Pulse - Value Added
← Library
Knowledge Library · Q
Powered by Pulse — Value Added. The #1 source of truth in revenue operations. Find the bottleneck. Fix the pipeline. Win the quarter.

How Many Sales Reps Do I Need to Hire for My Cybersecurity Company in 2027?

Curated by · Fractional CRO · Maryland
PULSEKNOWLEDGE LIBRARY
pulserevops.com

Quality
Certified
AdviceHow Many Sales Reps Do I Need to Hire for My Cybersecurity Company in 2027?
📖 3,314 words🗓️ Published Aug 24, 2026
Direct Answer

Most cybersecurity companies need one quota-carrying rep per $500K–$1M in net-new ARR, plus backfills for attrition and a ramp discount. Back into it: divide the gap your existing base won't cover by realistic per-rep production, then add roughly 30–50% more headcount to absorb the two-to-three-quarter security ramp.

What headcount math actually measures and why security breaks the shortcut

Every sales leader has run the same shortcut at least once: take the revenue gap, divide by quota, hire that many people. It produces a number in ten seconds and it is wrong almost every time, because quota is an aspiration and capacity is a fact. The two are not interchangeable. Quota is what you put on paper so the compensation plan works and the board sees coverage. Capacity is what a fully ramped rep actually books in a normal year at the attainment your team really hits. If your posted quota is $900K and your median attainment is 68%, your true per-rep capacity is closer to $610K, and building a hiring plan on the $900K figure guarantees a shortfall you won't detect until Q3.

Cybersecurity distorts the shortcut further than most categories. The buying committee is unusually crowded — a CISO who owns risk, a security architect who owns the technical evaluation, a procurement team that owns the paper, and increasingly a compliance or GRC stakeholder who owns the audit narrative. Each one can stall a deal without killing it, which stretches cycles without cleanly disqualifying anything. That means pipeline coverage ratios that work in transactional SaaS — 3x, maybe 4x — are dangerously thin here. Security teams selling six-figure platform deals commonly need 4x to 6x coverage against a quarterly number, and that coverage requirement translates directly into how many bodies you need generating and working pipeline.

The second distortion is proof-of-concept gating. A meaningful share of security deals require a technical validation stage — a POC, a pilot deployment, a bake-off against an incumbent, sometimes a red-team exercise. That stage consumes rep hours without producing revenue and it consumes sales-engineering hours in parallel. If you hire AEs without the SE coverage to support the POCs those AEs generate, you have not added capacity; you have added a queue. A useful planning ratio in security is one SE for every two to three AEs when deals are technical and POC-heavy, tightening toward 1:2 in enterprise and loosening toward 1:4 in mid-market or channel-led motions.

The third distortion is revenue mix. Cybersecurity revenue is rarely pure new-logo subscription. It's a blend of platform subscription, per-seat or per-endpoint expansion, managed detection and response retainers, professional services for deployment, and sometimes hardware or appliance pass-through. Your headcount model must run on the recurring subscription and managed-service line only. If you feed it total revenue including services and hardware, you will size the team against dollars your AEs don't actually sell, and you'll hire two or three people too many.

The last thing worth naming: headcount planning is a *timing* problem disguised as a counting problem. A rep who starts in September contributes almost nothing to that fiscal year in a category where the average cycle runs six to nine months. The count and the calendar are the same decision. Getting the number right but the start dates wrong produces the identical miss as getting the number wrong.

The step-by-step process for backing into a defensible number

Work it in this order, and write down every assumption as you go — the assumptions are what you'll defend to a board, not the arithmetic.

Step one: establish your net-new requirement. Start with current ARR and goal ARR. Subtract what your existing base produces on its own at your current net revenue retention. A $6M base at 108% NRR carries itself to roughly $6.5M without a single new logo, through seat expansion, module cross-sell, and renewals at higher tiers. If your goal is $9M, your AEs must produce roughly $2.5M net-new — not $3M. This single step routinely cuts a naive hiring plan by 15–20%. In security, NRR is often your cheapest lever: landing a single product like endpoint or email security and expanding into the full platform costs far less than acquiring a new logo, and every point of NRR you add reduces the headcount you must hire.

Step two: establish real per-rep capacity. Pull the trailing twelve months of closed-won new ARR per fully ramped AE. Use the median, not the mean — one whale distorts the average and will convince you your team is more productive than it is. Strip out any rep who wasn't fully ramped for the whole period. In cybersecurity, fully ramped AE production commonly lands between $500K and $1.2M depending on segment: mid-market platform deals in the $40K–$120K ACV range mean 8–15 wins a year, while enterprise reps closing $250K–$600K deals might win four to six times and still clear a higher number.

