Home/Insights/Security
Security · 19 May 2026

The cybersecurity talent gap and the managed services response

Competing for scarce specialists is expensive and often unsuccessful. The alternative is deciding which capabilities genuinely have to be internal.

Demand for experienced security practitioners in the Kingdom substantially exceeds supply, and has done for several years. The consequences are familiar to anyone hiring: extended vacancies, rapid salary escalation, and a retention problem that turns a functioning team into an understaffed one when two people leave in the same quarter.

Why hiring alone does not resolve it

The arithmetic is unfavourable at the level of the individual organization. Continuous monitoring requires enough analysts to sustain a shift pattern with redundancy. Specialist functions — incident response, threat hunting, security engineering — require people whose skills are in demand everywhere.

Organizations that compete purely on compensation find they have raised their cost base and remain exposed, because the constraint is the size of the talent pool rather than their position within it. And a team built by paying above market is a team that can be outbid.

A more workable framing

Rather than asking how to staff a full internal capability, ask which capabilities genuinely must be internal.

Some must be. Understanding your own environment, deciding what is acceptable risk, holding authority to act during an incident, and managing the providers — these depend on organizational context and cannot be meaningfully outsourced.

Others do not. Continuous monitoring, triage, platform operation and specialist forensics are all capabilities where a provider spreading cost across many clients can sustain depth that a single mid-sized organization cannot.

The distinction is between judgement and throughput. Judgement stays internal. Throughput can be bought.

Making it work

The failure mode is not the model, it is the boundary. Arrangements that underperform almost always have ambiguity about who is responsible for what — most commonly an alert the provider considers escalated and the client considers actioned.

That is a contracting problem: define what is monitored, what triggers escalation, to whom, in what time, and what the provider may do without waiting for approval. The last point is where most managed detection arrangements are weakest. A provider who can detect but not contain is a notification service, and at three in the morning that distinction is the whole value.

Retain enough internal capability to evaluate the provider's work. An organization that cannot assess whether its security provider is performing has replaced a staffing problem with a governance one.

Is this a live question for you?

We are happy to talk it through — no proposal attached.