Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Optimising Cyber Security Costs In A Recession
Articles Business and Policy Business Continuity and Disaster Recovery Data Protection Security Security Architecture

Optimising Cyber Security Costs In A Recession

Andy SwiftBy Andy SwiftMay 2, 2023Updated:August 22, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Malicious PyPI Package Found Posing as SentinelOne SDK in recent Hack Trend
Malicious PyPI Package Found Posing as SentinelOne SDK in recent Hack Trend
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Businesses today are facing two acute challenges – the economy and cybercrime. This is forcing CISOs to make some tough decisions about spending. The UK government’s Cyber Security Breaches Survey 2022 found that in the last 12 months, 39% of UK businesses identified a cyber-attack, while 31% of businesses estimated they were attacked at least once a week. Amidst these rising threat levels, never before has it been more important to stay secure while managing costs on a budget.

As cyber risks continue to increase, budgets remain stagnant – in fact, a report into cyber threat defence in 2022 highlights that security budgets in the UK have remained flat since 2021. This creates tension for CIOs who are still being advised to boost IT security while costs are such a monumental concern. The reality is that CIOs need to do more with less. Organisations must streamline outgoings where possible to remain lean and productive – and above all secure. With the right planning and effective processes, leaders can save on costs and put in place the controls that can reduce any unnecessary exposure to risks.

Taking a holistic approach to cyber defence

Effective security practices don’t always need to break the budget. Taking a holistic approach to cyber defence that covers the tech ecosystem can reduce the risks of any gaps in protection that would otherwise leave the organisation open to exploitation. Some ways to build a robust cyber security framework include:

  • Addressing asset management

This means maintaining an accurate and centralised inventory of all IT assets. Tracking the lifespan of each IT asset is essential to ensure that software patches and updates are kept up to date. Security pros can streamline resources by identifying and appropriately decommissioning any old equipment or software that is obsolete or end of life.

Knowing where hardware and software inventory is located and how it is protected makes it possible to identify misconfigurations and address potential security gaps. It also makes it easier to enforce security requirements, identify unmanaged devices, and evaluate which users that have access to critical systems don’t have protections like multi-factor authentication enabled.

  • Empowering employees to become the organisation’s first line of defence

Although it seems like yet another investment, training employees can play a major part in keeping the security budget lean. With human error becoming the top cause for ransomware breaches – in fact, according to the World Economic Forum, 95% of all cyber security issues can be traced to human error – cyber security has become as much a people problem as it is a technology problem. An employee that is ignorant about attack methods can open or click on an email which can potentially download malware or redirect to websites to steal intellectual property or money which leaves their organisation wide open to risk.

The initial time, cost and resources channelled into a proactive and continuous training programme are nothing when compared to the potentially devastating consequences and costs of a successful cyber security breach. Training on good cyber practices and behaviours and reporting of suspicious or unusual activity can stop a potential attack in its tracks.

The most effective way to conduct training for the wider workforce is through real-world training experiences that actively engage workers based on actual risk-based scenarios. For instance, running simulations and gamified interactive training can create a more relevant and rewarding learning experience.

  • Making smarter security choices

With cybercriminals’ sophisticated methods often keeping them a step ahead of security teams, making cuts in cyber security investments is a growing concern. However, an investment in expensive security tools can be misplaced if organisations fail to put in place strong foundations for security.

By systematically reviewing processes such as continual network monitoring and multi-factor authentication, keeping up to date with patching, and making the most of resources, as well as focusing on training, CIOs will elevate organisational resilience. This will increase their digital defences and overall security posture. Additionally, deploying dedicated cyber security tools will bolster these good practices while staying cost-effective.

In challenging economic times, a reset of cyber security priorities is essential to review all finite resources and where they can best be deployed. All too often organisations conflate good security practices with good security purchases, meaning efforts result in purchasing new and unrequired security tools that duplicate efforts and further compound team resource management challenges.

Cyber resilience is a perfect blend of tech and human expertise

With the risks of a cyber breach potentially including the loss of data, fines for non-compliance, a ransom, or lasting reputational damage, prevention is better than cure. Focusing spend on reviewing practices like asset management in a bid to minimise attack vectors, ensuring that security policies are clearly and widely articulated and implemented, and securing all endpoints will be mission-critical.

True cyber security means combining automation, human expertise and 24×7 support to defend against the constantly evolving threat landscape. A training programme that empowers the entire workforce with ways to detect and offset the latest threat vectors will build a culture of cyber security that enables the most advanced, affordable, and long-term resilience.

Andy Swift

Head of Offensive Security

  • Andy Swift
    Open To Attack: The Risks Of Open-Source Software Attacks
  • Andy Swift
    Five Cyber Security Resolutions For 2020

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}