MegaBanner-Right

MegaBanner-Left

LeaderBoad-Right

LeaderBoard-Left

Home » Industry News » Digital Transformation - Information Technology News » Tightening belts for a recession? Don’t skimp on cyber security

Tightening belts for a recession? Don’t skimp on cyber security

Is the global economy headed into a recession? South Africa’s economy has been flirting with a contracting state for several years. Numerous signs point to more countries landing in the same situation, even lapsing into persistent negative growth. While analysts are still studying their crystal balls, businesses have to prepare for the worst – and preparing for a recession means cutting costs and refocusing resources.

However, while doing so, they might end up creating an enormous risk that will cost them much more than the losses of shrinking economies.

Tim Collins, Chief Financial Officer of cyber security provider, Performanta, says: “In tough economic and uncertain times, companies need to take stock of their financial positions and make hard choices to become even more resilient. Technology spending increased during the pandemic’s digitisation priorities to improve productivity of staff working from home and increase cyber security. But as new priorities demand attention, technology resources and costs are now under pressure. Yet leaders must be careful: if they wield a sword instead of a scalpel and ignore important strategic and risk realities, they can do far more damage to themselves than they realise.”

In particular, cyber security is under the spotlight. KPMG International’s latest Global CEO reveals a massive drop in how companies rank cyber security risks, falling from first in February 2022 to not even making the top 5 in August 2022. Emerging/disruptive technology, operational issues, regulatory concerns, environmental/climate change and reputational risk all precede digital security.

Why such a drop in importance? Collins proposes two reasons: “Many organisations have invested in security systems so they might feel that box is ticked even though it contradicts the continuous operational need to mitigate cyber risks. And some might want to focus more on other risks, perhaps appreciating that cyber security is a factor in all of those. For example, CEOs worrying about disruptive technologies, regulation, operations and reputational damage should realise that cyber security heavily influences all those risks. If they don’t and start cutting back on security costs while only looking at the bottom line, they are making a big mistake.”

Cyber security in a recession

Cyber security is even more important during a recession than in good times. Though there is no definitive correlation between recessions and overall crime rates, World Economic Forum research suggests that more challenging financial times lead to increases in career criminals and malicious insider activities.

Cybercrime is a tempting opportunity for skilled IT professionals with ambiguous morals – especially in the face of a bear market downscaling employment. Recessions grow cybercrime talent pools. And the higher job pressures resulting from fewer resources create more disgruntled employees who might avenge their sentiments by using their access privileges. Cutting back too much on cyber security budgets and personnel is more likely to increase attack risks and undermine attempts to address other major risks, such as disruption and financial losses.

But does this mean companies should spend more on cybercrime, biting the budget bullet just because there is no alternative? They do have alternatives when they cease looking at cyber security only as a cost centre.

“A recession is an opportunity,” says Guy Golan, CEO of Performanta. “There has been incredible investment and growth in cyber security, and companies are right to expect some dividends from that. We can’t just keep saying they must spend, spend, spend. But they should then mature. The big issue is that they still put cyber security on a pedestal, as an operational must-have that they don’t really understand in context of their business. It’s not strategic and it’s not treated as an integrated business department, leading to wasted spending, poorly-managed resources and under-performing security. If they look at security efficiency before making security cuts, they’ll realise significant and long-term gains.”

Bank on Cyber Safety

Golan calls this concept cyber-safety: the notion that cyber security is framed within the business context and treated like any other department. When organisations treat cyber security as a black box – meaning they only see input and output but not how it creates that value – they risk misinterpreting its purpose and requirements.

This can lead to knee-jerk budget and staff cuts that have lasting negative implications. Fixing a cyber breach often costs considerably more than preventing or limiting an attack. Notably, IBM’s 2022 report found that a breach, on average, costs USD 4.35 million – a substantial amount at any time, but especially in a recession.

Yet companies that treat cybersecurity as a business function have more opportunities to manage costs. They can focus their energy to discover and optimise under-performing systems, assess security staff for allocation of duties and career development, develop and introduce business-savvy security leaders to the top of the company, formalise processes, and strategically integrate cybersecurity around their other pressing concerns.

“The right cybersecurity partners are catalysts for this exercise,” says Golan. “It’s fair to say that the security market often cares more about selling than about customer context and strategy. But the best security providers aren’t just about skills and technology. They have to take a real interest in your business and its security needs. A recession can put pressure on partners, on how well they perform as advisors and strategists.”

Recessions require sacrifice and compromise. Cyber security won’t be spared from tightening belts, but beware of bluntly reducing its capacity. Use the opportunity to collaborate with your security partners, tighten controls, discover unrealised value, and integrate cyber security as a part of business strategy and operations. The times ahead might be tough but improving security needn’t be.

To enquire about Cape Business News' digital marketing options please contact sales@cbn.co.za

Related articles

Visually impaired coders trained in cyber-security

ONE in every 200 coders globally is reportedly blind or visually impaired – and, thanks to some innovative education initiatives, the massive digital divide...

Security professionals brace for a new wave of emerging cyber security threats 

Security professionals have their jobs cut out for them, with 74% saying their organisation’s sensitive data was potentially compromised or breached in the last...

MUST READ

City delivering real change

Behind every budget line, every policy, and every project there are real people, real challenges, and a shared future we are shaping. In a...

RECOMMENDED

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.