There is an unspoken truth for executives in the cybersecurity industry. When selecting a solution for a business use case to mitigate risk, how do you justify its cost? Do you first measure risk and offset the cost of a potential incident to justify the solution? Or do you budget based on the need to satisfy a compliance initiative or audit finding? Truthfully, a CISO can apply many other approaches to justify the cost of a product that a board may accept or reject. However, in this CISO’s opinion, one calculation is emerging that can readily meet the scrutiny of even the most stringent economic buyer: the minimization of dwell time or outage costs.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Return on Investment

  • Morey Haber

摘要

There is an unspoken truth for executives in the cybersecurity industry. When selecting a solution for a business use case to mitigate risk, how do you justify its cost? Do you first measure risk and offset the cost of a potential incident to justify the solution? Or do you budget based on the need to satisfy a compliance initiative or audit finding? Truthfully, a CISO can apply many other approaches to justify the cost of a product that a board may accept or reject. However, in this CISO’s opinion, one calculation is emerging that can readily meet the scrutiny of even the most stringent economic buyer: the minimization of dwell time or outage costs.