Are cloud security tools worth the investment? Determining if any security tool is worth the cost can be tough because proving return on security investments isn’t easy. While time-saving efficiencies, such as single sign-on tools, are relatively simple to quantify, it is far more challenging to calculate the amount of money saved by a preventative measure.

There’s also the perception factor. Specifically, we notice what impacts us directly, and the avoidance of a breach doesn’t feel like a tangible impact even though it is a very positive one.

So are those cloud security tools worth it? Of course, it depends on a number of factors, including the type of tools, how they’re configured and how they’re implemented. But looking at data from the Ponemon Institute’s “2016 Cost of Data Breach Study” might give us some general insights.

Some Tools Pay for Themselves

The annual report quantifies the economic impacts of data breaches and observes cost trends over time. Understanding the real costs of these breaches and learning which tools and processes helped companies keep recovery costs down can provide hard-dollar inputs to professionals planning and optimizing their security programs.

This year’s report showed that certain tools, such as encryption and data loss prevention (DLP), could bring significant cost savings: $13 and $8 per record, respectively. Consider an example company that has deployed encryption extensively, then suffered a midsize breach of 50,000 lost records. Using study data, the use of encryption saves an average of $650,000. If the total cost of the encryption tools was under $650,000, they paid for themselves; if it was significantly under $650,000, they may have saved the company a large chunk of change.

Identifying the Right Cloud Security Tools

The report also identified areas that negatively impacted the recovery costs post-breach. The two most expensive factors were third-party involvement, which increased the cost by $14 per record, and extensive cloud migration, which increased the cost by $12 per record.

Let’s go back to the company that lost 50,000 records but decreased its recovery cost by $650,000 because it had deployed encryption. If that same company had extensively migrated to cloud, using the numbers from the study data, we can calculate that they’d have increased the recovery cost by $600,000 for that breach.

Is $12 the Whole Story?

Twelve dollars is not the whole story. Although it’d be neat and pretty to draw a straight line between survey data and real-world savings, the reality isn’t quite as simple. The Ponemon number is an excellent data point to consider, but it’s an aggregate based on all the survey respondents. Each company would need to answer another set of survey questions to hone in on the specifics of the breach as it relates to recovery cost and cloud adoption, such as:

  • Was the cloud itself the cause for the increased cost?
  • Was data breached from the cloud or from an on-premises source?
  • Was it a public, private or hybrid cloud?
  • Was the company using SaaS, IaaS or PaaS?

The inability to make a perfect, laser-focused prediction, however, doesn’t mean the $12 number isn’t valuable to consider; it absolutely is. It highlights that cloud adoption impacted data breach costs — there was a cost, and it was a fairly significant one on a per-record basis.

Apply Best Practices to the Cloud

So how can we extend data protection to our cloud deployments and, hopefully, drive down the cost of a data breach? Going back to the report, a few notable tools and practices brought down the cost of breach recovery, such as use of encryption, DLP and data classification.

These aren’t surprises: All of those are common elements of a strong data protection program. But failure to extend data best practices to the cloud may be leading to the cloud tax on data breach costs. If you’re not meeting or exceeding all of your data protection levels in your cloud environment, you’re putting the data at unnecessary risk.

Is Cloud Security Worth It?

Do data protection and controls for on-premises data extend explicitly to the cloud? Have you undertaken self-examination and analysis to determine if that is the case? Are you encrypting the cloud data at rest? Are you managing access to cloud data?

If your answers aren’t coming up yes, price out the cost of a solution such as encryption or a cloud access enforcement tool. If you can implement those solutions for less than $12 a record, there’s a good chance they’ll be paying your organization back not just in a better data protection posture and compliance readiness, but also in the unfortunate event of a breach. That, for most organizations, makes cloud security tools that protect data worthwhile indeed.

Read the complete 2016 Ponemon Institute Global Cost of a Data Breach Study

More from Cloud Security

Why security orchestration, automation and response (SOAR) is fundamental to a security platform

3 min read - Security teams today are facing increased challenges due to the remote and hybrid workforce expansion in the wake of COVID-19. Teams that were already struggling with too many tools and too much data are finding it even more difficult to collaborate and communicate as employees have moved to a virtual security operations center (SOC) model while addressing an increasing number of threats.  Disconnected teams accelerate the need for an open and connected platform approach to security . Adopting this type of…

Cloud security uncertainty: Do you know where your data is?

3 min read - How well are security leaders sleeping at night? According to a recent Gigamon report, it appears that many cyber professionals are restless and worried.In the report, 50% of IT and security leaders surveyed lack confidence in knowing where their most sensitive data is stored and how it’s secured. Meanwhile, another 56% of respondents say undiscovered blind spots being exploited is the leading concern making them restless.The report reveals the ongoing need for improved cloud and hybrid cloud security. Solutions to…

Cloud security evolution: Years of progress and challenges

7 min read - Over a decade since its advent, cloud computing continues to enable organizational agility through scalability, efficiency and resilience. As clients shift from early experiments to strategic workloads, persistent security gaps demand urgent attention even as providers expand infrastructure safeguards.The prevalence of cloud-native services has grown exponentially over the past decade, with cloud providers consistently introducing a multitude of new services at an impressive pace. Now, the contemporary cloud environment is not only larger but also more diverse. Unfortunately, that size…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today