IDG Contributor Network: Cybersecurity: Why do we spend more but get less?

Discussion in 'CSO' started by RSS, Jun 21, 2016.

    Why do we spend more for cybersecurity, but get less?

    I’m asked this question frequently when I’m at speaking engagements, and the answer is actually pretty simple. There are two reasons:

    1. We have an archaic view on security.
    2. We are spending money on the wrong things.

    There are some things in life we just can’t escape. It is in our DNA. Millions of years of evolution have wired our brains to think in a certain way, and without almost Herculean effort and will power, we will continue to think in that way. Our view of security is one of these things. Ask a child how to protect something and they’ll tell you to lock it away so no one can take it. Banks lock it in a vault. You probably secure your company by badging everyone in and out through the access points, and you probably protect your network by placing it behind a firewall that only lets people in who have the correct password. Unfortunately, in today's environment, each of these actions is flawed. Well…maybe not flawed, but certainly not sufficient.

