← Back to the slides AI-run IT infrastructure

Reduce IT staff 50% while increasing cybersecurity 17%

Headcount and security posture are normally assumed to trade off against each other. Driven through its own API by AI rather than by hand, a network moves both in the direction you want at once.

By David Radszuweit · linkedin.com/in/catalyzt · 26 July 2026 · This is the full prose version of a four-slide talk. The deck · PDF · PowerPoint

−50%IT headcount required to run the same estate
+17%Average improvement in measured security posture
24/7Config audit and drift detection, every device, every night

On the numbers. These are averages from my own client engagements — not vendor benchmarks, not a survey, not a modelled projection. Method, baseline and scope are things I explain in the room rather than assert on a slide, because they are the first thing a competent CFO will ask about and the answer depends on where the organisation started.

Why the security number goes up rather than down

The intuitive objection is that cutting an IT team in half must weaken security. It would, if the work simply went undone. The reason it does not is that the mechanism here is not faster configuration — it is continuous reading of actual device state.

A human specialist audits configuration occasionally: at build time, after an incident, before an annual review. In between, reality drifts away from intent. A firewall rule opened for a contractor in March is still open in November. A port enabled for a demo never gets closed. A site brought up during an outage never gets brought back to standard.

An AI holding read access to the Meraki Dashboard API audits every configuration on every device every night. Drift, open ports and stale rules surface the same day rather than at the next review. The measured improvement comes from closing that gap permanently, not from anyone working faster.

The infrastructure layer: Cisco Meraki and APIs

Meraki's relevant property is not its hardware. It is that the entire network — every device, VLAN, firewall rule, SSID and policy — is addressable through one cloud API.

Anyone with little networking skill can secure an entire network

The person doing the work describes the intended outcome in plain language. The AI produces the VLANs, the firewall rules, the SSIDs and the policies. The expertise that used to live in a specialist's head now lives in the description of what the business needs, which is knowledge the business already has.

The API connection goes straight to the cloud controller

No CLI session on forty separate boxes. One authenticated call reaches every site at once. This is what makes the headcount arithmetic work at all: effort stops scaling with device count.

The link is bidirectional

The AI reads state as well as writing it. It sees what actually happened, not what was intended. As above — this is where the security gain comes from, and it is the single most important sentence in the whole argument.

Continuous audit instead of an annual review

Every config, every device, nightly. Drift, open ports and stale rules surface the same day.

New sites in hours, not weeks

Build a template once, ship the hardware, plug it in. Policy applies itself on first boot. Zero-touch provisioning turns a site rollout from a project into a shipping task.

Where the headcount reduction actually comes from

Not from engineering. From Tier 1 support volume.

Most IT salary cost in a mid-sized organisation is not spent designing networks. It is spent answering the same forty questions forever — password resets, access requests, "my laptop is slow", "is the VPN down?". That is the part that becomes self-serve, and it is the part that was never a good use of a skilled engineer's day.

Humans keep the exceptions. The exceptions are where they were always worth paying for.

The questions I put to the room

The third slide of the talk carries these questions and no answers. They are deliberately the hard ones, and they are answered live from the actual deployment rather than from a prepared script — because an answer that only works in the abstract is not an answer.

  1. Where exactly does the 50% come from — which roles go, and which stay?
  2. How do you measure a 17% security improvement? Against what baseline?
  3. What happens the first time the AI pushes a wrong change to production?
  4. Who is accountable at 03:00 when the network is down and nobody is on staff?
  5. Is this really a saving, or just salary cost moved into licences and cloud?
  6. What does the AI see of our data, and where does that data physically go?
  7. Can the remaining team still operate the estate if the AI is unavailable?
  8. How long from decision to the first saving that shows up in the accounts?
  9. What breaks when we go from 5 sites to 50 — and what does it cost to fix?
  10. How does this survive an audit — NIS2, ISO 27001, cyber insurance?

What this is not

It is not an argument that IT expertise stops mattering. It is an argument that the expertise should be pointed at exceptions, architecture and accountability rather than at repetitive configuration and Tier 1 tickets — and that the tooling to make that shift now exists in a form a non-specialist can drive.