Step three: convert to rep-years. Divide net-new requirement by per-rep capacity. $2.5M divided by $600K is about 4.2 rep-years of productive capacity. This is not four hires. It's four *years of productive selling*, and a new hire delivers a fraction of a year in year one.

Step four: apply the ramp discount. A cybersecurity AE hired today is not productive for two to three quarters. They're learning the threat landscape vocabulary, the technical product, the compliance frameworks buyers care about — SOC 2, ISO 27001, FedRAMP, PCI DSS, and increasingly regional data-protection regimes — and building pipeline through evaluation cycles that don't compress just because the rep is new. A rep starting in month one of the fiscal year might deliver 50–60% of a ramped year. A rep starting in month four might deliver 25–30%. A rep starting in month seven delivers pipeline for next year and roughly nothing for this one.

Step five: add backfills. Apply your annual attrition rate to your current AE roster. Security sales talent is heavily poached and turnover in the 15–25% range is unremarkable. On a ten-AE team, 20% attrition means two hires that add zero net capacity — they replace people. Budget them separately so you never confuse standing still with growing.

Step six: assign start dates and re-run. This is where most plans fail. Take your ramp-discounted contribution per hire and lay hires across the calendar until cumulative contribution covers the net-new number. You'll usually find the plan only works if a majority of hires start in the first four months — which means recruiting must begin before the fiscal year does.

Run this whole sequence quarterly, not annually. Attainment drifts, ramp assumptions prove optimistic, and a single unexpected departure in a six-person team changes the answer by a full head.

Costs, timelines, and the ranges you should actually plan around

The hire count is only half the budget conversation. Fully loaded cost per cybersecurity AE — base, variable at target, benefits, payroll tax, equipment, travel, and the software seats that make them functional — commonly runs 1.4x to 1.6x on-target earnings. Security AEs command a premium over generalist SaaS reps because the technical bar and the buyer sophistication are higher, and because demand for people who can hold a credible conversation with a CISO consistently outruns supply.

Timeline is where plans quietly break. A realistic sequence for one enterprise security AE looks like this: four to ten weeks of recruiting and interviewing, two to six weeks of notice period at their current employer, four to eight weeks of onboarding and enablement before they're independently running discovery, and then a full sales cycle — six to nine months in enterprise security, three to five in mid-market — before their first self-sourced deal closes. Add it up and the gap between "we approved the req" and "that rep's first closed-won deal" is frequently nine to fourteen months in enterprise. If your board wants revenue in this fiscal year, the hiring decision needed to happen last quarter.

Ramp curves worth planning against, expressed as percentage of a ramped rep's quarterly production: quarter one at 10–25%, quarter two at 35–50%, quarter three at 60–80%, quarter four at full. Enterprise security sits at the slower end of every one of those bands. If your enablement is thin, add a quarter to the whole curve. If you're hiring people who've sold into security buyers before, you can shave four to six weeks off the front — the vocabulary and the objection patterns transfer even when the product doesn't.

Support-function costs ride along with every AE and are the most commonly forgotten line. SDR or BDR coverage at roughly one per two to three AEs in an outbound-heavy security motion. Sales engineering at one per two to three AEs where POCs are standard. Tooling — CRM seat, sales engagement platform, conversation intelligence, data and enrichment, e-signature — that adds a meaningful per-rep monthly cost on top of salary. And the least-visible cost of all: management. Span of control in complex security sales holds at roughly six to eight AEs per frontline manager. Cross that line and coaching quality degrades exactly when a batch of new hires most needs it. Hiring your seventh AE frequently means hiring a manager too, and that manager's cost belongs in the same plan.

Attrition costs deserve their own line. A rep who washes out at month five has consumed recruiting spend, base salary through ramp, manager and enablement hours, and — most expensively — a territory that sat underworked for half a year. The territory cost usually exceeds the salary cost. This is the single strongest argument for hiring in small batches: a bad hire in a batch of two is a setback, while a bad hire in a batch of eight is often three bad hires, because the enablement bandwidth that would have caught the problem was spread too thin to notice.

One practical range to hold onto: for most cybersecurity companies between $3M and $20M ARR growing 40–60% annually, the answer to "how many reps do I need to hire this year" lands between four and nine, and the number is more often at the low end than leaders expect. Above $20M, segment structure and channel motion start to dominate the arithmetic and the model needs territory-level detail rather than a company-level average.

