Cybersecurity Comes With a Price

Share this post

Cost of a cybersecurity program visualized as a car.

Thump, Thump, Clang!

Uh oh, there was clearly something wrong with the car. So I took it to the dealer to have a look.

They found a bunch of typical stuff in need of attention – brake pads, tires, etc. But they also discovered a problem with the subframe; the right rear trailing arm had broken off from excessive rust.

Is that a problem? Only if you want your rear axle to remain attached to the rest of the vehicle (we did). In other words, it was unsafe to drive.

All of this was fixable, but the total cost would have been more than two-thirds of the car’s value. It was time for a replacement.

But hey, no complaints. We had that car for more than 10 years (we bought it when vehicle CD players were still a big deal). It didn’t owe us anything.

And while we hadn’t really budgeted for a new car, it wasn’t a surprise. Every experienced car owner knows that sooner or later, things break, at which point there is a cost: either you fix the problem(s) or step up to a newer vehicle.

This same concept – there is always a cost – applies to cybersecurity as well. Interestingly, a lot of companies remain unaware of it.

vciso ebook

Below the Radar

Many businesses don’t think of cybersecurity as an expense that needs to be explicitly planned for. If they haven’t had an incident and their IT guy says, “I’ve got it handled,” things just chug along.

The fact is, for many companies, the first time they start spending dedicated dollars on cybersecurity is when…

1.  A new client demands it. They are ready to move ahead provided you can prove that you have a rock-solid cybersecurity program. (If you sell to enterprise or government, this is a given.)

2. The owner or a board member wants it.

3. A friend or colleague has an incident. At that point, like when a buddy has a heart attack, you realize it’s time for you to get in shape as well!

Whatever prompts you to invest meaningfully in cybersecurity for your company, it’s critical that you do. And soon. After all, the consequences of your business stopping in its tracks or your data being lost (possibly forever) are severe.

Plan for Tomorrow, Today

Often, companies equate cybersecurity with a set of discrete actions or tools: firewall, antivirus, multifactor authentication. That’s part of it, of course, but in order to be effective you need to think more comprehensively about overall protection.

That may include training for departments, processes regarding how customer data is captured and stored, software development and upgrades, additional personnel, and more. All of this has a cost.

As for how much, it’s like buying a car: it depends. If you are a medium-sized business and have someone on staff that is somewhat qualified (and has the bandwidth), you can assume tens of thousands of dollars of incremental spend. If you don’t have that person, that’s an additional cost that needs to be accounted for.

The exact number will depend on the quality of the program put in place and your expectations. But rest assured, it’s not something you can simply absorb into your existing budget.

vciso ebook

Make Security an Investment

If what’s prompting you to increase security are the requirements of a new client, that’s awesome – the new sale can fund the expense (although we recommend starting much sooner and not waiting until a prospective customer is at your door).

It’s often larger, enterprise customers that are most demanding of your own cybersecurity program. They have sophisticated security requirements and are generally willing to pay for the right solutions. You can cover the costs of your own program by being deliberate when charging enterprise customers.

For example, Slack charges more for advanced security features such as Single Sign On and enterprise key management

While you may not literally have an enterprise version of your product, you can and should plan to charge more for enterprise customers as they are demanding more from your company.

Pay Now or Pay Later

The uninterrupted operation of your business and the protection of your data are fundamental to the ongoing health of your company. Your cybersecurity program needs to be planned and budgeted for.

As to how much it will cost, your mileage will vary … but there will be a cost if done well.

Speaking of mileage, please get in touch if you know how to set up Apple CarPlay. I’d be happy to trade a few heavily used CDs in exchange.

Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click.

Rob Black
Rob founded Fractional CISO in 2017 and has helped dozens of mid-size SaaS and technology companies improve their security posture as a vCISO. He consults, speaks, and writes on IoT and security. Rob has held product security and corporate security leadership positions at PTC ThingWorx, Axeda and RSA Security. He received his MBA from the Kellogg School of Management and holds two Bachelor of Science degrees from Washington University in St. Louis in Computer Science and System Science and Engineering. He is also a Certified Information Systems Security Professional (CISSP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales