Transparent · versioned · bottom-up
Methodology
v1.0 · published Jun 2026 · next review Sep 2026
Every number on SecurityBudget is built from the ground up. We do not start with a target percentage and work backwards — we price each security control from public unit costs, sum them against the inputs you provide, and only then cross-check the total against multi-source spend benchmarks. This page documents the model in full so you can audit, challenge, or reproduce any figure.
How the budget is built
The estimate is a bottom-up unit-cost model. In plain terms:
budget = Σ (per-control unit cost × your inputs)
Your inputs are the things that actually drive cost: employees, endpoints, log sources / cloud workloads, applications, and the compliance frameworks you carry. Each control is priced against whichever of those inputs it scales with — EDR scales per user, SIEM scales with log and workload volume, vulnerability management scales with assets and apps, and so on.
Because a defensible security budget is mostly people, the model includes a security-staffing line: an estimate of in-house headcount (≈ 1 FTE per 300 employees) costed at a loaded salary derived from BLS wage data (~$162K per FTE). This is typically the largest single line, and it is what makes the total comparable to the published % -of-IT-budget benchmarks, which also include personnel.
The raw sum is then adjusted by four context multipliers: maturity (a less mature program needs more catch-up spend), threat exposure, data sensitivity, and geography (labor and licensing costs vary by region). Finally, the headline figure is shown as a band, not a point: the low end represents a lean, minimum-viable program and the high end an advanced program covering the same scope. The midpoint is the typical build.
| Control | Basis / unit | Risk reduction | Confidence |
|---|---|---|---|
| Security Staffing | ~$162K loaded / FTE (BLS) | High | Medium |
| Endpoint Protection (EDR/XDR) | $3–$20 / user / mo · ~$8 typical | High | High |
| Identity Security | $3–$12 / user / mo · ~$7 typical | High | High |
| Email Security | $2–$8 / user / mo · ~$4 typical | High | High |
| SIEM | Ingest-based · ~$30K–$150K mid-market | Medium | Medium |
| MDR / SOC | $3–$45 / endpoint / mo · ~$6 typical | High | Medium |
| Vulnerability Management | ~$17–$42 / asset / year | Medium | Medium |
| Security Awareness | $12–$45 / user / year | Medium | High |
| Compliance | Per framework / year | Low | Medium |
| Testing | $5K–$50K / engagement · ~$18K | Medium | High |
| Cloud Security (CSPM/CNAPP) | ~$60–$1,200 / workload / year | High | Medium |
| Network Security (NGFW/NDR) | NGFW + NDR · ~$50K–$200K / year | Medium | Medium |
| Privileged Access Management | Per privileged user (~10% of staff) | High | Medium |
| Data Loss Prevention | $3–$15 / user / month | Medium | Medium |
| Dark Web Monitoring & Threat Intel | ~$5K–$250K / year by size | Medium | Medium |
| Incident Response Retainer | Annual retainer · ~$10K–$150K | Medium | High |
Unit labels above are the human-readable basis; the model applies an annual per-unit rate inside that range and multiplies by your input counts.
Benchmark cross-check
A bottom-up total is only credible if it sits in a sane place relative to peers. We re-express the budget in three framings and compare each to a multi-source meta-benchmark:
- % of IT budget — the most common board-level framing (peer median ≈ 11%).
- % of revenue — useful when IT spend is opaque (peer median ≈ 0.69%).
- $ / employee — normalizes for headcount (cross-industry median ≈ $2,300).
The peer distributions come from the IANS / Artico 2025 Security Budget Benchmark (n≈587 CISOs) and Deloitte spend studies, expressed as p10–p90 percentile bands rather than single averages. These benchmarks reflect total security spend including personnel, which is why our estimate includes a security-staffing line. Because most organizations do not publish a clean IT-budget number, IT budget is estimated as a share of revenue using an industry-specific ratio (Avasant) — so the "% of IT budget" framing carries slightly lower confidence than the revenue- or headcount-based framings.