Where cybersecurity teams get headcount planning wrong

Using posted quota instead of median attainment. Already named, but it's the number-one error and worth restating because it compounds: an optimistic capacity input inflates every downstream figure in the model.

Ignoring ramp entirely. The naive "gap divided by quota" calculation implicitly assumes every hire is productive on day one. In a category with a two-to-three-quarter ramp and a six-to-nine-month cycle, that assumption is off by more than a year of production.

Hiring the count without hiring the support. Six new AEs and no additional SE means POCs queue, evaluations stall, and your new reps' pipeline ages out. You bought headcount and received bottleneck. The same is true for SDR coverage in an outbound motion, and for enablement bandwidth — the person who onboards two reps well cannot onboard six well at the same time.

Hiring in one large batch. Batching feels efficient and is not. Onboarding quality drops sharply with cohort size, territories get carved hastily to accommodate everyone at once, and if your ICP assumption turns out wrong you discover it with eight people's salaries running instead of two. Hire in waves of two or three, spaced a quarter apart, and let each wave's early results inform the next.

Sizing against total revenue instead of recurring subscription revenue. Services, deployment, and appliance revenue don't come from AE prospecting in the same way subscription ARR does. Mixing them inflates the gap and the headcount.

Treating NRR as fixed. In security, expansion is often the cheapest growth available — a customer who already trusts you with endpoint is far easier to sell email security or identity to than a stranger is to sell anything. Two points of NRR improvement can eliminate an entire hire. Before approving reqs, ask whether a customer-success or expansion-focused investment would deliver the same ARR at lower cost and shorter latency.

Hiring for a motion you haven't proven. If founder-led selling has produced your first fifteen customers and nobody has documented what actually works, hiring five AEs is buying five people the chance to fail at an undefined job. Get one non-founder rep to quota first. That single data point — a repeatable win by someone who isn't you — is worth more than any model.

Forgetting that territories are finite. At some point you run out of addressable accounts per rep and additional headcount cannibalizes rather than adds. In tightly-defined security niches — say, OT security for industrial manufacturers, or compliance tooling for a specific regulated vertical — this ceiling arrives earlier than in horizontal categories. Count the accounts before counting the reps.

Planning annually and never revisiting. A plan built in November against November assumptions is stale by March. Re-run it quarterly with actual attainment, actual ramp, and actual attrition.

A decision framework for when to hire, when to wait, and what to hire instead

Not every revenue gap is a headcount problem, and the most valuable thing this model does is tell you when hiring is the wrong answer.

If your existing reps are under 70% attainment, adding headcount rarely fixes anything. The constraint is enablement, product-market fit, lead quality, or territory design. Adding people to a system with a broken conversion rate produces more people converting badly. Fix the rate first — a team of five going from 65% to 85% attainment delivers the same production as two additional hires, faster and cheaper.

If your reps are at 95%+ attainment and pipeline coverage exceeds 4x, you are genuinely capacity-constrained. Hire, and hire faster than feels comfortable, because the ramp latency means you're already late.

If attainment is healthy but coverage is thin, your constraint is demand generation, not closing capacity. The right hire may be an SDR, a demand-gen marketer, or a partner manager rather than another AE. In cybersecurity specifically, channel and MSSP partnerships can generate qualified pipeline at a lower cost per opportunity than outbound, and a single strong partner manager sometimes outproduces two AEs on a pure-hunting motion.

If POCs are your bottleneck, hire sales engineers before AEs. A stalled technical evaluation is lost revenue on pipeline you already paid to create — recovering it is cheaper than generating new pipeline.

If you're pre-repeatability, hire one rep, not five. The goal of that hire is not revenue; it's proving that someone other than the founder can win. Only after that proof does the capacity model mean anything, because before it you have no honest capacity input to feed the model.

The framework's real value is that it makes "don't hire yet" a legitimate output. Most headcount models can only ever say *more*. This one can say *not yet, and here's the cheaper thing to do instead* — which in a category where a bad AE hire costs the better part of a year's territory production, is the more valuable answer more often than leaders expect.

Related questions

How does this change for a channel or MSSP-led security company?

Substantially. If partners source most pipeline, you need partner managers and channel-enablement resources more than direct AEs. Per-rep capacity is often higher because partners do prospecting, but deal control is lower. Model partner-sourced and direct ARR as separate streams with separate capacity assumptions.

Should I hire security-experienced reps or strong generalists?

