Our customers hear us talk about the full cost of security a lot. Effective information security means spending the least amount necessary to mitigate business risk to a level acceptable to senior management. When evaluating a new security initiative, you should never spend more than (the cost of an exposure) x (the probability of that exposure).
A True Business Approach
"Secure" doesn't mean your business assets cannot be lost or stolen. It means that you are able to control, to a suitable degree, who uses which assets for which purposes and/or to detect when a person uses an asset in an unauthorized way.
From a technical implementation view, our objective is to open up the system to authorized people while at the same time ensuring it is closed to unauthorized people. In addition, the changes we make to achieve that goal should cause minimal or no change to the end user experience.
How effectively you have secured your business assets can only be measured by comparing how well your IT environment enforces required behavior and prevents or detects prohibited behavior compared to rules defined for business assets.