Guide · budget by size
Cybersecurity budget by company size
Budget by size band
The table below maps each size band to a typical annual security budget, the rough share of IT budget it represents, and the per-employee figure that falls out. These are mid-market-intensity medians — regulated or high-threat businesses should plan toward the upper end of each range.
| Size band | Typical annual budget | % of IT budget | ~$ / employee |
|---|---|---|---|
| < 50 | $25K – $120K | 8% – 12% | $700 – $1,180 |
| 50 – 250 | $120K – $450K | 7% – 10% | $520 – $900 |
| 250 – 1,000 | $400K – $1.6M | 6% – 9% | $420 – $760 |
| 1,000 – 5,000 | $1.5M – $7M | 6% – 9% | $340 – $620 |
| 5,000+ | $7M – $40M+ | 6% – 10% | $280 – $520 |
Ranges blend Deloitte / IANS and Kaspersky benchmarks; the mid-market median is ~7% of IT budget.
What the budget buys at each stage
The dollar figure matters less than the sequencing. Spending out of order — say, a SIEM before MFA — wastes money and leaves the cheap, high-impact controls undone. Here is the rough order programs mature in.
| Stage | Priority controls | Team |
|---|---|---|
| < 50 | MFA/SSO, EDR, email security, backups, awareness training. | IT-led; vCISO advisory. |
| 50 – 250 | + MDR, vulnerability management, first compliance audit (SOC 2). | First security hire. |
| 250 – 1,000 | + SIEM, formal IR plan, pentesting, DLP, vendor risk. | Small security team. |
| 1,000 – 5,000 | + in-house/hybrid SOC, IAM platform, red teaming, GRC tooling. | Dedicated function + CISO. |
| 5,000+ | + platform consolidation, threat intel, global compliance, automation. | Full org under CISO. |
Why budgets scale sub-linearly
A company that grows 10× rarely sees its security budget grow 10×. The reason is structural: a large share of cost is fixed or volume-discounted. A single SIEM platform, an MDR contract, a compliance program, and a security leader cost roughly the same whether 800 or 1,200 people benefit. As headcount climbs, those fixed costs spread thinner and per-employee spend drops — even as absolute spend rises.
"Size tells you the order of magnitude and the sequence of investments — not the answer. A 300-person fintech and a 300-person logistics firm belong in the same row of the table and in different budgets entirely."
— SecurityBudget Research Team
Frequently asked questions
How much should a small business spend on cybersecurity?
A business under 50 employees typically spends $25K–$120K per year on security — often 8–12% of a small IT budget. The priorities are MFA, EDR, email security, backups, and awareness training before anything advanced.
What is a typical cybersecurity budget for a mid-market company?
A 250–1,000 employee mid-market company usually spends $400K–$1.6M annually, roughly 6–9% of IT budget. At this stage MDR, SIEM, vulnerability management, and a first dedicated security hire (or team) become standard.
How much do large enterprises spend on cybersecurity?
Enterprises with 5,000+ employees commonly spend $7M to $40M+ per year. Per-employee cost is lowest at this scale, but absolute spend is highest, dominated by staff, platform consolidation, and global compliance.
Does cybersecurity budget scale linearly with company size?
No. Spend grows with size but sub-linearly per employee, because tooling and compliance costs amortize across more people. A company 10× larger rarely spends 10× more per head — often closer to half the per-employee rate.
What percentage of IT budget should security be at each size?
Small firms often run higher (8–12%) because fixed costs loom large; mid-market clusters around the 7% median; large enterprises range 6–10% depending on regulation and threat profile. The percentage is a guide, not a target.
References
Go deeper
The full cost overview
Step back to the three framings — % of IT budget, % of revenue, and per employee — and what drives each.
Read the cost overviewSize your budget exactly
Enter your headcount, industry, and footprint for a bottom-up budget benchmarked against your size band.
Open the budget calculatorEstimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.