Breaking
SecurityDeveloping Story

Security budgets grow, but not for most CISOs

A new IANS and Artico Search report finds average security budget growth of 5% in 2026 masks a median of 0%.

··1 hour ago·4 min read
group of people sitting beside rectangular wooden table with laptops
Photo by Christina @ wocintechchat.com M on Unsplash

Security budgets may be growing on paper, but for a majority of CISOs, the money isn't moving in quite the same direction. The IANS and Artico Search 2026 Security Budget report found that while budgets grew by 5% on average in 2026, up from 4% last year, the median budget growth remained at 0%.

The findings come from responses from over 500 security executives between April and August 2026.

Average up, median flat

The report's headline figure of 5% average growth in 2026, up from 4% last year, hides a much weaker picture when looking at the middle of the distribution: median budget growth remained at 0%.

While 64% of CISOs asked for an increase this cycle, only 45% received one, meaning 55% of CISOs saw their budgets either remain flat or get cut.

Revenue performance and budget outcomes

Who gets to spend appears to depend heavily on the health and structure of the business. Companies that outperformed revenue targets by more than 5% were more than twice as likely to receive a double-digit security-budget increase as companies that hit their targets, 41% versus 15%, while 22% of significantly underperforming companies cut security budgets.

Ownership structure shapes spending

Ownership mattered as well: 71% of VC-backed companies increased security budgets, compared with 52% of publicly listed companies, while government and nonprofit organizations saw budgets grow least often and by the smallest margins.

What actually drives an increase

And when CISOs do get more money, a major breach may not be the argument that gets them there. Business or operational risk was the most common reason for budget increases, cited by 48% of CISOs whose budgets grew, while new regulations and stronger board or executive focus produced the largest average increase at 22% and 23%, respectively.

A major breach, meanwhile, was cited by just 3% as a reason for landing more money.

AI is the top new priority

Most of the new security dollars are going to AI, named by 69% of CISOs as their top net-new priority.

"Security is gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else's budget," said Steve Martano, IANS Faculty and partner in Artico Search's cyber practice.

Just 24% track AI as a separate security-budget line or subcategory, while 38% have AI embedded in the security budget and another 38% fund it through IT, data or innovation.

Fragmented accounting understates AI security spend

The fragmented accounting led to security budgets understating the money being directed toward securing AI. The report found that organizations formally tracking AI funding reported increases about 70% of the time, compared to 42% where AI is embedded in the general security budget and 31% where it is funded elsewhere.

Headcount expectations hold steady

AI taking a larger share of security spending isn't directly translating into headcount reductions, though: 81% of CISOs expect AI to create demand for new roles and skills, while 69% expect no reduction in existing headcount.

"AI and automation embedded in security workflows has led to the repurposing of team members and a change in hiring and resourcing," Martano said, adding CISOs now want staff to handle threats and make judgement calls that AI systems can't.

Aggressive AI spenders versus non-spenders

There was a marked difference in planning and leadership attitudes around AI security between organizations planning to increase AI-security spending by more than 10% (aggressive AI spenders) and those with no AI-specific spending planned. IANS didn't say whether this was cause or effect.

Aggressive AI spenders are substantially more likely to have the organizational foundations needed to support that investment, with respondents in 79% of such organizations saying their leadership has at least a fair understanding of AI risks, compared to 33% among organizations with no AI-specific spending plans, and 70% of aggressive spenders having clearly defined AI governance ownership, compared to 34% in the non-spending group.

Similarly, 50% of aggressive AI spenders reported having a mature AI-security program versus 17% of non-AI-spenders.

Increased spending on AI security happens when organizations spend more on security overall: 45% of aggressive AI spenders increased their overall security budget by more than 5%, and 51% expect to do so again next year, while only 12% of non-AI-spenders increased their overall budget by more than 5%, and only 9% expect to next year.

What the report advises

For CISOs trying to keep pace, the report's advice is to give AI its own budget line and start tracking what it actually costs before the next budget cycle.

Why it matters

For security leaders heading into the next budget cycle, the report's central finding — that average growth of 5% coexists with a median of 0% — suggests that the aggregate number many CISOs may cite in budget conversations isn't representative of what the typical security organization actually received. The gap between the 64% who asked for an increase and the 45% who got one could mean that the case for more funding is being made more often than it is being accepted.

The report's advice to give AI its own budget line is a practical starting point for CISOs who suspect their organization's security spend on AI is larger than the formal budget shows. Formal tracking doesn't guarantee more money, but the report's data indicates that organizations with a dedicated line reported increases more often than those funding AI through embedded or external budgets — a pattern worth testing in the next cycle rather than treating as a settled causal relationship.

#security budgets#ciso#ai security#cybersecurity spending#budget report#ians artico search

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories