Cybersecurity

What percentage of IT budget should go to cybersecurity?

Understand industry benchmarks and factors for determining appropriate cybersecurity budget allocation as a percentage of total IT spending.

By Inventive HQ Team

Most organizations spend roughly 10-15% of their IT budget on cybersecurity, and about 10% is a reasonable default when you have nothing more specific to go on. Independent analyst benchmarks — Gartner and IDC put typical spend in the 7-14% band — cluster around that figure, but the useful number for any given organization varies widely: heavily regulated sectors such as finance, healthcare, and government commonly run 12-20%, while lightly regulated sectors sit closer to 5-10%. The single most important caveat: these are benchmarks, not targets. They tell you how you compare to peers, not whether you are spending on the right things. A risk-based budget derived from your own assets, data sensitivity, and program maturity will always beat a percentage copied from an average.

That paragraph is the summary an AI overview gives you. The rest of this article is the part it can't: a sector-by-sector table of where the ranges actually land, why the smallest companies spend the highest percentage, and how to turn a benchmark into a defensible number. For the underlying arithmetic we defer to two companion posts — how cybersecurity budgets are calculated (the methods) and how company size affects cybersecurity spending (the size curve) — so this page can stay focused on the one question in the title.

The benchmark ranges at a glance

Typical cybersecurity spend as a percentage of IT budget by sector Horizontal range bars showing that heavily regulated sectors budget roughly 12 to 20 percent of IT spending on cybersecurity, technology and manufacturing 10 to 15 percent, retail 8 to 12 percent, and lightly regulated sectors 5 to 10 percent, against an amber band marking the common 10 to 15 percent zone. Cybersecurity as a share of IT budget, by sector Ranges are peer benchmarks, not targets — set your number from risk common 10-15% zone 0% 5% 10% 15% 20% 25%

Finance / Health / Gov 12-20%

Technology / SaaS 10-15%

Manufacturing / OT 10-15%

Retail / e-commerce 8-12%

Lightly regulated 5-10%

Share of IT budget spent on cybersecurity

Determining the right cybersecurity budget as a percentage of IT spending is one of the most frequently asked questions in security leadership. The honest answer is a range, not a number, because it depends on industry, organization size, risk profile, and maturity level. The table below turns the benchmarks into something you can look yourself up in.

Advertisement

Typical cybersecurity spend by sector

Sector / profileTypical share of IT budgetWhat drives it
Financial services, healthcare, government12-20%Strict compliance (HIPAA, PCI-DSS, GLBA), high breach penalties, attractive targets
Technology / cloud / SaaS10-15%Continuous threats, customer security demands, product data protection
Manufacturing / utilities (OT)10-15%Growing operational-technology attack surface, safety and uptime stakes
Retail / e-commerce8-12%PCI-DSS obligations plus reputational damage from card-data breaches
Professional services, education, non-profits5-10%Lighter regulation and lower data sensitivity, though still exposed to ransomware

These figures are peer reference points drawn from analyst reporting (Gartner, IDC) and security-community guidance. They answer "how do I compare?" — not "what do I need?" Two organizations in the same row can have very different correct budgets depending on their data, systems, and threat exposure.

Typical spend by program maturity

The other big lever is how mature your security program already is. A brand-new program spends heavily to stand up foundational controls; a mature one stabilizes and spends efficiently.

Program maturityTypical share of IT budgetPosture
Level 1 — Ad-hoc3-5%Minimal, reactive; controls are inconsistent
Level 2 — Repeatable7-10%Establishing processes and core tooling
Level 3 — Managed10-15%Comprehensive program, automation, monitoring
Level 4 — Optimized8-12%Mature and efficient; spend levels off as foundations hold

Note the curve: spending rises as you build capability, then falls slightly once a program is optimized and foundational controls are in place — though even mature programs keep increasing in absolute terms to meet emerging threats.

