Analysis
How to size a security budget (without the percentage myths)
How security budgets actually get set: why percent-of-IT benchmarks mislead, risk-based sizing, and how CISOs defend the number to a CFO.
TL;DR: Percent-of-IT benchmarks are a comfort blanket: easy to cite, wrong for your company. Durable budgets are built the other way around — from the risk register to the controls to the number — and defended in the CFO's language: what each dollar reduces, transfers, or knowingly accepts. The percentage is what you report afterward, not how you decide.
Why the benchmark approach fails
Benchmarks answer "what do others spend?" — but your budget must answer "what does it cost to hold our risk at a level our leadership accepts?" A payments processor and an industrial distributor with the same revenue face different attackers, obligations, and blast radii. Benchmarks also embed survivorship of bad decisions: the peer average includes companies that are under-spending and don't know it yet. Use benchmarks for one thing only — a smell test after the real work is done.
What does risk-based sizing look like?
Four steps. Start from the register: the top 10 risks, each with a plain-language consequence and a rough exposure estimate — even coarse ranges beat adjectives. Map controls to risks: every budget line should point at one or more register entries; a line that points at nothing is a candidate for cutting, whatever the vendor says. Cost the residual: for each major risk, show three prices — reduce (the control investment), transfer (insurance premium and its exclusions), accept (a signature from a named executive). Let leadership choose: the budget that survives cuts is the one where reductions map visibly to accepted risks; "cut $800K" becomes "sign here to accept slower ransomware recovery," which is a different conversation.
What's the right shape of spend?
Patterns from programs that hold up: people and services outweigh tools (a license-heavy budget usually hides shelfware and an exhausted team); identity, backup/recovery, and detection get funded before exotic categories; and every new tool line carries its operating cost — the analyst time, the tuning, the integration — not just the subscription. The most defensible line in any security budget is boring: tested, isolated backups. The least defensible: the platform bought after a conference that overlaps two things you already own.
How do you defend it to the CFO?
Three moves that change the meeting. Speak in exposure, not threats: "this reduces the likelihood of a multi-week fulfilment outage" lands; threat-actor lore doesn't. Show the deltas: budget-to-risk trend over time — what last year's spend measurably closed — earns the right to ask again. Bring the cut list yourself: arriving with your own ranked reductions and their risk consequences signals ownership and usually shrinks the cut. And one habit that compounds: never let a risk be silently unfunded. Either it's in the budget, transferred to insurance, or accepted in writing by someone empowered to accept it. Budgets built that way survive CFO transitions; budgets built on benchmarks survive until the first hard question.
Frequently asked questions
- What percentage of IT budget should go to security?
- Benchmarks commonly cited fall in the mid-to-high single digits of IT spend, but the honest answer is that the percentage is an output, not an input. Two companies with identical IT budgets can face wildly different threat exposure; the right number comes from the risk register, not the peer average.
- How should a CISO justify a security budget increase?
- By pricing risk, not fear: pair each requested line with the specific risk it reduces, the exposure of doing nothing, and the alternative options (transfer via insurance, accept in writing). CFOs fund tradeoffs, not threats.
- What usually dominates a security budget?
- People. Salaries and services typically outweigh tooling in mature programs — a useful sanity check, since a budget that is mostly software licenses often signals shelfware and understaffed operations.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.