Start using metrics to make security decisions, and don't get too hung up on the quality of the data, and don't get too hung up on complicated methodologies. Just start doing it.

I would say one of the worst things I could do is to spend too much money on security.