RSA Conference 2007
RSA Conference 2007
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Security investments remain a tough sell

IT staff struggle to make the case for return on investment

Tom Sanders at RSA Conference in San Francisco, vnunet.com 08 Feb 2007
ADVERTISEMENT

Corporate IT security staff continue to struggle with balancing security investments and business priorities.

Funds spent on security cannot be measured as a return on investment because they may or may not prevent a disaster.

In regulated businesses such as banking, insurance and medicine, security is mandated by regulations, but this does not completely alleviate the problem.

"Companies further along the security curve are saying: 'I spend lots of money on security. All I can tell my chief financial officer is that he can sleep well at night because I'm spending all this money,'" Arshad Matin, vice president for compliance and risk management at Symantec, said at a company event during the RSA Conference in San Francisco.

"They are looking for ways to quantify the benefits in a way that business leaders understand."

Christopher Leach, chief risk officer at First Horizon, recommended that companies treat security risks as a potential system outage to estimate the potential risk and justify investment.

"As soon as you put it back into business terms, [senior management] understands it and you're done," he said.

Return on investment is difficult to measure. If a security breach brings down a transactional system, the damage can be quantified fairly easily.

But in the rare case that an incident becomes public, a firm's reputation and stock price are also likely to suffer.

This requires enterprises to shift security policies from a reactive mode in which they respond to incidents, to a proactive mode in which they actively try to prevent incidents.

This in turn changes the jobs of a firm's security staff from plugging holes to educating business lines about the costs in case of an incident and building a consensus about the best solution.

"But the challenge to that approach is that the chief security officer is held accountable," warned Leach.


All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Foster Wheeler
Analyst Programmer - Applix TM1 -Competitive Salary - ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals ... more >
| Foster Wheeler
Analyst Programmer - JDEdwards- ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals lt;/p> Our UK-headquartered operations ... more >
| Google
The area: DoubleClick DoubleClick, a Google company, enables top marketers, publishers and agencies to utilize DoubleClick's expertise in ad serving, rich media, video and affiliate marketing to help them make the most of the digital ... more >
| Google
The area: Engineering Management Google's engineering teams exhibit high energy, deep technical skills and a drive to get things done. Our Engineering Managers need to be technical leaders and motivators who are comfortable leading these ... more >
More job opportunities