Many Information Security study books will tell you about the holy Security Trinity of Confidentially, Integrity and Availability, the so called CIA Triad, which is all fair and well. But I live by another holy Security Trinity, Policies, Users and Technology. The most important area is, and will always be, with User Security Awareness. However, you cannot sort the Users out until you have your Information Security Policies in order, so your first stop has to be tackling the policy paper work first, and then to ensure you get that all important senior management backing. Clearly Technology plays a very important role within the trinity, but unlike Policies and User awareness, technology has by far the highest the budget costs. You will always have to fork out for the basic security systems like firewalls, swipe card systems, Anti Virus systems and the rest of it. However depending on your business and some of the risk mitigation, a lot of the expensive “additional” security tech...