For years cybersecurity spending has experienced stratospheric growth. Then COVID-19 hit and forecasts took a grim turn.
As a result of the economic impact of the pandemic, Gartner estimates there will be a $6.7 billion decrease in global security spending in 2020. Meanwhile, Forrester warns security teams to expect lean budgets and the trimming of already-thin staff, reports Dark Reading.
The truth is, the era of infinite security spending was coming to an end even before the coronavirus struck. In the face of constantly evolving threats and seemingly unstoppable cybersecurity incidents, the C-suite and board have grown increasingly concerned about the ROI of their security investments.
Part of the problem lies in a disconnect between the C-suite and security managers. Executives don’t always fully understand cyber risk and might not comprehend that investment now can prevent cyber attacks in the future. Simultaneously, security leaders are still very technology focused and don’t always align with the business when evaluating how to spend security dollars.
In light of the current slowdown, it’s even more important for security leaders to justify the budgets they need to help drive their businesses forward, securely. Let’s take a look at how this can be achieved.
1. Understand the risk landscape so spend can be prioritized
In order for security leaders to justify their budgets and better align spend to outcomes, they must gain visibility into where the greatest risk exists across the digital ecosystem. To do this, teams must be able to quickly discover, assess, and report on areas of disproportionate risk across their digital assets — on-premise, in the cloud, and across remote office environments. Companies with subsidiaries or operations in multiple geographies can conduct similar analysis across their enterprises to pinpoint where the greatest cyber risk exists.
In this way, they can prioritize security spending and quickly introduce cyber risk reduction programs where they are most needed and will demonstrate the greatest ROI.
2. Use metrics to justify funding
Too often, when reporting to the board, security performance is quantified in terms of a vague scale of high, medium, and low grades, but senior management is likely looking for something more concrete. Therefore, security teams should leverage metrics that have a direct relationship to positive or negative outcomes. It is incumbent on security teams to show that their work has real world outcomes that help the business grow, scale, and increase profitability.
Security ratings, for example, correlate directly to an enhanced risk of data breaches. Independent research found that companies with a Bitsight Security Rating of 500 or lower are nearly five times more likely to have a breach than those with a rating of 700 or higher.
Security leaders can use security ratings to justify funds for their security programs. If their ratings drop, due to an increase in unpatched systems or other vulnerabilities, they can link that lapse to an increased likelihood of a breach — and make a case for X amount of dollars to address the problem and improve their security postures.