ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Doing more with what you have

Jonathan Wright at Global Cloud Xchange argues that, in a rapidly changing economic and threat environment, there is a need to make budgets work harder, by optimise existing cyber-security tools rather than simply grabbing the best of everything

 

The cyber-security landscape has undergone significant transformation in recent years, with organisations required to safeguard against a growing number of various, increasingly sophisticated threats. Struggling to keep up, cyber-teams have been compelled to quickly adopt different security solutions to meet their immediate needs.

 

In the current economic climate, however, the focus has shifted to security optimisation; security leaders must demonstrate to the board that they are effectively protecting the business without overspending on unnecessary – and often duplicate – measures.

 

Increasing security spend

The volume of global cyber-attacks rose by 38 percent between 2021 and 2022, and is expected to continue growing. It’s perhaps unsurprising, then, that spending on cyber-security measures has also increased in recent years as organisations seek ways to counter these attacks.

 

According to Gartner, worldwide spending on security and risk management is forecast to grow by 11.3 percent in 2023. Further recent research finds that two thirds of organisations plan to increase their cyber-security spending this year, with two in five claiming that improving their business’s cyber-security is the most important justification for investing in IT. 

 

But this situation is set to change. Required to cut costs due to the limitations of the current economic environment, security leaders are facing greater pressure to optimise their defences.

 

A reactive approach

Tackling the range of threats that make up today’s cyber-security landscape has led to a landgrab of various security solutions that operate separately and touch different areas of the IT environment.

 

Such solutions range from network security for protection against viruses and data exfiltration attempts; to endpoint security, used to protect users’ devices against ransomware and phishing; and application security, for protecting web applications which, like anything directly connected to the internet, represent a target for bad actors.

 

Many of these solutions will have been purchased reactively, often following a particular type of attack, and without a clear strategy for how they can be integrated with an organisation’s existing security solutions. As a result, many security leaders won’t have a comprehensive, holistic view of all their organisation’s cyber-security measures.

 

Without this, an organisation can experience inefficiencies, redundancies, and gaps in coverage, all of which can leave it vulnerable to cyber-threats.

 

Avoiding security silos

Clearly, this is a position no company wants to find itself in. It’s vital, therefore, that security leaders take the necessary steps to avoid the impacts of such a siloed approach to cyber-security.

 

It’s important, for example, that they identify any potential cracks in their defences arising from a lack of cohesion between the different types of security solutions used.

 

At the same time, while this absence of a joined-up approach can lead to gaps in coverage, there can also be such a thing as too much security. Over time, solutions can be added which, effectively, will perform the same task as others, already installed.

 

Doubling up in this way is not only inefficient, but can also be expensive. At a time when purse strings are becoming increasingly tighter, leaders should identify those areas where budget is being wasted on solutions that perform similar or duplicate functions. 

 

Finally, they must identify those areas where resources can be best optimised. It’s worth noting here, that while they may opt to take an optimal solution for everything, it may not be the most cost-effective approach, as the cost for managing every aspect of an organisation’s security posture can be high.

 

Instead, they might want to consider a solution which, although may not the best-in-class for every individual problem it addresses, offers greater ease of management and control, thereby improving overall control of the security posture and reducing the need for expenditure on both different licenses and the talent needed for management of multiple disparate solutions.

 

Optimising security measures

Ultimately, the answer lies in a move towards security optimisation. Having identified the areas outlined above, optimisation will help companies to recognise where they have solutions which duplicate on the services they offer, and which of these could be applied in different ways to provide more extensive coverage, and where additional protections can be applied today to avoid unnecessary purchases in the future.

 

Companies without a CISO with the strategic understanding of how to build an optimised security portfolio might find this challenging. In such cases, these companies should look to partners that can provide an interim CISO or serve in a consultancy role. 

 

Either way, economic and security concerns mean businesses need to move away from the reactive landgrab approach to cyber-security procurement. Instead, they must adopt a more holistic, strategic view, one that considers the integration of new solutions with existing ones, and the overall impact this has on their security posture.

 

By doing so, businesses can optimise their cyber-security measures, streamline their operations, and ensure their team is equipped with the tools and resources they need to effectively safeguard their organisation against the evolving cyber-threat landscape. 

 


 

Jonathan Wright, Director of Products and Operations, Global Cloud Xchange

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543