The security budget request is large. What should we fund first?

Fund the basics that stop most attacks and the recovery that limits the rest: strong login, patched systems, limited access, backups that restore, and a plan everyone knows. Buy a new product only when someone will run it. Anything beyond what a regulator or insurer requires is a choice.

Draft for Tamir's review. Not published.

Tamir Khason · Updated · Decision guides

Start from the basics and your own gaps

Ask IT to map each budget item to one job: prevent entry, limit spread, detect, respond or recover. An item that maps to none needs a reason. If a nearby organization was attacked, trace how the attack got in and spread, and check each step against your controls.

Most of a first budget usually belongs in backups, access control and patching before new platforms. Test restoring a critical system from backup, and time it. Ask the operations people how long the business could run without each main system.

Buy only what someone will run

A tool nobody operates leaves the same exposure at a higher cost. For each proposed product, name who will operate it and how many hours a week that takes. Count the tools you already own, and which are fully deployed and watched.

Sequence purchases so each one runs before the next is bought. Hardening comes first if the basics are missing, because monitoring an open environment produces alerts without protection. Where products overlap or have no owner, compare a smaller set someone can run with a full renewal.

Depending on your seat

If you're the CEO, ask what the regulator or insurer actually requires, and map the request to it line by line. Separate approval of the plan from the delivery contract, so another firm could deliver parts. This matters most when the firm that sized the program would also deliver it.

If you run IT, treat an insurer's questionnaire as a minimum, then check how you would actually run each control. Ask the insurer which items weigh most on premium or coverage, and start there. Ask the vendor to split any suite into products you can buy alone.

What to check before you decide

  • Map each budget item to prevent entry, limit spread, detect, respond or recover, or to nothing.
  • Test restoring a critical system from backup this month, and time it.
  • For each proposed product, name who will operate it and how many hours a week that takes.
  • Count the security tools you already own, and which are fully deployed and monitored.
  • Get the regulator's or insurer's requirements in writing, and map each item to one of them.
  • Ask which items are one-off and which are ongoing, including the people to run them.
  • Ask what the company would do in the first day of an attack, and who decides what.

Questions people ask

A competitor was hit by ransomware and my IT manager wants a budget I can't judge, what should I actually fund?

Fund the basics that stop most attacks and the recovery that limits the rest: strong login, patched systems, limited access, backups that restore, and a plan everyone knows. Ask the IT manager to map the request to those five and show what each item does. It depends on what you already have and on how long you could run without your systems.

Regulator wants a cyber plan for our plant and the assessor proposed a multi year program they would deliver, how do I judge the size?

Ask what the regulator actually requires and by when, and map the program to it line by line; anything beyond it is a choice and carries no obligation. Separate the plan's approval from the delivery contract so another firm could deliver parts. It depends on the regulator's specific requirements and on which plant systems matter most to safety and production.

Security monitoring service or one off hardening project, which should a mid size company buy first?

Hardening first if the basics are missing, because monitoring an unpatched, open environment generates alerts without protection. Monitoring first if the basics are in place and nobody watches. Ask each firm what it would say about the other's offer. It depends on your current state, which a short assessment shows.

Should we keep renewing cybersecurity products that nobody actively operates?

Assess the protection actually delivered and the work required to sustain it. Renewal depends on ownership, response capability, and whether a simpler control would address the same exposure.

Board approved cyber budget after a hospital attack, vendor wants to sell eight products, how do I decide what we need first?

Start from the attack path that hit the other hospital and from your own gaps, and buy what closes the biggest gap your team can operate. Most of the first budget belongs in basics such as backups, access control and patching before new platforms. It depends on your current controls and on how many people you have to run what you buy.

Cyber insurer requires controls we don't have and a vendor quoted a package to match, how do I decide what to buy?

Treat the questionnaire as a minimum, then check each required control against how you would actually run it. Insurers mostly want a few basics done well, and those basics also reduce your real risk. It depends on what you already have partly in place and on how the insurer weighs each control.

Do we need another refinery security assessment before buying monitoring tools?

Commission more assessment only where current evidence cannot support the monitoring purchase. It depends on inventory gaps, operational exposure, and the safety constraints on collecting missing information.

Should we keep overlapping security products after performance and support problems?

Map protection outcomes and operational conflicts before renewing either tool. The decision depends on verified coverage, response ownership, and what changes when an agent is removed.

How I can help with this decision

Ask or talk (Free)
I give my view on which items in a request like this usually matter most, and what to ask before you approve it.
Review (Pay if it was worth it)
I write an independent assessment of your exposure, the request or vendor proposal, and your team's capacity to run it. I recommend what to fund first, what to defer and what to decline.
Retain (When it makes sense)
I stay close through the year to review each funded item against the gap it was meant to close, and the restore tests.