“Deidre, Who the Hell Has Time for That? You Do It.”
That sentence is essentially how Workforce Intelligence was born.
For years, working in cybersecurity recruiting, we saw the same problem over and over again: great people were leaving organizations that could have kept them.
It is rarely about money.
One of the reasons we could successfully recruit cybersecurity professionals who were not actively looking was that so many of them had no clear career plan where they were. They did not know what came next. They did not know how they could grow. Many were spending significant amounts of time doing work they did not enjoy or that did not excite them.
And their leaders frequently did not know it.
That bothered me, because I could see how preventable so much of the turnover was, and it still is today.
The Idea Started With One Client Conversation
CyberSN had already built our cybersecurity job taxonomy and the job-building platform we use in our talent acquisition work.
When we bring on a talent acquisition client, we share our screen and build the job with them using our cyber job taxonomy. That platform gave us a way to get very specific about the work a person would actually be doing.
I remember talking with a client and saying:
Use our platform and sit down with every one of your permanent employees. Document what each person is actually doing. Understand how they are spending their time. Ask them how they feel about that work, what they want to be doing, where they want to grow, and then create career, training, and development plans for every individual.
The client looked at me and said:
“Deidre, who the hell has time for that? You do it.”
My answer was essentially, “Absolutely. Fund it and we will do it for you.”
He did.
So we did.
And that changed everything.
Retention as a Service Was Born
We used our job-building platform and cyber job taxonomy to document what every permanent employee was actually doing and how their time was being utilized.
Then we asked them how they felt about it.
We called those questions our Happiness Survey, and we still call it that today.
We asked people how they felt about the work they were doing, what they enjoyed, what they wanted to do more of, what they wanted to learn, and where they wanted their careers to go.
The value of that information became apparent immediately.
When someone can see, in detail, that they are spending 40% of their time doing one type of work, 25% doing another, and the remainder spread across several other responsibilities, they can react to something very concrete.
Then you ask:
The Happiness Survey Questions
- Do you like spending your time this way?
- What would you like to be doing more of?
- What would you like to be doing less of?
- Where do you want to grow?
- What matters to you next?
Security leaders tell us how valuable the answers are.
Many of them initially see the Happiness Survey as a smaller piece of the engagement. Then they read what their people have actually shared and realize how productive that information is.
They learn things they did not know.
They see where someone is frustrated.
They discover interests and capabilities they were not aware of.
They understand why someone may be disengaging.
And they gain information they can actually use to retain and develop their people.
That was true in the very first engagement, and it remains true today.
Career Development Had to Connect to Cybersecurity Strategy
We also knew very quickly that if we were going to do this work correctly, individual career, training, and development plans could not exist separately from the cybersecurity strategy.
If the organization needs different capabilities over the next three years, the people need opportunities to grow in that same direction.
That meant we needed to understand and develop the three-year cybersecurity strategy roadmap across workforce, process, technology, and KPIs as part of the work.
It is also why every engagement includes a cybersecurity subject matter expert who is instrumental throughout the project.
Creating a training plan without understanding where the organization is going does not make sense.
Creating a career plan without understanding which capabilities the organization will need does not make sense either.
And this is one of the reasons so many career and training plans never actually materialize.
For retention to work, the individual's growth and the organization's strategy have to become one connected plan.
We called the service Retention as a Service. RaaS was an internal moniker, never something we marketed, and it stuck because retention is where this entire journey began. What it grew into is Workforce Intelligence.
The first engagement worked. The client was happy. The employees were happy.
And then something happened that we had not anticipated.
The Visualization Changed the Budget Conversation
As we visualized the workforce, its utilization, the strategy, and the gaps, we created a picture of what was actually happening inside the cybersecurity organization.
For the first time, the cybersecurity leader could show executives, CFOs, and other business leaders what they had been explaining in words.
They could see where the workforce was spending its time.
They could see the gaps.
They could see dependencies.
They could see where capability was missing.
They could see why additional investment was needed.
And suddenly, selling up became easier.
That very first client secured budget that had previously been difficult to get.
We saw the same thing happen again as we continued the work, and it is still one of the outcomes I care most about.
When business leaders can actually see the operating reality, the conversation changes.
That outcome shows up in our case studies. Workforce Intelligence gives cyber and IT leaders a way to translate workforce needs into something the business can understand, evaluate, and fund.
We Could See the Gaps
Very quickly, the intelligence also showed us that understanding permanent employees alone was not enough.
Once we compared what the permanent workforce was actually doing to the cybersecurity strategy, the capability gaps became clear.
If we were going to recommend how to close those gaps, we needed to understand everyone and everything being used to perform the work.
We needed to know what contractors were doing.
We needed to understand what managed service providers were delivering.
We needed to account for consultants and interns.
AI agents were not part of the workforce conversation when we started this work. Today, they absolutely are.
So our definition of workforce expanded.
Today, workforce means permanent employees, contractors, managed service providers, consultants, interns, and AI agents.
It also changed how we count. A contractor covering part of a role is not another name on an org chart. That contractor might be contributing 0.5 FTE of coverage against a specific capability. Full time equivalent is a unit of measure, and using it as a unit rather than as a label for people is what lets you compare an employee, a contractor, and a managed service against the same capability.
Only by understanding that entire ecosystem could we accurately identify capability gaps and determine the right way to close them.
That allowed us to bring together the cyber strategy, the capabilities required to execute it, the work being performed across the full workforce ecosystem, the gaps that existed, and the career, training, and development goals of the permanent employees.
