ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

No consensus on cost of security

Tom Espiner ZDNet.co.uk

Published: 08 Dec 2005 15:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

When it comes to IT security, companies put products before people according to the latest research from security training company (ISC)² which shows that products and services eat up more money than spending on personnel. 

Organisations globally spend approximately 57 percent of their IT security budgets on security products and services. The remaining 43 percent is spent on personnel, education and training, according to the (ISC)² Global Information Security Workforce Study.

"That only 43 percent of IT security budgets is spent on hiring and training personnel is surprisingly low," said John Colley, director of (ISC)², a not-for-profit IT security training company.

"The rest is spent on products and third party services like PKI's [public key infrastructures], that are very expensive," said Colley.

The alternative — dealing with threats in-house — is not as cost effective as outsourcing, argued third-party email services provider MessageLabs.

"If you invest in products and manage them internally, you're going to push up personnel costs — some internal services have a higher cost of ownership," said Paul Wood, senior analyst at MessageLabs. "I don't think organisations should spent huge amounts on personnel," Woods concluded.

Managed services and products taking up a greater proportion of the global IT security budget did not surprise MessageLabs, as Wood says they mitigate threats effectively.

"With the rapidly changing nature of threats, outsourcing security has reached a tipping point — it's the option with the least risk," said Wood.

However, greater emphasis on managed products and services has not curbed enthusiasm for training for personnel, according to (ISC)².

Overall, respondents anticipated their level of education and training to increase by 22 percent over the coming year, while in Europe the Middle East and Africa 60 percent of respondents said they wanted to get a professional qualification in the same period.

Compliance, the evolution of information security professionals into a separate business unit, and greater financial rewards and job prospects for qualified chief security officers were all increasing the demand for training, (ISC)² said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
121 out of 233 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Trainee Recruitment Consultant

We will provide you with clear criteria for promotion, activity incentives and target rewards but, ultimately, you are responsible for the success of ...

The Head of Information Security and Privacy Incident Response

The Head of Information Security and Privacy Incident Response is a senior member of the Vulnerability Management team with primary responsibility ...

Java Connectivity Developer Equities Trading - Java, FIX

The team will be responsible for developing new systems to enable the anticipated growth in order flows over the next 2 years. Working with a small ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation