IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more
In-depth

The cost of IT security incidents in 5 charts

Where do enterprises and SMBs stand on security investment?

With the overall reduction of IT budgets and increasing number of incidents, protection will soon become a high priority issue for businesses trying to do more with less.

Crucial to their success will be their attitude towards IT security spending. The Kaspersky Lab Global Corporate IT Security Risks Survey explores the threats faced by businesses large and small, and IT security spending habits of over 5,000 interviewees across 30 countries.

Here, we draw out the key trends in IT security investment this year over a series of charts.

Serious data breaches are getting more expensive

Among SMBs, the average total impact of a data breach amounted to $84k, but this is more than ten times higher among enterprises, with the various aspects of a data breach costing as much as $938k.

Whereas last year, the reallocation of staff time represented the single largest additional cost for both enterprises and SMBs, this year the picture has changed, with SMBs and enterprises having different experiences.

The top pain points for SMBs include lost business and costs related to employing external professionals, but by contrast, enterprises incur the largest costs due to improving software and infrastructure.

Third-party infrastructure is a key security weakness

For both SMBs and enterprises, incidents affecting infrastructure hosted by a third party are expected to have the most severe financial impact. This is clear in the experiences of businesses working with third parties for their cloud or other infrastructure, and also among enterprises that share data with suppliers.

As soon as one business gives another access to data or infrastructure, their weaknesses are shared. However, this is not something that most organisations give proper consideration to.

The proportion of IT budgets spent on security is rising

This year, cost saving and outsourcing efforts across many organisations appear to have resulted in a reduction in overall IT budgets amongst larger businesses worldwide. Despite this, the proportion of IT budgets spent on IT security is rising. This pattern is consistent across businesses of all sizes globally, but particularly among enterprises with over 1,000 employees, where the IT security budgets have risen from a fifth to almost a quarter of the overall IT budget in the last 12 months.

This represents a healthy growth in the importance being placed on IT security - something promising if businesses are to start viewing IT security as an investment rather than a cost-centre, particularly when the prospect of an attack is an expensive one.

Government and financial institutions are IT security top spenders

Perhaps unsurprisingly, organisations involved in government (including defence) and financial institutions reported the highest expenditure on IT security this year, with both sectors reporting budgets over $5m on average.

IT and telecoms companies and utilities and power companies also spent more than average on IT security, although it is closer to $3m than the $5m+ spent by their government and finance counterparts.

For these firms, investment in IT security isn't just a cost that must be budgeted for. It's an increasingly crucial part of business continuity plans that will help organisations continue to function. When considering the cost of a cyber attack, IT security is, arguably, an investment with measurable benefits.

Featured Resources

Four strategies for building a hybrid workplace that works

All indications are that the future of work is hybrid, if it's not here already

Free webinar

The digital marketer’s guide to contextual insights and trends

How to use contextual intelligence to uncover new insights and inform strategies

Free Download

Ransomware and Microsoft 365 for business

What you need to know about reducing ransomware risk

Free Download

Building a modern strategy for analytics and machine learning success

Turning into business value

Free Download

Most Popular

Russian hackers declare war on 10 countries after failed Eurovision DDoS attack
hacking

Russian hackers declare war on 10 countries after failed Eurovision DDoS attack

16 May 2022
Researchers demonstrate how to install malware on iPhone after it's switched off
Security

Researchers demonstrate how to install malware on iPhone after it's switched off

18 May 2022
Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022