Article Details

Scrape Timestamp (UTC): 2024-09-05 14:39:01.362

Source: https://www.theregister.com/2024/09/05/security_spending_boom_slowing/

Original Article Text

Click to Toggle View

Security boom is over, with over a third of CISOs reporting flat or falling budgets. Good news? Security is still getting a growing part of IT budget. It looks like security budgets are coming up against belt-tightening policies, with chief security officers reporting budgets rising more slowly than ever and over a third saying their spending this year will be flat or even reduced. The same is true for staffing levels, according to the fifth annual survey of CISOs carried out by security analyst house IANS Research. Over a third of the 755 security bosses polled admitted they weren't hiring, although overall staffing growth rates were less than half of those seen in 2022. "There's still a continuing talent shortage, so finding and retaining people is very challenging," Nick Kakolowski, senior research director at IANS, told The Register. "Anecdotally, the biggest factor [in retention] ends up being opportunities for growth. If there's no way forward, people feel they are stagnating, especially after two to four years. It's a very special job that has levels of stress that exceed other roles." The survey does note that overall security spending is still up 8 percent in 2024, although nowhere near the heady days of 2021 (16 percent growth) and 2022 (17 percent). Kakolowski attributed this slowdown not to a general malaise but more to the fact that some sectors, notably manufacturing, had been playing catch-up on their security spending and were now up to speed. An encouraging sign also is that security spending as a proportion of the overall IT budget is on the rise, up from 8.6 percent in 2020 to 13.2 percent this year. That trend looks set to continue, Kakolowski opined, but still security spending was typically less than 1 percent of the revenue of those quizzed. The survey also showed signs that, at last, the C-suite execs are grokking the need for security spending. This is in part down to last year's SEC rule changes on reporting security incidents (The Reg's full guide on the topic is here) as well as concerns over corporate liability to lawsuits. The recent string of third-party supplier hacks also has board members (and CISOs) concerned. The question is, Kakolowski suggested, how you verify partners and whether companies should hire other orgs to check on supplier security. "No one has the definitive solution, but people are figuring out how far they need to go to secure their organizations," he explained. Finally, on the subject of cyber insurance, the market is booming, and not because CEOs and CISOs think it necessarily fully covers them. It's key that if an insurance contract is entered into, the terms and conditions are carefully checked, he warned, to make sure that if the worst happens, someone actually pays up.

Daily Brief Summary

MISCELLANEOUS // Security Spending Growth Slows, Yet Proportion of IT Budget Increases

Over a third of chief security officers surveyed reported flat or reduced security budgets in the current year, contrasting the rapid increases seen in previous years.

Despite stagnant individual budgets, security spending still exhibits an 8% growth in 2024, signifying a slowdown from the significant 16% and 17% increases recorded in 2021 and 2022.

Security's share of the overall IT budget has risen from 8.6% in 2020 to 13.2% in 2024, indicating a growing prioritization within IT expenditures.

Hiring challenges persist amidst a talent shortage, with staffing growth rates dropping to less than half those observed in 2022, and over a third of CISOs not increasing their teams.

Corporate concerns over liability from third-party supplier hacks and SEC regulations on security incident reporting are driving a better understanding and cautious approach towards security spending among C-suite executives.

The cyber insurance market continues to grow, although checks on the terms and conditions of such policies are crucial to ensure adequate coverage during security breaches.

Overall, despite economic pressures and a shift towards cost-efficiency, the importance of and investment in cybersecurity within organizations continue to rise.