Why security is an economic investment, not an expense
Dear Editor,
When organisations face financial pressure, security is often among the first areas targeted for reduction. Training is postponed, vacancies remain unfilled, maintenance is deferred, and equipment upgrades are delayed.
On paper, these decisions may appear to save money. In practice, they can expose an organisation to losses far greater than the amount removed from the security budget.
The true cost of poor security is not limited to stolen property, it can include business interruption, fraud, cyber breaches, legal liability, damaged equipment, regulatory penalties, increased insurance costs, lost productivity, and reputational harm.
A serious incident may suspend operations, divert management attention, and weaken the confidence of employees, customers, investors and business partners. The question is not simply how much an organisation spends on security. It is how much insecurity may already be costing it.
The Inter-American Development Bank estimated that the direct cost of crime and violence in Latin America and the Caribbean amounted to approximately 3.44 per cent of the region’s gross domestic product in 2022. These costs included losses in human capital, private-sector security expenditure, and public spending on crime prevention and criminal justice.
This demonstrates that insecurity is not only a law-enforcement or social problem, it is also an economic burden that absorbs resources which could otherwise support education, health care, infrastructure, and business development.
The financial impact is also visible in the digital environment. IBM’s 2025 Cost of a Data Breach Report estimated the global average cost of a data breach at approximately US$4.44 million. The financial consequences can include lost business, operational disruption, detection, investigation, legal expenses, regulatory obligations, and recovery.
Jamaica’s economy increasingly depends on interconnected financial systems, ports, airports, telecommunications networks, logistics operations, government services, and digital platforms. A security failure in any of these areas can extend beyond the organisation directly affected. It can disrupt supply chains, delay trade, expose confidential information, interrupt customer services, and weaken confidence in the wider economy.
The Bank of Jamaica’s 2024 Financial Stability Report, released in 2025, highlighted banking fraud among the evolving risks affecting the financial sector. Its assessment found that Internet-banking fraud incidents increased sharply between 2019 and 2023, rising to approximately nine times the pre-pandemic rate.
This does not mean Jamaica’s financial system is unstable. It does, however, illustrate how quickly security risks can evolve as technology, customer behaviour, and criminal methods change. Security must, therefore, develop at the same pace as the systems and services it protects.
Many security losses never appear under a budget line labelled “insecurity”. They may, instead, appear as overtime following an incident, damaged inventory, legal fees, compensation claims, emergency repairs, increased insurance premiums, missed deadlines, customer refunds, or declining revenue.
Poorly protected workplaces can contribute to stress, reduced morale, absenteeism, and lower productivity. Employees are less likely to perform at their best when they believe management is unwilling or unable to protect them, their information, or their working environment.
There is also a reputational cost. Customers may forgive an unavoidable incident, but they are less likely to forgive evidence that known vulnerabilities were ignored. How much does it cost to rebuild confidence after confidential information is exposed or essential operations are interrupted? The answer may be difficult to calculate, but the cost is real.
Effective security does not mean purchasing technology without understanding the risk it is intended to address, nor does it mean increasing the number of security officers without proper deployment, supervision, training, and accountability.
Consider a realistic scenario in a Jamaican organisation: An employee resigns, but the person’s access card remains active because human resources, information technology, and security do not complete the separation process together. Nothing may happen immediately. Yet that single administrative oversight can leave offices, records, equipment, or computer systems accessible to someone who no longer has a legitimate reason to enter.
The problem is not the absence of security equipment, it is the failure of people, procedures, and technology to work together. Security investment must, therefore, be guided by risk. It may include physical protection, cybersecurity, access control, staff awareness, emergency preparedness, maintenance, incident reporting, business continuity planning, and coordination among security, human resources, information technology, and senior management.
A camera that is not monitored, an alarm that is not tested, or an access card that remains active after an employee leaves may create the appearance of security without delivering meaningful protection.
Good security is not measured only by what an organisation owns, it is measured by whether its systems work when they are needed. Security should not be treated solely as an operational function discussed after an incident occurs, it belongs in corporate governance, strategic planning, and financial decision-making.
Boards and senior executives should understand their organisation’s most critical assets, likely threats, major vulnerabilities, and ability to continue operating after disruption. They should also assess the return on security investment. That return may appear in prevented losses, reduced downtime, stronger regulatory compliance, lower exposure to liability, safer employees, and greater customer confidence.
Effective security may sometimes appear invisible because the incident never occurs. Yet prevented loss, reduced disruption, and preserved trust are part of its value. Jamaica’s economic future will depend not only on attracting investment, modernising infrastructure, and expanding digital services, but also on protecting them.
The organisations that treat security as a strategic investment are more likely to withstand disruption, recover quickly, and retain public confidence.
Therefore, the most important question for every boardroom is not: How much does security cost? It is: How much could poor security cost if we get it wrong?
Renee Watkis
reneedicken@hotmail.com