With a limited IT/IT Security budget, should an organization make investments in the area of Security Awareness Training or Zero Trust?

Security Awareness training74%

Zero Trust25%

516 PARTICIPANTS
2.9k viewscircle icon2 Upvotescircle icon3 Comments
Sort by:
VP of Information Security5 months ago

Zero trust topic is a part of security awareness training. 

Senior Director, Defense Programs in Software3 years ago

Zero Trust is nebulous here, but technical implementations are critical. Normally security awareness training is limited and often not well tailored to enterprise specific use cases.

Given that, invest in the basics - patching, monitoring, identity management, encryption, compliance… some of that can fit the zero trust buzzword, but don’t chase it.

Lightbulb on1
Director of IT in Software4 years ago

Technology can still not compensate for the negligence and naivety of humans. The weakest link in the chain is still employees, so it's always better to invest in training/awareness than fancy technology if you don't have the basics.
There is no single product that is Zero Trust. It's a concept and can be achieved by combining various technologies.
If someone is selling you a Zero Trust product ... run away.
With limited budgets starting from the low-hanging fruits and education, employees are the obvious choice.

Lightbulb on4

Content you might like

Strongly agree10%

Agree57%

Neutral11%

Disagree13%

Strongly disagree6%

View Results

Yes59%

Not yet, but we’re working on it36%

No4%

View Results