Healthcare Cybersecurity Spend Rises: 4 Steps to a Wisely Spent Budget

By Eric Noonan • February 29, 2016

Predictably cyber/data security continues to be a rising concern from within the Healthcare industry, according to Modern Healthcare’s 26th annual Survey of Executive Opinions on Key Information Technology Issues. That being said the percentage of total IT spend devoted to security is still woefully inadequate if the survey numbers are to be believed. You simply can’t be secure on the spend levels highlighted in this survey.

I’m always skeptical of survey numbers because you can’t qualify the data or responses and there is no right answer as to how much to spend on security. However, there are best practices and industry standards that will ensure your organization is spending the money you have wisely.

4 Steps to Ensure a Wisely Spent Cybersecurity Budget

1: Make Security a Line Item in the Budget, Separate from IT

There is no right metric for security spend but you should at least be able to articulate what you are spending annually. With a defined security budget you can slice and dice any way you want, as a percentage of IT spend, cost per employee, as a percentage of revenue, etc.

2: Select a Framework

NIST, ISO, 20 CSC, just pick one! Whatever you select will give you a way to measure your current capabilities and prioritize investments, you can always change your mind later.

3: Assess Yourself

If you don’t take the time to objectively measure what you are doing today against a selected framework you will be doomed to keep doing the same things year over year. Maybe that works for some organizations, but my experience is that a comprehensive assessment against an accepted framework can serve as the burning platform for year over year improvement.

4: Roadmap the Journey

Use your assessment results to create a multi-year roadmap that ties security compliance efforts to operational efforts and tell the story to your business. Share the vision for security and articulate just how much the business is getting for its investment in security so you can have a conversation around outcomes and expectations rather than fear, uncertainty, and doubt (FUD).
Articulating the value of security and defending the budget is hard, but it’s not impossible if you use facts and figures relevant to your business and organization.

Don’t Know Where To Start?

CyberSheath’s Strategic Security Planning service offering can help you plan, build, and manage a strategic information security organization that enables your business. Our operational strategy and budgeting plans aggressively drive security organizations towards pursuing higher levels of performance.  Our Strategic Security Planning service will assist you in successfully creating a security budget that directly aligns with your business needs and goals.

CyberSheath Blog

2022 in Review: The CyberSheath Story Expands

This year marked a deluge of messaging about the Cybersecurity Maturity Model Certification (CMMC) and federal contractors were rightfully confused. With our keystone event, CMMC CON, we aimed to set the record straight and offer the best guidance for those in the Defense Industrial Base (DIB).   CMMC CON 2022…

CyberSheath Endorsed by Frost & Sullivan in First Independent Analyst Commentary on CMMC

Independent analyst firms have weighed in with commentary on nearly every discipline of information technology. Security has garnered a large portion of that IT discussion, yet until recently, Cybersecurity Maturity Model Certification (CMMC) compliance has been left out.   Frost & Sullivan changed that by selecting CyberSheath as its preferred…

Be Prepared: CMMC 2.0 Is Coming

Cybersecurity is increasingly important to safeguard your company, your customers, and your partners. We're moving into a global cyber era and we've got to get better at protecting ourselves.   Our adversaries are capitalizing on the lack of security controls in place in the defense industrial base (DIB) and we…

Our Trusted Partners

Tenable Microsoft Siemplify KnowBe4 ConnectWise DUO