Wednesday, 19 August 2026
Nigeria Communications Week
News

Finding Reveals Significant Savings Potential for Information Security and Audit

Comms Week9 Mar 20090 Comments
Kindly share this post

A new research co-sponsored by the Computer Security Institute, The Institute of Internal Auditors, Protiviti, ISACA, IT Governance Institute, and Symantec Corp  has outlined a risk-based…

A new research co-sponsored by the Computer Security Institute, The Institute of Internal Auditors, Protiviti, ISACA, IT Governance Institute, and Symantec Corp  has outlined a risk-based approach to budgeting for information security that rewards results; the practices responsible for managing business and financial risks from the use of IT; and the substantial reductions in spending on audit in IT. 

  IT Policy Compliance Group (IT PCG) has announced its latest research report titled, “Managing Spend on Information Security and Audit to Improve Results” based on research conducted with more than 2,600 firms.  The study reveals that 68 percent of firms are under-spending on information security in relation to the financial risks and losses they are experiencing. Yet incremental increases toward the funding of best practices are responsible for financial returns that can exceed more than 200 percent for most organizations. 

   “Like an insurance deductible, all organizations are willing to sustain some level of financial risk and loss from theft of customer data or some level of business downtime from IT disruptions,” said Errol Rhoden, regional specialist manager, Symantec IRM. “However, the research findings show that an organization’s loss-tolerance is exceedingly low, and the financial returns for small improvements are extraordinarily high.”
  Firms ranked three business risks from IT well ahead of other possible risks: Confidentiality of sensitive information; Integrity of information, assets and controls in IT; and Availability of IT services. The IT PCG report leverages ongoing benchmarks to measure the performance of firms against these three risk areas. The results of the benchmark surveys can be broken up as follows:  Worst Outcomes: 19 percent of all firms are experiencing more than 15 losses or thefts of data each year, 80 or more hours of business downtime from IT failures, and more than 15 audit-failing deficiencies. 

Normative Outcomes: 68 percent of all firms are operating at ‘normal’ levels experiencing between 3-15 losses or thefts of data each year, between 7-79 hours of business downtime from IT failures, and between 3-15 audit-failing deficiencies while in Best Outcomes: 13 percent of all firms are achieving the best results, experiencing fewer than 3 losses or thefts of sensitive information each year, less than 7 hours of business downtime, and fewer than 3 audit-failing deficiencies. The financial returns among these organizations range from 22 percent to more than 3,000 percent annually. 

Surprisingly, the study said that the difference in outcome between the worst performers and the best performers was not as a result of the size of security budgets. In fact, the differences in size of security budgets were negligible. What mattered was how those budgets were used.  

The new report details the following five practices being leveraged by those with the best outcomes and the least financial losses: Leveraging a senior management team to manage risk, prioritizing risks, improving controls, and automating procedures, continuously assessing controls and risks, leveraging technical controls, policies, and IT change management, and comprehensive reporting.

C
Published by

Comms Week

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in News