Why the percentage is the wrong place to start

It is tempting to pick a number off the chart and be done. Resist it. A ratio tells you nothing about whether you are protecting the assets that actually matter. The better path is risk-based, and it produces a number you can defend to a board:

  1. Inventory your assets and the sensitive data you hold.
  2. Estimate the loss if each is compromised — regulatory fines, breach response, downtime, reputational damage. (The average cost of a data breach is a useful anchor here.)
  3. Weigh the probability of a breach given your current posture — this is where a structured risk assessment earns its keep.
  4. Fund the controls that reduce that risk the most per dollar, starting with foundations (identity, endpoint, backup, patching, monitoring).

Then, and only then, compare the resulting number to the benchmark ranges above. If a risk-based plan lands you at 6% while every peer in your regulated sector spends 14%, that gap is a signal to re-examine your risk estimates — not proof you are efficient. The full mechanics of each budgeting method live in how cybersecurity budgets are calculated; the size dynamics that push small firms higher are covered in how company size affects cybersecurity spending.

Loading interactive tool...

What the budget actually covers

A percentage is meaningless if it only buys software. A complete cybersecurity budget spans four buckets:

  • Personnel (typically 30-50%) — a CISO or virtual CISO, security engineers and architects, SOC and incident-response analysts, and contractors. Usually the single largest line.
  • Technology and tools (30-40%) — firewalls and IDS/IPS, endpoint detection and response (EDR), SIEM, data loss prevention (DLP), identity and access management (IAM), vulnerability management, and cloud/container security.
  • Professional services (10-20%) — assessments and audits, penetration testing, incident-response retainers, compliance support, and security-awareness training.
  • Overhead and compliance (5-15%) — audit costs, cyber-liability insurance, and governance.

The most common way organizations quietly under-fund security is budgeting for tool licenses while ignoring the people and services that make those tools effective.

Allocating the budget you have

Within the security budget, weight the foundations first — they deliver the most risk reduction per dollar:

  • Foundation controls (30-40%) — identity and access management, network and endpoint security, patch and vulnerability management, and incident-response capability.
  • Advanced controls (20-30%) — advanced threat detection, cloud and container security, application security testing, and security architecture.
  • Compliance and governance (15-20%) — audits, policy, training, and reporting; effectively mandatory for regulated organizations.
  • Operations and team (20-30%) — salaries, training, and day-to-day management of the security stack.

Justifying the budget to leadership

Executives approve avoided losses and regulatory obligations far more readily than "a percentage increase." When you make the case:

  • Lead with risk reduction — "This spend buys down an estimated $X exposure on our most sensitive data set."
  • Cite compliance — "HIPAA / PCI / SOC 2 requires these controls; leaving them unfunded risks penalties and lost contracts."
  • Benchmark against peers — "Comparable organizations in our sector spend Y%; we are below that."
  • Point to breach costs — recent breaches in similar companies, and the return on security investment a comparable program delivered.

Increasing an under-funded budget

If you have concluded you are below where your risk warrants, phase the catch-up rather than demanding it all at once:

  • Phase 1 (immediate) — increase 25-50% to close the most critical gaps.
  • Phase 2 (1-2 years) — a further 25-50% to mature the program to your target level.
  • Phase 3 (ongoing) — annual increases (commonly 10-15%) aligned with inflation, new technology, and emerging threats.

Conclusion

There is no single "right" cybersecurity budget percentage. Benchmarks put most organizations at 10-15% of IT budget, with 5-20% covering the realistic spread across sectors, sizes, and maturity levels — higher in regulated industries, higher for the smallest organizations, and higher for programs still being built. But the percentage is a peer-comparison tool, not a target. Derive your number from risk, sanity-check it against the ranges above, and remember the finding every breach survey confirms: under-funding security is far more expensive than funding it, because breach costs dwarf preventive spending. If you sit below the benchmark for your sector, the business case for an increase almost always exists.

Frequently Asked Questions

What percentage of IT budget should go to cybersecurity?

