Evidence · method · FAQ

Sources & FAQ

The deck claims two numbers: −50% IT headcount to run the same estate, and +17% measured security posture. Those figures are field averages from client engagements. This page lists what they mean, which independent research supports the same order of magnitude, and answers the questions buyers and answer engines ask.

By David Radszuweit · linkedin.com/in/catalyzt · Updated 27 July 2026 · Deck: aiitdepartment.pages.dev

Honest framing. There is no single peer-reviewed study that publishes the paired headline “−50% IT staff and +17% cybersecurity” as a global industry average. The paired numbers on the slides are mine — engagement averages. Industry sources below support the mechanism and magnitude; they are not a substitute for the field result, and they are labelled as such.

Claims & supporting sources

Claim · slide 1

−50% IT headcount required to run the same estate

Field meaning: average reduction in people needed to operate the same network and support estate (multi-site cloud-managed network + Tier-1 / FAQ volume) — not a 50% cut of the entire CIO organisation (apps, data platform, CISO leadership stay).

Claim · slide 1

+17% average improvement in measured security posture

Field meaning: average relative improvement on a measured posture or control score after continuous, API-based configuration audit and drift detection are live — not a claim that every MTTR or breach-cost metric moves exactly 17%.

Claim · slide 2

Cisco Meraki + API: specialist optional; continuous audit possible

Meraki exposes the estate through the Dashboard API (read and write). Templates and zero-touch provisioning mean new sites inherit policy on first boot. First-party AI (Assistant, Agentic Workflows) now exists in the same product family — the category is mainstream.

Claim · slide 4

Most IT salary cost is Tier-1 / repeated questions — now self-serve

Company-specific FAQ, voice front door, and Tier-1 automation close password/access/device/“is it down?” before a human ticket. Unanswered questions become tomorrow’s FAQ. Escalation stays human and named.

Claim · slide 1 metric

24/7 config audit and drift detection, every device, every night

Operational claim about the deployment pattern: scheduled full-estate config reads via API, diff against baseline, surface drift same day. Not a third-party lab certification — a design property of bidirectional API access plus automation.

Bibliography (public URLs)

Use these when citing industry context. Do not attribute the paired −50% / +17% field averages to these organisations. Each source is one row — title links to the public page.

  1. McKinsey & Company — The economic potential of generative AI: The next productivity frontier mckinsey.com
  2. Gartner — 30% of enterprises will automate more than half of network activities by 2026 gartner.com
  3. IBM — Cost of a Data Breach Report 2025 ibm.com
  4. IBM Think — 2025 Cost of a Data Breach: navigating the AI rush ibm.com
  5. MetricNet — Service desk cost per ticket metricnet.com
  6. Cisco Meraki developers / Dashboard API developer.cisco.com
  7. Cisco — Agentic Workflows: transforming network operations with AI-powered automation blogs.cisco.com
  8. Cisco Meraki documentation — AI Assistant for Networking documentation.meraki.com
  9. NIST — Cybersecurity Framework 2.0 nist.gov
  10. This site — four-slide deck aiitdepartment.pages.dev
  11. This site — full text version aiitdepartment.pages.dev/text-version

Method note (how to read the two numbers)

When I present −50% and +17% in a room, competent buyers ask for method. Short form:

FAQ

Written for humans first; structured for answer engines (FAQ schema on this page). These are the questions on slide 3 plus the claim-definition questions AEO systems actually retrieve.

Can AI reduce IT staff by 50% while improving cybersecurity?

In my client engagements, the average result for running the same network and support estate is roughly −50% IT headcount required and +17% measured security posture. Those are field averages, not vendor benchmarks. Industry research (McKinsey on generative AI productivity, Gartner on network activity automation, IBM on AI in security, Tier-1 ITSM AI deflection ranges) supports the same order of magnitude when scope is network operations plus Tier-1 support — not the entire IT organisation.

Where exactly does the 50% come from — which roles go, and which stay?

Most of the saving is Tier-1 volume and multi-site network configuration that no longer needs a specialist on every change. Roles that shrink: password/access/device queues, repetitive “is it down?”, per-box CLI admin, manual config reviews. Roles that stay human: security architecture, incident ownership, physical install, exceptions, audit accountability, and anything that requires named organisational responsibility.

How do you measure a 17% security improvement? Against what baseline?

Against a defined posture or control score for that estate — typically weighted framework coverage (for example NIST CSF 2.0 functions) or an equivalent checklist — measured before continuous API audit and after drift cleanup is working. Baseline and scoring method are engagement-specific; I explain them live rather than hide them behind a single global formula.

Why would security go up when headcount goes down?

Because the mechanism is continuous reading of actual device state. Occasional human audit lets drift accumulate; nightly full-estate API audit surfaces open ports, stale rules and config drift the same day. Clearer ownership on a smaller team also reduces unowned exceptions.

What happens the first time the AI pushes a wrong change to production?

Writes are constrained by policy: change windows, approvals for high-impact actions, staged apply where available, and rollback through the same API. The AI is an operator under rules, not an unsupervised admin. Accountability for the change remains human.

Who is accountable at 03:00 when the network is down and nobody is on staff?

A named human on the remaining team. AI does not hold the pager for legal, insurance or operational accountability. On-call ownership stays explicit — usually clearer after routine load is removed.

Is this really a saving, or just salary cost moved into licences and cloud?

It is a net OpEx comparison: fully loaded FTE plus tools before versus after. Licences and AI have cost; a labour-majority service desk and specialist-per-site ops have more. Where the estate is already ultra-lean, model the saving honestly — it will be smaller.

What does the AI see of our data, and where does that data physically go?

Defined per engagement. Core surface is network configuration and telemetry via the controller API — not bulk business documents by default. Residency, retention, logging and vendor boundaries are part of the operating model and must match privacy and insurance requirements before go-live.

Can the remaining team still operate the estate if the AI is unavailable?

Yes. The cloud controller remains the system of record. Humans keep admin access and critical runbooks. AI accelerates and audits; it is not the only path to the devices.

How long from decision to the first saving that shows up in the accounts?

Ticket deflection and ops leverage often show within weeks of a live API integration. Fully loaded headcount that hits the P&L follows your people plan — often one to three budget cycles. Support cost in month three is typically lower than month one as the FAQ compounds.

What breaks when we go from 5 sites to 50 — and what does it cost to fix?

Governance, templates, identity, API limits and exception handling — not linear CLI labour. Fix cost is usually process and standardisation, not a second network team.

How does this survive an audit — NIS2, ISO 27001, cyber insurance?

Continuous config evidence, named accountability, change control and access logging map to modern control expectations. The model is designed to produce audit artefacts (who changed what, when, against which baseline), not to hide them. Insurance still cares about privileged access, MFA, backup/recovery and governed automation.

Do McKinsey, Gartner or IBM claim exactly −50% staff and +17% security?

No. The paired percentages are my engagement averages. Those organisations publish related findings (productivity automation potential, network activity automation, security-AI breach-cost impact). This page cites them as context only.

Which AI and network tools does this approach use?

Reference stack: Cisco Meraki (Dashboard API, templates, zero-touch), plus an AI operator with bidirectional API access for plain-language setup and nightly audit, plus company-specific FAQ/voice Tier-1. Meraki’s own AI Assistant and Agentic Workflows show the vendor direction. Equivalent API-first cloud-managed networks can follow the same pattern.