Recession? Do not skimp on cybersecurity

Issue 1 2023 Information Security, Security Services & Risk Management

Is the global economy headed into a recession? South Africa’s economy has been flirting with a contracting state for several years. Numerous signs point to more countries landing in the same situation, even lapsing into persistent negative growth.

While analysts are still studying their crystal balls, businesses have to prepare for the worst, and preparing for a recession means cutting costs and refocusing resources. However, while doing so, they might end up creating an enormous risk that will cost them much more than the losses of shrinking economies.

Tim Collins, Chief Financial Officer of cybersecurity provider, Performanta, says, “In tough economic and uncertain times, companies need to take stock of their financial positions and make hard choices to become even more resilient. Technology spending increased during the pandemic’s digitisation priorities to improve productivity of staff working from home and increase cybersecurity. However, as new priorities demand attention, technology resources and costs are now under pressure. Yet leaders must be careful: if they wield a sword instead of a scalpel and ignore important strategic and risk realities, they can do far more damage to themselves than they realise.”

In particular, cybersecurity is under the spotlight. KPMG International’s latest Global CEO reveals a massive drop in how companies rank cybersecurity risks, falling from first in February 2022 to not even making the top five in August 2022. Emerging/disruptive technology, operational issues, regulatory concerns, environmental/climate change and reputational risk all precede digital security.

Why such a drop in importance? Collins proposes two reasons: “Many organisations have invested in security systems, so they might feel that box is ticked, even though it contradicts the continuous operational need to mitigate cyber risks. Some might want to focus more on other risks; perhaps appreciating that cybersecurity is a factor in all of those. For example, CEOs worrying about disruptive technologies, regulations, operations and reputational damage should realise that cybersecurity heavily influences all those risks. If they do not, and start cutting back on security costs while only looking at the bottom line, they are making a big mistake.”

Cybersecurity in a recession

Cybersecurity is even more important during a recession than in good times. Although there is no definitive correlation between recessions and overall crime rates, World Economic Forum research suggests that, more challenging financial times lead to increases in career criminals and malicious insider activities.

Cybercrime is a tempting opportunity for skilled IT professionals with ambiguous morals – especially in the face of a bear market downscaling employment. Recessions grow cybercrime talent pools. The higher job pressures, resulting from fewer resources, create more disgruntled employees, who might avenge their sentiments by using their access privileges. Cutting back too much on cybersecurity budgets and personnel is more likely to increase attack risks and undermine attempts to address other major risks, such as disruption and financial losses.

Does this mean companies should spend more on cybercrime, biting the budget bullet, just because there is no alternative? They do have alternatives when they cease looking at cybersecurity only as a cost centre.

“A recession is an opportunity,” says Guy Golan, CEO of Performanta. “There has been incredible investment and growth in cybersecurity, and companies are right to expect some dividends from that. We cannot just keep saying they must spend, spend, spend, but they should then mature.

The big issue is that they still put cybersecurity on a pedestal, as an operational must-have that they do not really understand in context of their business. It is not strategic and it is not treated as an integrated business department, leading to wasted spending, poorly managed resources and under-performing security. If they look at security efficiency before making security cuts, they’ll realise significant and long-term gains.”

Bank on cyber safety

Golan calls this concept cyber-safety: the notion that cybersecurity is framed within the business context and treated like any other department. When organisations treat cybersecurity as a black box – meaning they only see input and output but not how it creates that value – they risk misinterpreting its purpose and requirements.

This can lead to unthinking budget and staff cuts that have lasting negative implications. Fixing a cyber breach often costs considerably more than preventing or limiting an attack. Notably, IBM’s 2022 report found that a breach, on average, costs $4.35 million, a substantial amount at any time, but especially in a recession.

Companies that treat cybersecurity as a business function have more opportunities to manage costs. They can focus their energy to discover and optimise under-performing systems, assess security staff for allocation of duties and career development, develop and introduce business-savvy security leaders to the top of the company, formalise processes, and strategically integrate cybersecurity around their other pressing concerns.

“The right cybersecurity partners are catalysts for this exercise,” says Golan. “It is fair to say that the security market often cares more about selling than about customer context and strategy, but the best security providers are not just about skills and technology. They have to take a real interest in your business and its security needs. A recession can put pressure on partners, on how well they perform as advisors and strategists.”

Recessions require sacrifice and compromise. Cybersecurity will not be spared from tightening belts, but beware of bluntly reducing its capacity. Use the opportunity to collaborate with your security partners, tighten controls, discover unrealised value, and integrate cybersecurity as a part of business strategy and operations. The times ahead might be tough, but improving security need not be




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...
What does Agentic AI mean for cybersecurity?
Information Security AI & Data Analytics
AI agents will change how we work by scheduling meetings on our behalf and even managing supply chain items. However, without adequate protection, they become soft targets for criminals.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Crypto in SA: between progress and precaution
Information Security
“As cryptocurrency gains momentum and legitimacy, it’s becoming increasingly important for people to pay attention to financial security”, says Richard Frost, head of technology and innovation at Armata Cyber Security.

Read more...
Cyber recovery requires a different approach to disaster recovery
Information Security
Disaster recovery is about getting operations back on track after unexpected disruptions; cyber recovery, however, is about calculated actions by bad actors aiming to disrupt your business, steal sensitive data, or hold your system hostage.

Read more...
MDR users claim 97,5% less
Sophos Information Security
The average cyber insurance claim following a significant cyberattack is just $75 000 for MDR users, compared with $3 million for endpoint-only users, according to a new independent study.

Read more...
The impact of GenAI on cybersecurity
Sophos News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.

Read more...
Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...
How can South African organisations fast-track their AI initiatives?
AI & Data Analytics Security Services & Risk Management
While the AI market in South Africa is anticipated to grow by nearly 30% annually over the next five years, tapping into the promise and potential of AI is not easy.

Read more...