I've watched it happen too many times. A CISO leaves unexpectedly. The security architect gets poached. The head of threat intelligence gets fed up with organisational politics and walks. And then what happens? The role sits vacant for three months while the "perfect candidate" gets sourced.
Think that's just business as usual? Think again.
In my six years placing cybersecurity professionals across London and New York, I've developed a theory: most hiring managers massively underestimate what those 90 days of vacancy actually cost them. And I'm not just talking about the obvious security risks, though those are certainly real enough.
The hidden costs - financial, operational, cultural - are where the real damage happens. And nobody's talking about it.
The Security Exposure Is Just the Beginning
Let's start with the obvious. When critical security roles sit empty, your attack surface expands dramatically. But security exposure isn't just theoretical - it's financial.
Last month, I was working with a financial services client who'd left their principal security architect role unfilled for 14 weeks. During that gap, they suffered a relatively minor breach that wouldn't have happened with proper security oversight. The cost of incident response alone topped £120,000. That's before we talk about regulatory implications, customer notifications, or reputation management.
The thing is, security isn't just about preventing disasters. It's about maintaining continuous improvement. Every day without your security leader is a day your organisation isn't evolving its security posture.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
The Operational Tax of Security Vacancies
Here's where the costs really start to pile up, and most CFOs don't see it coming.
When I place CISOs and senior security leaders in financial services, I always ask about their first three months. Almost universally, they report a significant backlog of security reviews blocking product releases. One CISO I placed at a London fintech found over 35 product updates waiting for security sign-off.
Do the maths. Let's say each of those product updates represents £50,000 in potential monthly recurring revenue. That's £1.75 million in delayed revenue. Even if only delayed by 60 days, that's nearly £3 million in revenue timing impact.
And what about the cost to your existing security team? When a senior role stays vacant, the work doesn't disappear - it gets redistributed. Your remaining security professionals start burning out fast.
But wait, it gets worse.
The Compliance Time Bomb
Most major compliance frameworks require specific security leadership roles to be filled. GDPR specifically requires data protection expertise. PCI DSS demands security oversight. Financial services regulations like those from the FCA require clear accountability for security controls.
Sure, you can temporarily assign those responsibilities elsewhere. But when those temporary arrangements extend beyond a reasonable timeframe, auditors start asking questions. And in my experience, those questions eventually turn into findings.
One candidate I placed last April walked into a financial services firm that had gone six months without a permanent CISO. Their first task? Addressing 14 high-priority audit findings that had accumulated during the vacancy. The remediation costs alone ran into the hundreds of thousands.
Think about this: you're not just paying for the eventual hire. You're paying for all the remediation work they'll have to do because the role sat empty.
The Snowballing Recruitment Costs
Hiring managers tend to think the cost of recruitment is fixed. You pay a fee (or internal costs), and you get a person. But security hiring doesn't work that way.
The longer a role sits open, the more problematic it becomes to fill. Candidates start asking why nobody has taken the job. The market begins to perceive issues with the role.
I've seen this firsthand. When a security role has been open for over 90 days, we typically need to increase the salary band by 10-15% to attract the same calibre of candidate who might have accepted earlier. The perceived risk premium is real.
Slow hiring also means you're competing with new security roles hitting the market every week. The candidate who might have been perfect in month one is evaluating five other options by month three.
The Leadership Vacuum Effect
Security isn't an isolated function anymore. Modern security leaders work across engineering, product, operations, and the C-suite. When that connector role disappears, cross-functional initiatives stall.
One fintech I work with regularly lost their Head of Security last year. During the four-month gap before replacement, their Zero Trust implementation completely stalled. The project delay cost them approximately £80,000 in consulting fees they'd already committed to, plus internal resource time.
Security leadership vacancies create strategic blind spots too. I've seen organisations make significant architectural decisions without proper security input during leadership gaps, only to face expensive remediation later when the new security leader finally arrives.
The Talent Cascade
Here's something most hiring managers miss completely: security talent follows strong security leadership. When key security roles stay vacant too long, it triggers a talent cascade.
A client in Manchester left their CISO role unfilled for over four months last year. During that time, they lost two senior security engineers and a threat analyst. Why? Those professionals wanted career development and technical direction that wasn't available without leadership.
Now you're not just filling one role - you're rebuilding a team. And in today's market, replacing a full security team can easily add six months to your recovery timeline.
What Does This Actually Cost in 2026?
So what's the actual cost? Based on what I'm seeing across UK and US markets, a 90-day vacancy in a senior security role typically costs organisations between 2-4 times the annual salary of the position.
For a CISO role with a £180,000 base salary, that's £360,000-£720,000 in total organisational impact. And frankly, in regulated industries, I think that's conservative.
How to Break the Cycle
So what's the solution? Having placed security leaders across two continents, I've noticed some patterns among organisations that manage this well:
-
Build your security talent pipeline before you need it. The best security hires come through relationship networks, not panic-driven searches.
-
Consider interim leadership. Yes, it's expensive hourly, but far cheaper than leaving the role empty. Most security contractors I place can be productive within days.
-
Accept the 80% candidate. The "perfect" security hire doesn't exist. The ones who are 80% right but can start next month are almost always better than waiting for the mythical 100% candidate.
-
Prioritise security hiring. When security roles come open, they should jump to the front of the recruitment queue. The cost of delay is simply too high.
-
Benchmark your time-to-hire for security roles. If you're consistently taking 90+ days to fill security positions, something fundamental is broken in your hiring process.
Across both UK and US markets, the organisations moving fastest on security hiring are gaining a genuine competitive advantage. They're not just reducing risk - they're accelerating their entire business.
The Bottom Line
That security role sitting empty for 90+ days isn't just an HR metric. It's actively costing your organisation money, capability, and competitive positioning. The real cost is far higher than most hiring managers understand.
And the market isn't getting any easier. With the UK's cybersecurity skills gap still widening despite government initiatives, waiting for the perfect candidate is increasingly becoming a luxury nobody can afford.
Just something to think about next time your security recruitment brief has been open for 60 days and you're "still looking for the right fit."
Connor Walsh is a cybersecurity recruitment specialist working between London and New York. He has placed over 200 security professionals across financial services and defence technology firms since 2020.
Looking to accelerate your security hiring process? The OHub's specialised cybersecurity recruitment platform connects pre-vetted security talent with urgent roles, reducing time-to-hire by an average of 38 days compared to traditional recruitment methods.
