Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

2/27/2016
10:30 AM
Yoran Sirkis
Yoran Sirkis
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

The ROI Of Infosec: 11 Dos and Don’ts For Management Buy In

The case for a bigger bottom line depends on how well you argue that the business can't run without a specific level of security infrastructure.

Selling IT security up the ladder isn’t as hard as it used to be but it still isn’t the easiest thing to do. Budgets are always squeezed, and you’re constantly asked to do more with less. Security managers need to prove that the company is better off with a tight, streamline security infrastructure in place across all aspects of the organization -- a daunting challenge.

Your best strategy is to show that information security is a critical part of your company’s everyday business process. Demonstrating the return on your information security investment can go a long way towards helping your cause. Here are a 11 points to take to the C-suite and boardroom.

  1. Do make it personal. It’s critical that CEOs and board members grasp the fact that they can be held criminally liable when something goes wrong – and things always go wrong; myriad attacks on your system occur every hour, at minimum. Only the damages vary. Systems and forensics must be in place demonstrating that everyone did their utmost to secure the information.
  2. Do speak the same language. Listen and pay attention to how the CEO positions her priorities and requests. Mirror that language when you approach her.
  3. Do offer a comprehensive view of corporate vulnerability. Data today is everywhere – network, cloud, mobile devices, remote employees, third party partners and service providers, etc. Clearly explain that security resources must be decentralized and cover everything If you protect your information in one area only, the attacker will find the weakest link and use that to reach everything.
  4. Don’t portray IT security as a “complication.” Stress that while security is largely invisible, it is also a business enabler. Demonstrate how IT security facilitates operations, for example, policies within a classification system can ensure that everyone in the accounting department can access certain files and folders automatically without having to make change requests.
  5. Do tie data security classification to expenses. A company’s ability able to find and classify the data will determine how it should be stored and the level of protection it requires. You may end up with a list that shows that only 10% of corporate data needs to be protected at the highest level, immediately reducing operating expenses and longer-term capital expenses.
  6. Do more than simply present the CEO with a list of security vulnerabilities. Explain  the consequences of the vulns, in terms of legal issues, damage to reputation, fines, etc.
  7. Don’t ignore the bottom line. You can  demonstrate the actual cost of security breaches with a quick Google search for recent examples. Here’s one at our fingertips: Target settled for $39 million to pay financial institutions affected by its breach.
  8. Do remind upper management of your company’s legal obligations and how they are affected by security breaches. For example, your company probably agreed to multiple NDAs before business partners agreed to send you proprietary information. Should an outsider access that information from your internal systems, you’ve basically voided the NDA, opening you up to legal action.
  9. Do review the statutes. Most companies are either obligated to follow SOX, PCI-DSS, NASD, SEC or other regulatory bodies. Compliance audits are a regular occurrence, and it is cheaper and easier to be in continual compliance than have to make corrections to integral corporate systems once you’ve failed the audit and are liable for massive fines. (Another ROI feature.)
  10. Do create alliances within your organization to present “group” priorities. Pay particular attention to the corporate risk management team.
  11. Do explain how data security is a critical part of supporting the employee relationship. Employers have access to employees’ healthcare records and personal family information, etc. If they become part of the public record it is a significant breach of trust. Employees can also sue you for putting them at risk of identity theft.

At the end of the day, security needs to be a significant part of the IT budget. You’ve got your wish list, and you have your actual priorities. You need to determine where the dollars will be best spent – and then make your case. How much you get for your department’s bottom line depends on how well you demonstrate that the business cannot run without a specific level of security infrastructure.

Related Content:

 

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Yoran Sirkis is a seasoned senior executive with deep domain expertise in information security and well-rounded experience in leadership, business development, professional services, consulting, customer management, and international management. Yoran served as a managing ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
2/29/2016 | 1:50:57 PM
Don’t portray IT security as a “complication.”
It's important to understand that the business is the main reason as to why you need to successfully implement security. Without it, there would be none to implement. I always prefer to say that its not security vs functionality, its more like security to complement functionality.
ivadumont
50%
50%
ivadumont,
User Rank: Apprentice
2/28/2016 | 5:19:16 PM
Re: #8The ROI Of Infosec: 11 Dos and Don’ts For Management Buy In
I really think that everybody don't have the same view. But for this case most of us will convey that security is an important part.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/27/2016 | 5:28:58 PM
#8
I'd reword #8, though the point is well taken.  Executives hate to be "reminded of" legal details and compliance obligations.  Rather, they prefer to view legal and compliance issues as a matter of risk management.  Present things that way and you're much more likely to at least get informed action.
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-35519
PUBLISHED: 2021-05-06
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel i...
CVE-2021-20204
PUBLISHED: 2021-05-06
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbi...
CVE-2021-30473
PUBLISHED: 2021-05-06
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
CVE-2021-32030
PUBLISHED: 2021-05-06
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_chec...
CVE-2021-22209
PUBLISHED: 2021-05-06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.