Desk live·
ForensicPost
Breaches/Workforce/File 25-0325

Understaffed Breaches Cost $1.76 Million More

Organisations with significant security staff shortages recorded average breach costs $1.76 million higher than well-staffed peers. It is the closest thing to a return-on-investment figure in this database.

Constructed geometry · not a chart of case data
TargetUnderstaffed organisations
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

Published research reports that organisations with significant security staffing shortages experienced data breach costs averaging $1.76 million higher than organisations considered well-staffed.

This Is The Argument The Discipline Has Always Lacked

Security spending is defended with avoided-loss reasoning, which is unfalsifiable: nobody can price the incident that did not happen. It is why the funding files in this corpus keep recording the same defeat — the case is made in hypotheticals against budget lines that are concrete.

A differential is different. It does not require estimating prevented incidents. It compares what happened to two groups when incidents occurred, and it can be set directly against the salary cost of the difference.

The Mechanism Is Plausible And Mostly About Time

A well-staffed team detects sooner, contains faster and restores earlier. Every hour of dwell is more data taken and more systems reached, and the corpus records the long-dwell cases: ten months at 26-0620, five at 25-0820, seventy-four days before clients were told at 25-1027.

It is also about what happens during the incident. An understaffed organisation buys emergency consultants at emergency rates, which is a direct and immediate cost.

Correlation, And The Direction Is Not Obvious

Graded medium, and this is the reason. Organisations that underinvest in security staff plausibly underinvest in everything else that limits breach cost — logging, segmentation, backups, incident planning. The staffing variable may be a marker rather than a cause.

And causation could run backwards at the margins: an organisation that has already had an expensive incident is a harder place to hire into.

The figure is still the most usable thing in the workforce set, because it is the only one denominated in the currency the budget conversation actually uses.

This is an analysis file

Built on published research, listed below. The differential is an observed association across surveyed organisations, not a demonstrated causal effect. Corrections: corrections@forensicpost.com.

Sources
  1. Cybersecurity skills gap statistics for 2025: record 4.8M roles unfilledDeepStrike
  2. Cybersecurity workforce shortage: a comprehensive 2025 studyACSMI
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary