Forget the FUD line and stop the “geek-speak”

By
Follow google news

Some stats indicate that the IT security market is going to reach $40 billion by 2007. If you are a vendor offering something in that space that executives feel they need, you are going to be rolling in cash. For now, though, buyers are still a bit covetous with the green stuff.

Called "Selling Infosecurity to the Board," the session was led by The Thomson Corporation's corporate security officer and VP Dennis Devlin, who is responsible for securing the proprietary data of a provider of integrated information that has offices in 50-plus countries and reportedly made $7.6 billion in revenues in 2003.


Even though suppliers and purchasers are optimistic about spending, buying cycles are long and procurements are based on how well the IT security professional in an organization sells infosec to his bosses. That is why one of our workshops at the recent SC Magazine Forum held in N.C. received particular interest from readers who attended the event.

Giving pragmatic advice to attendees on what to consider when angling for budget for security purchases, he said CSOs need to find common ground with boards of directors and CXOs to gain leverage. This means addressing what keeps everyone up at night: increasing government, industry and international regulations to which companies must comply; revenue loss that hits companies in the wallet and reduces customer confidence; and a downgrading of the corporation's reputation, which is hard to quantify until something goes wrong.

By aligning your goals with those of the boss, noted Devlin, you are more likely to gain the ear of your higher-ups and get the money necessary for you to do your job. For CSOs to do this right, he added, they have to realize their roles as facilitators of fiduciary success and educators of their colleagues. In understanding this, the job of obtaining budget gets easier, because the stereotypical IT security geek can enlist business arguments to prove need and get business owners to help with business justification for IT security spend.

As the CSO role evolves, this will be one of its main traits. The problem will be one of finding knowledgeable IT professionals who are comfortable with their business acumen and can eloquently wrench money from CXOs. This CSO will be more difficult to find as more regulations pass and attacks become more complex.

In the meantime, said Devlin, security professionals in companies today must help their managers understand that security done correctly is not a business impediment – and they must achieve this by skipping the "fear, uncertainty and doubt" (FUD) argument. Protecting organizations from business interruptions and liabilities that trail IT attacks is an integral part of today's business. Allocating budget to prevent such occurrences when possible, and react to them when necessary, is the best thing money can buy.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Hundreds of old, vulnerable Exchange servers remain in Australia

Hundreds of old, vulnerable Exchange servers remain in Australia

NSW Police gets extra $15m for "digital forensics" technology

NSW Police gets extra $15m for "digital forensics" technology

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Late patching of Metabase SQLi bug claims Sydney's Mathspace

ASD warns Aussie Adobe Commerce and Magento stores under attack

ASD warns Aussie Adobe Commerce and Magento stores under attack

Log In

  |  Forgot your password?