WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) CISA Report – Making the Business Case for Security
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA Report – Making the Business Case for Security

TLP:CLEAR

Author: Alec Davison

Created: Thursday, March 27, 2025 - 15:14

Categories: Federal & State Resources, General Security and Resilience, Security Preparedness

Summary: Making the business case for security and rationalizing the allocation of resources for a security project can be difficult. To help security professionals with these efforts, CISA has published a product titled “The Business Case for Security,” which provides data and considerations for senior leaders as they set financial priorities. 

Analyst Note: The guide emphasizes that the cost to recover from a security incident is often more expensive than implementing preventive measures. As the guide notes, “Though the cost of remediating a physical or cyber incident is quantifiable, recovering a company’s damaged infrastructure and reputation can be difficult to assess.” Developing a business case for security, therefore, adds value and drives the importance of physical and cybersecurity investments within an organization. Included in the steps for building a case for security are:

  • Understanding the business’ security posture
  • Identifying business assets that need to be protected
  • Aligning security investments to business objectives
  • Determining the right areas for investment
  • Implementing a security plan and schedule
  • Preparation

Original Source: https://www.cisa.gov/resources-tools/resources/business-case-security

Additional Reading:

  • ISC Best Practices for Making a Business Case for Security
  • Focus on Metrics: Measuring and Communicating Effectiveness

Related WaterISAC PIRs: 5 & 12

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar