@inproceedings{db3e644a23e241e3a3f1e59a9eafde97,
title = "Secure it now or secure it later: The benefits of addressing cybersecurity from the outset",
abstract = "The majority of funding for research and development (R&D) in cyber-security is focused on the end of the software lifecycle where systems have been deployed or are nearing deployment. Recruiting of cyber-security personnel is similarly focused on end-of-life expertise. By emphasizing cyber-security at these late stages, security problems are found and corrected when it is most expensive to do so, thus increasing the cost of owning and operating complex software systems. Worse, expenditures on expensive security measures often mean less money for innovative developments. These unwanted increases in cost and potential slowing of innovation are unavoidable consequences of an approach to security that finds and remediate faults after software has been implemented. We argue that software security can be improved and the total cost of a software system can be substantially reduced by an appropriate allocation of resources to the early stages of a software project. By adopting a similar allocation of R&D funds to the early stages of the software lifecycle, we propose that the costs of cyber-security can be better controlled and, consequently, the positive effects of this R&D on industry will be much more pronounced.",
keywords = "Cyber-security, cyber-attack, software lifecycle, software total cost",
author = "Olama, {Mohammed M.} and James Nutaro",
year = "2013",
doi = "10.1117/12.2015465",
language = "English",
isbn = "9780819495488",
series = "Proceedings of SPIE - The International Society for Optical Engineering",
booktitle = "Cyber Sensing 2013",
note = "Cyber Sensing 2013 ; Conference date: 30-04-2013 Through 01-05-2013",
}