How to reduce cybersecurity costs without compromising safety

An image of , News, How to reduce cybersecurity costs without compromising safety

The numbers are bleak. Despite the estimated global cybersecurity spend forecast to reach $133.7 billion by the end of this year, data breaches and cybersecurity threats are evolving and increasing too. 
Despite the importance of cybersecurity, organizations are struggling to manage their budget. While we may be going into a tough economic time for businesses globally, not just here in the UK, it’s also very important not to let your cyber security lapse. 
Here, Ryan Sheldrake, Field CTO – EMEA answers five key questions on how to ensure you are not putting your business or self through any cyber security incidents if you decide to cut costs during a recession……..
What are the key areas of expenditure when it comes to a business’s cyber security outlay?
After a challenging couple of years, not least due to the global pandemic, spending on IT and more specifically on cyber security is starting to show upward, future-proofing trends. The trends are very much indicating that spending is increasing. This spans industry sectors with a range from 3.0 % in Retail to 11.4% in Financial services of percentage revenue.
In 2019 and 2020 the primary focus was on cloud and digital transformation. This has shifted in recent times to be cyber security. The “rise of ransomware” could very well be a driver for this. An alarming prediction from a recent cyberthreat report states “global ransomware damages to exceed $30bn by 2023”.
Another big percentage jump saw credential leaks taking the headlines with global companies such as Uber allegedly falling foul of this type of attack in recent months. Boards and executives are now investing in tools, automation and protective layers to prevent, detect and recover from such pervasive attacks. This is certainly a contributing factor to the shift and increase in cyber spending in 2021-2022.
What guiding principles should you be aware of with any attempt to cut cyber security costs?
Any organisation attempting to reduce spending in cyber security at the current time should do so with caution. The number of attacks is demonstrably increasing and the types of attacks such as ransomware are even being commoditised. “Ransomware as Service” is very real. If an individual, organisation or state wishes to attack a perceived adversary or target, they can now simply buy this and not have to create or even manage/execute the attack themselves.
If cuts are absolutely necessary tools consolidation, more automation can make things more efficient whilst not negatively impacting coverage or protection. Someone once said “work smarter not harder’ and in cyber terms this could mean replacing five tools with two or a platform that leverages more modern automation.
What are the steps a business should take when cutting cyber security spending?
The first step is to take stock of what has been put in place in the past. If the business has operated for a medium to long time, there are likely to be legacy tools and some level of duplication. These are easy targets for removal and could constitute a significant saving.
Next up would be to look at the IT strategy and make sure the cyber strategy is aligned. An example of this would be a move to the cloud or a hybrid onsite/cloud move. 
Consider whether some spend from, say, direct network monitoring hardware could be re-allocated to a cloud security platform that may also consolidate some other monitoring tools. This would have immediate advantages of reduction of complexity, duplication but also means the target infrastructure and systems are secured upon delivery and into the future.
What sort of cost savings can businesses realistically make?
In the past many security information and event management tools (SIEMs) have charged per gigabyte of ingested logs and data. This sounds reasonable until you start to ingest data from multiple sources. Start to think about containers, hybrid cloud, multi-cloud etc etc. The amount of data becomes very large, very quickly. Some list prices for 10 Gb/day are around $25,000/per annum. 10Gb is not a lot of logs so even a small business may need to multiply this by five or even 10. Changing a logging level from INFO to DEBUG could increase costs by many factors!
Now consider how many of the log entries are actually of interest. Perhaps less than 10% – even as low as 2%. This is of course depending on the application, infrastructure etc. Even at 10% that’s 90% waste! Using modern machine learning to avoid this type of waste presents an opportunity to save costs whilst maintaining or increasing coverage.
How can businesses ensure they don’t compromise overall security protection?
Gaining visibility into cloud infrastructure and workload, and across hybrid environments to understand what is actually running, is a great first step. Why expend effort and cost on things that don’t run. An example of this is containers that are built but never actually run. Why fix the vulnerabilities in them? This trick is to know what to safely ignore.
Then comes prioritisation, fixing the riskiest thing to the business first. Trying to fix everything is doomed to fail as more vulnerabilities are published every week. Using tools and processes to surface where to apply critical fixes and avoiding waste means coverage can be kept at an acceptable level whilst keeping costs in check.

Organizations can save time and money through a cloud-first approach to security. While the landscape may seem bleak, by following the advice above, you can secure your cloud and company without it costing a fortune.

An image of , News, How to reduce cybersecurity costs without compromising safety

Ryan Sheldrake

Ryan Sheldrake, Field CTO, EMEA, Lacework

Ryan has been working within IT infrastructure for over 20 years and is a prominent DevSecOps thought leader and multi-cloud advocate. As an early adopter of AWS, Ryan now specialises in Security and DevSecOps.

Nutanix on OVHcloud US Offers a Hybrid Multicloud Solution

Joon Lee • 11th September 2023

Nutanix is a leading cloud computing software company that helps companies simplify their cloud strategies by using hyperconverged infrastructure (HCI) environments. Hyperconvergence is a software-centric architecture that tightly integrates compute, storage, networking, and virtualization resources and other technologies on commodity hardware servers supported by a single vendor.

OVHcloud Is at the Forefront of the Data Revolution

Karen Kokiko • 11th September 2023

Information technology is going through a digital transformation and reshaping how we do business, how we interact, how we make decisions, and how we influence our society. OVHcloud® is at the forefront of this data revolution, standing apart from the competition with a strong commitment to creating a level playing field and the opportunity for...

Right Sizing & Workload Optimization in the Cloud

Joon Lee • 11th September 2023

Organizations facing the challenges of scaling their cloud infrastructure can achieve improved performance by implementing the principles of right sizing their infrastructure. This practice is essential for optimizing cloud infrastructure and enhancing its overall effectiveness. In this guide, we will discuss the benefits of right sizing, including optimizing costs, eliminating waste and improving performance. We’ll...

OVHcloud Is at the Forefront of the Data Revolution

Karen Kokiko • 11th September 2023

Information technology is going through a digital transformation and reshaping how we do business, how we interact, how we make decisions, and how we influence our society. OVHcloud® is at the forefront of this data revolution, standing apart from the competition with a strong commitment to creating a level playing field and the opportunity for...

Can Europe take on the US Cloud giants?

Richard Hilton • 30th August 2023

With so many issues coming up about cloud storage, what is the solution to the dominance of the major giants like AWS (32%), Microsoft (23%) and Google (10%) taking 65% of the world cloud market?

The race to dominate the AI space

Kevin Cole • 24th August 2023

The launch of Chat GPT-4 in March of this year provided the catalyst for a conversation that has been gaining momentum for some time now: How will artificial intelligence (AI) change the world?