In 2014, the global economic damage caused by cybercrime was estimated at approximately $445 billion. Fast forward eight years, and by 2022, that figure had surged to $7.08 trillion. What is the outlook? According to data published by Statista, the forecast is that by 2028, the economic damage from cybercrime will reach an unimaginable sum of approximately $13.82 trillion globally.
How are organizations and nations worldwide attempting to deal with this “runaway train” heading for a precipice? By pouring money—and lots of it—into the problem. Companies have increased their information security budgets by an average of about 10% annually. Consequently, the obvious question is: why is cyber damage not decreasing (or at least stabilizing) if budgets are growing so drastically?
To answer this, we must return to the fundamentals and the “ABCs” of organizational structure. The pillars of any organization are: 1. Technology, 2. People, 3. Processes. An examination of the cyber industry and the solutions offered to combat cyber threats reveals an unequivocal situation—the vast majority of cybersecurity solutions are technological, promising ‘magic’ fixes to reduce organizational risk. But what about people and processes? It appears these two pillars have been left behind.
Many companies focus on technological solutions hoping to reduce the likelihood of a breach. In practice, a grim reality emerges: products purchased at great expense are not properly implemented, are not operated as required, and worst of all, do not undergo periodic audits to ensure they are providing the necessary protection.
If companies are spending vast sums on security products, why are they failing to translate these capabilities into risk reduction? The answer can be found by observing how security teams in many organizations manage their daily operations. Typically, the daily routine of security teams consists of jumping from one urgent incident to the next, lacking the capacity to manage a structured annual plan that includes all the controls and processes required for effective cybersecurity operations. Furthermore, the vast majority of security teams manage their work using Excel spreadsheets, endless folders, WhatsApp correspondence, and so on. In the “best-case” scenario, security teams manage and prioritize their work using standard task or project management systems.
In many ways, the cybersecurity industry has yet to reach maturity. When examining the evolution of other organizational fields—such as sales or customer relationship management—one can see that work management initially began manually with documents, spreadsheets, and folders. The next stage involved task and project management systems. Today, it is taken for granted in many organizations that sales and customer management departments use dedicated CRM or ticketing systems tailored to their needs, providing a complete framework for ongoing operations.
Is this evolution expected to occur in the cyber world as well? The answer lies in the figures mentioned at the beginning of this article. If current trends continue—increasing budgets without effective risk reduction—organizations will eventually reach a point where they can no longer meet the needs of their information security teams. To avoid this, the root cause must be addressed: processes and people. Only when information security teams operate according to a structured plan—with clarity on where to focus, what impacts the organization’s risk level most, and how—will we see a reversal of the trend.
Insights from Senior Cybersecurity Experts at IPV Security:
Many organizations focus on technological solutions in hopes of reducing breach risks. In reality, expensive products are often improperly implemented and operated, lacking the periodic oversight necessary to ensure required protection. Security teams often find themselves trapped in a cycle of reactive “firefighting” between urgent tasks, unable to maintain a structured annual plan with the controls and processes essential for effective defense.
If the trend of increasing budgets without risk reduction continues, organizations will eventually fail to satisfy the requirements of their security teams. Therefore, there is a need to shift focus toward the root of the problem: proper and effective management of people and processes within the organization.