Skip to content

Transparent · versioned · bottom-up

Methodology

v1.0 · published Jun 2026 · next review Sep 2026

Every number on SecurityBudget is built from the ground up. We do not start with a target percentage and work backwards — we price each security control from public unit costs, sum them against the inputs you provide, and only then cross-check the total against multi-source spend benchmarks. This page documents the model in full so you can audit, challenge, or reproduce any figure.

How the budget is built

The estimate is a bottom-up unit-cost model. In plain terms:

budget = Σ (per-control unit cost × your inputs)

Your inputs are the things that actually drive cost: employees, endpoints, log sources / cloud workloads, applications, and the compliance frameworks you carry. Each control is priced against whichever of those inputs it scales with — EDR scales per user, SIEM scales with log and workload volume, vulnerability management scales with assets and apps, and so on.

Because a defensible security budget is mostly people, the model includes a security-staffing line: an estimate of in-house headcount (≈ 1 FTE per 300 employees) costed at a loaded salary derived from BLS wage data (~$162K per FTE). This is typically the largest single line, and it is what makes the total comparable to the published % -of-IT-budget benchmarks, which also include personnel.

The raw sum is then adjusted by four context multipliers: maturity (a less mature program needs more catch-up spend), threat exposure, data sensitivity, and geography (labor and licensing costs vary by region). Finally, the headline figure is shown as a band, not a point: the low end represents a lean, minimum-viable program and the high end an advanced program covering the same scope. The midpoint is the typical build.

Control Basis / unit Risk reduction Confidence
Security Staffing ~$162K loaded / FTE (BLS) High Medium
Endpoint Protection (EDR/XDR) $3–$20 / user / mo · ~$8 typical High High
Identity Security $3–$12 / user / mo · ~$7 typical High High
Email Security $2–$8 / user / mo · ~$4 typical High High
SIEM Ingest-based · ~$30K–$150K mid-market Medium Medium
MDR / SOC $3–$45 / endpoint / mo · ~$6 typical High Medium
Vulnerability Management ~$17–$42 / asset / year Medium Medium
Security Awareness $12–$45 / user / year Medium High
Compliance Per framework / year Low Medium
Testing $5K–$50K / engagement · ~$18K Medium High
Cloud Security (CSPM/CNAPP) ~$60–$1,200 / workload / year High Medium
Network Security (NGFW/NDR) NGFW + NDR · ~$50K–$200K / year Medium Medium
Privileged Access Management Per privileged user (~10% of staff) High Medium
Data Loss Prevention $3–$15 / user / month Medium Medium
Dark Web Monitoring & Threat Intel ~$5K–$250K / year by size Medium Medium
Incident Response Retainer Annual retainer · ~$10K–$150K Medium High

Unit labels above are the human-readable basis; the model applies an annual per-unit rate inside that range and multiplies by your input counts.

Benchmark cross-check

A bottom-up total is only credible if it sits in a sane place relative to peers. We re-express the budget in three framings and compare each to a multi-source meta-benchmark:

  • % of IT budget — the most common board-level framing (peer median ≈ 11%).
  • % of revenue — useful when IT spend is opaque (peer median ≈ 0.69%).
  • $ / employee — normalizes for headcount (cross-industry median ≈ $2,300).

The peer distributions come from the IANS / Artico 2025 Security Budget Benchmark (n≈587 CISOs) and Deloitte spend studies, expressed as p10–p90 percentile bands rather than single averages. These benchmarks reflect total security spend including personnel, which is why our estimate includes a security-staffing line. Because most organizations do not publish a clean IT-budget number, IT budget is estimated as a share of revenue using an industry-specific ratio (Avasant) — so the "% of IT budget" framing carries slightly lower confidence than the revenue- or headcount-based framings.

Maturity scoring

Maturity is scored on a 0–100 scale, decomposed across the five NIST CSF functions. Each function gets its own sub-score and the overall figure is their weighted blend:

  • Identify — asset, risk, and supply-chain visibility.
  • Protect — identity, email, endpoint, and awareness controls.
  • Detect — logging, SIEM, and monitoring coverage.
  • Respond — incident response capability and runbooks.
  • Recover — backup, restoration, and continuity.

Scores ladder up across five tiers — initial, developing, defined, managed, and optimized — so the same profile at a higher tier reduces the required catch-up spend in the budget model.

Confidence levels

Every priced line carries a confidence flag so you know how hard to lean on it:

Level What it means
High Backed by multiple published pricing points or a public framework; the range is narrow and well-corroborated.
Medium Based on a smaller sample or list pricing that varies widely by deal size; treat the range as indicative.
Low Highly situational — driven by scope, audit cadence, or one-off engagements. Use as a placeholder pending a quote.

List price vs negotiated

Public list prices systematically overstate what organizations actually pay. Multi-year commitments, volume tiers, bundling, and competitive displacement routinely produce 20–40% savings off list. Rather than bake in a single discount assumption, we show ranges: the low end of each control's band already reflects realistically negotiated pricing, while the high end reflects list or premium-tier pricing. Your real number will usually fall inside the band, closer to the low end if you negotiate hard.

Source-to-claim mapping

We only use a source for what it actually proves. Frameworks define what to buy; breach-cost research weights how much risk each control removes; spend benchmarks tell us where the total should land; pricing and salary data set the unit costs.

Source type Sources What it proves
Frameworks Verizon Data Breach Investigations Report 2025, NIST Cybersecurity Framework 2.0, CISA guidance & Known Exploited Vulnerabilities Which controls belong in the program and how maturity maps to NIST CSF functions.
Breach cost IBM Cost of a Data Breach 2025 Risk weighting and the ROI denominator — the loss a control is reducing.
Spend benchmark IANS / Artico 2025 Security Budget Benchmark, Deloitte / FS-ISAC cybersecurity spend study, Kaspersky IT Security Economics, Avasant IT Spending as % of Revenue by Industry The peer percentile benchmarks: % of IT budget, % of revenue, and $/employee.
Pricing Endpoint pricing — CrowdStrike, SentinelOne, Microsoft Defender (list), Identity pricing — Microsoft Entra, Okta, Cisco Duo (list), Email security pricing — Microsoft Defender for O365, Proofpoint, Mimecast, SIEM pricing — Splunk, Microsoft Sentinel (ingest-based), MDR pricing — Huntress, Arctic Wolf, CrowdStrike, SentinelOne, Vulnerability management pricing — Tenable, Qualys, Rapid7, Security awareness pricing — KnowBe4, Proofpoint, Penetration test pricing — Astra & industry guides, Compliance cost guides — Secureframe, Centraleyes, Thoropass, Cloud security pricing — Microsoft Defender for Cloud, Wiz, Prisma Cloud, Orca, Network security pricing — Palo Alto, Fortinet, Cisco, Darktrace, Vectra, PAM pricing — CyberArk, Delinea, BeyondTrust, DLP pricing — Microsoft Purview, Forcepoint, Zscaler, Symantec, Threat intel / dark web pricing — Recorded Future, Flare, ZeroFox, SpyCloud, HIBP, IR retainer pricing — Mandiant, CrowdStrike, Unit 42, Arctic Wolf Per-control unit costs that drive the bottom-up build.
Salary BLS — Information Security Analysts (OES wage data) Staffing inputs for SOC / MDR and in-house analyst cost.

See the full registry, with links and verification dates, on the Data Sources page.

Changelog

  • v1.0 Jun 2026 Initial public methodology.

Estimates are based on public pricing, industry benchmarks, and security frameworks. For planning only — not professional, financial, or legal advice.