There’s a very common and lazy analogy that people often make between insurance and IT security. I could buck the trend and think of something different but to be honest I’m up against a tight deadline (which has already been extended once), so I won’t. Anyway, to continue with our analogy, both are things that people hate spending money on but feel compelled to do so. In both instances, the only time people appreciate the value of what they are paying for is if something goes wrong. It’s no surprise that people hate paying for something that only works when something goes wrong rather than something that works all the time.
However, this is where the analogy reveals the laziness of its creation because, in actual fact, unlike insurance, IT security tends to work all the time (it’s just that, if it works well, we don’t see it). All of which is by way of preamble to a report published in the UK last month by the Department for Business Innovation & Skills entitled 2013 Information Security Breaches Survey.
It found that the number of security breaches affecting UK businesses was increasing and that most large organisations (93%) and small businesses (87%) had been affected. There were increases in attacks from unauthorised outsiders and in denial of service attacks for large organisations and small businesses. The average cost of a security breach for a small business in terms of lost business was £300-£600 and the figure for large organisations was £10,000-£15,000. The cost of dealing with security breaches in terms of time spent was £2,000-£5,000 for small businesses (with another £500-£1,500 in cash costs) and £6,000-£13,000 in time (and £35,000-£60,000 in cash costs) for large organisations.
The report found more than 80% of organisations – big and small – placed a high or very high priority on security and were prepared to spend the money to back it up. Spending on security increased from 8% of the IT budget to 10% (the figure is higher for small businesses at 12%) and as many as 92% of respondents expected to spend at least the same on security next year.
It’s probably worth pointing out that while some companies are spending quite significant sums on IT security, others aren’t. Around one in six organisations spends less than 1% of IT budget on security (compared to one in eight in 2012).
For those channel partners with a strong foundation in the security space, there’s comfort in the fact organisations are devoting more of their IT budget to security in these straitened times"
While this is a UK report, I’m sure the results are probably common to many other countries and Ireland is likely to be fairly similar. As one of the primary supply routes for the provision of IT security to large and small organisations, the channel has a very significant role to play in helping them secure their IT. For those channel partners with a strong foundation in the security space, there’s comfort in the fact organisations are devoting more of their IT budget to security in these straitened times.
Perhaps unsurprisingly, the report found those organisations that suffered a breach had spent less of their IT budget on security than those that didn’t which provides some evidence to support the case for spending on IT security. That’s helpful given that very few organisations (12%) try to calculate the return on investment of their security expenditure and a third don’t try to evaluate its effectiveness.
You would think they might be tempted to do so given that the increase in spending on security as part of the overall IT budget has been accompanied by a rise in the number of breaches and in their impact. Which brings me back to the point about IT security and insurance. If people view IT security as a necessary evil, like insurance, they are unlikely to look too deeply into what they are paying for until something goes wrong. While this might make selling IT security easier in the short term, it causes problems further down the line.
For example, smart channel partners and vendors could do more to help organisations understand that IT security is working all the time to try and protect their data, so they’re paying for something that’s always there. They can help to give customers an appreciation of what security is doing to stop bad things happening all the time. Secondly, if they can get customers to understand and appreciate IT security more, they can get them more involved in the process of ensuring better policies, along with proper awareness and training for their internal staff to make it more effective. And if they do that, they can hold on to more business because customers start to understand there’s a little bit more to IT security than there is for insurance and you shouldn’t just choose your supplier solely on the basis of an annual ring around to see who has the best quote.
The full report is available at http://tinyurl.com/cvkjj82







Ltd