Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Getting Your IT Security Budget Right.

by The Gurus
January 22, 2019
in Opinions & Analysis
Getting Your IT Security Budget Right.
Share on FacebookShare on Twitter

By Alastair Hartrup, Global CEO of Network Critical

Every year for many technology organisations, seeing headlines on a daily basis with reports of data breaches and cyberattacks from all corners of the globe is highlighting the need to ensure they are protected. Board rooms and executive management are more aware of the need for effective cybersecurity today than they ever have been. This awareness is driving action as many organisations look at frameworks for guidance on building effective security programs and ensuring the right budget is set aside.

We know that a strict security regime, rigorous employee training and sound accounting policies can help prevent costly attacks. Yet, it is surprising how few companies are deploying robust cyber security mitigation and remediation processes. One big reason for this lack of security diligence is the difficulty in justifying the expense.

According to last year’s Hiscox Cyber Readiness Report, most businesses lack cyber-expertise to prevent attacks. The reason for this is first, a lack of investment in streamlined technologies and secondly, a shortage of talent is both barriers to fine-tuning data security programs.

The budget justification question for IT security is difficult to answer. How much is saved by not getting hacked? Well, if an event does not occur, it cannot be quantified. However, we can look at instances where companies with lax security policies that have been successfully attacked and extrapolate potential liability from their experiences.

According to the same report, the average cost of cyber-crime across the globe, amassing all incidents, to each business over the past year was £250,000. Behind this number masks some wide variations to businesses on the different scales. For the largest organisations in the report (those with 1,000-plus employees), the average costs ranged between £394,000 in Spain and £1.4 million in the US. Some organisations faced still higher costs – here in the UK and our neighbours Germany the cost was £25 million. These cybersecurity costs only increased throughout 2018 as cyber-crime numbers rose.

The Ponemon Institute’s 2017 Cost of Data Breach Study: Global Overview, highlighted regulated industries such as healthcare, education and financial organisation suffer higher data breaches.

In 2017, the WannaCry ransomware cryptoworm was one of the biggest cyber-attacks in the UK. The worldwide attack happened in May and targeted computers that were running Microsoft Windows OS by encrypting the data and demanding ransom payments in Bitcoin cryptocurrency. In the UK the most damaged business by WannaCry was the NHS, with over 80 practices in England alone being taking down. This resulted in almost 20,000 cancelled appointments, 600 GP surgeries having to abandon the use of their computers and five hospitals that could not accept any more patients due to the influx of emergency cases.

So, when a CFO asks what benefit network security and training can be brought to the company, it is the CIOs that oversees the accessibility, confidentiality and integrity of files and systems. Therefore, CIOs are responsible for securing and allocating budget.

Here are a couple of key components to ensure your security budget provides best practice for your business.

Understand your current systems

We recommend you consider investing in a full risk assessment, which includes vulnerability scans and an in-depth penetration test. Working with a reputable information security firm with proven business acumen will provide a stake-holder readiness report as well as a remediation plan from which you can derive budget numbers.

Understand regulatory bodies and compliance requirements

Many regulatory requirements, such as PCI, HIPAA, and the soon-to-be introduced GDPR pose a very real threat to the company bottom line in the form of fines. These regulations require data security implementations, regular penetration tests and system monitoring. Failure to comply can also lead to heavy fines and damage to brand.

Align your plan with the CFO’s vision

Since IT purchases can be costly, big time technology spending in one quarter versus another can mean the difference between a good year and a bad year for the entire company. I recommend aligning spending with the CFO and the calendar. Purchasing on a relatively even scale throughout the year makes forecasting easier for the CFO and limits any year-end surprises that may come about from overruns or unplanned purchases

Once budgets tend to get to the finalised stage it is also important to include access and visibility to the initial budget and plan. Taps and Packet Brokers are critical components providing the necessary security appliance connectivity and accurate visibility to network traffic. These relatively low-cost devices can actually save money overall by being able to combine traffic from multiple links and reduce the number of high cost security appliances that need to be deployed.

Taps and packet brokers can help keep your budget in line without compromising the protection provided by security appliances. They can also provide the scale necessary to grow without going off-budget. In both budgeting and design, diligent planning and disciplined execution can save, not cost.

ShareTweet
Previous Post

Plexal Bolsters Global Cybersecurity Hub With Two International Partnerships.

Next Post

Wiltshire Payments Security Specialist Selected Again For Top Industry Body In Brazil.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol