Whenever we protect an IT asset, we factor in the cost of the hardware. As an example when we are protecting a computer, we are inclined to think why spend $50,000 in protecting a $1000 computer. We need to drill down and think:
1. What kind of information the computer has?
2. How relevant and valuable that information is for the business?
Based on 1 & 2 - $50,000 spent in protecting the business may be well worth it!
My security blog peer Rob pointed to an excellent link about Katrina: tough lesson in security.




