IT security professionals struggle to measure return on security spend

Study finds 83 percent of respondents not confident security requirements map directly to organizational business needs.

  • 7 years ago Posted in
A survey conducted during Infosecurity Europe 2016 by Tenable Network Security has found that the majority of IT security professionals can only measure the return on less than 25 percent of their security spend.
“It’s undisputed that security is one of the top priorities for organizations across the globe,” said Gavin Millard, EMEA technical director, Tenable Network Security. “However, our research revealed that many organizations struggle to accurately measure the return on IT investment and have little confidence that the money is being used effectively. This lack of accountability creates a gap between the security team and the c-suite, leaving the organization vulnerable.”
Survey data of 250 IT security professionals showed just 17 percent of respondents felt confident that the money being spent on security was being invested properly.
“The security team needs to understand the business needs of the organization, define and map security requirements based on those needs, collect relevant metrics and measure their success,” said Millard. “This is one of the best ways to not only demonstrate the value of IT, but also ensure security across the entire IT environment.
Tenable recently asked 33 security experts how they communicate security program effectiveness to business executives and the board. To read more about the collected recommendations and best practices, check out the Using Security Metrics to Drive Action ebook.
Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
73% of organizations lack automated patch management, and 62% experienced incidents involving...
Quest Software has signed a definitive agreement with Clearlake Capital Group, L.P. (together with...
Dell EMC PowerProtect Cyber Recovery for AWS provides a fast, easy-to-deploy public cloud vault to...
Aqua’s cloud native application protection platform becomes the only solution that protects cloud...
54% of organisations working on a security transformation project now or in the next 12 months.
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Zscaler Zero Trust exchange cloud-based architecture enables superior green security capabilities...