Can you cut information security in hard times and survive

21.04.2009

But you may have no choice if the money is not there. Experts say companies that have done the hard work of really understanding their risk posture can trim spending without increasing risk. And companies that have taken security seriously can be equally smart about how they reduce their security costs, says USC's Meister. Sadly, he notes, the companies that are in this position are exceptional: "I don't think enough companies have done a great job of managing their risk profile. And it doesn't really occur [to them] until somebody loses a laptop."

So how do you cut security safely?

One method is to get your security intelligence from free projects, such as the Shadowserver project, rather than paying for the information, Cummings says.