Maturity scoring
Maturity is scored on a 0–100 scale, decomposed across the five NIST CSF functions. Each function gets its own sub-score and the overall figure is their weighted blend:
- Identify — asset, risk, and supply-chain visibility.
- Protect — identity, email, endpoint, and awareness controls.
- Detect — logging, SIEM, and monitoring coverage.
- Respond — incident response capability and runbooks.
- Recover — backup, restoration, and continuity.
Scores ladder up across five tiers — initial, developing, defined, managed, and optimized — so the same profile at a higher tier reduces the required catch-up spend in the budget model.
Confidence levels
Every priced line carries a confidence flag so you know how hard to lean on it:
| Level | What it means |
|---|---|
| High | Backed by multiple published pricing points or a public framework; the range is narrow and well-corroborated. |
| Medium | Based on a smaller sample or list pricing that varies widely by deal size; treat the range as indicative. |
| Low | Highly situational — driven by scope, audit cadence, or one-off engagements. Use as a placeholder pending a quote. |
List price vs negotiated
Public list prices systematically overstate what organizations actually pay. Multi-year commitments, volume tiers, bundling, and competitive displacement routinely produce 20–40% savings off list. Rather than bake in a single discount assumption, we show ranges: the low end of each control's band already reflects realistically negotiated pricing, while the high end reflects list or premium-tier pricing. Your real number will usually fall inside the band, closer to the low end if you negotiate hard.
Source-to-claim mapping
We only use a source for what it actually proves. Frameworks define what to buy; breach-cost research weights how much risk each control removes; spend benchmarks tell us where the total should land; pricing and salary data set the unit costs.
| Source type | Sources | What it proves |
|---|---|---|
| Frameworks | Verizon Data Breach Investigations Report 2025, NIST Cybersecurity Framework 2.0, CISA guidance & Known Exploited Vulnerabilities | Which controls belong in the program and how maturity maps to NIST CSF functions. |
| Breach cost | IBM Cost of a Data Breach 2025 | Risk weighting and the ROI denominator — the loss a control is reducing. |
| Spend benchmark | IANS / Artico 2025 Security Budget Benchmark, Deloitte / FS-ISAC cybersecurity spend study, Kaspersky IT Security Economics, Avasant IT Spending as % of Revenue by Industry | The peer percentile benchmarks: % of IT budget, % of revenue, and $/employee. |
| Pricing | Endpoint pricing — CrowdStrike, SentinelOne, Microsoft Defender (list), Identity pricing — Microsoft Entra, Okta, Cisco Duo (list), Email security pricing — Microsoft Defender for O365, Proofpoint, Mimecast, SIEM pricing — Splunk, Microsoft Sentinel (ingest-based), MDR pricing — Huntress, Arctic Wolf, CrowdStrike, SentinelOne, Vulnerability management pricing — Tenable, Qualys, Rapid7, Security awareness pricing — KnowBe4, Proofpoint, Penetration test pricing — Astra & industry guides, Compliance cost guides — Secureframe, Centraleyes, Thoropass, Cloud security pricing — Microsoft Defender for Cloud, Wiz, Prisma Cloud, Orca, Network security pricing — Palo Alto, Fortinet, Cisco, Darktrace, Vectra, PAM pricing — CyberArk, Delinea, BeyondTrust, DLP pricing — Microsoft Purview, Forcepoint, Zscaler, Symantec, Threat intel / dark web pricing — Recorded Future, Flare, ZeroFox, SpyCloud, HIBP, IR retainer pricing — Mandiant, CrowdStrike, Unit 42, Arctic Wolf | Per-control unit costs that drive the bottom-up build. |
| Salary | BLS — Information Security Analysts (OES wage data) | Staffing inputs for SOC / MDR and in-house analyst cost. |
See the full registry, with links and verification dates, on the Data Sources page.
Changelog
- v1.0 Jun 2026 Initial public methodology.
Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.