Skip to content
Home » Blogs » How to build a defensible cyber securitybudget

How to build a defensible cyber securitybudget

A defensible cyber security budget starts with a risk assessment, not a shopping list. Identify
your most valuable assets, the threats most likely to hit them, and the potential impact. Then
allocate spend across people, process and technology so every pound maps to a specific
business risk you can defend to the board.

For many businesses, creating a cyber security budget feels like a bit of a guessing game.
Spend too little and you leave yourself exposed. Spend too much and you’re left trying to justify
costs to boards that don’t obviously contribute to revenue.

The reality is that a cyber security budget shouldn’t be built around guesswork, how many
vendor sales pitches you receive, or what you spent last year. It should be built around risk.

One of the biggest mistakes businesses make is simply rolling over the previous year’s budget.

The problem with that approach is that cyber threats don’t stand still. New vulnerabilities
emerge, businesses adopt new technology, employees work differently, and attackers
constantly change their tactics. If your budget isn’t evolving alongside those changes, there’s a
good chance it’s no longer protecting the parts of your business that matter most.

Start with a risk assessment, not a shopping list

If you’re wondering how to create a cyber security budget, the first step isn’t choosing new
security tools. It’s understanding what you’re actually trying to protect.

This is where risk-based budgeting comes in. Rather than buying cyber security solutions
because they’re popular or because a supplier recommends them, you identify the risks that are
most likely to affect your business and prioritise investment accordingly.

A formal risk assessment helps you answer questions such as:
● What are our most valuable assets?
● Which threats are most likely to affect us?
● What would the financial or operational impact be?
● Where are our biggest weaknesses?

Once you understand those answers, your cyber security budget becomes much easier to
justify, especially to the board, because every pound is linked to reducing a genuine business
risk rather than ticking a compliance box.

(Read more: Your guide to reporting cyber risk to your board)

How should you categorise cyber security spending?

An effective budget isn’t just about technology. Strong security comes from balancing
investment across people, processes and technical controls.

  1. People
    Employee awareness training is often seen as an optional extra, but the evidence says
    otherwise. The Verizon Data Breach Investigations Report found that the human element was
    present in 62% of breaches analysed in its 2026 edition.

    The data shows that investing in employee training is one of the highest-value areas of your
    cyber security budget. Helping people recognise phishing emails, use strong passwords and
    report suspicious activity can prevent incidents long before technology gets involved.
  2. Process
    Policies, incident response plans, backup testing and regular risk reviews all fall into this
    category.

    Good processes help people know what to do before, during and after an incident. They’re also
    increasingly important when demonstrating compliance to regulators, insurers and customers.
  3. Technology
    Technology still matters, of course. Firewalls, endpoint protection, multi-factor authentication,
    vulnerability management and monitoring tools all have an important role to play.
    The key is making sure those investments solve an identified business risk rather than simply
    adding another security product to the stack.

    A pattern we see repeatedly at Incursion Cyber Security in penetration testing engagements:
    organisations with substantial tooling budgets still failing on fundamentals that cost a fraction of
    the spend. An unpatched externally facing service, a shared admin credential, an MFA gap on a
    legacy VPN. Before you add another product to the stack, test whether the controls you already
    own actually work.

How do you justify cyber security spending to the board?

One of the biggest challenges for leaders is justifying cyber security spending to senior
management or the board.

The conversation becomes much easier when you stop talking about software and start talking
about risk.

    Instead of saying:
    “We need £15,000 for a new security platform.”
    Frame it in terms of business outcomes:
    “We’re investing £15,000 to reduce the likelihood of ransomware disrupting business
    operations.”

    Using recognised risk management terminology can also help. For example:

    ● We’re spending this amount to mitigate our highest risks.
    ● We’re transferring some financial risk through cyber insurance.
    ● We’ve chosen to accept certain low-level risks because the cost of removing them
    outweighs the potential impact.

    This approach makes the rationale for spending far easier to explain because every decision
    has a clear business justification.

    How much should you be spending on your cybersecurity?

    One of the most common questions we’re asked is how much UK organisations set aside each
    year.

    The IANS/Artico Security Budget Benchmark measured average security spend at 10.9% of IT
    budget in 2025, down from 11.9% in 2024, and analysts commonly recommend 10 to 15% for
    most organisations, more in regulated sectors. While that’s a useful benchmark, it shouldn’t
    become the target.

    A business handling sensitive customer data will almost certainly need to invest more than one
    operating in a lower-risk environment. Likewise, a company working towards certifications or
    meeting strict regulatory requirements may have very different priorities.

    Benchmarks provide context, but they shouldn’t replace a proper assessment of your own risks.

    Don’t forget the unexpected costs

    No matter how well prepared you are, incidents can still happen.

    The UK government’s Cyber Security Breaches Survey 2025/2026 found 43% of businesses
    identified a breach or attack in the past year, yet only 25% have a formal incident response
    plan.

    That’s why every cyber security budget for small, medium and enterprise businesses should
    include some provision for responding to an incident.

    For many organisations, maintaining a full-time incident response team isn’t realistic. A more
    practical option is an incident response retainer with a specialist cyber security provider.

    Budgeting for response is only half the picture. The cheapest incident is the one that never
    lands, which is why validation work such as penetration testing and Cyber Essentials belongs in
    the same budget line as your response provision.

    This gives you access to experienced professionals when you need them most without carrying
    the cost of employing a dedicated in-house team year-round. When every minute counts during
    a security incident, having experts ready to step in can make a significant difference to both
    recovery time and overall costs.

    Cyber security is an investment, not just a cost

    Cyber security can often be viewed as just another business expense, especially by boards who
    haven’t heard about why it matters to a business, but a well-planned budget delivers far more
    than technical protection.

    It helps reduce operational risk, supports regulatory compliance, strengthens customer
    confidence and demonstrates to auditors, insurers and clients that cyber risk is being managed
    in a structured and responsible way.

    When your budget is built around genuine business risks, it becomes much easier to explain
    where the money is going and why it’s being spent.

    Instead of being seen as a cost centre, cyber security becomes an investment in business
    resilience.

    Ready to build a budget that makes sense?

    If your current security budget is based on guesswork or simply repeats last year’s figures, now
    is the perfect time to take a different approach.

    We help you replace assumptions with evidence. A precisely scoped penetration test or Cyber
    Essentials assessment shows you exactly where your business needs investment, and where it
    doesn’t.

    Get in touch now for a chat about how we can help.

    Leave a Reply

    Your email address will not be published. Required fields are marked *