• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
Compliance, IT Infrastructure, Network Security

Why You Should Take A Risk-Based Approach To Cybersecurity

Taking a risk-based approach to cybersecurity can help ensure you're not investing in unnecessary solutions and bogging down systems.

June 1, 2021 Zachary Comeau Leave a Comment

Risk Based Cybersecurity

All of these news headline about cyberattacks, nation-state actors and ransomware are daunting, and they’re probably keeping IT professionals and executives up at night, thinking about when they’ll wind up in those headlines themselves.

In today’s business climate, all eyes are on cybersecurity. For the most part, organizations investing heavily to secure their IT environment and keep malicious actors out of their network are doing the right thing. However, businesses need to ensure that they’re investing in solutions that are actually protecting them from real threats.

Or else, organizations could run the risk of overinvesting in cybersecurity and not have enough of a budget to hire more personnel or train end users, says Danielle Parks, a research analyst at Nucleus Research who studies the return-on-investment (ROI) of cybersecurity.

“With all of the recent attacks gong on, you don’t want your company to be the next Colonial Pipeline, and that is making a lot of companies very fearful and take the sky-is-falling approach,” Parks says.

That could overload the network, slow down endpoints and suck money away from other areas that badly need investment.

Look for overlap vs layers

Cybersecurity and IT professionals always advocate for a layered approach to cybersecurity, which means investing in solutions that address different aspects of an organization’s network security. Things like network protection, multi-factor authentication, VPNs and others all serve different purposes but all contribute to the overall security of an organization’s IT environment.

The idea there is to cover up every potential vulnerability and make it as hard as possible for bad actors to access your network at every phase. Doing so typically requires several different cybersecurity products.

However, many organizations have different solutions doing the same thing, which means the organizations is paying for things it doesn’t need, which could also be slowing down systems that end users rely on for their day-to-day work.

Over time, costs associated with systems so bogged down that it takes employees longer to do their jobs.

“That’s an indirect cost of just having an overly secure system,” Parks says.

Read Next: You Need To Focus On These New Cybersecurity Threats

Take a risk-based approach

Instead of blindly throwing money at cybersecurity solutions, Parks suggests a more thoughtful and strategic approach based on an evaluation of the risk an organization faces, which can help make IT spending more efficient.

Although the threat and potential damage of a cyberattack are very real, organizations shouldn’t buy into fear and spend needlessly on cyber solutions just because they’re afraid of being compromised and losing business.

Organizations should ask themselves:

  • Who are the possible threat actors targeting us?
  • How could they possibly get into our network?
  • What have those actors and others like it done to similar organizations?
  • Where are our weak points?

Some companies would be better served by a security information event management system, while others should double down on their endpoint protection investment, but that depends on where organizations are most vulnerable.

Depending on the size of the organization, nature of its business and budget, cyberattacks attacks can be handled very differently. For example, a smaller organization might be better off scrapping compromised computers and buying a new one rather than paying for software or a third-party forensics team to clean up the systems.

Think of cybersecurity as an insurance market

Parks says organizations should evaluate the size of the company, identify the company’s specific cyber risks and form a cybersecurity spending plan based off of that data.

“Once you realize how much your company’s worth, then you think, ‘Okay, how vulnerable are we to an attack? What is the risk associated with it? Are my employees going on websites that that could be potentially harmful? Do we have a system that we could receive phishing emails from?’ You have to have a rational approach.”

When purchasing cybersecurity solutions, IT directors should consider what it would be like to purchase insurance for a vehicle or real estate. When doing that, the price of insurance is always based on how much the asset is worth and the risk of it being damaged or stolen.

“Once you weigh all those risks associated with your business, you’re not going to spend more than your company is worth to secure it,” Parks says.

Tagged With: Cybersecurity

Related Content:

  • ScreenBeam Logo ScreenBeam Invites K-12 Institutions to Apply for Wireless…
  • 1E Patch Insights, Patch Management, Software update 1E Releases Patch Insights to Augment Microsoft Patching…
  • Google AI Investment, Anthropic, OpenAI, ChatGPT Google Makes Key AI Investment as Microsoft Begins…
  • Xilica Sennheiser small room kit Xilica, Sennheiser Add Small Room Audio Kits for…

Free downloadable guide you may like:

  • Harnessing the Power of Digital SignageHarnessing the Power of Digital Signage

    Choosing the best solutions for messaging, branding, and communicating in today’s content-everywhere landscape

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Harnessing the Power of Digital Signage
Harnessing the Power of Digital Signage

Choosing the best solutions for messaging, branding, and communicating in today’s content-everywhere landscape

Blueprint Series Cover: What works for hybrid work
Blueprint Series: What Works for Hybrid Work

Download this free resource to learn about how IT leaders can effectively manage and implement a hybrid work model.

Guide to creating a ransomware response plan download
Blueprint Series: Creating a Ransomware Response Plan

Chances are ransomware hackers are researching your company right now. They’re investing time and money to choose the most profitable targets and a...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2023 Emerald X, LLC. All rights reserved.