• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • COVID-19 Update
  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
Compliance, IT Infrastructure, Network Security

Why You Should Take A Risk-Based Approach To Cybersecurity

Taking a risk-based approach to cybersecurity can help ensure you're not investing in unnecessary solutions and bogging down systems.

June 1, 2021 Zachary Comeau Leave a Comment

Risk Based Cybersecurity

All of these news headline about cyberattacks, nation-state actors and ransomware are daunting, and they’re probably keeping IT professionals and executives up at night, thinking about when they’ll wind up in those headlines themselves.

In today’s business climate, all eyes are on cybersecurity. For the most part, organizations investing heavily to secure their IT environment and keep malicious actors out of their network are doing the right thing. However, businesses need to ensure that they’re investing in solutions that are actually protecting them from real threats.

Or else, organizations could run the risk of overinvesting in cybersecurity and not have enough of a budget to hire more personnel or train end users, says Danielle Parks, a research analyst at Nucleus Research who studies the return-on-investment (ROI) of cybersecurity.

“With all of the recent attacks gong on, you don’t want your company to be the next Colonial Pipeline, and that is making a lot of companies very fearful and take the sky-is-falling approach,” Parks says.

That could overload the network, slow down endpoints and suck money away from other areas that badly need investment.

Look for overlap vs layers

Cybersecurity and IT professionals always advocate for a layered approach to cybersecurity, which means investing in solutions that address different aspects of an organization’s network security. Things like network protection, multi-factor authentication, VPNs and others all serve different purposes but all contribute to the overall security of an organization’s IT environment.

The idea there is to cover up every potential vulnerability and make it as hard as possible for bad actors to access your network at every phase. Doing so typically requires several different cybersecurity products.

However, many organizations have different solutions doing the same thing, which means the organizations is paying for things it doesn’t need, which could also be slowing down systems that end users rely on for their day-to-day work.

Over time, costs associated with systems so bogged down that it takes employees longer to do their jobs.

“That’s an indirect cost of just having an overly secure system,” Parks says.

Read Next: You Need To Focus On These New Cybersecurity Threats

Take a risk-based approach

Instead of blindly throwing money at cybersecurity solutions, Parks suggests a more thoughtful and strategic approach based on an evaluation of the risk an organization faces, which can help make IT spending more efficient.

Although the threat and potential damage of a cyberattack are very real, organizations shouldn’t buy into fear and spend needlessly on cyber solutions just because they’re afraid of being compromised and losing business.

Organizations should ask themselves:

  • Who are the possible threat actors targeting us?
  • How could they possibly get into our network?
  • What have those actors and others like it done to similar organizations?
  • Where are our weak points?

Some companies would be better served by a security information event management system, while others should double down on their endpoint protection investment, but that depends on where organizations are most vulnerable.

Depending on the size of the organization, nature of its business and budget, cyberattacks attacks can be handled very differently. For example, a smaller organization might be better off scrapping compromised computers and buying a new one rather than paying for software or a third-party forensics team to clean up the systems.

Think of cybersecurity as an insurance market

Parks says organizations should evaluate the size of the company, identify the company’s specific cyber risks and form a cybersecurity spending plan based off of that data.

“Once you realize how much your company’s worth, then you think, ‘Okay, how vulnerable are we to an attack? What is the risk associated with it? Are my employees going on websites that that could be potentially harmful? Do we have a system that we could receive phishing emails from?’ You have to have a rational approach.”

When purchasing cybersecurity solutions, IT directors should consider what it would be like to purchase insurance for a vehicle or real estate. When doing that, the price of insurance is always based on how much the asset is worth and the risk of it being damaged or stolen.

“Once you weigh all those risks associated with your business, you’re not going to spend more than your company is worth to secure it,” Parks says.

Tagged With: Cybersecurity

Related Content:

  • This Week in IT, IT News, Microsoft, Google, Dell This Week in IT: Windows 11 Update, Tech…
  • Cloud THreats, Proofpoint Third Parties and Partners are Leading to Increased…
  • Google Curated Detections Chronicle Google Releases Curated Detections in Chronicle
  • Fortinet, ransomware, zero day vulnerabilities, log4shell Ransomware, Zero-Day Vulnerabilities On the Rise

Free downloadable guide you may like:

  • Shadow ITBlueprint Series: How to Reduce Shadow IT

    The distributed work model gives employees the flexibility they demand, but it can lead to shadow IT and introduce unnecessary security risk. Research finds that this distributed work environment is leading to IT management blind spots and shadow IT.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Shadow IT
Blueprint Series: How to Reduce Shadow IT

The distributed work model gives employees the flexibility they demand, but it can lead to shadow IT and introduce unnecessary security risk. Resea...

Hybrid Work webinar
Featured Webcast: Collaboration 2.0 — Where Are We Now?

In this webinar, subject matter experts discuss the transformation of the workplace, the rise of hybrid workers, the importance of open connectivit...

guide to end user training cover
Pro Tips for Conducting End User Training

Effective trainings are the glue that can make the difference following a new technology implementation that your team has spent so much time, effo...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2022 Emerald X, LLC. All rights reserved.