Guide · cost overview
How much does cybersecurity cost?
Three ways to frame the number
"How much does cybersecurity cost?" has no single answer because there is no single denominator. A $50M manufacturer and a $50M fintech can both be spending "the right amount" and land on very different figures. The useful move is to express the budget three ways and triangulate — a number that looks sane in all three framings is defensible to a board, an auditor, or an insurer.
| Framing | 25th pct | Median | 75th pct | When to use it |
|---|---|---|---|---|
| % of IT budget | 5.4% | 7.0% | 10.2% | Board-level framing; IT spend is known. |
| % of revenue | 0.27% | 0.40% | 0.62% | When IT spend is opaque or shared. |
| $ / employee | $380 | $520 | $760 | Normalizes across headcount. |
| $ / endpoint | $260 | $360 | $520 | Device-heavy or OT-heavy orgs. |
Percentile bands blend Kaspersky IT Security Economics and the Deloitte / IANS Security Budget Benchmark. Treat them as a sanity range, not a target — the right number depends on your risk, not the median.
What it works out to by company size
Converting those percentages into dollars makes the trade-offs concrete. The figures below assume a mid-market security program at roughly the median intensity; a regulated or high-threat business should plan toward the upper end.
| Company size | Typical annual security spend | ~$ / employee |
|---|---|---|
| < 50 employees | $25K – $120K | $700 – $1,180 |
| 50 – 250 | $120K – $450K | $520 – $900 |
| 250 – 1,000 | $400K – $1.6M | $420 – $760 |
| 1,000 – 5,000 | $1.5M – $7M | $340 – $620 |
| 5,000+ | $7M – $40M+ | $280 – $520 |
Ranges, not point estimates — actual spend depends on industry, regulation, and maturity. See the company-size guide for the full breakdown.
What actually drives the cost
Two companies of identical size can differ 3× in security spend. The variance comes from a handful of structural factors — not from "buying more tools." Understanding which lever you are pulling keeps the conversation honest.
| Driver | Effect on budget | Why |
|---|---|---|
| Industry & regulation | +20% to +60% | HIPAA, PCI, SOC 2 and sector rules add audits, tooling, and evidence work. |
| Program maturity | ±15% | Immature programs carry catch-up spend; optimized ones run leaner per control. |
| Threat exposure | +5% to +12% | High-value targets need 24/7 monitoring and faster response. |
| Data sensitivity | +5% to +10% | Regulated or PII-heavy data raises detection, encryption, and DLP needs. |
| Cloud & asset footprint | scales linearly | SIEM, vuln management, and CSPM all scale with log volume and assets. |
Where the money goes
A healthy program is not one giant line item — it is a portfolio. Endpoint, identity, and email security protect the common attack paths; SIEM and MDR provide detection and response; vulnerability management and testing find problems before attackers do; awareness training and compliance cover people and obligations. As a rough split, detection & response (SIEM + MDR/SOC) tends to be the single largest category for mid-market and up, followed by identity and endpoint.
"The most expensive security budget is the one you set by copying a percentage. Build it bottom-up from the controls your risk actually requires, then check it against the benchmark — not the other way around."
— SecurityBudget Research Team
Frequently asked questions
What percentage of the IT budget should go to cybersecurity?
The median mid-market organization spends about 7% of its IT budget on security, with most landing between 5.4% (25th percentile) and 10.2% (75th percentile). Regulated industries and less mature programs skew higher; very lean shops can sit near 4%.
How much does cybersecurity cost as a percentage of revenue?
Security spend typically runs about 0.4% of annual revenue at the median, ranging from roughly 0.18% to 0.95% across the 10th–90th percentiles. Financial services and technology firms tend toward the high end.
How much does cybersecurity cost per employee?
Per-employee spend has a median near $520/year, with a band of roughly $280–$1,180. Smaller companies pay more per head because fixed costs (tooling minimums, compliance, a baseline of expertise) spread across fewer people.
Why is cybersecurity so expensive for small businesses?
Many security costs are fixed or have license minimums, so a 30-person company cannot amortize a SIEM, an MDR contract, or a SOC 2 audit across thousands of employees. That pushes per-employee cost up even though the absolute dollar figure is small.
Is cybersecurity spending increasing?
Yes. Security budgets have grown faster than overall IT budgets for several years, driven by ransomware, cloud sprawl, regulatory pressure, and rising cyber-insurance requirements. Most benchmarks show low-double-digit annual growth, though headcount growth is slower than tooling growth.
References
Build your number in 2 minutes
Skip the copy-a-percentage trap. Get a defensible, source-cited budget from your own risk profile.
Open the budget calculatorEstimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.