| | July - AUG 2020ENTERPRISE SECURITY8In My OpinionGet Back to Your SecurityProgram FundamentalsBy Erik Hart, Chief Information Security Officer, Cushman & Wakefieldnformation Security is the topic that every organization is trying to answer as part of their strategy, but is there "an answer"? Recently, Gartner reported approximately $114 billion was spent in 2018 on security; an increase of 12.4%. Furthermore,2019 is projected to have spending exceed $124 billion (8.7% growth). But with this spending, we are still seeing a record number of breaches and a continual trend in expanding regulations. What is the right amount of investment that an organization should make Information Security--is it a percentage of IT spend? And, in which areas should an organization be investing in its security program? An organization's security leader must answer these questions and create alignment to their business strategy and risk tolerance. Organizations that process personal information or financial transactions (ex. banks, credit bureaus, etc.) typically have larger spends due to their risk profiles as well as regulatory and privacy requirements. Historically, executives have thought that security is all about spending and that more cost equals better protection, but the focus should really be about how you drive value for your organization. There are thousands of security vendors (and more coming every day) who tell you that buying their solution will "stop every threat" or "protect your information no matter where it is," but if this were the case why does the number of breaches keep increasing? I would suggest that this trend of purchasing new security tools without first focusing on the basics may be in part to blame. A new "flashy" security system is useless without proper forethought on integration with existing technologies and how to operationalize new alerts. The best investment for any organization is to not always buy the newest tool, but to get back to being good at the fundamentals and creating measurements for the security program. Your Board of Directors is increasingly aware that throwing money at the problem is not a sound investment strategy. They also know having a longer-term strategy and Erik HartIBefore you invest in a new tool or platform, take time to assess your security program
<
Page 7 |
Page 9 >