From: Forbes | Tech
Every IT department has struggled for years to justify spending on security. Various models have been used with more or less effect to encourage upper management to open the coffers. Return on Security Investment models attempt to quantify the money saved from preventing future breaches. The factors cited include: cost of lost productivity, the direct costs of notification in the case of a breach that must be reported under 45 different State laws, and the hardest to quantify of all, loss of trust or brand value.
Obviously these attempts to justify security spending are failing. How could organizations that should know better still be suffering major breaches? The theft of 21.5 million highly confidential records of government employees, past and present(and that of their families) from the Office of Personnel Management is only the latest, most egregious, example.
Leave a Reply