Problem with security spending is that a lot of it comes down to useless audits which really don't find any holes - they just "enforce" compliance. Yes, PCI compliance is important but how many PCI compliant companies have been breached in the past decade?