Benchmarks
What the 2026 IANS benchmark says about security spend
The latest IANS / Artico data shows budgets flat to slightly down, with growth concentrated in cloud and identity.
The IANS / Artico security budget benchmark remains the most-cited reference point for sizing a program, and the latest read shows a market that has stopped accelerating. The headline numbers are stable, but where the money goes is shifting.
The headline numbers
Across the surveyed CISOs, the central figures are:
- Security as % of IT budget: median about 10.9% — down slightly year over year.
- Security as % of revenue: median about 0.69%.
- Per employee: roughly $2,300 per employee across industries.
The small dip in the IT-budget share is the most interesting signal. After several years of steady growth, the median share has flattened and edged down — a sign that the era of automatic security budget increases is pausing, even as expectations on programs keep rising.
Flat-to-down share does not necessarily mean smaller budgets in absolute terms. If IT budgets grow, 10.9% of a larger base can still be more dollars — but the priority premium security enjoyed is no longer expanding.
Staffing is still the largest cost
The benchmark is consistent on one structural point: staffing is the single largest cost in most security budgets, ahead of any tool or service line. With loaded costs around $162K per FTE and common planning ratios near one security FTE per few hundred employees, people dominate the budget before software is even considered.
That has a direct planning consequence. When the overall budget share flattens, the pressure lands first on discretionary tooling, because headcount is hard to cut without losing capability. Teams under flat budgets tend to rationalize their tool stack rather than reduce staff.
Where the growth is going
Even with flat overall share, spend is not static — it is rotating. The two clear growth areas are:
- Cloud security. As workloads and data continue moving to cloud platforms, posture management and workload protection are absorbing a growing slice of the budget.
- Identity. Identity has become the primary control plane and a primary attack path, so identity protection, privileged access, and related controls are expanding.
The pattern is reallocation more than expansion: dollars shifting toward cloud and identity, often funded by squeezing legacy or overlapping tooling elsewhere.
What a flat year does to behavior
A flat or slightly declining budget share changes how teams operate, not just what they buy. Three behaviors show up consistently when the envelope stops growing:
- Tool consolidation accelerates. Overlapping point products become the obvious place to find room, so platforms that fold several functions together gain ground over best-of-breed sprawl.
- Justification gets sharper. With no automatic increase to absorb a weak case, every new line needs a clear risk it reduces. Vague “best practice” asks lose out to spend tied to a named exposure.
- Outcomes beat coverage. Buyers increasingly ask what a control measurably changes — detection time, incident volume — rather than how many boxes it checks on a capability map.
None of this signals a program in retreat. It signals a market maturing past the phase where more spend was assumed to mean more security.
How to read this for your own budget
A few practical takeaways:
- Benchmark against the median, but expect a wide band. The distribution is broad; being above or below 10.9% of IT is only meaningful alongside your industry and risk context. See why % of IT and % of revenue can disagree before drawing conclusions.
- Defend staffing first. Since it is the largest line and the hardest to rebuild, protect it ahead of tooling in a flat year.
- Fund cloud and identity from rationalization. If you need to grow those areas without a bigger envelope, the realistic source is consolidating overlapping tools.
- Anchor the case to risk. With IBM putting the global average breach at $4.44M (and the US average at $10.22M), reallocating toward the areas where intrusions now begin is straightforward to justify — without claiming any control eliminates the risk.
A flat budget year rewards discipline over expansion. The benchmark suggests the winning move in 2026 is to hold staffing, consolidate tools, and redirect the savings into cloud and identity.
To see how your numbers compare against these benchmarks, try the cybersecurity budget calculator.
References
- IANS / Artico 2025 Security Budget Benchmark (opens in a new tab) · verified Jun 2026
- BLS — Information Security Analysts (OES wage data) (opens in a new tab) · verified May 2024
- IBM Cost of a Data Breach 2025 (opens in a new tab) · verified Jun 2026
Put this into a number
Build a sourced, defensible budget from your own risk profile — free and ungated.