Skip to content

Guide · cost overview

How much does cybersecurity cost?

Three ways to frame the number

"How much does cybersecurity cost?" has no single answer because there is no single denominator. A $50M manufacturer and a $50M fintech can both be spending "the right amount" and land on very different figures. The useful move is to express the budget three ways and triangulate — a number that looks sane in all three framings is defensible to a board, an auditor, or an insurer.

Framing 25th pct Median 75th pct When to use it
% of IT budget5.4%7.0%10.2%Board-level framing; IT spend is known.
% of revenue0.27%0.40%0.62%When IT spend is opaque or shared.
$ / employee$380$520$760Normalizes across headcount.
$ / endpoint$260$360$520Device-heavy or OT-heavy orgs.

Percentile bands blend Kaspersky IT Security Economics and the Deloitte / IANS Security Budget Benchmark. Treat them as a sanity range, not a target — the right number depends on your risk, not the median.

What it works out to by company size

Converting those percentages into dollars makes the trade-offs concrete. The figures below assume a mid-market security program at roughly the median intensity; a regulated or high-threat business should plan toward the upper end.

Company size Typical annual security spend ~$ / employee
< 50 employees$25K – $120K$700 – $1,180
50 – 250$120K – $450K$520 – $900
250 – 1,000$400K – $1.6M$420 – $760
1,000 – 5,000$1.5M – $7M$340 – $620
5,000+$7M – $40M+$280 – $520

Ranges, not point estimates — actual spend depends on industry, regulation, and maturity. See the company-size guide for the full breakdown.

What actually drives the cost

Two companies of identical size can differ 3× in security spend. The variance comes from a handful of structural factors — not from "buying more tools." Understanding which lever you are pulling keeps the conversation honest.

Driver Effect on budget Why
Industry & regulation+20% to +60%HIPAA, PCI, SOC 2 and sector rules add audits, tooling, and evidence work.
Program maturity±15%Immature programs carry catch-up spend; optimized ones run leaner per control.
Threat exposure+5% to +12%High-value targets need 24/7 monitoring and faster response.
Data sensitivity+5% to +10%Regulated or PII-heavy data raises detection, encryption, and DLP needs.
Cloud & asset footprintscales linearlySIEM, vuln management, and CSPM all scale with log volume and assets.

Where the money goes

A healthy program is not one giant line item — it is a portfolio. Endpoint, identity, and email security protect the common attack paths; SIEM and MDR provide detection and response; vulnerability management and testing find problems before attackers do; awareness training and compliance cover people and obligations. As a rough split, detection & response (SIEM + MDR/SOC) tends to be the single largest category for mid-market and up, followed by identity and endpoint.

"The most expensive security budget is the one you set by copying a percentage. Build it bottom-up from the controls your risk actually requires, then check it against the benchmark — not the other way around."

— SecurityBudget Research Team

Frequently asked questions

What percentage of the IT budget should go to cybersecurity?

The median mid-market organization spends about 7% of its IT budget on security, with most landing between 5.4% (25th percentile) and 10.2% (75th percentile). Regulated industries and less mature programs skew higher; very lean shops can sit near 4%.

How much does cybersecurity cost as a percentage of revenue?

Security spend typically runs about 0.4% of annual revenue at the median, ranging from roughly 0.18% to 0.95% across the 10th–90th percentiles. Financial services and technology firms tend toward the high end.

How much does cybersecurity cost per employee?

Per-employee spend has a median near $520/year, with a band of roughly $280–$1,180. Smaller companies pay more per head because fixed costs (tooling minimums, compliance, a baseline of expertise) spread across fewer people.

Why is cybersecurity so expensive for small businesses?

Many security costs are fixed or have license minimums, so a 30-person company cannot amortize a SIEM, an MDR contract, or a SOC 2 audit across thousands of employees. That pushes per-employee cost up even though the absolute dollar figure is small.

Is cybersecurity spending increasing?

Yes. Security budgets have grown faster than overall IT budgets for several years, driven by ransomware, cloud sprawl, regulatory pressure, and rising cyber-insurance requirements. Most benchmarks show low-double-digit annual growth, though headcount growth is slower than tooling growth.

References

Build your number in 2 minutes

Skip the copy-a-percentage trap. Get a defensible, source-cited budget from your own risk profile.

Open the budget calculator

Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.