Budget
With evolving and emerging cyber threats, setting aside enough budget for cyber security initiatives is increasingly important. Recent standards indicate that many firms set aside about ten percent of the total IT budget for cybersecurity. The question is if a fixed amount is the correct way of allocating resources? The budget needs to be set in correlations with other costs in the organization. But, is a percentage of IT budget enough for protecting all your IT environment and investing in security training and awareness, new security solutions, network essentials, perimeter and next-gen data loss prevention, as well as regulatory and compliance adherence? In modern organizations, ten percent may just be a starting point.
Use these approaches for setting your cyber security budget in the year ahead.
Benchmark Approach to Cyber Security Budgeting
How’s your company doing regarding cybersecurity?prevention, detection, and response? It might be difficult to answer this question. If it is difficult to answer that question, then you might consider a benchmarked approach to setting your cyber security budgets and investments.
A benchmark approach looks at how you’re operating and compares it to your peers, a framework, a comprehensive study, or a group of interviewed organizations. When an organization can observe the best practices of other security teams (organizational structure, level of investment in security, KPIs, etc.), the organization can quantify its results and prepare a standard cybersecurity budget that begins to improve on weaknesses and strengthen opportunities.
Risk-Based Approach to Cyber Security Budgeting
If you start with a risk-based approach to setting your budget, you begin to share with your Leadership Team the categories of risk for each area in your information security portfolio. A risk-based approach is often considered a budgeting method for mature security organizations because they can categorize risks across several domains and budget based on the cost to mitigate cyber risks. Uses a framework similar to the NIST Cybersecurity Framework where five domains represent the information security lifecycle.
Other things to consider is
领英推荐
A?study by Deloitte and the Financial Services Information Sharing and Analysis Center?found that financial services on average spend?10%?of their IT budgets on cybersecurity. That’s approximately?0.2% to 0.9%?of company revenue or?$1,300 to $3,000?spent per full time employee. For a bigger picture benchmark, consider that Microsoft CEO Satya Nadella revealed in a statement that the tech behemoth “will invest more than?$1 billion each year?in cybersecurity for the foreseeable future”. Finally, it’s worth noting that the 2019?U.S. President’s budget?allocated?$15 billion?in spending on cybersecurity, about?0.3%?of the entire fiscal budget?($4.746 trillion).
And while none of these figures can clarify what a “typical” budget should look like for the average business or organization, they can at least provide a benchmark for how larger tech firms, financial service companies and governments are allocating cybersecurity spend as a percentage of overall budget.
Back link
Forward link