Headcount and security posture are normally assumed to trade off against each other. Driven through its own API by AI rather than by hand, a network moves both in the direction you want at once.
On the numbers. These are averages from my own client engagements — not vendor benchmarks, not a survey, not a modelled projection. Method, baseline and scope are things I explain in the room rather than assert on a slide, because they are the first thing a competent CFO will ask about and the answer depends on where the organisation started.
The intuitive objection is that cutting an IT team in half must weaken security. It would, if the work simply went undone. The reason it does not is that the mechanism here is not faster configuration — it is continuous reading of actual device state.
A human specialist audits configuration occasionally: at build time, after an incident, before an annual review. In between, reality drifts away from intent. A firewall rule opened for a contractor in March is still open in November. A port enabled for a demo never gets closed. A site brought up during an outage never gets brought back to standard.
An AI holding read access to the Meraki Dashboard API audits every configuration on every device every night. Drift, open ports and stale rules surface the same day rather than at the next review. The measured improvement comes from closing that gap permanently, not from anyone working faster.
Meraki's relevant property is not its hardware. It is that the entire network — every device, VLAN, firewall rule, SSID and policy — is addressable through one cloud API.
The person doing the work describes the intended outcome in plain language. The AI produces the VLANs, the firewall rules, the SSIDs and the policies. The expertise that used to live in a specialist's head now lives in the description of what the business needs, which is knowledge the business already has.
No CLI session on forty separate boxes. One authenticated call reaches every site at once. This is what makes the headcount arithmetic work at all: effort stops scaling with device count.
The AI reads state as well as writing it. It sees what actually happened, not what was intended. As above — this is where the security gain comes from, and it is the single most important sentence in the whole argument.
Every config, every device, nightly. Drift, open ports and stale rules surface the same day.
Build a template once, ship the hardware, plug it in. Policy applies itself on first boot. Zero-touch provisioning turns a site rollout from a project into a shipping task.
Not from engineering. From Tier 1 support volume.
Most IT salary cost in a mid-sized organisation is not spent designing networks. It is spent answering the same forty questions forever — password resets, access requests, "my laptop is slow", "is the VPN down?". That is the part that becomes self-serve, and it is the part that was never a good use of a skilled engineer's day.
Humans keep the exceptions. The exceptions are where they were always worth paying for.
The third slide of the talk carries these questions and no answers. They are deliberately the hard ones, and they are answered live from the actual deployment rather than from a prepared script — because an answer that only works in the abstract is not an answer.
It is not an argument that IT expertise stops mattering. It is an argument that the expertise should be pointed at exceptions, architecture and accountability rather than at repetitive configuration and Tier 1 tickets — and that the tooling to make that shift now exists in a form a non-specialist can drive.