John Pescatore

A member of the Gartner Blog Network

John Pescatore
VP Distinguished Analyst
11 years at Gartner
32 years IT industry

John Pescatore is a vice president and research fellow in Gartner Research. Mr. Pescatore has 32 years of experience in computer, network and information security. Prior to joining Gartner, Mr. Pescatore was senior consultant for Entrust Technologies and Trusted Information Systems… Read Full Bio

Coverage Areas:

Follow-up Friday: Cost vs. Value of Security

by John Pescatore  |  November 21, 2008  |  Submit a Comment

We had a fun bloggie style discussion on measuring the value of security programs a while back. All attempts to do so always run into problems measuring the cost or the benefits.  Everyone talks as if businesses make business decisions based on hard facts used to scientifically calculate return on investment or hurdle rates or discounted cash flow, but if you dig into most of those you find a lot of squishy assumptions as the foundation of the analysis. Security is no different – we just don’t have the cover of good spreadsheets, though ROSI is a start.

It invariably comes down to driving change – we know there are weaknesses in our security protections or the business side knows that security policies are inhibiting business. We’re both trying to drive towards the balance of where security costs to contain risks are balanced with business needs to take risk. Since the threats and business conditions change constantly, it is a constant negotiation – like pretty much the rest of life. That doesn’t means security is just a journey, not a destination – it means every time we reach a destination we need to be prepared to pick the right path to the next stop.

 

Security Spending Sweet Spot

Security Spending Sweet Spot

Submit a Comment »

Category: Uncategorized     Tags:

0 responses so far ↓

  • There are no comments yet...Kick things off by filling out the form below.

Leave a Comment