Commentary

Larry Greenemeier
 

Are You Spending Your IT Security Dollars Wisely? If You Don't Know, You're Not Alone

How do companies know they're getting their money's worth when they invest in IT security products and services? InformationWeek's upcoming 10th Annual Global Security Survey indicates that a surprising number of companies don't measure the value of their security investments at all. (Hint: it's up from last year).

How do companies know they're getting their money's worth when they invest in IT security products and services? InformationWeek's upcoming 10th Annual Global Security Survey indicates that a surprising number of companies don't measure the value of their security investments at all. (Hint: it's up from last year).It was one of the most surprising results I came across as I studied the data in preparation to write this year's security survey story, which will debut on InformationWeek.com July 14. IT budgets have always been tightly controlled; some companies won't even talk about how much they spend. But security is different. Companies have a longer leash when it comes to spending on security because no one wants to be the next company to make headlines because of a major data breach, either through lost or stolen information.

That's why the Veterans Affairs Department last year signed up SMS Inc. to a $3.7 million contract to install GuardianEdge Technologies and Trust Digital mobile encryption software on all laptops. Is that investment paying off? Hard to say because the VA has since found new ways of losing information about the men and women who've served this country. In January, an IT specialist with the VA lost an external hard drive that may have contained information on more than 1 million vets as well as non-VA physicians, and it's unclear how much of that information was encrypted. What is clear is that not all of that information was encrypted, a condition that pokes holes in the VA's efforts following the landmark theft of a VA laptop in May 2006 containing about 27 million records.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Maybe this is why not every organization measures the value of its security investments. In the 2006 Annual Global Security Survey, about half of the U.S. respondents measured value based on workers spending less time on security-related issues, while 41% used any decline in the amount of network downtime to justify security spending. Forty-percent cited better protection of customer records as an important factor in determining whether their security investments cut the muster. Yet 22% of U.S. survey respondents said they didn't measure the value at all.

Are IT security dollars that easy to come by, or have companies simply written IT security off as an exercise in futility? Be sure to check out the 10th Annual Global Security Survey next week to see how you compare with your peers.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links