Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

AppSecEu: Two year CISO strategies enable better budget negotiation

by The Gurus
June 30, 2014
in Editor's News
Share on FacebookShare on Twitter

CISO strategies are commonly built for two year plans.
Speaking at the AppSec conference in Cambridge, Tobias Gondrom, OWASP Global Board Member and project lead for OWASP, featured highlights from the 2013 OWASP CISO survey report which found that there was more investment in application security than infrastructure.
Gondrum said that 38 per cent of the 100 CISOs surveyed invested in infrastructure, compared to 47 per cent who invested in application security. He said that it could be concluded that “investment is the answer to the threat” as to where you put your money and where you talk. “The top result was training, and this was a clear number one for spending, then it was software development and testing, then management.”
He said that, in his view, commonly strategies are two years into the future (according to 27.8 per cent) as “we have no idea where the world will be in five years in terms of technology”. He also claimed that even in the cases where there has been a security breach there is no real change, and while it is believed that business usually invest more after an incident, there was no significant statistical evidence for that.
He said: “However there is a small benefit if there is a two year strategy, as you can increase on the security investment. My hypothesis is that a CISO cannot move much, and cannot put in money in the first year, but can in year two so they are planning it for next year. If you go into the budget negotiation, you can come in with advantageous position on budget decision. We see a correlation.”
The survey also found that 75 per cent of respondents were not using a maturity model or benchmark themselves and not looking in structured ways at where they are, but he said that there was a “glimmer of hope on the horizon” with 40 per cent considering doing it in the next 12 months.
For the future, Gondrom said that the identified top four challenges were in order: the availability of skilled resources; the level of security awareness by developers; management awareness and sponsorship; and adequate budget, which he said: “We need to teach people more about.”

Tags: 2014CISO
ShareTweet
Previous Post

Public and private sector partnerships key to cyber crime fight, say BBA and NCCU

Next Post

OWASP AppSecEU – Focus on attacker capabilities, not identity

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol