Most organizations spend roughly 10-15% of their IT budget on cybersecurity, and about 10% is a reasonable default when you have nothing more specific to go on. Independent analyst benchmarks — Gartner and IDC put typical spend in the 7-14% band — cluster around that figure, but the useful number for any given organization varies widely: heavily regulated sectors such as finance, healthcare, and government commonly run 12-20%, while lightly regulated sectors sit closer to 5-10%. The single most important caveat: these are benchmarks, not targets. They tell you how you compare to peers, not whether you are spending on the right things. A risk-based budget derived from your own assets, data sensitivity, and program maturity will always beat a percentage copied from an average.
That paragraph is the summary an AI overview gives you. The rest of this article is the part it can't: a sector-by-sector table of where the ranges actually land, why the smallest companies spend the highest percentage, and how to turn a benchmark into a defensible number. For the underlying arithmetic we defer to two companion posts — how cybersecurity budgets are calculated (the methods) and how company size affects cybersecurity spending (the size curve) — so this page can stay focused on the one question in the title.
The benchmark ranges at a glance
Determining the right cybersecurity budget as a percentage of IT spending is one of the most frequently asked questions in security leadership. The honest answer is a range, not a number, because it depends on industry, organization size, risk profile, and maturity level. The table below turns the benchmarks into something you can look yourself up in.
Typical cybersecurity spend by sector
| Sector / profile | Typical share of IT budget | What drives it |
|---|---|---|
| Financial services, healthcare, government | 12-20% | Strict compliance (HIPAA, PCI-DSS, GLBA), high breach penalties, attractive targets |
| Technology / cloud / SaaS | 10-15% | Continuous threats, customer security demands, product data protection |
| Manufacturing / utilities (OT) | 10-15% | Growing operational-technology attack surface, safety and uptime stakes |
| Retail / e-commerce | 8-12% | PCI-DSS obligations plus reputational damage from card-data breaches |
| Professional services, education, non-profits | 5-10% | Lighter regulation and lower data sensitivity, though still exposed to ransomware |
These figures are peer reference points drawn from analyst reporting (Gartner, IDC) and security-community guidance. They answer "how do I compare?" — not "what do I need?" Two organizations in the same row can have very different correct budgets depending on their data, systems, and threat exposure.
Typical spend by program maturity
The other big lever is how mature your security program already is. A brand-new program spends heavily to stand up foundational controls; a mature one stabilizes and spends efficiently.
| Program maturity | Typical share of IT budget | Posture |
|---|---|---|
| Level 1 — Ad-hoc | 3-5% | Minimal, reactive; controls are inconsistent |
| Level 2 — Repeatable | 7-10% | Establishing processes and core tooling |
| Level 3 — Managed | 10-15% | Comprehensive program, automation, monitoring |
| Level 4 — Optimized | 8-12% | Mature and efficient; spend levels off as foundations hold |
Note the curve: spending rises as you build capability, then falls slightly once a program is optimized and foundational controls are in place — though even mature programs keep increasing in absolute terms to meet emerging threats.
Why the percentage is the wrong place to start
It is tempting to pick a number off the chart and be done. Resist it. A ratio tells you nothing about whether you are protecting the assets that actually matter. The better path is risk-based, and it produces a number you can defend to a board:
- Inventory your assets and the sensitive data you hold.
- Estimate the loss if each is compromised — regulatory fines, breach response, downtime, reputational damage. (The average cost of a data breach is a useful anchor here.)
- Weigh the probability of a breach given your current posture — this is where a structured risk assessment earns its keep.
- Fund the controls that reduce that risk the most per dollar, starting with foundations (identity, endpoint, backup, patching, monitoring).
Then, and only then, compare the resulting number to the benchmark ranges above. If a risk-based plan lands you at 6% while every peer in your regulated sector spends 14%, that gap is a signal to re-examine your risk estimates — not proof you are efficient. The full mechanics of each budgeting method live in how cybersecurity budgets are calculated; the size dynamics that push small firms higher are covered in how company size affects cybersecurity spending.
What the budget actually covers
A percentage is meaningless if it only buys software. A complete cybersecurity budget spans four buckets:
- Personnel (typically 30-50%) — a CISO or virtual CISO, security engineers and architects, SOC and incident-response analysts, and contractors. Usually the single largest line.
- Technology and tools (30-40%) — firewalls and IDS/IPS, endpoint detection and response (EDR), SIEM, data loss prevention (DLP), identity and access management (IAM), vulnerability management, and cloud/container security.
- Professional services (10-20%) — assessments and audits, penetration testing, incident-response retainers, compliance support, and security-awareness training.
- Overhead and compliance (5-15%) — audit costs, cyber-liability insurance, and governance.
The most common way organizations quietly under-fund security is budgeting for tool licenses while ignoring the people and services that make those tools effective.
Allocating the budget you have
Within the security budget, weight the foundations first — they deliver the most risk reduction per dollar:
- Foundation controls (30-40%) — identity and access management, network and endpoint security, patch and vulnerability management, and incident-response capability.
- Advanced controls (20-30%) — advanced threat detection, cloud and container security, application security testing, and security architecture.
- Compliance and governance (15-20%) — audits, policy, training, and reporting; effectively mandatory for regulated organizations.
- Operations and team (20-30%) — salaries, training, and day-to-day management of the security stack.
Justifying the budget to leadership
Executives approve avoided losses and regulatory obligations far more readily than "a percentage increase." When you make the case:
- Lead with risk reduction — "This spend buys down an estimated $X exposure on our most sensitive data set."
- Cite compliance — "HIPAA / PCI / SOC 2 requires these controls; leaving them unfunded risks penalties and lost contracts."
- Benchmark against peers — "Comparable organizations in our sector spend Y%; we are below that."
- Point to breach costs — recent breaches in similar companies, and the return on security investment a comparable program delivered.
Increasing an under-funded budget
If you have concluded you are below where your risk warrants, phase the catch-up rather than demanding it all at once:
- Phase 1 (immediate) — increase 25-50% to close the most critical gaps.
- Phase 2 (1-2 years) — a further 25-50% to mature the program to your target level.
- Phase 3 (ongoing) — annual increases (commonly 10-15%) aligned with inflation, new technology, and emerging threats.
Conclusion
There is no single "right" cybersecurity budget percentage. Benchmarks put most organizations at 10-15% of IT budget, with 5-20% covering the realistic spread across sectors, sizes, and maturity levels — higher in regulated industries, higher for the smallest organizations, and higher for programs still being built. But the percentage is a peer-comparison tool, not a target. Derive your number from risk, sanity-check it against the ranges above, and remember the finding every breach survey confirms: under-funding security is far more expensive than funding it, because breach costs dwarf preventive spending. If you sit below the benchmark for your sector, the business case for an increase almost always exists.