{"id":2577,"date":"2020-07-28T09:36:12","date_gmt":"2020-07-28T13:36:12","guid":{"rendered":"https:\/\/zzzptm.com\/wordpress\/?p=2577"},"modified":"2020-07-28T09:36:12","modified_gmt":"2020-07-28T13:36:12","slug":"prioritizing-security-spending-2","status":"publish","type":"post","link":"https:\/\/zzzptm.com\/wordpress\/?p=2577","title":{"rendered":"Prioritizing Security Spending"},"content":{"rendered":"\n<p>I&#8217;ll put on my manager\/owner hat, since I have one laying about the house, and will look at the receiving side of my constant cries to emphasize security spending. There, it&#8217;s on, although it seems to restrict blood flow to the part of my brain that handles technological details&#8230; never mind, let&#8217;s get to budgeting!<\/p>\n\n\n\n<p>First off, security is very important. It&#8217;s so important, I&#8217;ll use a few more &#8220;verys&#8221; to emphasize that importance. It&#8217;s very very very very very important. But, before I can pay for security, I have to pay for a few other things.<\/p>\n\n\n\n<p>Out of my revenue, first to go through are my loan payments. If I don&#8217;t keep current on my business loans, I close my doors. That&#8217;s a certainty. Ditto for&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/payroll\">payroll<\/a>, rent, and utilities. I have to pay those, on time, every month, or I *will* close my doors.<\/p>\n\n\n\n<p>Next up, I have to pay for my materials that I use in my business, whether those materials be solid manufacturing inputs or intangible information, it&#8217;s what I use to make my stuff. Without those inputs, my business is no more.<\/p>\n\n\n\n<p>Then there&#8217;s advertising. I have to have that, right? I also need money for fees, which I pay to local, regional, and national&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/government\">government<\/a>&nbsp;authorities in order to stay in business. If I don&#8217;t pay those, my business will certainly not be able to operate.<\/p>\n\n\n\n<p>Now, I&#8217;ve got some money left over. Part of me wants to have a little more for myself, to compensate for all those days I lived out of my office, getting this business off the ground. That&#8217;s why I went into business, right, to make a little something for myself, over and above what The Man would pay me in a regular gig? I&#8217;ve got a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/business-partner\">business partner<\/a>, as well, and we&#8217;ve been through everything together, all these years. I&#8217;ve got to give him his cut, fair&#8217;s fair.<\/p>\n\n\n\n<p>What&#8217;s left is my IT budget. Before anyone panics, let me assure you that there&#8217;s still quite a lot of money in that pot.<\/p>\n\n\n\n<p>But, before I pay for any security, I need to pay for my existing licenses. If my PCs don&#8217;t have an&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/operating-system\">operating system<\/a>, they don&#8217;t run, and I don&#8217;t have a business anymore. Then I pay for my productivity software because what&#8217;s the point of having PCs if they don&#8217;t do anything useful? No, I must have word&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/processors\">processors<\/a>, spreadsheets, and email! No compromise on that!<\/p>\n\n\n\n<p>If I have specialized software for my line of business, you better believe there are some big-time license fees to run that stuff. But, without it, I can&#8217;t produce what my customers want. Honestly, security is important to me, you saw how many &#8220;verys&#8221; I used up there, but I have to first allocate money for what&#8217;s core to my business.<\/p>\n\n\n\n<p>But I&#8217;m almost to security in my line-items. Let me first cover printing costs, VoIP services,&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/internet\">Internet<\/a>&nbsp;connections, and a new box fan for my server closet. As long as we keep the fans on and the door open, the servers won&#8217;t overheat. That&#8217;s a good feeling to have, the feeling you get when you know the servers won&#8217;t overheat.<\/p>\n\n\n\n<p>Now that I&#8217;m ready to buy some security, please don&#8217;t bring up the issue of locks on the doors. I can&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/lock\">lock<\/a>&nbsp;the outside doors, but if I lock the door to the server closet, we&#8217;re finished as a going concern.<\/p>\n\n\n\n<p>Looking at the budget, there&#8217;s not a lot, so maybe I should get the most important piece of security gear and hope it does most of the work I need it to do. I&#8217;ll get a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/firewall\">firewall<\/a>&nbsp;and pay for that annual license\/maintenance.<\/p>\n\n\n\n<p>Then there&#8217;s an&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/antivirus\">antivirus<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/program\">program<\/a>&nbsp;that&#8217;s only $21.95 per&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/workstation\">workstation<\/a>&nbsp;when I buy in bulk, I&#8217;ll get that. I don&#8217;t know if it&#8217;s any good, but it&#8217;s at least something.