Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Shortage of technology a greater concern than people or budget

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

A survey of 300 UK IT directors and managers by Cyber Security EXPO found that more than a third (37 per cent) were most concerned about a shortage of security technology, compared to nine per cent who cited lack of budget as the most significant challenge. Almost a quarter (23 per cent) claimed the biggest challenge was the shortage of well-qualified people.

Asked if it was a surprise that professionals were bemoaning a lack of people rather than technology, Brian Honan, CEO of BH Consulting told IT Security Guru that this was no big surprise as many organisations are struggling to maintain and keep their existing technology solutions updated and effective against security threats.

He said: “The main cause behind this is lack of skilled personnel to ensure this work happens. Technology by itself will not secure a company. Experienced and skilled staff is what is required, not just to manage existing technology but to select appropriate new technologies to augment the organisation’s security.”

David Gibson, vice president of Varonis, said: “This isn’t surprising because many times you need people to operate the technology. Most great security products augment human intelligence; they don’t replace it.

“Technology can alert you to dangerous behaviour or help you prioritise your risks, but ultimately humans are responsible for deciding which security policies to put in place and when and where to take action.”

David Howorth, EMEA vice president at Alert Logic, said that it was surprising that it the impact of security spend was not higher, as threats are coming from all angles and companies are spending on security technologies to attempt to prevent and/or remediate those threats.

“But, they are not spending the money on increasing the IT team, who are now expected to keep companies secure and be a jack of all trades, and master of none,” he said.

“If you look at high profile breaches such as the Target breach in the US, they had the technology they needed to protect against that breach, they just didn’t have the IT people to be able to sift through millions of events and incidents, correlate the information with other threat intelligence resources and escalate the top items for immediate remediation.  If they had more people, they could have had a higher chance of dealing with the potential breach.  That is why a lot of companies are looking to security delivered as a managed service: you get the technology and the expertise and the people.”

The survey also found that 91 per cent of respondents are satisfied with the budget they have. Honan said that if the question had been “what’s the most significant challenge?”, then budget may be a challenge, but there are other more significant ones that organisations face, such as lack of skilled staff, ensuring effective security awareness training for staff, effective monitoring, etc.

Howorth said: “Do I think that 91 per cent are happy with the budget they have? Yes and No. ‘Lack of budget’ is an easy cop-out for why systems are not secured. According to Gartner, 80 per cent of security breaches could be prevented by security best practices that are in the control of the IT team, such as basics like patching, implementing two-factor authentication for administrator access, continuous monitoring and analytics etc.

“Budget is not the main issue: it is the skills and resources and bandwidth to be able to be proactive in IT and not just reactive.”
n

The survey also found that 18 per cent of respondents block the use of USB sticks, while 55 per cent would immediately ban the use of USBs.

Gibson said: “A USB stick is one of many ways data can escape. Data can escape via an email, FTP, printers, a lost laptop, or even in a picture of a computer screen taken by a phone. Before focusing on blocking all the escape routes, companies should really prioritise restricting employee access to only the information they need to do their jobs.

“Most employees have access to far more data than they need, and once they have access it’s very difficult to “put the horse back in the barn.”  Once access is restricted, it’s important to monitor and analyse access activity and alert on any abuse.”

Scott Gordon, CMO of ForeScout, said that if you look at data loss and compliance issues for personally identifiable information leaving the organisation, and also look at how USBs sticks have evolved to store more data wirelessly, it is a true threat.

“Companies need to look at the safeguards deployed on intrusion that range from Digital Rights Management to data loss prevention to encryption, and network access control technology,” he said. “We see bans in Government, insurance, financial services, pharmaceuticals. There is no one control for this by itself.”

Looking at the survey data overall,  Steve Durbin, managing director of the Information Security Forum, told IT Security Guru that these findings reinforces something that it had been saying for some time now, that the lack of skills is a very real threat.

He said: “We highlighted it in our Threat Horizon 2015 report, the skills shortage is not getting better. If anything, the clamour for cyber skills it is getting worse.

“We’re seeing this reflected in all parts of the world. People have always been the weakest link and whilst we are continuing to see advances in technology, from a security standpoint we are nowhere near the stage where we can do without the cyber savvy expert to both interpret findings and more importantly, align the use of technology with the emerging business needs that we see developing.

“Are 91 per cent happy with the budget they receive?  I’d be surprised!  I think they have other things getting in the way and frankly, the business astute CIO knows that budget can be made available if (s)he can make the case linking IT and security spend with strategic business intent and demonstrate a solid return on investment.”

TK Keanini, CTO of Lancope, said: “My advice is to look at the larger picture and if you are not going to employ experts on your staff, make sure you still have access to them via partners or connections.”

Cyber Security EXPO will be held next week, 8th and 9th October at London’s Excel centre.

Tags: Cyber Security EXPOSecurity TechnologyShortageSurvey
ShareTweet
Previous Post

Lottery winner’s Facebook profile "wide open" as Camelot admits it does not offer security advice

Next Post

PwC – 9% of businesses "unaware" if they have suffered a data breach in the past 12 months

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol