How to reduce cybersecurity costs without compromising safety

The numbers are bleak. Despite the estimated global cybersecurity spend forecast to reach $133.7 billion by the end of this year, data breaches and cybersecurity threats are evolving and increasing too. 
Despite the importance of cybersecurity, organizations are struggling to manage their budget. While we may be going into a tough economic time for businesses globally, not just here in the UK, it’s also very important not to let your cyber security lapse. 
Here, Ryan Sheldrake, Field CTO – EMEA answers five key questions on how to ensure you are not putting your business or self through any cyber security incidents if you decide to cut costs during a recession……..
What are the key areas of expenditure when it comes to a business’s cyber security outlay?
After a challenging couple of years, not least due to the global pandemic, spending on IT and more specifically on cyber security is starting to show upward, future-proofing trends. The trends are very much indicating that spending is increasing. This spans industry sectors with a range from 3.0 % in Retail to 11.4% in Financial services of percentage revenue.
In 2019 and 2020 the primary focus was on cloud and digital transformation. This has shifted in recent times to be cyber security. The “rise of ransomware” could very well be a driver for this. An alarming prediction from a recent cyberthreat report states “global ransomware damages to exceed $30bn by 2023”.
Another big percentage jump saw credential leaks taking the headlines with global companies such as Uber allegedly falling foul of this type of attack in recent months. Boards and executives are now investing in tools, automation and protective layers to prevent, detect and recover from such pervasive attacks. This is certainly a contributing factor to the shift and increase in cyber spending in 2021-2022.
What guiding principles should you be aware of with any attempt to cut cyber security costs?
Any organisation attempting to reduce spending in cyber security at the current time should do so with caution. The number of attacks is demonstrably increasing and the types of attacks such as ransomware are even being commoditised. “Ransomware as Service” is very real. If an individual, organisation or state wishes to attack a perceived adversary or target, they can now simply buy this and not have to create or even manage/execute the attack themselves.
If cuts are absolutely necessary tools consolidation, more automation can make things more efficient whilst not negatively impacting coverage or protection. Someone once said “work smarter not harder’ and in cyber terms this could mean replacing five tools with two or a platform that leverages more modern automation.
What are the steps a business should take when cutting cyber security spending?
The first step is to take stock of what has been put in place in the past. If the business has operated for a medium to long time, there are likely to be legacy tools and some level of duplication. These are easy targets for removal and could constitute a significant saving.
Next up would be to look at the IT strategy and make sure the cyber strategy is aligned. An example of this would be a move to the cloud or a hybrid onsite/cloud move. 
Consider whether some spend from, say, direct network monitoring hardware could be re-allocated to a cloud security platform that may also consolidate some other monitoring tools. This would have immediate advantages of reduction of complexity, duplication but also means the target infrastructure and systems are secured upon delivery and into the future.
What sort of cost savings can businesses realistically make?
In the past many security information and event management tools (SIEMs) have charged per gigabyte of ingested logs and data. This sounds reasonable until you start to ingest data from multiple sources. Start to think about containers, hybrid cloud, multi-cloud etc etc. The amount of data becomes very large, very quickly. Some list prices for 10 Gb/day are around $25,000/per annum. 10Gb is not a lot of logs so even a small business may need to multiply this by five or even 10. Changing a logging level from INFO to DEBUG could increase costs by many factors!
Now consider how many of the log entries are actually of interest. Perhaps less than 10% – even as low as 2%. This is of course depending on the application, infrastructure etc. Even at 10% that’s 90% waste! Using modern machine learning to avoid this type of waste presents an opportunity to save costs whilst maintaining or increasing coverage.
How can businesses ensure they don’t compromise overall security protection?
Gaining visibility into cloud infrastructure and workload, and across hybrid environments to understand what is actually running, is a great first step. Why expend effort and cost on things that don’t run. An example of this is containers that are built but never actually run. Why fix the vulnerabilities in them? This trick is to know what to safely ignore.
Then comes prioritisation, fixing the riskiest thing to the business first. Trying to fix everything is doomed to fail as more vulnerabilities are published every week. Using tools and processes to surface where to apply critical fixes and avoiding waste means coverage can be kept at an acceptable level whilst keeping costs in check.

Organizations can save time and money through a cloud-first approach to security. While the landscape may seem bleak, by following the advice above, you can secure your cloud and company without it costing a fortune.

Ryan Sheldrake

Ryan Sheldrake, Field CTO, EMEA, Lacework

Ryan has been working within IT infrastructure for over 20 years and is a prominent DevSecOps thought leader and multi-cloud advocate. As an early adopter of AWS, Ryan now specialises in Security and DevSecOps.

Is It Time for a VMware Alternative?

Wind River • 22nd May 2025

Companies have options when it comes to replacing VMware as their cloud platform, to address rising costs, support concerns, and a shrinking partner ecosystem. If you are ready to contemplate a different vendor, here are five reasons why Wind River Cloud Platform should be on your short list of VMware alternatives.

AI Leads as VivaTech Unveils Top 100 Startups

Viva Technology • 14th May 2025

Viva Technology has unveiled the first edition of its “Top 100 Rising European Startups for 2025,” spotlighting the most promising young companies shaping Europe’s tech future. Germany, France, and the UK lead the ranking, which highlights high-growth startups across 13 countries. Artificial intelligence dominates the list, with 15 companies spanning AI agents, models, and infrastructure....

Birmingham Unveils the UK’s Best Emerging HealthTech Advances

Kosta Mavroulakis • 03rd April 2025

The National HealthTech Series hosted its latest event in Birmingham this month, showcasing innovative startups driving advanced health technology, including AI-assisted diagnostics, wearable devices and revolutionary educational tools for healthcare professionals. Health stakeholders drawn from the NHS, universities, industry and front-line patient care met with new and emerging businesses to define the future trajectory of...

Why DEIB is Imperative to Tech’s Future

Hadas Almog from AppsFlyer • 17th March 2025

We’ve been seeing Diversity, Equity, Inclusion, and Belonging (DEIB) initiatives being cut time and time again throughout the tech industry. DEIB dedicated roles have been eliminated, employee resource groups have lost funding, and initiatives once considered crucial have been deprioritised in favour of “more immediate business needs.” The justification for these cuts is often the...

The need to eradicate platform dependence

Sue Azari • 10th March 2025

The advertising industry is undergoing a seismic shift. Connected TV (CTV), Retail Media Networks (RMNs), and omnichannel strategies are rapidly redefining how brands engage with consumers. As digital privacy regulations evolve and platform dynamics shift, advertisers must recognise a fundamental truth. You cannot build a sustainable business on borrowed ground. The recent uncertainty surrounding TikTok...