How-to
How to build a defensible cybersecurity budget in 5 steps
A practical, vendor-neutral process for turning headcount, tooling, and risk into a security budget you can defend to your CFO.
A defensible budget is one you can explain line by line and tie back to either a benchmark or a risk decision. It does not need to be large or precise to the dollar — it needs to be reasoned, comparable, and honest about uncertainty.
Step 1: Anchor to a benchmark before you build line items
Start top-down so you know roughly where you should land, then build bottom-up to fill it in. The two most useful anchors come from the IANS / Artico 2025 benchmark of roughly 587 CISOs:
- Security as a share of IT budget: the median sits near 11%, with a wide spread (about 7% at the 10th percentile and 20% at the 90th).
- Security as a share of revenue: the median is about 0.69%.
- Per-employee spend: roughly $2,300 per employee across industries.
These three framings will not always agree, and that is expected — we cover why in our framing analysis. Use them as guardrails, not targets.
Step 2: Size staffing first — it is your biggest line
For most organizations, people are the single largest cost in the budget, so estimate them before tooling. A common planning ratio is roughly 1 security FTE per 300 employees, though regulated and high-target industries run richer. Using a loaded cost of about $162K per FTE (salary plus benefits and overhead, per BLS-derived figures), a 1,500-person company would model around five security FTEs, or roughly $810K in staffing alone.
Loaded cost matters. Budgeting at base salary understates the real number by 30–40% and is the fastest way to lose credibility in the second budget meeting.
If you cannot hire to the ratio, that gap is not a failure — it is a documented decision to accept more risk or to offset it with managed services. Write it down either way.
Step 3: Build the tooling stack in tiers
Group tools into must-have, should-have, and defer tiers. Per-user and per-endpoint list prices give you a quick sanity check before vendor quotes arrive:
| Capability | Typical range | Planning midpoint |
|---|---|---|
| EDR (endpoint detection) | $3–$20 / user / mo | ~$8 |
| MDR (managed detection) | $3–$45 / endpoint / mo | ~$6 |
| XDR (cross-domain platform tier) | $5–$25 / user / mo | premium tier |
The difference between these is mostly who does the work — a distinction worth understanding before you commit, which our EDR vs MDR vs XDR breakdown walks through. List prices are a starting point; negotiated rates commonly land below them at scale.
Step 4: Tie discretionary spend to risk, not fear
Everything above the must-have tier should map to a specific, named risk. The cleanest way to defend a control is to express what it reduces. For example, IBM’s 2025 figures put the global average breach at $4.44M and the US average at $10.22M — a useful upper anchor when you frame a detection or response investment as buying down the probability or cost of that event.
Avoid implying any control eliminates risk. No tool removes risk entirely, and a budget that promises certainty invites exactly the scrutiny you are trying to survive. Speak in ranges and probabilities:
- Name the risk (e.g., business email compromise).
- State the rough exposure (a fraction of that breach figure).
- State what the control changes (faster detection, fewer successful intrusions).
- State the residual risk you are still accepting.
Step 5: Document assumptions and present a range
Finish by writing down every assumption — headcount ratio, loaded cost, growth rate, and which benchmark percentile you targeted. Present the budget as a range (for example, a lean case, a recommended case, and a richer case) rather than a single number. A range signals that you understand the uncertainty, and it gives finance a structured set of trade-offs instead of an all-or-nothing ask.
When the assumptions are explicit, a budget review becomes a conversation about risk appetite rather than a line-by-line interrogation. That is what “defensible” actually means.
Ready to put numbers behind these steps? Try the cybersecurity budget calculator to model staffing and tooling against the benchmarks above.
References
- IANS / Artico 2025 Security Budget Benchmark (opens in a new tab) · verified Jun 2026
- BLS — Information Security Analysts (OES wage data) (opens in a new tab) · verified May 2024
- IBM Cost of a Data Breach 2025 (opens in a new tab) · verified Jun 2026
Put this into a number
Build a sourced, defensible budget from your own risk profile — free and ungated.