Budgeting for cyber security - count the costs
ONE of the hallmarks of a successful cyber security strategy is a business that does not fall victim to damaging cyber attacks which costs money (and face). This makes it difficult to measure the return on investment in cyber security solutions, because success is demonstrated through the absence of something rather than the generation of business income. This can make it tough for chief information security officers (CISOs) to make a compelling business case for bigger cyber security budgets.
Oftentimes, it is also a challenge to prioritise or determine which cyber security solutions are working and which are superfluous. This is especially tricky given the disruptions brought about by Covid-19 in the past few months. Organisations are dealing with unprecedented levels of change, and are likely to take on a more vigilant and cautious approach to spending as they figure out how to adapt to the new normal.
One way to effectively budget for cyber security is to attach real numbers to hypothetical situations. Determining how much a successful breach could cost the organisation is a compelling way to demonstrate the value of the technology that prevents that breach from occurring.
When budget decision-makers understand the real cost of a cyber breach, they can start to make more realistic and appropriate budgeting decisions to mitigate risk.
It is also important to understand that the existing cyber security systems that have protected the organisation for the past 12 months may not be sufficient to continue protecting it in the coming year. As cyber attacks continue to gain momentum, velocity and severity, so do cyber risks.
The only way to approach cyber security effectively is to think of it as a way to help mitigate cyber risk. Just like any other business risk, cyber risk needs to be included in the organisation's overarching risk-management strategy.
KNOW YOUR NEEDS
Managing cyber risk begins with cyber security risk assessment that comprehensively measures the organisation's security posture across a range of industry best practices. In order to ensure a holistic assessment when measuring the effectiveness of cyber security, it is vital to also look at policies, asset management, supplier relationships and more, instead of just the tools being used.
There are various standards that can be helpful when conducting the risk assessment, such as the ISO 27001 Security Framework. However, the most crucial aspect of any framework is for it to be both understandable and measurable for the board and senior management.
Once the assessment is complete, it should illuminate gaps and vulnerabilities. However, not all of these need to be addressed with urgency. It is essential to identify the most important assets, known as the crown jewels, and understand how to protect them effectively. Therefore, the goal of the assessment should not be to identify and close all possible gaps, but to create a strategic roadmap for risk mitigation.
The security framework used for risk assessment can also be used to identify the most critical risk factors to address. This can include lack of visibility, lack of control, overcomplexity, lack of resources, and others.
The strategic roadmap should also align with the organisation's goals and priorities. Once it is in place, the budgeting process can begin. The direct costs of cyber security are likely to be clear in terms of technologies, operational costs, and personnel required.
However, this still leaves a challenge in terms of measuring the financial impact of investment associated with risk mitigation.
For an organisation that lacks experience, it might be helpful to consult a managed security services provider. Alternatively, it is also possible to create a holistic security umbrella that measures where, when, and how changes in policies, investments, personnel, and more can deliver improvements. Doing so makes it easier to compare the costs of those improvements to the benefits they offer.
MEASURING THE COST
Measurement of risk mitigation can be more effective if CISOs leverage accepted industry research and best practices. For example, reports on the cost of data breaches can shed enormous light on the true value of cyber security investments.
Our upcoming report The State of Cybersecurity in Asean reveals that 18 per cent of organisations in the region lost at least US$100,000 as a result of cyber breaches in 2019. If the cost associated with a certain type of breach is known, then CISOs can see that it is not worth investing more than that to mitigate the risk. Conversely, if the cost of a breach is typically very high, it is then clear that it is worth investing more in preventing that type of breach.
Because reports on the cost of data breaches are numbers-driven, they can be powerful tools in the business case for increased investment in cyber security resources. Knowing exactly where the highest priorities are can make it far easier to budget effectively for cyber security.
TRENDING NOW
MAS allocates S$1.45 billion to five asset managers in third EQDP batch: Chee Hong Tat
‘My grandfather’s legacy’: Sherman Kwek lays out three-year plan for CDL to drive returns
‘How many will survive?’: Bubble fears arise as China’s humanoid robotics face reality check
CDL to hire dedicated CEO for fund management as it steps up push into private funds