Benchmarks
How much do companies spend on cybersecurity? (2026 benchmarks)
Companies spend around 11% of their IT budget — roughly 0.69% of revenue, or about $2,300 per employee — on cybersecurity. Here's what the 2026 benchmarks say, by industry and size.
The most-cited answer to “how much do companies spend on cybersecurity” is a single ratio: about 11% of the IT budget. It’s a useful anchor, but on its own it hides a lot — the same organisation can look like a big spender by one measure and a small one by another. Here’s what the 2026 benchmarks actually say, and how to read them without getting misled.
The three headline numbers
Across the IANS/Artico 2025 Security Budget Benchmark (based on roughly 587 CISOs) and Deloitte spend studies, security investment clusters around three framings:
| Framing | Peer median | Typical range (p25–p75) |
|---|---|---|
| % of IT budget | ~11% | 9%–14% |
| % of revenue | ~0.69% | 0.5%–1.0% |
| $ per employee | ~$2,300 | $1,500–$3,400 |
Importantly, these figures reflect total security spend — including staff salaries, not just tools. Security headcount (loaded at roughly $162K per FTE, per BLS wage data) is usually the single largest line in the budget.
Why the ”% of IT budget” number can mislead
The catch: % of IT budget depends on how much a company spends on IT in the first place. IT budgets range from ~2.5% of revenue in manufacturing to ~7.5% in financial services and technology. So a lean-IT industry like healthcare can show a high security-as-%-of-IT ratio while spending relatively little in absolute terms — simply because its IT budget is small.
That’s why you should never rely on one framing. A healthcare firm might sit at the 90th percentile on ”% of IT budget” but below the median on ”$ per employee.” Both are true; they just use different denominators.
Spend by company size
Absolute security budgets scale with size, but the rate often falls per employee as organisations get larger and spread fixed costs:
- Small business (< 50): often outsources detection (MDR) instead of hiring; spend is dominated by a few core tools plus a fractional or single security hire.
- Mid-market (250–1,000): a small in-house team plus a fuller tool stack; this is where ”% of IT budget” benchmarks fit best.
- Enterprise (5,000+): large security teams, multiple tool categories, and dedicated compliance and GRC functions.
What a “typical” program includes
When benchmarks say a company spends 11% of IT on security, that budget is spread across roughly a dozen line items — security staffing (usually the biggest), endpoint (EDR/MDR), identity, email security, SIEM, cloud security, vulnerability management, awareness training, compliance, testing, and incident response. No single tool dominates; people do.
Find your own number
Benchmarks are a reference point, not a target — the right spend depends on your industry, size, data sensitivity and risk exposure. To turn these averages into a figure for your organisation, run the free, ungated cybersecurity budget calculator, or read the full Cybersecurity Budget Benchmark 2026 report for the percentile detail behind these numbers.
References
- IANS / Artico 2025 Security Budget Benchmark (opens in a new tab) · verified Jun 2026
- Deloitte / FS-ISAC cybersecurity spend study (opens in a new tab) · verified Jun 2026
- BLS — Information Security Analysts (OES wage data) (opens in a new tab) · verified May 2024
Put this into a number
Build a sourced, defensible budget from your own risk profile — free and ungated.