background Layer 1

Tough Negotiations Answering 5 Questions When Defending Your Information Security Budget

Author: Evgeny Andreevich Balk, Head of the Development and Architecture Department, Krostech.

"Information security is an expense," "I don't understand what we're paying for," "Information security prohibits everything" – these are the kinds of things an information security director hears from other C-level executives. In this article, we'll explain what needs to be researched and prepared to convince everyone that an information security budget is a completely justified necessity.

For clarity, we've identified five key issues you're likely to encounter when protecting your information security budget.

What will we pay for? What problems will you protect us from?

Simply answering "we're paying to stay safe" isn't enough. A company might go several years without experiencing a security incident, which could lead some management to believe they're invulnerable. Serious preparation is needed.

  • First, if you haven't already done so or if you've recently taken up the position, determine the regulatory requirements the organization must comply with (consider the critical information infrastructure, personal data system, and, for the public sector, the state information system). Prepare a roadmap for ensuring compliance with regulatory requirements.
  • Secondly, study the company's development strategy and, together with the CEO and other top managers, identify key processes and areas – these will be the focus of the defense.
  • Third, define a list of unacceptable events. Research the situation in your industry – select key incidents and check their relevance to your business. Add estimates of financial and reputational damage, as well as potential fines, to the list. Be sure to coordinate the list with key decision-makers in the company.
  • Fourth, develop a 3-5-year information security strategy and package it in a way that's convenient for the business, for example: the total cost of ownership of protection against threats A, B, and C is X dollars. This approach will allow the business to decide whether it's willing to accept the risk.
  • Fifth, consider what additional value information security can bring to a business: for example, by increasing the company's attractiveness to clients by shifting the focus to data security and service stability.

You may also be interested in the following material from the IT Leaders Club Compass CIO

How will you measure the achievement of goals?

Objective metrics are an important element of argumentation because, let's be objective, words always sound more persuasive. Developing metrics is essential.

  • First, regulate how you currently assess the company's security (frequency and number of recorded information security incidents, penetration testing results, and, for more advanced users, bug bounty results).
  • Second, define metrics for evaluating information security investments: these will include both security metrics and financial ones—ROI, or even a modified version designed for cybersecurity—ROSI, or the total cost of ownership (TCO) of security tools. Then conduct benchmarking and compare them with similar market metrics.
  • Third, identify the dashboards and reports you will present to your business on a regular basis.
  • Fourth, consider what measures to plan to determine the effectiveness of the strategy: this could be an external information security audit or a pentest.

What benefit have you brought to business this year?

For those who measure business benefits in terms of revenue, number of products launched, and customer acquisition, it's difficult to understand the true impact of information security, especially without high-profile incidents prevented. It's crucial to be prepared for this question.

  • First, identify a range of cases that demonstrate the effectiveness of information security.
  • Second, review the incidents you managed to prevent and assess their potential damage, taking into account the attack vectors and potential attack progression, etc.
  • Third, evaluate the effectiveness of your employee cybersecurity awareness program. How has this changed over the past year?
  • Fourth, identify the regulatory risks that were avoided and calculate their cost. It's also best to include the results of regulatory audits, if any, along with an explanation of the reputational risks that the identified violations would have posed.
  • Fifth, describe how you work with innovations and assess the risks of using new technologies, including in the field of information security.

What regulatory requirements will apply to us next year?

Regulations and the consequences of noncompliance are a very clear concept for those who approve budgets. And, of course, this is an important area of ​​work for the information security department; understanding the requirements in your industry today is a basic requirement. Therefore, we are preparing to respond.

  • First, assess the extent to which compliance with requirements is ensured over a 1-2 year period.
  • Secondly, check what new regulatory requirements apply to your business. Perhaps new business lines will be introduced or new assets acquired, for example, through mergers and acquisitions.
  • Third, assess the consequences of failure to comply with the requirements and study law enforcement practices.

How do competitors approach the issue of information security?

To make an informed decision, it's important to understand the current market practices. Initiatives are easier to defend if competitors have similar ones and they're showing results. Conversely, if competitors lacked something and suffered, this can also be an important argument.

  • First, indirectly estimate the volume of purchases from your competitors based on publications and open tenders.
  • Second, research what incidents your competitors have experienced. You'll likely be asked how your organization protects itself from similar problems.
  • Third, try to organize reference visits for you and other senior management to companies of similar structure and scale, not necessarily direct competitors: for example, a construction materials manufacturer visiting a textile factory. This will help demonstrate to management the rationale for your information security decisions and demonstrate existing approaches in the market.

So, are you ready?

Information security is a functional department just like any other. Being able to justify a budget is an essential skill that will allow you to begin (or continue) building an effective security system. And questions from top management are not inherently bad or unnecessary. The desire to understand what's going on and how the company will spend money is an understandable business initiative, especially given the challenging economic times, so it's important to defend your initiatives reasonably and respectfully.


We use cookies for analytical purposes and to deliver you the best experience with our website. Continuing to the site, you agree to the Cookie Policy.