Mo' money, mo' problems doesn't apply when it comes to your cybersecurity budget.
Cybersecurity spending is one of the more misunderstood line items in a company's budget. It's easy to default to matching whatever a competitor spends or padding last year's numbers without much thought, but that approach rarely holds up under scrutiny from leadership or against the risks a business actually faces.
Huntress research found that more than a quarter of IT and security professionals allocate 16 to 20% of their IT budget to cybersecurity, and nearly three-quarters rate that budget as at least adequate, a sign that thoughtful planning, not guesswork, is what separates a budget that works from one that just exists on paper.
That's exactly what this article walks through, from benchmarking your spend to building the case for the budget you need.
How much do companies spend on cybersecurity?
Data shows that cybersecurity budgets currently average 10.9% of IT spend, down slightly from 11.9% in 2024, according to the 2025 Security Budget Benchmark Report from IANS Research and Artico Search. When expressing it as a share of revenue, that same report puts the average at 0.69%, flat year over year. Either way you look at it, the number varies a lot by industry and organization size.
Average cybersecurity spend by industry
Industry averages tell a clearer story when they're shared consistently, so this table sticks to a single metric: cybersecurity spend as a percentage of the overall IT budget.
Industry | Cybersecurity spend as % of IT budget |
|---|---|
All industries (overall average) | 10.9% |
Financial services | 10–15%* |
Healthcare | 10–15%* |
Manufacturing | 15.74% |
State & local government | 0–2%** |
Sources: IANS Research and Artico Search, 2025 Security Budget Benchmark Report, Deloitte, 2025 Smart Manufacturing and Operations Survey, and Forrester 2026 Budget Planning Guide *Financial services and healthcare figures reflect a range compiled across industry analyses rather than a single named primary study. **The state and local government figure is a well-documented, recurring finding from the NASCIO-Deloitte Cybersecurity Study series; the specific percentage was last confirmed in an earlier edition of the biennial study, though the 2026 edition confirms the same underlying trend of flat-to-declining budgets. | |
Manufacturing sits well above the overall average, largely a byproduct of smart manufacturing trends that pull cybersecurity spending in alongside investments in sensors, cloud infrastructure, and connected equipment. Financial services and healthcare both trend toward the higher end of the typical range, too, driven by regulatory requirements and the value of the data they hold.
State and local governments stand out for the opposite reason. Some state cybersecurity budgets run as low as zero to two percent of the state's IT budget, per the NASCIO-Deloitte Cybersecurity Study series, a gap that's persisted even as threats targeting government systems have grown more sophisticated. That contrast alone makes the case for why an industry average is only ever a starting point, not a target.
Cybersecurity spend by business size
Huntress has direct data here for the small end. From our small business cybersecurity guide, businesses under 50 employees typically spend $5,000 to $50,000 per year on cybersecurity, or roughly $2,500 to $2,800 per employee for full protection.
For larger organizations, IANS Research and Artico Search's 2025 Comp and Budget Data for Small and Midmarket CISOs reports security budget as a percentage of IT spend, averaging 26.1% for companies under $50 million in revenue, declining to 11.6% for those between $600 million and $1 billion.
As a share of revenue, smaller companies spend upwards of 2%, larger firms closer to 0.6%. Smaller companies spend a higher share overall, since fixed costs like baseline monitoring and tooling don't scale down, while larger companies spend more in absolute dollars but a smaller overall share thanks to economies of scale.
A complete cybersecurity budget breakdown: How to allocate costs
A cybersecurity budget is a handful of categories working together. Endpoint protection, identity security, security awareness training, log management, compliance, and incident response all draw from the same pool of dollars, and the right mix depends entirely on your business risk profile.
Most organizations benchmark their spending in one of two ways:
As a percentage of the overall IT budget is the more common starting point, and it typically lands between 10 and 15%, though, as we covered above, the 2025 IANS Research and Artico Search benchmark puts the actual average closer to 10.9%.
As a percentage of company revenue is less common day to day but useful for board-level conversations, since it ties security spend directly to the size of the business.
Regulated industries tend to spend more under either model. Healthcare, financial services, and government all carry compliance requirements, like HIPAA, PCI DSS, or state-level mandates, that build a spending floor into the budget before a single risk assessment happens.
That said, benchmarks are a starting point, not a ceiling. Treating an industry average as the target number is exactly how gaps form. Your threat exposure, not someone else's average, should set the final figure. A company holding sensitive customer data with a small IT team may need to spend well above its industry's average just to close obvious gaps.
What underfunding actually costs: The average global data breach now costs $4.44 million, according to IBM's 2025 Cost of a Data Breach Report. This is down 9% from $4.88 million the year before, thanks largely to faster detection. Healthcare organizations have it worse, averaging $7.42 million per breach, the highest of any industry tracked. Against those numbers, a modest annual increase in the security budget is often the cheaper option.
