Demand for experienced security practitioners in the Kingdom substantially exceeds supply, and has done for several years. The consequences are familiar to anyone hiring: extended vacancies, rapid salary escalation, and a retention problem that turns a functioning team into an understaffed one when two people leave in the same quarter.
Why hiring alone does not resolve it
The arithmetic is unfavourable at the level of the individual organization. Continuous monitoring requires enough analysts to sustain a shift pattern with redundancy. Specialist functions — incident response, threat hunting, security engineering — require people whose skills are in demand everywhere.
Organizations that compete purely on compensation find they have raised their cost base and remain exposed, because the constraint is the size of the talent pool rather than their position within it. And a team built by paying above market is a team that can be outbid.
A more workable framing
Rather than asking how to staff a full internal capability, ask which capabilities genuinely must be internal.
Some must be. Understanding your own environment, deciding what is acceptable risk, holding authority to act during an incident, and managing the providers — these depend on organizational context and cannot be meaningfully outsourced.
Others do not. Continuous monitoring, triage, platform operation and specialist forensics are all capabilities where a provider spreading cost across many clients can sustain depth that a single mid-sized organization cannot.
The distinction is between judgement and throughput. Judgement stays internal. Throughput can be bought.
Making it work
The failure mode is not the model, it is the boundary. Arrangements that underperform almost always have ambiguity about who is responsible for what — most commonly an alert the provider considers escalated and the client considers actioned.
That is a contracting problem: define what is monitored, what triggers escalation, to whom, in what time, and what the provider may do without waiting for approval. The last point is where most managed detection arrangements are weakest. A provider who can detect but not contain is a notification service, and at three in the morning that distinction is the whole value.
Retain enough internal capability to evaluate the provider's work. An organization that cannot assess whether its security provider is performing has replaced a staffing problem with a governance one.