Back to Blog
Risk Management
4 min read

How Much Should You Spend on Security? Benchmarks That Mean Something

The percentage-of-IT-spend benchmark is the most quoted and least useful number in the field. What to use instead when defending a budget.

GuardsArm Team

Security Experts

September 25, 2026

Cybersecurity budget benchmarks

Somebody on your board has read that organisations spend a certain percentage of their IT budget on security, and wants to know why yours is different. It is the most quoted benchmark in the field and among the least useful.

A ratio you can game
Move to cloud and the percentage rises on its own
Ignores what you protect
Health records and fasteners are not comparable
Useful only as an alarm
Far below comparable spend is worth knowing

Why the percentage is a poor guide

It is a ratio of two numbers you control. Outsource infrastructure to the cloud and your IT budget falls; your security percentage rises without your security improving at all. Two organisations with identical security postures can report very different percentages purely from accounting.

It says nothing about what you are protecting. A company holding health records of a million people and one selling industrial fasteners should not spend alike, whatever their IT budgets.

It ignores where the spend went. A budget consumed by a tool nobody has tuned is not equivalent to the same money spent on staff who respond.

It ignores inherited risk. An organisation running unsupported clinical systems needs to spend more than one that modernised, for the same outcome.


What actually determines the right number

What should actually set the budgetData sensitivity, regulatory exposure, technical debt, downtime tolerance, current maturity and whether capability is built or bought.What you holdSensitivity and volume of data, and who wants itRegulatory exposureWhat you must demonstrate, and to whomInherited technical debtUnsupported systems cost more to defendConsequence of downtimeHours of outage before real harm occursExisting maturityStarting from nothing costs more than maintainingBuild versus buy postureIn-house capability against managed services
None of these appear in a percentage-of-IT-spend figure.

Building a number you can defend

Building a defensible security budgetStart from a ranked and costed risk register, categorise each item, price the options, present them as decisions, and track spend against movement in the register.Risk registerranked, costedCategoriseobligation vs reduction vs revenuePrice optionseach with a decisionPresent choicesnot a percentageTrackspend against register movement
Boards decline percentages. They decide between options.

Start from the risks, not the benchmark. A prioritised risk register with rough impact figures turns a budget request into a set of decisions the board can make. "We need 18 per cent more" invites negotiation; "these four risks are currently unmitigated, here is what closing each costs" invites a decision.

Separate the categories. Boards respond differently to different lines:

CategoryHow to frame it
Keeping the lights onLicences, renewals — non-discretionary
Regulatory obligationRequired to operate or to hold a contract
Risk reductionTied to a named risk on the register
Enabling revenueCertification a customer demanded
Recovery capabilityWhat an incident costs without it

The fourth category is the most persuasive and the least used. A SOC 2 report that unblocks enterprise deals is a revenue argument, not a cost.


The ratio worth tracking instead

If you want a single internal number, track spend against your own risk register over time rather than against an industry percentage. Are the highest-rated risks getting the money? Has the top of the register changed as a result of last year's spend?

That is a question a board can engage with, and it has the useful property of being about your organisation rather than an average of organisations that are nothing like you.

Useful supporting measures:

  • Coverage — proportion of assets with your baseline controls actually applied
  • Time to detect and respond, trending
  • Unmitigated high risks, and how long they have been open
  • Recovery capability — last tested restore, and how long it took

See security metrics boards understand.


When the benchmark is genuinely useful

One case: when you are far below it. If you are spending a small fraction of what comparable organisations spend, that is worth knowing and worth saying. The benchmark is a poor target and a reasonable alarm.


Where to start

Build the risk register with rough costs attached to the top five items. It converts the budget conversation from a percentage argument into a set of choices, and the choices are what a board is actually there to make.


Where the money tends to go wrong

Even a well-sized budget gets misallocated in predictable ways:

  1. Tools without operators. A platform bought and never tuned costs its licence every year and returns alerts nobody reads. See your SIEM is an expensive log dump.
  2. Overlapping coverage. Three products doing variations of the same job, bought at different times by different people. See tool consolidation.
  3. Nothing for recovery. Prevention and detection funded; backup testing and continuity work unfunded, which is the capability that determines how bad the worst day is.
  4. No remediation budget behind assessments. Paying to discover problems and not to fix them.
  5. All capital, no people. Licences are easier to approve than headcount, so budgets skew toward products that need staff nobody hired.

A rough allocation worth arguing about

There is no correct split, but a budget wildly out of balance on these proportions is usually worth questioning:

AreaRough share
People — internal staff or managed servicesThe largest single share
Detection and response capabilitySubstantial, and rising with estate size
Preventive controls and identitySteady, mostly licensing
Recovery and continuitySmall in money, decisive in outcome
Assessment and assuranceModest, and must be paired with remediation
Training and awarenessSmall, high return

The row most often at zero is recovery, and it is the one that determines whether a ransomware event is a bad week or an existential one.

GuardsArm helps organisations build risk-based security budgets and present them. See security risk assessments or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.