Where Should Cybersecurity Budgets Be Allocated?
Getting an adequate cybersecurity budget can be one of the most challenging tasks that many CISOs face. The board wants to keep shareholders happy, which means that they prefer spending on IT to be devoted to business growth and revenue generation. The frequency of breaches makes desensitization more likely, leading to a decreased feeling of urgency to ensure the strength of cybersecurity. Furthermore, many executives have been lulled into a false or misguided sense of security; companies have survived major breaches, and the impact on companies' stock prices has not been as extreme as the declines that followed on the heels of early breaches. It does not help that the return …show more content…
Many cite the need for help to develop runbooks and workflows. However, 45 percent of the respondents stated that their organizations were already using or planning to use automation for runbooks and/or workflows.
• Testing: About 43 percent of the respondents plan to schedule more frequent testing of their IR processes. This points to the need to make IR a series of standard, repeatable tasks rather than an ad hoc activity relegated to senior analysts.
• Staffing: Given the skills gap, this may be a challenging goal to meet, but 38 percent of the respondents stated that they plan to hire additional IR personnel. Many CISOs may find that their organizations will reap greater benefits by engaging vendors to provide them with solutions that enhance automation and collaboration.
There is no doubt that CISOs are going to face abundant challenges in the coming years. Cybersecurity is becoming increasingly difficult every year, and it is becoming harder to stay one step ahead of the criminals. Automation, collaboration, technology integration and external security partners can help CISOs defend their organizations' assets from those who are intent on penetrating the systems to wreak whatever havoc suits their