Search

  
 
How to sustain security on a tight budget


October 28 2008

How to sustain security on a tight budget

 

Whether you believe we are in or about to enter a recession, IT budgets are certainly tightening up for 2009. In a climate of uncertainty, CIOs are asking for across-the-board budget "constraint" until the uncertainty clears. Perhaps spending on operations is not being cut, but capital projects are being postponed unless they have clear and short-term return on investment. Even then it may be difficult to get the initial investment approved. So in this environment, what happens to security budgets?


Security spending has been increasing for most of the past decade. Our research has seen security budgets increase from about 2% to about 8% of IT budgets. With sustained investment in security we have also seen a correlation in reported success. Companies that have consistently invested more than 5% of the IT budget in security report fewer challenges with malware, security breaches and identity theft. Sustained investment in the technology, people and process leads to increased security.

In a time of constrained budgets, this type of sustained investment can carry a company through a period of cutbacks. Having developed operational processes and trained security and risk management professionals, companies can reduce capital-intensive projects and sustain consistent levels of security for a short period of time. Of course, at some point capital investments have to resume or companies will fall behind the technology adoption curve and find themselves scrambling to catch up.

For companies that have not invested in security at a sustained level above 5% of IT budgets, scrambling to catch up is the norm. As budgets tighten it will get harder and harder to keep up with the new threats. Even so, there are ways to sustain security with less spending:

Use your skills and acumen to find solutions that are cost effective and make the best use of your existing investments in technology, people and process. Get your employees to help you improve security through training and awareness. In difficult economic times, good security professionals not only survive, they thrive.


 

Reproduced from an article published by ComputerWorld
© ComputerWorld

The original article can be viewed here:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&art...

 Bookmark Digg this story

RSS feed  |  About RSS feeds

Get the Industry's top stories delivered straight to your inbox...
Firstname:

Surname:

Email:

Frequency:
 Daily  Weekly