Some security professionals argue that because their profession mitigates risk, it should be excluded from the need to return capital. Moreover, some make the case that project governance could be hijacked and reputation damaged if financial returns, based on an extrapolation of risk reduction, are not delivered.
That ROI-free attitude could be changing. Stuart Guest-Smith, former projects and operations director at software company Microgenx, said organisations that rely on e-commerce or already have instances of fraud occurring can more easily guarantee ROI.
“In this climate, everything IT puts forward needs a dollar value,” Guest-Smith said.
“Security is one of those grey areas with intangible outcomes — until something happens — so you have to be confident that the ROI you promise is what you can return.
“A few years ago, the rationale behind the value wasn't as scrutinised, but now all the CIOs and execs I know have to justify spend.
Security managers in most finance organisations have plenty of rationale for a business case, Guest-Smith said, including an immediate decline in active fraud. Those in other organisations should point to tightening compliance regulations, improved retail services and customer trust, and efficiency gains.
Other industry professionals say that ROI can be achieved by automating manual projects like identity management and provisioning.
CSC Australia CIO Stephen Kowal said audit and compliance teams can be potentially cut in half if security is made tighter and more efficient.
“Anywhere where there is a frequent spend on security can have an immediate benefit. Banks may have a certain amount of existing credit card fraud so there are direct financial gains when fraud drops from x to y.”
However projects may be crushed by management if they do not deliver on promised returns. IBRS security analyst James Turner said some inexperienced security managers may use dicey figures in an attempt to formulate ROI.
“It's the system being protected that makes the money, not the security. The minute you start using rubbery figures, you begin to make a loss prevention tool look like an investment tool which it is confusing, because governance people then see security as a way to increase wealth,” Turner said.
“Productivity experts will see through the small productivity gains from an identity management system, for example, and know they will never be realised.”
Turner said security professionals can use the potential costs of data breaches to help build business cases, and suggests using figures from AusCERT and the Australian Institute of Criminology.
Almost every business can make cheap but substantial improvements security by better integrating existing systems into the architecture, running audits and tightening policies. Assurance.com.au director Neal Wise said security managers should be more pragmatic about purchases and weight the cost of the product against the value of the asset.
“It's not hard to make a business case if there is a genuine threat, but the processes of risk management must show the likeliness of the threat is great, and that the cost of investment is less than the value of the asset,” Wise said. “The security industry can be guilty of proving solutions where the cost of the product is less than the asset, [however] organisations have a greater awareness of appropriate spend in security.”
Latest on Security
- CA brings SOA security to open source JBoss
- PayPal suspends personal payments to India
- Extorted companies silent on stolen data
- Indian pleads guilty in overseas stock hacking scheme
- Researcher reveals how IE flaw can turn your PC into a public file server
- Fake Firefox update spreads unwanted app
- Too many people re-use logins, study finds
- How Wi-Fi attackers are poisoning Web browsers
- Spam, e-mail threats high in the Asia Pacific in January
- E-mail scam steals €3 million in carbon credits
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- Instructional Designer (Training Developer) (s15)10/02/2010
Other
I.T. & T
Instructional Designer (Training Developer) (s15) - BUSINESS DEVELOPMENT MANAGER - CONTENT MANAGEMENT SYSTEMS, INTRANETS,10/02/2010
Other
I.T. & T
BUSINESS DEVELOPMENT MANAGER - CONTENT MANAGEMENT SYSTEMS, INTRANETS, - Informatica PowerCenter Consultants10/02/2010
Other
I.T. & T
Informatica PowerCenter Consultants - WEB CONTENT MANAGEMENT SYSTEMS - BUSINESS DEVELOPMENT MANAGER10/02/2010
Other
I.T. & T
WEB CONTENT MANAGEMENT SYSTEMS - BUSINESS DEVELOPMENT MANAGER - Senior Tester9/02/2010
Other
I.T. & T
Senior Tester
Whitepapers
-
Operational Responsiveness | An Executive Guide -
Business Continuity: A Guide to Choosing the Right Technology Solution -
Justifying Business Intelligence Applications: A white paper exploring the Buy vs. Build argument -
Video Case Study | Unified Communications for Small Business -
E-mail Continuity | You don't know what you've got till it's gone
TechWorld Blogs
Recent blog posts
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
- Happy Nexus Year
- So long 2009, and thanks for another decade in tech
- KDE 4.4 enters beta, bring on mainstream computing
- Chromium OS source released: another way of thinking
- Dell goes Android for mobile market entrance
Recent comments
- Buy 2 get 1 free: Apple iphone 3gs 32gb,Nokia N97,BB Bold,HTC HD
2 hours 36 min ago - My Take:
2 hours 53 min ago - PDA Smart phone users
12 hours 5 min ago - Touch Phone Accessories
12 hours 13 min ago - joo joo
13 hours 4 min ago - Thanks!
1 day 8 hours ago - Transcription mistake
2 days 9 hours ago - Freeway is hardly Australian
2 days 11 hours ago - Great Business Initiative
3 days 6 hours ago - www.mintfly.com
3 days 10 hours ago - also creating unemployment
4 days 3 hours ago - How to save in one page???
5 days 5 hours ago - Well it's 2010 now...
5 days 14 hours ago - Man, catch up. You're being
6 days 15 hours ago - Rhapsody in Australia
6 days 16 hours ago - ipad reaction
1 week 6 hours ago - Capacity Bollenecks
1 week 21 hours ago - not only for "young folks"
1 week 1 day ago - Take action now
1 week 1 day ago - u guys are a idiots. i have
1 week 1 day ago







Comments
Post new comment