Balancing Cybersecurity Training and Technology

If I were a Chief Information Security Officer and had to stretch a limited cybersecurity budget, I would lean slightly more toward training, but not by much. I would likely spend 60% on training and 40% on technology. My reasoning is that many cybersecurity problems begin because people make poor choices, such as using weak passwords, reusing passwords, clicking suspicious links, ignoring policy, or taking shortcuts. If employees do not understand the risks they should be watching for, having more tools will not solve the main problem.

At the same time, I would not rely on training alone because people will still make mistakes. Because of that, I would use the rest of the budget on a few strong controls such as multi-factor authentication, email filtering, and limiting access to only what employees need. Training helps prevent mistakes before they happen, while technology helps contain the damage when prevention fails. With a limited budget, that percentage split makes the most sense because it addresses both human error and technical risk instead of focusing only on one.

Leave a Reply

Your email address will not be published. Required fields are marked *