheer desperation.
How to Calculate Your Actual Cost of Vacancy
While every organisation differs, here's a simplified framework I use with clients to build cost awareness:
- Base salary cost × time-to-productivity ratio
- Overtime and contractor coverage expenses
- Team efficiency reduction percentage × affected team salaries
- Attrition risk premium (calculated as replacement cost × increased departure probability)
- Market rate inflation during vacancy period
For a mid-level security analyst role vacant for 4 months, this often totals between 1.5-2.3× their annual salary - and that's conservative.
What's maddening is that most organisations track time-to-fill as a recruitment KPI, but almost none track cost-of-vacancy as a business KPI. It's the blind spot costing UK businesses millions annually.
Beyond the Maths: The Strategic Cost
Some costs can't be easily quantified but are no less real. Security debt is like technical debt but with sharper teeth. Vulnerability backlogs that grow during staff shortages don't just represent future work - they represent unmitigated risk.
I've watched companies miss market opportunities because security resource constraints prevented them from meeting compliance requirements for new verticals. I've seen product launches delayed because security reviews couldn't be completed on schedule. I've witnessed acquisitions stumble because security due diligence teams were stretched too thin.
But what's the answer? Am I just saying "hire faster at any cost"? Not quite.
Practical Steps to Reduce Vacancy Costs
Smarter organisations are adapting with several approaches:
- Maintaining a continuous candidate pipeline even when not actively hiring
- Creating flexible security resource pools that can shift between projects
- Implementing phased onboarding plans that get new hires productive faster
- Using partial backfills through specialised contractors while searching for permanent staff
- Revisiting compensation bands quarterly rather than annually
One FTSE 250 client implemented what they call "vacancy cost tracking" - a simple dashboard that calculates the accumulating cost of each open role based on the formula above. When hiring managers can see the daily burn rate of an unfilled position, approval processes mysteriously speed up.
The Bottom Line
I'm not suggesting companies should panic-hire or abandon due diligence in talent selection. Quality still matters enormously. But the delusion that unfilled roles represent savings needs to die.
In cybersecurity especially, your talent gaps are your attack surface. Every week a key role stays vacant increases organisational risk and bleeds money in ways that rarely appear on conventional balance sheets.
The next time your finance team celebrates "headcount savings" from unfilled roles, show them the real maths. That vacant security position isn't saving you money - it's probably the most expensive non-employee on your books.
Check out The OHub's cyber recruitment platform if you're ready to close those costly security gaps before they compound further. The best security talent doesn't wait - and neither should you.
