
How Much Should You Spend on Security? Benchmarks That Mean Something
The percentage-of-IT-spend benchmark is the most quoted and least useful number in the field. What to use instead when defending a budget.
GuardsArm Team
Security Experts

Somebody on your board has read that organisations spend a certain percentage of their IT budget on security, and wants to know why yours is different. It is the most quoted benchmark in the field and among the least useful.
Why the percentage is a poor guide
It is a ratio of two numbers you control. Outsource infrastructure to the cloud and your IT budget falls; your security percentage rises without your security improving at all. Two organisations with identical security postures can report very different percentages purely from accounting.
It says nothing about what you are protecting. A company holding health records of a million people and one selling industrial fasteners should not spend alike, whatever their IT budgets.
It ignores where the spend went. A budget consumed by a tool nobody has tuned is not equivalent to the same money spent on staff who respond.
It ignores inherited risk. An organisation running unsupported clinical systems needs to spend more than one that modernised, for the same outcome.
What actually determines the right number
Building a number you can defend
Start from the risks, not the benchmark. A prioritised risk register with rough impact figures turns a budget request into a set of decisions the board can make. "We need 18 per cent more" invites negotiation; "these four risks are currently unmitigated, here is what closing each costs" invites a decision.
Separate the categories. Boards respond differently to different lines:
| Category | How to frame it |
|---|---|
| Keeping the lights on | Licences, renewals — non-discretionary |
| Regulatory obligation | Required to operate or to hold a contract |
| Risk reduction | Tied to a named risk on the register |
| Enabling revenue | Certification a customer demanded |
| Recovery capability | What an incident costs without it |
The fourth category is the most persuasive and the least used. A SOC 2 report that unblocks enterprise deals is a revenue argument, not a cost.
The ratio worth tracking instead
If you want a single internal number, track spend against your own risk register over time rather than against an industry percentage. Are the highest-rated risks getting the money? Has the top of the register changed as a result of last year's spend?
That is a question a board can engage with, and it has the useful property of being about your organisation rather than an average of organisations that are nothing like you.
Useful supporting measures:
- Coverage — proportion of assets with your baseline controls actually applied
- Time to detect and respond, trending
- Unmitigated high risks, and how long they have been open
- Recovery capability — last tested restore, and how long it took
See security metrics boards understand.
When the benchmark is genuinely useful
One case: when you are far below it. If you are spending a small fraction of what comparable organisations spend, that is worth knowing and worth saying. The benchmark is a poor target and a reasonable alarm.
Where to start
Build the risk register with rough costs attached to the top five items. It converts the budget conversation from a percentage argument into a set of choices, and the choices are what a board is actually there to make.
Where the money tends to go wrong
Even a well-sized budget gets misallocated in predictable ways:
- Tools without operators. A platform bought and never tuned costs its licence every year and returns alerts nobody reads. See your SIEM is an expensive log dump.
- Overlapping coverage. Three products doing variations of the same job, bought at different times by different people. See tool consolidation.
- Nothing for recovery. Prevention and detection funded; backup testing and continuity work unfunded, which is the capability that determines how bad the worst day is.
- No remediation budget behind assessments. Paying to discover problems and not to fix them.
- All capital, no people. Licences are easier to approve than headcount, so budgets skew toward products that need staff nobody hired.
A rough allocation worth arguing about
There is no correct split, but a budget wildly out of balance on these proportions is usually worth questioning:
| Area | Rough share |
|---|---|
| People — internal staff or managed services | The largest single share |
| Detection and response capability | Substantial, and rising with estate size |
| Preventive controls and identity | Steady, mostly licensing |
| Recovery and continuity | Small in money, decisive in outcome |
| Assessment and assurance | Modest, and must be paired with remediation |
| Training and awareness | Small, high return |
The row most often at zero is recovery, and it is the one that determines whether a ransomware event is a bad week or an existential one.
GuardsArm helps organisations build risk-based security budgets and present them. See security risk assessments or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