1. Endpoint detection and response (EDR)
Every device connected to your network is a potential entry point for an attacker, which makes EDR one of the most foundational line items in a cybersecurity budget. It continuously monitors endpoint activity and flags or stops suspicious behavior before it spreads.
Basic antivirus checks files against known threats and calls it done. Managed EDR watches for unusual behavior, like a legitimate process suddenly trying to encrypt files, and pairs that monitoring with a human team ready to respond.
Threats can seem overwhelming, but with our in-depth understanding of how threat actors think, we know what to look for. Huntress gives you fully managed EDR, so you've got 24/7 support from a human-led AI-Centric security operation center (SOC) ready to respond to threats.
2. Identity threat detection and response (ITDR)
Attackers don't need to break through a firewall if they can just log in. Stolen credentials are now one of the most common ways attackers get inside a network, making identity its own attack surface, not just a subset of endpoint security.
ITDR tools watch for suspicious logins, privilege escalation, and lateral movement: the signs that an account has been compromised and is being used to move deeper into a network.
We understand what threats like credential theft and unauthorized access mean for your business, and we're here to help. Huntress has you covered with managed identity threat detection and response (ITDR), protecting identities across your organization 24/7.
3. Security awareness training (SAT)
Technology can only catch so much. A huge share of successful attacks start with a person clicking a link or entering credentials into a fake login page, meaning employees are either your biggest vulnerability…or your first line of defense.
Effective training goes beyond an annual slideshow. It includes phishing simulations, role-based content tailored to what different teams actually encounter, and ongoing reinforcement so the lessons stick.
Huntress empowers your employees to be part of the cybersecurity solution with SAT, by sharing personalized phishing defense coaching based on the real threats our security experts see.
4. SIEM and log management
A SIEM collects log data from across your systems and looks for patterns that suggest something's wrong, helping you notice unusual activity across your whole environment.
The catch with traditional SIEMs is noise. Left unfiltered, they generate so many alerts that real threats get buried, and many teams can't keep up to spot what actually matters. Managed SIEM with smart filtering solves that.
Huntress managed SIEM uses proprietary smart filtering technology that only captures the data you need and cuts through all the noise. Our 24/7 expert-led monitoring helps you find and wreck elusive hackers.
5. Compliance and audit readiness
Compliance spending belongs in the cybersecurity budget because most cybersecurity frameworks—like SOC 2, HIPAA, PCI DSS, and CMMC—enforce a baseline level of protection, and getting there takes real tooling, documentation, and staff time.
It's worth repeating: Compliance and security are not the same thing. Passing an audit confirms you met a specific standard, not that you're protected against every relevant threat.
6. Incident response (IR) planning and retainers
An IR retainer is a pre-negotiated agreement with an IR firm that guarantees fast access to experts when something goes wrong, instead of scrambling mid-breach. It's cost-effective because emergency, no-retainer rates typically run two to three times higher, with response times stretching to 24 to 72 hours.
Typical inclusions in an incident response plan include forensics, breach notification support, and legal coordination. Annual retainer fees generally run $10,000 to $100,000, with many organizations starting around $25,000 for an entry-level agreement.
How to build a cybersecurity budget: A step-by-step approach
Whether you're building a cybersecurity budget from scratch or revisiting one that needs some fine-tuning, this section walks through it step by step. Think of it as a practical checklist for the year ahead, from figuring out where your real risk sits to deciding what to fund first.
Step 1: Assess your current risk exposure
Start by identifying what you're actually protecting: your critical assets, the threats most likely to target them, and the gaps between your current defenses and the threat landscape. This is the foundation every other budgeting decision builds on.
A formal third-party risk assessment brings an outside perspective and often satisfies compliance requirements, while an internal audit is faster and cheaper but can miss blind spots your own team is used to. Frameworks like NIST CSF and CIS Controls give you a structured way to run either one.
Step 2: Inventory your existing security tools and spending
Before adding anything new, audit what you're already paying for: licenses, subscriptions, personnel time, and managed services. Many organizations discover they're paying for overlapping tools or licenses nobody's actively using.
A useful tip is to categorize existing spend by function, endpoint, identity, network, training, response, so gaps and overlaps become visible at a glance instead of being buried across a dozen invoices.
Step 3: Align spending to your biggest risks
Once you know your exposure and current spend, prioritize dollars toward the risks with the highest combination of likelihood and impact, rather than spreading the budget evenly across every category.
Organizations with a remote-heavy workforce, for example, should probably weigh spending toward identity security and endpoint protection over physical security controls, since that's where their actual exposure sits.
