Skip to content

Guide · budget by size

Cybersecurity budget by company size

Budget by size band

The table below maps each size band to a typical annual security budget, the rough share of IT budget it represents, and the per-employee figure that falls out. These are mid-market-intensity medians — regulated or high-threat businesses should plan toward the upper end of each range.

Size band Typical annual budget % of IT budget ~$ / employee
< 50$25K – $120K8% – 12%$700 – $1,180
50 – 250$120K – $450K7% – 10%$520 – $900
250 – 1,000$400K – $1.6M6% – 9%$420 – $760
1,000 – 5,000$1.5M – $7M6% – 9%$340 – $620
5,000+$7M – $40M+6% – 10%$280 – $520

Ranges blend Deloitte / IANS and Kaspersky benchmarks; the mid-market median is ~7% of IT budget.

What the budget buys at each stage

The dollar figure matters less than the sequencing. Spending out of order — say, a SIEM before MFA — wastes money and leaves the cheap, high-impact controls undone. Here is the rough order programs mature in.

Stage Priority controls Team
< 50MFA/SSO, EDR, email security, backups, awareness training.IT-led; vCISO advisory.
50 – 250+ MDR, vulnerability management, first compliance audit (SOC 2).First security hire.
250 – 1,000+ SIEM, formal IR plan, pentesting, DLP, vendor risk.Small security team.
1,000 – 5,000+ in-house/hybrid SOC, IAM platform, red teaming, GRC tooling.Dedicated function + CISO.
5,000++ platform consolidation, threat intel, global compliance, automation.Full org under CISO.

Why budgets scale sub-linearly

A company that grows 10× rarely sees its security budget grow 10×. The reason is structural: a large share of cost is fixed or volume-discounted. A single SIEM platform, an MDR contract, a compliance program, and a security leader cost roughly the same whether 800 or 1,200 people benefit. As headcount climbs, those fixed costs spread thinner and per-employee spend drops — even as absolute spend rises.

"Size tells you the order of magnitude and the sequence of investments — not the answer. A 300-person fintech and a 300-person logistics firm belong in the same row of the table and in different budgets entirely."

— SecurityBudget Research Team

Frequently asked questions

How much should a small business spend on cybersecurity?

A business under 50 employees typically spends $25K–$120K per year on security — often 8–12% of a small IT budget. The priorities are MFA, EDR, email security, backups, and awareness training before anything advanced.

What is a typical cybersecurity budget for a mid-market company?

A 250–1,000 employee mid-market company usually spends $400K–$1.6M annually, roughly 6–9% of IT budget. At this stage MDR, SIEM, vulnerability management, and a first dedicated security hire (or team) become standard.

How much do large enterprises spend on cybersecurity?

Enterprises with 5,000+ employees commonly spend $7M to $40M+ per year. Per-employee cost is lowest at this scale, but absolute spend is highest, dominated by staff, platform consolidation, and global compliance.

Does cybersecurity budget scale linearly with company size?

No. Spend grows with size but sub-linearly per employee, because tooling and compliance costs amortize across more people. A company 10× larger rarely spends 10× more per head — often closer to half the per-employee rate.

What percentage of IT budget should security be at each size?

Small firms often run higher (8–12%) because fixed costs loom large; mid-market clusters around the 7% median; large enterprises range 6–10% depending on regulation and threat profile. The percentage is a guide, not a target.

References

Go deeper

The full cost overview

Step back to the three framings — % of IT budget, % of revenue, and per employee — and what drives each.

Read the cost overview

Size your budget exactly

Enter your headcount, industry, and footprint for a bottom-up budget benchmarked against your size band.

Open the budget calculator

Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.