<\/p>\n\n\n\n<p>I need to buy a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/backup-and-recovery\">backup and recovery<\/a>&nbsp;solution, so that&#8217;s going to set me back a bit.<\/p>\n\n\n\n<p>I also have to pay for&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/spam-filtering\">spam filtering<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ddos-protection\">DDoS protection<\/a>&nbsp;through my&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/isp\">ISP<\/a>, or I get shut down by spammers and\/or DDoSers. This expenditure, in fact, should have come before the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/backup\">backup<\/a>&nbsp;and recovery.<\/p>\n\n\n\n<p>When I ask the guy that comes in twice a week after lunch to do my IT about what else I should get, he&#8217;s got a long list of cool stuff. But when I look at the prices he quotes for them, I have to shake my head. I really can&#8217;t afford to spend thousands on a big piece of&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/hardware\">hardware<\/a>&nbsp;like a&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/proxy\">proxy<\/a>&nbsp;server or an IPS. Maybe if I saved up, I could, but I can&#8217;t spend that kind of money right now. And don&#8217;t even talk to me about&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ip-protection\">IP protection<\/a>&nbsp;or&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ueba\">UEBA<\/a>&nbsp;or other big&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/systems\">systems<\/a>&nbsp;like that, there&#8217;s no way I can buy one of those solutions.<\/p>\n\n\n\n<p>The thing is, security is a matter of maybe I&#8217;ll lose my business if I don&#8217;t have it. The other things are a matter of I *WILL* lose my business if I don&#8217;t have them. Will beats maybe, every time. That good feeling I have about the servers not overheating is countered by the worry I have that one day, maybe tomorrow, I&#8217;m the next&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/small-business\">small business<\/a>&nbsp;that gets hit with something that the firewall, antivirus, and\/or antispam-antiDDoS can&#8217;t deal with. But that&#8217;s a maybe, a roll of the dice.<\/p>\n\n\n\n<p>Eventually, I learn to live with &#8220;maybe&#8221; and I just focus on running my business, the best I can.<\/p>\n\n\n\n<p>And if all my PCs, unbeknownst to me, are secretly mining bitcoins for&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/north-korea\">North Korea<\/a>&nbsp;or participating in Mafia-run botnets, it&#8217;s no concern to me as long as I keep in business. What I don&#8217;t know doesn&#8217;t impact my bottom line.<\/p>\n\n\n\n<p>I&#8217;m not being callow or flippant about wanting to emphasize security but simply not having the budget for it. That&#8217;s a reality. And if I get to where the &#8220;maybe&#8221; doesn&#8217;t nag at me anymore, then I can live with myself and my decisions.<\/p>\n\n\n\n<p>I just took off my manager\/owner hat and read that over. It does make sense to me. As a security person, I see all the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/breaches\">breaches<\/a>&nbsp;and crashes and outbreaks. But I don&#8217;t see that, for most people, these are only rumors, things that happen to someone else. Daily bashing away at&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/firewalls\">firewalls<\/a>, constant&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/spam\">spam<\/a>&nbsp;and DDoS, legacy&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/malware\">malware<\/a>&nbsp;trying to infect your PC like it&#8217;s 1999, those are the constants that happen to everyone. Businesses must&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/protect\">protect<\/a>&nbsp;against them. The other stuff, though, that&#8217;s in the realm of &#8220;maybe&#8221; and that&#8217;s not a strong enough case to justify a major expenditure, particularly one that could cut deep into the profitability of a firm.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ll put on my manager\/owner hat, since I have one laying about the house, and will look at the receiving side of my constant cries to emphasize security spending. There, it&#8217;s on, although it seems to restrict blood flow to the part of my brain that handles technological details&#8230; never mind, let&#8217;s get to budgeting! [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2577","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2577"}],"version-history":[{"count":1,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2577\/revisions"}],"predecessor-version":[{"id":2578,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2577\/revisions\/2578"}],"wp:attachment":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}