The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Security Recession Proof?


Posted by George Hulme, Dec 9, 2008 08:29 PM

There have been numerous stories lately about whether or not IT security is recession proof. The answer is: no


The latest IT security recession story came from SC Magazine in Is Security Recession Proof? The story offered no conclusion, and seemed to conclude a resounding "maybe" security is recession-proof. The bulk of the story focused on the demand side of the economic equation: attacks are increasing, regulatory compliance isn't going away, and companies will increasingly seek return-on-investment for their security spend.

I've no argument with any of that. Attacks will increase, regulatory compliance demands will no doubt escalate, and companies will seek justification for their security budget. But these conditions were true before December 2007, when the recession is now believed to have started.

Consider the quote from Phil Neray, of Guardium:

Phil Neray, VP of strategy at Guardium, a Waltham, Mass.-based database security company, agrees that most companies, especially those in financial services, absolutely must safeguard the integrity of their data. But, he adds, when times are tough, companies look at how they can do more with less. "If you can replace manual processes with automated processes, you have a good shot of being approved by the CFO," he says.

While security personnel may not be accustomed to making an ROI argument to get budget approval, he says, outlining how an automated, centralized, appliance-based approach can replace licenses, mass storage of log files, third-party personnel digging through those logs, makes for a persuasive case.

He's right. But businesses and security professionals should always be looking for ways to improve their processes and ways to do more with less. And, security managers already should be making strong business cases for any acquisitions. When the business and security departments are run this way, things tend to go much more smoothly when tight times arrive. If you're rushing to increase automation now, and cut costs, you're already too late. And your only hope is that your direct competitors failed to streamline their business operations, just as you have. That's a bad position to be in, as you've handed part of your destiny into the hands of the competition.

The point I'm trying to make is that if you've been automating where possible, putting the right controls in place, and streamlining dead weight, then you're sitting just as well as you possibly can right now.

Now, as to whether IT security is recession proof. Of it's course not. If business initiatives get shelved, or cut down, so does the security associated with those initiatives. If new hiring is down, so is the need to manage the on-boarding of those identities. If new remote offices aren't being built, there's no need to secure and monitor those network segments. If new application development has been curtailed, so has the need for application security analysis. You get the picture.

Yet, all of these things will need to be maintained for the existing infrastructure. But the rate of IT security growth will slow with the rest of the businesses' IT initiatives. And opportunities always will exist for those vendors and employees who help businesses be more effective.

So, while IT security isn't recession proof, it is more recession resilient than other areas of the business.

« Thoughts On The BlackBerry Storm | Main | DirecTV Shelves Its Microsoft Media Plans »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Hurry Quick! There is Pandemonium on the Blackboard!
  2. Microsoft Extends Visual Studio 2010 and .NET Framework 4 Beta Period
  3. Visual Basic 10 Beta 2 Also Supports Task-Based Programming


Join The InformationWeek Group On LinkedIn


                           


  1. Mobile Round-Up: iPhone On Verizon Edition
  2. Google Earth Brings 3D Maps To Audi A8
  3. 9 Reasons Enterprises Shouldnęt Switch To Hyper-V
  4. AT&T: No Tiered Plans, But Network Remedies Forthcoming


  1. Taser Builds Cisco-Based Data Warehouse
  2. Top 10 Smartphone Advances Of 2009
  3. Chief Of The Year: Vivek Kundra
  4. Federal CIO Kundra Talks IT Strategy
  5. Government Technologist: Holding The Fed CIO's Feet To The Fire
  6. CIO Profiles: Mujib U. Lodhi, CIO At DC Water And Sewer Authority

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007