← All transcripts

Rethinking the ROI of cybersecurity Transcript, AI Summary & Key Points

IBM Technology · Jun 22, 2026 · Education · 00:59 · EN

📄 Transcript

Searchable transcript of Rethinking the ROI of cybersecurity — IBM Technology (00:59). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 I'm quoting Kendrick here. He says that, um, "executives have learned that more spending on security means more business costs, slower speed to market, stalled innovation, dated AI tools, more red tape, excessive fear mongering and drained productivity. Is that a fair assessment? It seems a little harsh to me. Austin, I'm going to ask you, do you think that's a it's a fair assessment of what we get for spending on security.

00:17 How you feel about that? The role of security kind of shifts from less technical to more of a strategic risk standpoint. And looking at the bigger picture there, where the ability to communicate business impact and guide those key business decision- making, um, outcomes becomes just as critical as stopping the threat in the first place. So as defenders, you know, there is explicit trade offs here.

00:48 Um, but I think, you know, where you're allocating resources, uh, business continuity and growth can outweigh those strict security controls.

💡 Answer

Cybersecurity ROI improves when security spending is aligned with business impact, continuity, and growth rather than relying solely on stricter controls.

🧠 AI Summary

Cybersecurity spending should be evaluated as a strategic risk decision rather than solely a technical control. Security leaders need to communicate business impact and guide decisions while balancing threat prevention against business continuity and growth.

🔑 Key Points

  • The security function is shifting from a primarily technical role toward strategic risk management.
  • Communicating business impact and guiding business decisions is as important as stopping threats.
  • Security resource allocation involves explicit trade-offs between strict controls, business continuity, and growth.
  • Excessive security spending can increase costs, slow time to market, stall innovation, and reduce productivity.

✅ Actionable items

  • Evaluate security resource allocation against business continuity and growth objectives.
  • Communicate the business impact of security decisions to guide executive decision-making.
  • Balance threat prevention with the operational costs of stricter security controls.

⚖️ Advantages, risks & lessons

Advantages

  • A strategic risk approach connects security decisions to business continuity and growth.
  • Business-impact communication helps security leaders influence key business decisions.

Risks

  • Higher security spending can increase business costs and red tape.
  • Strict security controls can slow time to market, stall innovation, and reduce productivity.
  • Insufficient security controls can leave threats unaddressed.

Lessons

  • Security effectiveness should be considered alongside its operational and business costs.
  • Security leaders need to balance protection with broader business outcomes.

💬 Quotes

business continuity and growth can outweigh those strict security controls.

It captures the central trade-off in allocating cybersecurity resources.00:51

👤 People & companies

Kendrick

Person whose assessment of the costs of increased security spending is quoted.

00:00
Austin

Person asked to assess the business impact of security spending.

00:15