How to sustain security on a tight budget

By Andreas M. Antonopoulos, Network World |  Security, economy, IT management Add a new comment

Whether you believe we are in or about to enter a recession, IT budgets are certainly tightening up for 2009.

In a climate of uncertainty, CIOs are asking for across the board budget "constraint" until the uncertainty clears. Perhaps spending on operations is not being cut, but capital projects are being postponed unless they have clear and short-term return on investment. Even then it may be difficult to get the initial investment approved. So in this environment, what happens to security budgets?

Security spending has been increasing for most of the past decade. Our research has seen security budgets increase from about 2% to about 8% of IT budgets. With sustained investment in security we have also seen a correlation in reported success. Companies that have consistently invested more than 5% of the IT budget in security report fewer challenges with malware, security breaches and identity theft. Sustained investment in the technology, people and process leads to increased security. In a time of constrained budgets, this type of sustained investment can carry a company through a period of cutbacks. Having developed operational processes and trained security and risk management professionals, companies can reduce capital-intensive projects and sustain consistent levels of security for a short period of time. Of course, at some point capital investments have to resume or companies will fall behind the technology adoption curve and find themselves scrambling to catch up.

For companies that have not invested in security at a sustained level above 5% of IT budgets, scrambling to catch up is the norm. As budgets tighten it will get harder and harder to keep up with the new threats. Even so, there are ways to sustain security with less spending:

-- Focus on training and awareness. Organize weekly or monthly security awareness seminars, post security awareness posters, print a security tips brochure. Training not only reduces unintentional employee security lapses but may also increase early notice of problems by increasing employee awareness and vigilance.

-- Renegotiate license contracts. If you're hurting, so are the sales teams of security vendors. Now is the time to negotiate a better volume license. Shop around with competitors of your incumbent vendor and ask them to offer pricing that will cover the cost of transition. Then turn that around as leverage with your incumbent vendors. Ask for a discount for higher volumes or ask them to throw in one year's maintenance for free. We've seen vendors willing to do all of the above.

-- Investigate open source. There are many robust and sophisticated open source security solutions. If you have the skills to test, deploy and maintain these with community support they're worth checking out. You can find good solutions in vulnerability analysis, monitoring, IDP, firewalls, directory and identity management, etc. Many of these solutions are also available as virtual appliances that are easy to test and install.

Use your skills and acumen to find solutions that are cost effective and make the best use of your existing investments in technology, people and process. Get your employees to help you improve security through training and awareness. In difficult economic times, good security professionals not only survive, they thrive.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question