Calculate a defensible cybersecurity budget from three benchmark methods, plus compliance and risk costs. Get an allocation split and PDF justification.
This cybersecurity budget calculator produces a defensible annual security budget figure, a recommended range around it, and an allocation across software, personnel, services, hardware, and training. It is built for the conversation where someone asks “how much should we be spending on security?” and a gut answer is not good enough. The tool triangulates three independent benchmarking methods, then adds explicit line items for compliance obligations and risk factors, so every dollar in the recommendation traces back to something you can point at.
It is aimed at IT directors, vCISOs, MSPs building a client roadmap, and CFOs who want to know whether the security line is defensible. Everything runs client-side, your scenario is preserved in the URL, and the output exports to PDF with a written justification narrative you can paste into a board paper.
Any single security-spend benchmark is easy to dismiss. The calculator uses three and blends them, which is harder to argue with.
The three are combined as a weighted average:
Baseline = (IT-budget method × 0.40) + (revenue method × 0.35) + (per-FTE method × 0.25)
If you do not supply a current IT budget, the model drops that term and reweights to 60% revenue and 40% per-FTE. This matters in practice: many organisations genuinely do not know their fully-loaded IT spend, and forcing a guess would poison the strongest-weighted input.
Compliance is added as a real cost, not a percentage. Each framework you select contributes an initial cost, an annual cost, and a technology cost. Year one totals initial + annual + technology; year two onward drops the initial cost and retains 30% of the technology cost. The technology component is scaled by your current maturity — 1.0 at minimal, 0.7 at basic, 0.4 at moderate, 0.1 at advanced — on the reasoning that a mature organisation already owns most of the tooling an auditor will ask about. The initial cost is only included at minimal or basic maturity.
Indicative year-one framework costs in the model: HIPAA around $35,000, GDPR around $60,000, SOC 2 around $75,000, ISO 27001 around $85,000, and CMMC around $120,000 at minimal maturity. Note that SOC 2 auditor fees are additional and typically run $15,000–$50,000 on top.
Risk factors are applied as compounding multipliers against the baseline, and each one appears in the results as a named line with its own dollar figure:
Recommended budget = baseline + compliance costs + (baseline × (compounded risk multiplier − 1)), presented as a range of ±15%.
A 250-person professional services firm, $40M revenue, $3M IT budget, basic maturity, pursuing SOC 2, 30 vendors, 60% remote, one incident in the past year.
Recommended budget: roughly $899,000, with a planning range of $764,000 to $1,034,000. The spread between the three baseline methods — $297,000 against $1,000,000 — is itself informative: it usually means the IT budget is understated relative to revenue, and that is worth raising before the security number is challenged.
The default split is 40% software, 30% personnel, 15% services, 10% hardware, 5% training. At minimal maturity it becomes 30/20/30/15/5, weighting services heavily because early-stage programmes buy expertise before tools. At optimised it becomes 42/38/8/6/6, with automation and skilled staff displacing external consulting. If your actual spend looks nothing like the recommended shape, that gap is often more actionable than the total.
Budget benchmarks are only persuasive next to the loss they are meant to prevent. IBM’s Cost of a Data Breach Report 2026, based on 602 organisations breached between March 2025 and February 2026, reported a global average breach cost of $4.99M and a US average of $11.5M, with healthcare highest at $6.64M and financial services at $6.3M. The same research found the average time to identify and contain a breach was 247 days. Verizon’s 2025 Data Breach Investigations Report, covering more than 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 44% of breaches — and in 88% of breaches at small and medium businesses. Those are the figures that make a security budget a risk-transfer decision rather than an overhead line.
The industry benchmarks in this model range from about 5.9% in education to 13.3% in healthcare, with a cross-industry figure near 10%. Percentage-of-IT is a sanity check, not a target — it is only one of three methods here precisely because organisations with an understated IT budget will always look adequately funded by that measure alone.
Because they measure different things. High-revenue, low-headcount firms look under-funded on the per-FTE method and over-funded on the revenue method. The disagreement is diagnostic: a large gap usually points at an unusual revenue-per-employee ratio or an incomplete IT budget figure.
Yes. The personnel allocation covers security staff salaries and retention, and defaults to 30% of the total, rising to 38% at optimised maturity. If you outsource to an MSP or MDR provider, that spend lands under services instead.
Mostly not. They cover readiness work, policy development, ongoing programme management, and the technology needed to satisfy controls. External auditor fees are separate — for SOC 2 typically another $15,000 to $50,000 depending on scope and type.
Because post-incident spend is real and front-loaded: enhanced monitoring, remediation, forensics retainers, and often insurer-mandated controls. The model applies +25% within six months, decaying to +3% for older incidents.
