6 hours ago · 10 min read2018 words · Tech · hide · 0 comments

Consider a business owner being asked to approve $15,000 a year for better recovery capability. The proposal lists backup storage, protected copies, and scheduled restore testing. It explains the service well enough to price it. It says much less about what would happen if the company’s order-processing system were unavailable for three days.That is a hypothetical example, but it exposes a weakness in a security budget request. The provider has described the purchase. The owner still has to work out its value.Cyber Management Alliance’s article on using cyber risk quantification to justify security budgets argues for expressing cyber exposure in financial terms instead of relying on severity ratings. That is a useful direction. Getting the numbers into dollars, however, does not make them reliable or guarantee that the request will be funded. The business needs to understand what could fail, how the estimate was built, and what the proposed spending would actually change.For IT teams…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.