From there, we could build three-year strategy and gap-closure roadmaps across workforce, process, technology, and KPIs while creating meaningful growth opportunities for the people already inside the organization.
This work also drove the development of our Cyber Fusion Model and cyber capability maturity model.
The more complete the workforce picture became, the more clearly leaders could understand whether they actually had the capabilities required to execute their strategy.
Then We Discovered Another Problem: The Information Changes Constantly
After we had about a year of this work under our belt, something else became impossible to ignore.
The information changed fast.
Someone who had been spending 40% of their time on incident response might, three months later, be spending 40% of their time on analyst work because somebody left.
Another person might suddenly spend a significant amount of time on automation.
A new project might change priorities across an entire team.
People leave. People join. Business priorities change. Threats change. Technologies change. The attack surface changes.
And the way the workforce is actually being utilized changes right along with all of it.
Within six months, a meaningful amount of the information we had documented could already be different.
That meant a point-in-time workforce assessment was never going to be enough.
So we thought we had the answer.
We would leave our platform with the client so managers could sit down with their direct reports, keep the information updated, and continuously understand utilization and capability coverage.
Clients loved the idea.
They bought the platform.
And then reality happened.
Nobody had time to keep it updated.
I do not blame them.
Cybersecurity leaders and managers are overwhelmed. Attack surfaces continue to expand. Operational demands are relentless. New technologies, threats, audits, incidents, business priorities, and constant change are already competing for their attention.
Expecting managers to manually maintain all of this workforce intelligence was not realistic.
And that realization changed the service again.
Workforce Intelligence Had to Be a Managed Service
If this intelligence was going to drive decisions, it had to stay current.
So we took responsibility for keeping it current.
The service evolved into a managed Workforce Intelligence service where we do the work for the client.
That is what makes it possible for leaders to stay on top of this information instead of receiving an assessment that begins aging the day it is delivered.
They can know how the workforce is being utilized.
They can know where capabilities exist.
They can see where coverage is changing.
They can identify single points of failure and dependencies.
They can understand capacity and capability risk.
They can see whether their workforce can execute the strategy.
And they can make decisions using information that reflects what is actually happening now.
Cyber Led Us Directly Into IT
We were not even a year into this work when the CIO of one of our clients saw what we had done for the cybersecurity organization and said, essentially:
You have to do this for IT.
So we built the IT taxonomy.
And for the last couple of years, we have been doing this work across IT as well.
The same fundamental need exists there. Leaders need a current understanding of what work is actually being performed, who or what is performing it, which capabilities exist, where gaps and risks are developing, and whether the workforce can execute the strategy.
And Now, We Can Turn All of This Intelligence Into Risk
One of the most important evolutions in the work is happening right now.
After years of building this intelligence, including workforce utilization, capability maturity, dependencies, gaps, coverage, strategy alignment, and the full workforce ecosystem, we have been able to create workforce risk profiles and risk cards.
The thinking is similar to a risk register.
Instead of discussing workforce issues as broad concerns, leaders can identify and communicate specific workforce risks in a structured way.
Where is a critical capability dependent on one person?
Where is the organization relying too heavily on an external provider?
Where does the strategy require a capability that does not exist today?
Where is capacity creating execution risk?
Where could turnover materially affect the cyber strategy?
Those risks can now be documented, scored, visualized, and communicated to the business in a language the business already understands: risk.
This is having a real impact for our clients, because it brings the workforce risk conversation much closer to the way executives, boards, finance leaders, and risk leaders already make decisions.
This Is the CyberSN Workforce Intelligence Journey
We did not sit in a room three years ago and design what Workforce Intelligence looks like today.
It evolved through solving real problems with real clients.
A retention problem led to Retention as a Service.
Retention led us to understand actual workforce utilization.
The Happiness Survey gave leaders a level of insight into their people they had never had before.
That intelligence exposed capability gaps.
Those gaps required us to understand the entire workforce ecosystem.
That led to capability maturity, our Cyber Fusion Model, three-year gap-closure roadmaps, and deeper alignment between the workforce and cybersecurity strategy.
The visualization gave leaders a way to show the business what was actually happening, and to secure budget they had previously struggled to get.
Then we recognized how quickly the intelligence changes.
That led us to a managed service capable of keeping it current.
The success of the work in cybersecurity led us into IT.
And today, that intelligence is allowing us to turn workforce issues into clear, measurable risk profiles that leaders can take directly to the business.
I originally envisioned solving a retention problem. What CyberSN has built from that idea could never have come to life without the extraordinary people who have developed, challenged, operationalized, and delivered this work alongside me.
There are many key players at CyberSN who have shaped Workforce Intelligence into what it is today, incredibly talented human beings I have the privilege of working with every day.
This is our work. And I am incredibly proud of it.
What started with one client saying, “You do it,” has become a new way for cybersecurity and IT leaders to understand their workforce, execute their strategy, develop their people, communicate risk, and make decisions.
Join Us August 26
On Wednesday, August 26 from 12:00 to 1:00 PM ET, I am hosting a webinar with Shannon Brewster, CISO, to talk about what we have learned through more than three years of doing this work, and what Workforce Intelligence tells you that other assessments do not.
Shannon has experienced the service firsthand, so this will be much more than a theoretical conversation.
We are going to talk about what leaders can actually know when they have this intelligence, and what they can do with it.
See what your workforce is actually doing
CyberSN's Workforce Intelligence Engagement gives cybersecurity and IT leaders a clear view of where time is spent, what capabilities exist, where dependencies and gaps are forming, and how the full workforce ecosystem lines up against the strategy it has to execute.
Request a Workforce Intelligence Briefing

