I think that's part of Schneier's point though. This spending seems to be primarily on cyber "weapons", not cyber "shields". We DO need to spend money on making our networks more secure and redundant. But instead of that, we seem to just be taking more of a MAD-style first strike approach to things. Glass cannons, essentially.