Step 4: Decide between in-house and managed services
Building a 24/7 in-house SOC typically requires eight to 10 analysts and runs well over $1 million annually once salaries, tooling, and training are factored in. A managed detection and response (MDR) provider delivering similar coverage generally runs $50,000 to $300,000 or more annually, depending on the environment size.
For growing businesses with a small IT team, that gap is usually decisive: Managed services provide access to expertise and 24/7 coverage that would otherwise take years and a lot of hiring to build internally.
Step 5: Build in flexibility for incident response
Set aside a portion of the budget for unplanned events like breach response and forensics rather than assuming everything will go according to your cybersecurity plan. A common approach is to reserve 5-10% of the total security budget for this purpose, though it should scale with your actual risk profile.
Without that reserve, an incident forces you to pull funds from other budget lines mid-year, which usually means delaying planned improvements right when you can least afford to.
Cybersecurity budget best practices, or how to ensure buy-in from leadership
Getting leadership buy-in for a cybersecurity budget comes down to speaking the same language by translating technical risk into business terms.
Executives don't need to understand the mechanics of a phishing attack; they need to understand what it costs the business if one succeeds, and what it takes to prevent it. This is just one reason managing cybersecurity budgets is a critical responsibility that goes well beyond the technical implications.
"Some executives are security-savvy, but many also are not," says Gavin Hill, Vice President, Product Marketing, at Huntress. "You have to speak in terms they'll understand for buy-in, but it's about balancing the conversation with the risks versus reward based on the cybersecurity maturity of the organization. We know that investing in cybersecurity isn't just about risk reduction. It's also about the potential ROI."
Here are some ways you can secure buy-in:
Speak in risk and dollars, not technical terms: Frame requests around potential financial impact and business disruption, not acronyms and tool names. A board understands "this could cost us $4 million" far better than "we need better EDR coverage."
Use benchmarks to anchor the conversation: Industry data gives leadership a reference point for whether current spending is reasonable, underfunded, or excessive. It's a starting point for discussion, not a target to hit exactly.
Show what the current budget is and isn't covering: A clear map of existing coverage versus known gaps makes the case for new spending concrete instead of hypothetical.
Treat cybersecurity as an ongoing investment: Positioning security as a one-time project rather than a continuous need sets budgets up to shrink the moment other priorities compete for funding.
Invest in people and training: Tools alone don't stop attacks. Skilled staff and a well-trained workforce catch what automated systems miss.
Don't borrow budget: Pulling security funds to cover shortfalls elsewhere leaves real gaps that tend to surface at the worst possible time.
Be mindful of third-party and supply chain risk: Vendors and partners with access to your systems extend your attack surface, and budgets should account for vetting and monitoring that risk.
Your cybersecurity budget, made easier with a unified solution
Building a cybersecurity budget is about matching your spending to your actual risk, then making sure every dollar is doing real work. Whether you're just starting to formalize your cybersecurity budget or rebuilding one to optimize costs, the approach is the same: assess, prioritize, and revisit often.
One of the fastest ways to stretch a cybersecurity budget further is by consolidating tools. Huntress's suite of cybersecurity tools brings your monitoring, detection, and response under one roof, backed by a 24/7 team, so you're not paying for overlapping coverage or drowning your team in alerts.
See the managed SIEM platform for yourself.
FAQ
What's the average budget for cybersecurity?
There's no single average cybersecurity budget, since it varies widely by industry and organization size. As a rough anchor, cybersecurity budgets average around 10.9% of IT spend or 0.69% of revenue, though regulated industries and larger organizations often land outside that range in either direction.
What percentage of an IT budget should go to cybersecurity?
Around 10–15% is the standard benchmark for cybersecurity budgets, which most organizations use as a starting point. That said, the right number depends on your actual risk exposure, not the benchmark itself, so it's worth treating that range as a baseline to check against rather than a target to hit exactly.
What's the difference between a cybersecurity budget and an IT budget?
An IT budget covers all technology spending, hardware, software, infrastructure, and support. A cybersecurity budget is the slice of that spending focused specifically on protecting the organization from threats.
How often should a cybersecurity budget be reviewed?
At a minimum, review your cybersecurity budget annually. Ideally, review it quarterly or whenever there's a significant business change, like a new office, a big shift to remote work, or an acquisition, since those changes can shift your risk exposure fast.
What should be the top cybersecurity budget priority for most businesses?
Priorities should follow your specific risk profile, but for most businesses, endpoint protection, identity security, and employee training cover the most common attack paths and tend to deliver the most value per dollar spent.
How does cyber insurance affect cybersecurity budgeting?
Cyber insurance and cybersecurity spending feed into each other. Insurers increasingly require specific controls, like MFA or endpoint monitoring, before they'll issue or renew a policy. This effectively sets a spending floor. In turn, stronger security controls typically qualify a business for better rates, so the investment can pay for itself over time.