• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
Cybersecurity Spend

Cybersecurity Spend

April 22, 2019 Posted by Michael Lydon IT Security

How Much Will It Take To Keep My Organization Safe?

A study by ZDNet reveals that 80% of organizations planned to increase their security spend in 2019 compared to their 2018 spend.  This makes sense; considering the number of data breaches and the number of records exposed increased at an unprecedented rate from 2016 to 2018 as depicted in the graphic below.

https://www.statista.com/statistics/273550/data-breaches-recorded-in-the-united-states-by-number-of-breaches-and-records-exposed/

Here are a few more related stats for those number-lovers out there:

  • A separate study conducted by Statista showed the global number of web attacks blocked per day increased by 56.1 % between 2017 and 2018
  • Gartner reports that the average annual security spend per employee has doubled, from $584 in 2012 to $1,178 in 2018.  Another report says that spending is estimated to reach $6 trillion annually by 2021 which is double the $3 trillion spend from 2015.

While certainly reliable, Gartner is not the only market-provider with data-backed research.  As outlined in an excellent article by the Boston Consulting Group, there is no real agreed upon consensus as to how an organization should determine its ideal cybersecurity spend.

https://www.bcg.com/publications/2019/are-you-spending-enough-cybersecurity.aspx

It is encouraging to see executives invest more resources into adding cybersecurity tools and solutions; however, this change brings with it a new set of more challenging questions:

How much should my organization spend on cybersecurity? Which areas of my organization are most vulnerable thus requiring more attention?  What is our organizational risk-appetite?

Start by completing an annual vulnerability scan and/or risk assessment to identify possible weak-points within your environment. Identifying vulnerabilities is only half the battle; you must also develop an actionable remediation plan to mitigate known vulnerabilities.  Breaches are on the rise, with hackers constantly inventing new ways to penetrate security defenses.  Will your company be 100% safe once you’ve completed a security assessment and implemented a remediation plan?  The short answer is no, an organization can never truly eliminate all risk.

An auto-insurance policy provides a safety-net for car owners; by paying monthly insurance premiums, the policy owner receives peace of mind knowing his insurer will provide financial assistance in the event of an accident. For very similar reasons, numerous organizations are opting to purchase Cybersecurity Insurance Policies to further manage their risk.  According to an Insurance Journal article, cybersecurity policy sales ballooned from $2.5 billion in 2015 to $4.3 billion in 2017.  Sales are expected to reach the $7.5 billion mark by 2020. 

Does your organization need to consider purchasing cybersecurity insurance? How much coverage is enough? What type of policy would suit my organization best? Does the policy require an annual assessment?

To answer these questions and a whole lot more, contact OCD Tech for a complimentary consultation of your organization’s IT environment and/or for a third-party security assessment.

Tags: cybersecuritycybersecurity insurance policyrisk assessmentvunerabilities
Share
1
Avatar photo

About Michael Lydon

Michael is the Business Development Manager for OCD Tech/O’Connor & Drew. He is involved in a number of engagements for the firm working to identify new clients, partners, and general opportunities. Previously Michael has held positions with All Covered-Konica Minolta & The Warren Group.

You also might be interested in

WPA3: Next Generation Wireless Security

WPA3: Next Generation Wireless Security

Jul 24, 2018

For the first time in over a decade, the current Wi-Fi security standard is receiving an upgrade.

ftc safeguards

FTC Safeguards

Jun 11, 2024

Protecting Information & Avoiding Penalties  Safeguarding customer information is paramount[...]

OCD TECH NIST UPDATE

NIST Framework update

Aug 16, 2023

The National Institute of Standards and Technology (NIST) has recently[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next