Experienced security reps ramp meaningfully faster because the vocabulary, buyer personas, and objection patterns transfer. Generalists can succeed with strong enablement and simpler products, but expect a noticeably longer ramp. If your runway is short, pay the premium for domain experience.

How many SDRs do I need alongside these AEs?

In outbound-heavy security motions, roughly one SDR per two to three AEs. If inbound or channel supplies most pipeline, the ratio loosens. Size it by meetings required: work backward from AE pipeline coverage needs to meetings per month to SDR productivity.

When do I need a sales manager instead of another rep?

Around six to eight AEs per frontline manager. If you're crossing that line while also onboarding new hires, the manager hire comes first — coaching capacity is what makes the new reps productive, and understaffing it wastes the hires you just made.

Does the same model work for adjacent categories like devtools or compliance software?

The structure holds — net-new divided by real capacity, adjusted for ramp and attrition. The inputs shift: shorter cycles and lower ACV in devtools mean faster ramp and higher deal counts, while compliance software often sits between devtools and enterprise security on both dimensions.

FAQ

How many sales reps should an early-stage cybersecurity company start with?

Most start with one to three, frequently including a founder or fractional revenue leader in that count. The purpose of the first non-founder hire is proving the motion is repeatable, not hitting a number. Scale only after one rep outside the founding team reaches quota on a documented process.

What per-rep quota is realistic in cybersecurity?

It varies widely by segment and ACV. Mid-market security AEs commonly carry quotas in the mid-six figures; enterprise reps selling large platform deals carry meaningfully more. The number that matters for planning isn't the posted quota — it's your team's median attainment against it, which is typically well under 100%.

How long until a new cybersecurity rep is fully productive?

Plan on two to three quarters to full productivity, longer in enterprise where a single cycle can run six to nine months. Reps with prior security-domain experience compress the front end of that curve; reps new to the category often need an extra quarter to build credibility with technical buyers.

Should I count expansion revenue against AE capacity?

Only if your AEs actually own expansion. Many security companies route expansion through customer success or a dedicated account-management function, in which case expansion belongs in your NRR assumption rather than your AE capacity input. Counting it twice is one of the most common ways headcount plans overstate coverage.

How do I know if I hired too many reps?

Watch pipeline per rep and territory saturation. If coverage per rep drops below 3x, if reps are working overlapping accounts, or if median attainment falls after a hiring wave, you added bodies faster than you added addressable demand. The fix is usually territory redesign and demand-gen investment, not more hiring.

How often should I re-run the capacity model?

Quarterly at minimum. Attainment drifts, ramp assumptions prove optimistic, and a single departure on a small team changes the answer by a full head. Treat the model as a living plan you revise with actuals, not a document you produce once at budget season.

Sources

flowchart TD A[Current ARR and Goal ARR] --> B[Subtract base growth at current NRR] B --> C[Net-new ARR the AE team must produce] C --> D[Divide by real per-rep capacity] D --> E[Rep-years of capacity required] E --> F[Apply ramp discount by start month] F --> G[Add backfills for expected attrition] G --> H[Check SE and SDR support ratios] H --> I[Assign start dates across the calendar] I --> J{Cumulative contribution covers gap?} J -->|No| K[Pull start dates earlier or raise NRR goal] K --> F J -->|Yes| L[Final hiring plan with dates]
flowchart TD A[Revenue gap identified] --> B{Existing rep attainment} B -->|Under 70%| C[Fix enablement, ICP, or territory first] B -->|70 to 95%| D{Pipeline coverage} B -->|Above 95%| E[Genuine capacity constraint] D -->|Under 3x| F[Invest in demand gen, SDR, or channel] D -->|3x to 4x| G[Hire selectively in waves of two] D -->|Above 4x| E E --> H{POC or technical stage stalling?} H -->|Yes| I[Hire sales engineers before AEs] H -->|No| J{Repeatable non-founder win proven?} J -->|No| K[Hire one rep and prove the motion] J -->|Yes| L[Run the capacity model and hire to plan] L --> M{Crossing seven AEs per manager?} M -->|Yes| N[Add frontline manager in the same plan] M -->|No| O[Execute hiring plan with staged start dates]

Related on PULSE

Download:
Was this helpful?  
This page will be disappearing soon.
Download the whole page as a PDF to keep — just $1.
⌬ Apply this in PULSE
Pillar · Deal Desk ArchitectureFrom founder override to scaled governanceGross Profit CalculatorModel margin per deal, per rep, per territoryRecruiting CalculatorHow many reps you need before you hire