Some security professionals argue that because their profession mitigates risk, it should be excluded from the need to return capital. Moreover, some make the case that project governance could be hijacked and reputation damaged if financial returns, based on an extrapolation of risk reduction, are not delivered.
That ROI-free attitude could be changing. Stuart Guest-Smith, former projects and operations director at software company Microgenx, said organisations that rely on e-commerce or already have instances of fraud occurring can more easily guarantee ROI.
“In this climate, everything IT puts forward needs a dollar value,” Guest-Smith said.
“Security is one of those grey areas with intangible outcomes — until something happens — so you have to be confident that the ROI you promise is what you can return.
“A few years ago, the rationale behind the value wasn't as scrutinised, but now all the CIOs and execs I know have to justify spend.
Security managers in most finance organisations have plenty of rationale for a business case, Guest-Smith said, including an immediate decline in active fraud. Those in other organisations should point to tightening compliance regulations, improved retail services and customer trust, and efficiency gains.
Other industry professionals say that ROI can be achieved by automating manual projects like identity management and provisioning.
CSC Australia CIO Stephen Kowal said audit and compliance teams can be potentially cut in half if security is made tighter and more efficient.
“Anywhere where there is a frequent spend on security can have an immediate benefit. Banks may have a certain amount of existing credit card fraud so there are direct financial gains when fraud drops from x to y.”
However projects may be crushed by management if they do not deliver on promised returns. IBRS security analyst James Turner said some inexperienced security managers may use dicey figures in an attempt to formulate ROI.
“It's the system being protected that makes the money, not the security. The minute you start using rubbery figures, you begin to make a loss prevention tool look like an investment tool which it is confusing, because governance people then see security as a way to increase wealth,” Turner said.
“Productivity experts will see through the small productivity gains from an identity management system, for example, and know they will never be realised.”
Turner said security professionals can use the potential costs of data breaches to help build business cases, and suggests using figures from AusCERT and the Australian Institute of Criminology.
Almost every business can make cheap but substantial improvements security by better integrating existing systems into the architecture, running audits and tightening policies. Assurance.com.au director Neal Wise said security managers should be more pragmatic about purchases and weight the cost of the product against the value of the asset.
“It's not hard to make a business case if there is a genuine threat, but the processes of risk management must show the likeliness of the threat is great, and that the cost of investment is less than the value of the asset,” Wise said. “The security industry can be guilty of proving solutions where the cost of the product is less than the asset, [however] organisations have a greater awareness of appropriate spend in security.”
Latest on Security
- Alleged ransomware gang investigated by Moscow police
- WikiLeaks founder Assange questioned by Swedish police
- uTorrent patches application against DLL vulnerability
- Wikileaks' Assange to be questioned, says Swedish prosecutor
- Adobe fixes 20 vulnerabilities in Shockwave Player
- Apple fixes big security bugs in Mac OS X
- Facebook deletes North Korean account, but it resurfaces
- Apple can't stop ongoing iTunes charge scam
- Swedish prosecutor aims to decide on Assange case on Tuesday
- NBN liked, ISP filter dogs Labor in election wake
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- WebSphere Solution Design (S20) - CBD, contract role3/09/2010
Other
I.T. & T
WebSphere Solution Design (S20) - CBD, contract role - Solution Architect - Web Application Architecture Project!3/09/2010
Other
I.T. & T
Solution Architect to provide strategic and operational consulting for the end-to-end Web Application System project! Experienced with J2EE or .NET?! - Principal Consultant - ITIL2/09/2010
Other
I.T. & T
Excellent opportunity for an experienced ITIL Principal Consultant to join an innovative leading IT Service management consultancy. Attractive packag - Mainframe Developer - COBOL - 12 Month Contract2/09/2010
Other
I.T. & T
Mainframe Developer - COBOL - 12 Month Contract - Business Systems Analyst2/09/2010
Other
I.T. & T
Perm CBD based role for an experienced Business Systems Analyst - Senior SAP Project Manager2/09/2010
Other
I.T. & T
Senior SAP Project Manager - SAP FICO Consultant - 6 week contract - West Sydney2/09/2010
Other
I.T. & T
SAP FICO Consultant - 6 week contract - West Sydney
Whitepapers
TechWorld Blogs
Recent blog posts
- Windows Phone 7: how big can it get?
- NBN gets a turn at political football
- Internet filter gets caught up in politics
- TechWorld Forums goes live
- Selective sourcing the hybrid of cloud services
- Social networks catch more business attention
- RIP Kin
- Telstra’s copper and NBN’s fibre: will the two ends meet?
- RIP Windows 2000, XP lives on
- Does the world need another iPhone? Why not
Recent comments
- java development
12 hours 28 min ago - When mine called they
13 hours 11 min ago - 3D TV cannot fall - no way! Why?
16 hours 25 min ago - Thanks for taking the time to
1 day 4 hours ago - Windows scam
1 day 12 hours ago - My only anti fraud method is
2 days 6 hours ago - Private Cloud Taxonomies
2 days 7 hours ago - ...however...
2 days 16 hours ago - This Guy
2 days 16 hours ago - Glasses Free technology
2 days 17 hours ago - FOSS community
3 days 3 min ago - i have dv6000 with nvidia
3 days 1 hour ago - i have dv6000 and suddenly
3 days 1 hour ago - This is an awesome comment.
3 days 5 hours ago - Real Estate
3 days 7 hours ago - Scam - eventvwr scammers
3 days 11 hours ago - Well I never...
5 days 1 hour ago - Too bad Microsoft was mentioned
5 days 4 hours ago - Phone card is a better option to make calls at a lower rate
5 days 8 hours ago - In other words: "Developers,
5 days 14 hours ago










Comments
Post new comment