Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Your 2017 IT Security Budget Should Start With A Blank Piece Of Paper
Articles

Your 2017 IT Security Budget Should Start With A Blank Piece Of Paper

ISBuzz TeamBy ISBuzz TeamFebruary 2, 20173 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Businessman pressing a Budget concept button.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Collectively, we spend tens of billions of dollars a year on security systems. And still, we lose billions in business email compromise (BEC) spoofing attacks. We fall victim to an onslaught of ransomware. We suffer high-profile breaches. And we continue to be embarrassed by data leaks engineered by foreign governments, the 2016 U.S. presidential election as the most recent example.

Now it’s 2017. As a new year begins, it’s time to take a fresh look at our defense strategies and reassess our security budgets. Many organizations realize they need to invest in security. But many are unsure where to best direct their spending.

What’s the best way to secure your data and stay in budget? Reinvest in your current security technology? Buy the new trendy security suite?

The easiest and least expensive choice may appear to be to re-sign a contract or upgrade to the next protection level. But easy may not be smart—especially if doesn’t work. And low-cost options become expensive if company secrets are stolen or your leadership team wires more than $50 million to an attacker.

The threat landscape is constantly evolving. The security strategy you adopted last year may not be the right approach to defend against today’s threats.

Maybe your organization invested heavily in endpoint protection in 2016 because it’s a mainstay in your budget. 2017 might be a good time to rethink this approach.

Studies consistently find that about 95% of advanced attacks begin with email. (The reason is simple: attacks target people, and email is a tool we rely on every day.) Despite this reality, businesses still spend about 80% of their security product budgets on network and endpoint technologies, according to Gartner figures.

This spending probably made sense at the time. But threats have changed. To protect your company today, security spending needs to change, too.

Beyond email, attackers are targeting vectors outside of what we’ve traditionally considered the domain of IT.

Social networks and mobile apps are a way to compromise your people without confronting traditional defenses—and can badly tarnish your brand reputation. In the first six months of 2016, we saw a 150% increase in social media phishing attacks when compared with the same period last year. That volume increased by 300% Q3 vs. Q2 2016.

In 2017, stopping threats through these channels will be critical. Tooth plaque is easy brush away; a cavity that has broken through the tooth enamel is a bigger problem. In the same way, detecting and resolving threats before they reach your network and endpoints is easier and more effective than trying to stop those already in your environment. Stopping a potential data breach, ransomware or BEC loss at the source—email—takes pressure off your other controls.

We also see this as the year your security team will need to expand its reach beyond your employees. Protecting your brand today means protecting customers and others who interact with your brand through email, social networks and mobile devices. That includes shutting down copycat social-media accounts and mobile apps that commit fraud in your name. Digital risk, inside and outside the organization, will loom large in 2017.

Taking a moment to survey today’s threat landscape is the smartest first step you can take when it comes to security budgeting. Starting from scratch, might seem daunting. But simply doing the same thing because it’s always seemed worked in the past leaves you exposed to new threats.

That’s why when it’s time to submit 2017 budgets, cybersecurity should start from the ground up—with a blank piece of paper.

[su_box title=”About ” style=”noise” box_color=”#336588″][short_info id=’70187′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}