Not all cuts are equal: Security budget choices disproportionately impact risk

Tuesday, March 18, 2025
Security leaders must fight proposed cuts by justifying return on investments and zeroing in on the risk narrative. A recent survey of CISO peers sheds light on which cuts are more likely to result in security consequences.
Align and communicate on risk
Ilia Kolochenko, CEO of application security testing vendor Immuniweb, argues that security leaders need to formulate a coherent cybersecurity strategy.
“Numerous organizations tend to have overlapping and thus redundant solutions from different vendors, while allocating from little to no time to do proper triage of security alerts and incident response,” Kolochenko said.
“Worse, an alarmingly small percentage of organizations have a well-defined, long-term oriented, and holistic cybersecurity strategy, which would encompass such crucial areas as third-party risk management, misconfigurations, and broken IAM in a multi-cloud environment, container security, or emerging gen AI risks, including over-reliance of software engineers on synthetic code from gen AI bots that frequently contains vulnerabilities or even backdoors,” Kolochenko said.
CISOs and boards need to align their priorities and agree on a communication style where cyber risk can be understood, articulated, and mitigated on a constant basis. Read Full Article
Information Security Buzz: OpenAI Pushes for Federal-Only AI Regulation
The Register: OpenAI asks Uncle Sam to let it scrape everything, stop other countries complaining