Cost and business impact are critical but often overlooked factors in security architecture. Effective security proposals require translating technical requirements into financial terms that executive stakeholders understand and can approve.
Cost in Security Architecture
I've had the opportunity to work with some amazing IT professionals, ones that really cared about their work and wanted to implement things correctly with high availability and resiliency and security. They just wanted to implement things the right way. But often what I find gets overlooked is the expense, the cost. This can be very detrimental to what we're trying to achieve. It's really important for our success to understand how expense and cost play into these projects and into architecting security.
As IT professionals, I really hope we're thinking a lot about security and how to implement it correctly and how to implement it at a high level. But this can be problematic in the way we think sometimes. The thing is that many times what I'm implementing is going to cost money. It's going to take up resources, and I need to get approval for those resources to invest into the project that I want to implement. So what I have to do is go to the board of directors, to the exec team, to the management team, and get approval for that.
The problem is that they speak a very different language. They don't think of security directly, although that is changing, in that people are thinking much more about security than they ever have before. But they mainly think in numbers. It's important to understand that so we can convey and get approvals in the right way.
When it comes to design requirements and developing security, often we're thinking about best practices and security models and security principles and the laws and regulations and ways we need to implement things in a correct way. But we're overlooking one of the most key factors out of all of this. I see even a lot of exams and a lot of professionals and a lot of sources out there overlook this one key factor. Really, out of all of these sources, the most prevalent is going to be the business needs. If you think about it, the customers and clients that we have, and the security models and the security principles and best practices and laws and regulations, all play into these business needs. What are the business needs, and what do we need to carry out for the business or the organization that we work for?
Almost all businesses really have just one primary focus. The business is designed to make money, to make revenue, to make profit. They need to pull in a profit.
Now, there are a lot of businesses that have other values involved, like they want to be environmentally friendly, or they have some sort of social concern that they are working towards. This is great. I really do hope that you work for a company like this, because it's great to work for companies like this. In fact, all of the companies that I've worked for really have these sets of values that they go after. But even with great companies that have great sets of values that they operate by, that they don't want to compromise, they still have this underlying that profit is the main motivator for the business.
There are organizations that are not businesses, that are not for-profit, that are public entities or whatever the case may be, that really put a primary focus on their mission and carrying out whatever their mission is. But even with these companies, they take funds to carry out that mission. So they really still can't put the money aside and say, "Well, money is not a concern at all," because they still have to have the money to carry out their mission.
So why is this important to understand? It's because when we go to the board of directors, when we go to the execs, when we go to the CEO, and we're trying to tell them what we're trying to do, and we're saying that this is going to make our company more secure or is going to make our data more secure, they're not always listening to exactly what you're saying. They're thinking of the numbers and how much this is going to cost.
A company is really designed to make profits. They want profits to increase over time. Basically, profit is just taking the revenue minus your expense, and that is going to be what your profit is. So the two things that we can really do to increase profit are increase revenue or decrease expense.
This is a problem when it comes to security, because security costs a lot of money. It costs a lot of money. Implementing these projects is not cheap. And so this is a big negative to us being able to carry out the proper security requirements that we need to put into place.
So how we need to start thinking about security is that we need to think about what architecting security means to the business. From a revenue perspective, we can start meeting or exceeding customer demands. That's going to increase our revenue. This is one of the things that we can take if we go through this process of making our stuff more secure than our competitor: we can use this as advertising of our services and how our services are better.
And then we also need to think about how this actually does reduce expenses. Even though there's a cost to it, many times it's to reduce expenses, and it comes in the form of reducing risk. It's kind of like an insurance program. By reducing risk, there's going to be fewer issues and the business is going to be more secure, because if something does happen, that can be even more costly than whatever we're implementing, whatever we're putting into place.
As we go to the CEO and try to get approval for our project, now we not only have the design requirements to make a secure network, but we've got the data to back up that this is the right decision for the company, because we're either reducing our expenses or we're increasing revenue in some way. Now we're speaking the language of management, of the execs, of the board of directors, of the CEO, and can get our projects approved.
One of the great things about cyber security, even though it can be very expensive, is that the least expensive things that we can do give us the most value. So here we have the sliding scale of cyber security. This came out quite a while ago, and essentially what it's saying is that there are some things that have a high level of value that we can implement, things that are at this architect level, that cost very little. If we want to put in passive defense, we get a huge value out of this with not that much more money. And with active defense, then we can have some level of value out of it with some level of cost. So really, the things that are going to be the easiest and most secure to implement and create the most amount of value are going to have the least cost.
Really, this is all to say that there are going to be a lot of design requirements that we're going to pull from all of these different sources. But don't overlook one of them: the expense, or the cost of this. There is a business need here, and we need to keep that in mind as we roll out our new technologies and as we're architecting security.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →