The AI Layoff Paradox: Cutting IT Staff While Your Attack Surface Explodes
UK SMEs are shrinking internal IT teams just as AI-driven attacks multiply threat volume and speed. Here's an honest buy-vs-build framework for CFOs and IT leaders weighing redundancies.
A mid-sized manufacturing firm in the East Midlands let two of its three IT staff go last spring. The maths looked sound on a spreadsheet: roughly £90,000 in annual salaries removed, a promise to "do more with AI tools", and a lean team that would keep the lights on. Six months later, a phishing email — well-written, personalised, and almost certainly generated by a language model — slipped past their remaining engineer, who was too busy resetting passwords and chasing printer faults to notice anything odd. The firm spent the next fortnight rebuilding from backups and explaining to customers why orders were late.
That story is not unusual, and it points to something genuinely strange happening in British business right now. Companies are cutting IT and security headcount at the exact moment the threats those people defend against are getting faster, cheaper, and far more convincing. Call it the AI layoff paradox: the same technology being used to justify the redundancies is arming the attackers who exploit them.
Two lines heading in opposite directions
Start with the headcount side. Redundancies across technology roles have been running hot for a couple of years, driven partly by post-pandemic overhiring and partly by a belief — sometimes reasonable, often wishful — that AI will absorb the work. When budgets tighten, IT is an easy target because it's a cost centre. It doesn't sell anything. Its wins are invisible: the breach that didn't happen, the outage that never occurred. That invisibility makes it vulnerable to the finance director's red pen.
Now the other line. The volume and sophistication of attacks aimed at smaller organisations has climbed sharply, and AI is a big reason why. Three shifts matter for an SME:
Phishing has stopped looking like phishing. The old advice — watch for bad spelling, odd grammar, generic greetings — is nearly useless now. Language models produce fluent, context-aware emails at scale. An attacker can scrape a company's website and LinkedIn, then generate a message that references your actual projects, your actual suppliers, and your actual colleagues' names. The tell-tale clumsiness is gone.
The barrier to entry has collapsed. You no longer need to be a skilled coder to run a credible campaign. Off-the-shelf criminal tools, some with AI baked in, let low-skill operators launch attacks that would have needed a team a few years ago. More attackers, more attempts, more automation.
Speed has changed the game. Automated tools now scan for exposed systems and known vulnerabilities within hours of a flaw being published. If your patching is slow because you've lost the person who did it, that gap between disclosure and exploitation is where you get hurt.
So you have shrinking defence meeting expanding offence. The two trends are not just coincidental; they feed each other. The tools that let a business justify cutting staff are cousins of the tools attackers use to exploit that thinner defence.
Why 'the AI will handle it' doesn't hold up
There's a comforting assumption buried in a lot of these decisions: that AI security tools will simply replace the humans who left. They won't, and it's worth being precise about why.
AI is genuinely good at pattern-matching across huge volumes of data — spotting the anomaly, flagging the unusual login, sorting the noise. That's real and useful. But security is not only detection. It's judgement, context, and response. When an alert fires at 2am, someone has to decide whether it's a false alarm or the start of a ransomware event, then act fast. When a supplier's account gets compromised and starts sending your finance team invoices, someone has to notice the pattern across systems that don't talk to each other. When your business changes — a new office, a new cloud service, an acquisition — someone has to redesign the defences around it.
AI tools also need people to run them. They need tuning, monitoring, and interpretation. Handing a sophisticated detection platform to an overstretched generalist who's also fixing laptops is like buying a fire alarm and asking the receptionist to be the fire brigade. The alarm works fine. The response is the problem.
The honest buy-vs-build decision
This is where CFOs and IT leaders need a clear-eyed framework rather than a gut call. The question isn't "can we afford IT staff?" It's "what level of risk are we carrying, and what's the most sensible way to cover it?"
Here are the questions worth working through before any redundancy is signed off.
What does 24/7 actually cost to build? Attacks don't respect office hours. A genuine round-the-clock in-house capability needs roughly five to six full-time people to cover shifts, holidays, and sickness — plus the tooling. For most SMEs that number is absurd. This is the single strongest argument for buying rather than building: you cannot recreate a managed security operations centre with two people, no matter how talented they are.
What's the true cost of the gap? Compare like with like. The in-house cost isn't just salary — it's recruitment, training, tooling licences, and the risk of a single person leaving and taking all the knowledge with them. The managed cost is a predictable monthly fee that spreads specialist expertise across many clients. Put both on the same page.
What breaks if your one remaining person is off? If the honest answer is "quite a lot", you have a resilience problem, not a staffing plan. Key-person risk in IT is a genuine business continuity issue, and it rarely appears on a redundancy business case.
Where does your team add real value? Here's the useful reframe. The point of managed services isn't to eliminate your internal people — it's to stop wasting them on commodity work. Password resets, patching, monitoring, and first-line support are jobs a managed provider does at scale and often better. That frees your internal staff to focus on things only they can do: understanding your business, running projects, and making technology decisions that fit your actual operations. Buy the plumbing; keep the architect.
What does the insurance require? Cyber insurers now ask hard questions about monitoring, response times, and controls. If you can't demonstrate them, you either can't get cover or you pay a premium for the privilege. That's a concrete cost of the gap, not a hypothetical.
Framing it correctly for the board
The mistake is presenting managed services as a cost-saving measure. Sometimes it saves money and sometimes it doesn't, but that's the wrong lens. Frame it as risk management. The relevant comparison isn't the monthly fee versus a salary — it's the monthly fee versus the cost of a serious incident: the ransom, the downtime, the lost orders, the regulatory exposure, the customers who quietly move to a competitor.
For a smaller business, a single ransomware event can run into six figures once you count recovery, lost revenue, and reputational damage. Set that against a predictable monthly service that keeps eyes on your systems at all hours, and the arithmetic looks very different from the tidy salary-line saving on the original spreadsheet.
The manufacturer at the top of this piece eventually moved to a managed model — after the breach, when it was more expensive and more painful than it needed to be. The lesson isn't that cutting IT staff is always wrong. It's that headcount decisions and risk decisions are being confused for each other, at precisely the moment the risk is climbing fastest.
If you're weighing redundancies right now, run the framework first. Work out what you're really carrying, decide honestly what your people should be doing, and price the gap properly. That's the difference between a lean IT operation and an exposed one.
