PHD Discussions Logo

Ask, Learn and Accelerate in your PhD Research

Question Icon Post Your Answer

Question Icon

6 months ago in Cybersecurity By Shreya K

How False Beliefs About Cyber Risks Waste Security Budgets

 I've seen companies pour money into fancy "advanced threat" systems while basic phishing training is underfunded. Do common misconceptions about threats actually lead to poor security spending?

All Answers (1 Answers In All)

By Kumar Answered 3 months ago

This is a huge problem. If leadership believes the biggest threat is only from sophisticated foreign hackers, they'll overspend on complex perimeter defenses. Meanwhile, they underinvest in the "boring" basics like employee training, patch management, and incident response—which are what stop the vast majority of actual attacks. This misallocation creates critical gaps, reduces the overall return on security investment, and ironically makes the company more vulnerable. Fixing this starts with accurate, data-driven risk assessments to combat those biases.

Your Answer