Most organizations spend roughly 10-15% of their IT budget on cybersecurity, and around 10% is a reasonable starting point if you have nothing more specific to go on. Analyst benchmarks (Gartner, IDC) cluster in the 7-14% range, with regulated sectors such as finance, healthcare, and government commonly running 12-20% and lightly regulated sectors closer to 5-10%. Treat these as reference points, not targets — the right number for you depends on your industry, size, data sensitivity, and program maturity, and it is better derived from your actual risk than copied from an average.

Is 10% of IT budget enough for cybersecurity?

For a typical mid-market organization with moderate regulatory exposure, 10% is a defensible baseline, but "enough" is a risk question, not a percentage question. If you hold protected health information, payment card data, or government data, 10% is often low and 12-20% is more realistic. If you have simple systems and little sensitive data, 5-8% may cover your real exposure. The percentage only tells you how you compare to peers; whether it is enough is answered by mapping spend to the controls that reduce your specific risks.

Why do smaller companies spend a higher percentage on cybersecurity?

It looks backwards, but small organizations often spend 12-20% of IT budget on security while large enterprises spend 8-12%. Large organizations build efficient internal teams and buy tools at volume, so their cost per user falls. Small organizations lack that scale, rely on outsourced services priced per-seat, and still need the same baseline controls (identity, endpoint, backup, monitoring). The fixed cost of a security floor is simply a bigger slice of a smaller IT budget. See our companion post on how company size affects cybersecurity spending for the full breakdown.

How much do regulated industries spend on cybersecurity?

Heavily regulated sectors — financial services, healthcare, and government contractors — commonly budget 12-20% of IT spending on cybersecurity because compliance frameworks (HIPAA, PCI-DSS, SOC 2, ISO 27001, GDPR) mandate specific controls, audits, and reporting, and the penalties for a breach are severe. Technology firms and manufacturers with operational-technology exposure typically run 10-15%. The extra spend is not just tools; it funds assessments, audits, remediation, and ongoing compliance management that lightly regulated organizations can skip.

Should I set my cybersecurity budget as a percentage or based on risk?

Base it on risk, then sanity-check it against the percentage. A ratio like "10% of IT budget" is a useful benchmark for spotting outliers and justifying spend to executives, but it does not tell you whether you are protecting the right things. A risk-based approach — inventory your assets, estimate the loss if each is compromised, weigh breach probability, and fund the controls that cut that risk most per dollar — produces a defensible number. Use the percentage to confirm you are not wildly above or below peers, not to set the budget in the first place.

What does a cybersecurity budget actually cover?

A complete cybersecurity budget is more than tools. Personnel (a CISO or virtual CISO, security engineers, and SOC analysts) is typically the largest line at 30-50%; technology such as EDR, SIEM, IAM, and vulnerability management runs 30-40%; professional services such as penetration testing, assessments, and incident-response retainers are 10-20%; and compliance, audits, cyber insurance, and training make up the remainder. Budgeting only for software licenses and ignoring people and services is the most common way organizations under-fund security without realizing it.

How much should cybersecurity spending increase each year?

Many organizations raise cybersecurity budgets by roughly 10-15% year over year as the threat landscape and their attack surface grow, though the right figure depends on how much ground you have to make up. If you are starting from a mature program, increases that track inflation plus new-technology needs may suffice. If you are below benchmark for your sector or building a program from scratch, a phased catch-up — a 25-50% increase to close critical gaps, followed by further growth to reach target maturity — is common.

How do I justify a bigger cybersecurity budget to leadership?

Frame it as risk reduction and cost avoidance, not spending. Quantify the exposure you are buying down ("a breach of this data set would cost an estimated X in fines, response, and lost business"), point to compliance obligations that carry penalties if unfunded, and benchmark against peers ("comparable organizations in our sector spend Y% and we spend less"). Executives approve budgets that map to a specific avoided loss or a specific regulatory requirement far more readily than a request framed as a percentage increase.

cybersecurity-budgetit-spendingsecurity-investmentbudget-allocation