Monthly Archives: January 2010

Network Security Data Considerations

Posted on by John Reno in Main | 1 Comment

Earlier this month Google discussed the nature of the cyber attacks they have been facing from China. The targets included not only politically motivated email accounts, but also attacks on the corporate infrastructure that resulted in theft of intellectual property. During their investigations, Google also found evidence of ongoing attacks on major U.S. corporations including Dow Chemical, Goldman Sachs, and Juniper Networks with intellectual property as the target. One outcome of this chain of events for any enterprise organization should …

ROI, NPV and a few other words about predicting the financial performance of information security projects

Posted on by John Reno in Main | Leave a comment

Over the course of many years in the information security profession, I have heard claims that the return on investment associated with security projects cannot be calculated. Most often the perspective is that security is a cost center and should be treated as such. I do not have that opinion. The following discussion summarizes Redspin’s work with one of its healthcare customers to calculate return on investment (ROI) and Net Present Value (NPV) in order to justify and manage an …