Security pros complain about small budgets, clueless employees

IDC's survey of 435 IT security professionals -- at small, medium and large enterprises -- indicates that the top 3 security challenges for the next 12 months are:

  1. Increasing sophistication of attacks
  2. Employees underestimate the importance of following security policy
  3. Budget too small to cover necessary security purchases

So what would IT security pros do if they actually got more money? The top answers are revealing:

Wish List
What security measures would you undertake if you had a larger security budget?

  1. Increase IT staff dedicated to enterprise security
  2. Train employees to avert human error
  3. Purchase new security products
  4. Hire a third party to audit security risks and vulnerabilities

----------
Base: 435 IT security professionals, at small, medium and large enterprises; multiple responses allowed
Source: IDC, December 2005

----------
Related: How to boost security spending into the 'Prudent Zone'
Get the CFO to buy into your plans for beefing up IT security, by Doug Lewis