It is a deliberate acknowledgement that a benchmark model cannot produce a single correct number. Use the low end as a floor to defend and the high end as the ask, and let the compliance and risk line items justify where in the range you land.
It changes compliance technology costs and the allocation shape, not the baseline. A mature organisation needs less new tooling to satisfy an auditor and less external consulting, so more of the same budget goes to people and automation. Assess your level with the cybersecurity maturity assessment before setting it here.
Justify it against avoided loss. Estimate the downside with the data breach cost calculator, then test individual line items for payback in the cybersecurity ROI calculator.
No. The calculation is entirely client-side. Your figures stay in your browser and in the URL you control.
A cybersecurity budget calculator estimates the appropriate security spending for an organization based on industry benchmarks, organizational size, regulatory requirements, risk profile, and security maturity. Security budgets typically range from 3-10% of the overall IT budget, but the right number depends on many factors specific to each organization.
Underspending on security leads to breaches, compliance failures, and business disruption. Overspending diverts resources from business growth. This tool helps CISOs and IT leaders build defensible budget proposals grounded in industry benchmarks and risk-based analysis.
| Industry | Security as % of IT Budget | Security per Employee | Key Drivers |
|---|---|---|---|
| Financial Services | 8-14% | $2,500-$4,000 | Regulatory requirements, high-value targets |
| Healthcare | 5-10% | $1,500-$2,500 | HIPAA, PHI protection, ransomware targeting |
| Technology | 5-8% | $2,000-$3,500 | IP protection, customer data, competitive advantage |
| Government | 8-15% | $2,000-$3,000 | Compliance mandates, nation-state threats |
| Retail | 4-7% | $1,000-$2,000 | PCI DSS, payment data, customer trust |
| Manufacturing | 3-6% | $800-$1,500 | OT security, supply chain, IP protection |
| Category | Typical Allocation | Components |
|---|---|---|
| People | 40-50% | Security team salaries, training, certifications |
| Technology | 25-35% | Tools, platforms, licenses, cloud security services |
| Managed Services | 10-20% | MSSP, MDR, consulting, penetration testing |
| Compliance | 5-10% | Audits, assessments, certifications |
| Incident Response | 3-5% | Retainers, tabletop exercises, insurance |
Industry averages range from 10-15% of total IT budget, with highly regulated sectors (financial services, healthcare) allocating 15-20%. Gartner research suggests organizations spend 5.6% of IT budget on security on average, but this is increasing. Your allocation depends on risk tolerance, regulatory requirements, current security posture, and threat landscape. High-risk industries justify higher percentages.
Typical allocation: Personnel (40-50%), technology and tools (25-35%), training and awareness (5-10%), incident response and insurance (10-15%), compliance and audits (5-10%). Adjust based on maturity level—immature programs need more technology investment, mature programs emphasize personnel and process. Balance preventive controls with detection, response, and recovery capabilities for comprehensive protection.
Key factors include company size and revenue, industry and regulatory requirements, current security maturity, data sensitivity, threat exposure, geographic footprint, cloud vs. on-premises infrastructure, compliance mandates (HIPAA, PCI-DSS, SOC 2), recent security incidents, and merger/acquisition activity. Organizations handling sensitive data or operating in high-risk sectors require larger budgets.
Essential items: security staff salaries, endpoint protection, SIEM/log management, firewall and network security, vulnerability management, identity and access management, security awareness training, penetration testing, cyber insurance, incident response retainer, backup and disaster recovery, compliance audits, threat intelligence, and cloud security tools. Prioritize based on risk assessment and compliance requirements.
Quantify risk in business terms: potential breach costs (Ponemon reports average $4.45M per breach), regulatory fines, business disruption, and reputation damage. Compare investment to insurance—spending 5-15% of potential loss is reasonable. Show ROI through risk reduction, compliance achievement, and operational efficiency. Present peer benchmarks and industry standards. Frame security as business enabler.
Yes, cyber insurance is crucial risk transfer mechanism. Allocate 5-10% of security budget for premiums, typically $1,000-7,000 per $1M coverage depending on security posture. Insurance complements (not replaces) security controls. Coverage should include breach response, legal costs, notification expenses, and business interruption. Strong security controls reduce premiums significantly.
Small businesses (under 500 employees) spend $500-2,000 per employee annually on security. Mid-market (500-5,000) spends $300-1,000 per employee. Enterprises achieve economies of scale at $200-500 per employee. Smaller organizations face proportionally higher costs due to less specialized staff and fewer volume discounts. However, all sizes need baseline protections.
Conduct annual risk assessments to identify priorities. Align budget with business objectives and compliance requirements. Plan for 10-20% growth annually to address evolving threats. Include contingency (15-20%) for incidents and emergencies. Track spending and ROI metrics. Review quarterly and adjust based on threat landscape. Engage stakeholders early. Consider multi-year roadmaps for major initiatives.