The Risk and The Spend
You already know where your risk is. Everyone I ask can name it, usually inside sixty seconds. It’s people. There’s a team, or a process, or a particular habit… and you’ve known about it for a while.
Now go and look at what you spent on cyber security controls last year. And how much of that budget went on fixing the people risk.
I’d put money on the two not lining up. And I don’t think that this is about anyone’s judgement before you all get uppity at me. I don’t think anyone sat in a planning meeting and decided that people were only worth 5% (or less) of the budget. It just happened the way budgets happen… one renewal at a time.
How we got to this point is the interesting bit. So let’s pull it apart, shall we?
A new shiny tool arrives with a vendor, a contract, a renewal date, a quadrant it sits in, and a line somebody can point to in an audit. It can be justified in one sentence to a board.
Behaviour arrives with none of that. There’s no logo for the slide, no square on a grid. And the honest business case for it is complicated, because the thing you’re proposing to shift has an enormous number of moving parts. Somebody’s workload. Their mood. Their own appetite for risk. Their home life, their team mates, whether they’ve eaten, etc etc etc.
So it loses. Not to a better argument… but to a shorter one.
Which is roughly where the numbers come from. Verizon puts the human element behind 62% of breaches, and that figure went UP last year, after another twelve months of everybody diligently rolling out their modules. Gartner asked security teams what they spend on awareness and six in ten of them put 5% or less of the budget anywhere near it.
The thing present in nearly two thirds of incidents gets…for most teams… about a twentieth of the money.
And the split holds, year after year, because of how reviews work. When one comes round, the tool is arguing from incumbency. It’s in, it’s integrated, pulling it out is a project on its own. The people line turns up each time with none of that, making the case for its own existence from scratch.
None of which is an argument for spending more. I’d honestly rather you did nothing this year than reshuffle the same 5% into a slightly different module.
It’s an argument for knowing where your budget is actually going. And I bet a lot of companies haven’t actually sat down to work it out. So, go and take last year’s security spend and put every line into one of two columns. Things that defend the technology. Things that prepare the people. Be strict about the second column, because a platform that sends emails and produces a report belongs in the first one. Then get your incident log out, the real one, with the near misses and the daft mistakes and the thing that got escalated at four on a Friday, and work out what was actually behind each of them.
Put the two ratios next to each other.
If your risk is mostly human and your money is mostly technical, you haven’t got a budget problem. You’ve got a plan that stopped matching reality some time ago, and it renews itself every year without anybody having to sign off on the mismatch.
The useful thing about doing this on a Tuesday morning rather than in a budget meeting is that nothing is at stake yet. Nobody is watching, nobody has to defend anything, and you get to decide in your own time whether the split you’ve inherited is the split you’d actually choose.
That's it for this week. Reply and tell me what you think.
Amy
Amy Stokes-Waters · Founder, The Cyber Escape Room Co.
