Boards are expecting CIOs and chief security officers (CSOs) to provide increased security at a time when budgets are either flat or increasing only slightly, according to IDC program manager Eric Domage, who was speaking at the analyst firm's IT Security Conference today.
The increase in security requirements is related to the fact that the IT skills of staff are no match for the increase in volume and complexity of security threats, he said.
"This means there's a gap between what you have to do, and what you're given as a resource to do it."
Domage said a survey of delegates at the event showed that 40 per cent of respondents had had their security budgets frozen, and that many were making cuts in order to fund mobile device protection.
Domage said he had seen four strategies employed by CIOs looking to achieve improved security from a smaller budget.
Domage added that 70 per cent of respondents to the survey believed that squeezing vendor pricing was the best way to get the most from tight security budgets.
Des Powley, director security and identity management, Oracle, said that part of the problem is that boards do not fully understand security.
"Does the business understand the value of security? My US paymasters think the whole world revolves around compliance."
Domage concluded that compliance was a key factor of security, but is an increasingly complex area as more regulations appear, placing further demands on budgets.
Have your say on this article
Newsletters
Latest stories from Security
You may also like
Security jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?