ANTenna Blog -- Security
Security Is Part Of The Cost Of Doing Business
Posted by Benjamin Tomkins Friday, May 15, 2009, 05:54 PM ET
Looking for ROI on a security investment is misguided -- how do you measure the cost of something that doesn't happen? But nothing happening is exactly the return you hope for when you invest in securing your business IT.
At bMighty's recent virtual event, bMighty bSecure: SMB Security On A Budget, much of the conversation swirled around costs, which makes sense given our current economic state. Just as at a face-to-face event, the interaction between the audience and the various presenters during the Q&A sessions yielded some sparks -- and was where much of the "cost" discussion occurred. During the Q&A for the Security Appliances session one response that particularly caught my ear.
Andrew Braunberg, research director, enterprise software and security, Current Analysis, responded to a question about how to measure the effectiveness of security investment by saying:
"That's the wrong way to look it. Security is never a return on investment argument, it's a TCO argument. Security is the cost of doing business. We're 20 years into the Web now and we all want the benefits of advances in communications and collaboration, but we don't want to pay the bill for it. Security is a cost of doing business. Don't try to sell this as return on investment, sell it as cost of doing business. That's much healthier way to look at it."
He's right -- gauging ROI when the desired outcome is the absence of an event is folly. The best-case return on a security investment is that NOTHING happens. Despite the inherent irony of preventing security failures, measurement is vital to success -- just measure differently. As Braunberg mentioned you should be looking TCO rather than ROI. I'll invoke the quote widely attributed to Peter Drucker, "What get's measured, get's done." If you don't apply some form of quantifiable rigor to how you allocate your budget, how do you know if you're spending too much or too little; the latter being the more perilous imbalance when it comes to security. Of course, measurement can run amuck and if you're looking to literally recoup your investment on security you may be chasing your tail.
It's really hard to quantify something not happening, but that doesn't mean it's a waste of time (or money). By way of example, I'll invoke a snippet of dialog from the 2001 David Mamet film "Heist" between Joe Moore (played by Gene Hackman) and Jimmy Silk (played by Sam Rockwell) discussing the planning of the titular heist.
Jimmy: "Why should it go sour?" ["it" meaning the planned heist]
Joe doesn't respond
Jimmy: "Was that such a stupid question?"
Joe: "You ever cheat on a woman? Something, stand her up, step out on her?"
Jimmy: "What?"
Joe: "Ever do that?"
Jimmy: "Yeah."
Joe: "Did you have an excuse?"
Jimmy: "Yeah."
Joe: "What if she didn't ask? Was your alibi a waste of time?"
The point of course being that simply not using a contingency plan doesn't make developing one a poor use of resources. That's an obvious point with disaster recovery (another of the great sessions at bMighty bSecure), but what is security if not a contingency plan against inevitable threats.
The on-demand version of bMighty bSecure: SMB Security On A Budget is now available and I'd encourage you to check out any or all of the sessions and don't miss our next virtual event in October live.
Follow me on Twitter @ http://twitter.com/benjamintomkins
Follow bMighty.com on Twitter @ http://twitter.com/bMighty
Add the bMighty gadget to your iGoogle page @ http://www.bmighty.com/tools/gadgets_google/index.jhtml
Get bMighty on your mobile device @ http://mobile.bmighty.com
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
- Phone Systems Guide - What kind of phone system is right for your business
- Web Design Guide - What to look for in a Web designer
- Merchant Services Guide - Credit card processing and more
- Online Marketing Guide - Leverage the Net to market your business
- Alternative Financing Guide - How to find the cash your business needs
- View all guides
Explore ANTenna Blog
Most Recent Posts
- Why Google Buzz Could Be A Bust For SMBs
- Nasuni Offers Cloud-Based Primary Storage
- Automobiles: The Next Network Security Challenge?
- Cachengo Rolls Out Appliance + Cloud Storage Option
- For SMBs, PayPal Could Mean Risky Business
ANTenna Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 250-999
- Company Size: 50-249
- Company Size: 1-49
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- Hospitality
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Manufacturing/Mining
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Printers/Printing
- Professional/Creative Services
- Retail
- Unified Communications
- Sales/Marketing
- Start-Ups
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- The rANT
- Transportation
- Travel
- Windows
- Web 2.0
- Women in Business
ANTenna Bloggers
ANTenna Blog Roll
- ANTenna Archive
- Ars Technica
- Business Know-How
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- Mashable
- MonkeyBrains
- Network Computing Blog
- Scott Berkun
- Search Engine Land
- Search Engine Watch
- SmallBizResource
- SmallBizTechnology.com
- SmallBusinessHub
- Small Business Trends
- TechCrunch
- Technologizer
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
InformationWeek SMB email newsletter!
Browse by Category
IW SMB Tech
Term Of Day:
Boost your tech
vocabulary!
InformationWeek SMB's
TechEncyclopedia
defines more than
20,000 IT terms.
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
go




