Skip to content

How-to

How to build a defensible cybersecurity budget in 5 steps

A practical, vendor-neutral process for turning headcount, tooling, and risk into a security budget you can defend to your CFO.

A defensible budget is one you can explain line by line and tie back to either a benchmark or a risk decision. It does not need to be large or precise to the dollar — it needs to be reasoned, comparable, and honest about uncertainty.

Step 1: Anchor to a benchmark before you build line items

Start top-down so you know roughly where you should land, then build bottom-up to fill it in. The two most useful anchors come from the IANS / Artico 2025 benchmark of roughly 587 CISOs:

  • Security as a share of IT budget: the median sits near 11%, with a wide spread (about 7% at the 10th percentile and 20% at the 90th).
  • Security as a share of revenue: the median is about 0.69%.
  • Per-employee spend: roughly $2,300 per employee across industries.

These three framings will not always agree, and that is expected — we cover why in our framing analysis. Use them as guardrails, not targets.

Step 2: Size staffing first — it is your biggest line

For most organizations, people are the single largest cost in the budget, so estimate them before tooling. A common planning ratio is roughly 1 security FTE per 300 employees, though regulated and high-target industries run richer. Using a loaded cost of about $162K per FTE (salary plus benefits and overhead, per BLS-derived figures), a 1,500-person company would model around five security FTEs, or roughly $810K in staffing alone.

Loaded cost matters. Budgeting at base salary understates the real number by 30–40% and is the fastest way to lose credibility in the second budget meeting.

If you cannot hire to the ratio, that gap is not a failure — it is a documented decision to accept more risk or to offset it with managed services. Write it down either way.

Step 3: Build the tooling stack in tiers

Group tools into must-have, should-have, and defer tiers. Per-user and per-endpoint list prices give you a quick sanity check before vendor quotes arrive:

CapabilityTypical rangePlanning midpoint
EDR (endpoint detection)$3–$20 / user / mo~$8
MDR (managed detection)$3–$45 / endpoint / mo~$6
XDR (cross-domain platform tier)$5–$25 / user / mopremium tier

The difference between these is mostly who does the work — a distinction worth understanding before you commit, which our EDR vs MDR vs XDR breakdown walks through. List prices are a starting point; negotiated rates commonly land below them at scale.

Step 4: Tie discretionary spend to risk, not fear

Everything above the must-have tier should map to a specific, named risk. The cleanest way to defend a control is to express what it reduces. For example, IBM’s 2025 figures put the global average breach at $4.44M and the US average at $10.22M — a useful upper anchor when you frame a detection or response investment as buying down the probability or cost of that event.

Avoid implying any control eliminates risk. No tool removes risk entirely, and a budget that promises certainty invites exactly the scrutiny you are trying to survive. Speak in ranges and probabilities:

  1. Name the risk (e.g., business email compromise).
  2. State the rough exposure (a fraction of that breach figure).
  3. State what the control changes (faster detection, fewer successful intrusions).
  4. State the residual risk you are still accepting.

Step 5: Document assumptions and present a range

Finish by writing down every assumption — headcount ratio, loaded cost, growth rate, and which benchmark percentile you targeted. Present the budget as a range (for example, a lean case, a recommended case, and a richer case) rather than a single number. A range signals that you understand the uncertainty, and it gives finance a structured set of trade-offs instead of an all-or-nothing ask.

When the assumptions are explicit, a budget review becomes a conversation about risk appetite rather than a line-by-line interrogation. That is what “defensible” actually means.

Ready to put numbers behind these steps? Try the cybersecurity budget calculator to model staffing and tooling against the benchmarks above.

References

Related

Put this into a number

Build a sourced, defensible budget from your own risk profile — free and ungated.

Open the calculator