ابدأ من المخاطر لا من الأدواتStart from risks, not tools
قائمة مخاطر الأعمال تحدد ما يستحق الإنفاق. الأدوات تختلف في السعر كثيراً وتتشابه في القيمة إن لم تكن مرتبطة بمخاطرة واضحة.The business risk list determines what deserves spending. Tools vary widely in price and converge in value when not tied to a clear risk.
الأولويات المعتادةTypical priorities
تقليل الصلاحيات، المصادقة متعددة العوامل للحسابات الحساسة، النسخ الاحتياطي المُختبر، التوعية، ثم المراقبة والكشف. الترتيب مبني على الأثر مقابل التكلفة.Access reduction, multi-factor authentication for privileged accounts, tested backup, awareness, then monitoring and detection. The order reflects impact against cost.
التكلفة الكاملةTotal cost
الترخيص ليس التكلفة: التنفيذ، التدريب، الوقت الداخلي، الصيانة، والتجديد السنوي. الميزانية التي تُظهر الترخيص فقط تُنتج مفاجأة في السنة الثانية.Licence is not the cost: implementation, training, internal time, maintenance and annual renewal. A budget showing only licence produces a second-year surprise.
ما لا يحتاج ميزانيةWhat needs no budget
كثير من التحسينات لا تكلف شيئاً: إلغاء حسابات غير مستخدمة، فصل المهام، مراجعة الصلاحيات، وإغلاق منافذ غير مستخدمة. البدء بها يبني مصداقية للطلب.Many improvements cost nothing: removing unused accounts, separating duties, reviewing access and closing unused ports. Starting there builds credibility for the request.
قياس الأثرMeasuring effect
المؤشرات المفيدة: زمن اكتشاف الحادثة، نسبة الأصول المعروفة، نسبة الحسابات المميزة المحمية، ونتائج اختبارات الاستعادة. هذه أرقام يمكن الدفاع عنها.Useful indicators: incident detection time, share of known assets, share of privileged accounts protected, and restore-test results. These are defensible numbers.
التجديد والتطورRenewal and evolution
الميزانية ليست قراراً سنوياً بل دورة: قيّم، نفّذ، اختبر، حدّث. مراجعة نصف سنوية للتهديدات والأصول تُبقي الميزانية مرتبطة بالواقع.The budget is not an annual decision but a cycle: assess, implement, test, update. A semi-annual review of threats and assets keeps the budget tied to reality.

