A defensible cyber security budget starts with a risk assessment, not a shopping list. Identify
your most valuable assets, the threats most likely to hit them, and the potential impact. Then
allocate spend across people, process and technology so every pound maps to a specific
business risk you can defend to the board.
For many businesses, creating a cyber security budget feels like a bit of a guessing game.
Spend too little and you leave yourself exposed. Spend too much and you’re left trying to justify
costs to boards that don’t obviously contribute to revenue.
The reality is that a cyber security budget shouldn’t be built around guesswork, how many
vendor sales pitches you receive, or what you spent last year. It should be built around risk.
One of the biggest mistakes businesses make is simply rolling over the previous year’s budget.
The problem with that approach is that cyber threats don’t stand still. New vulnerabilities
emerge, businesses adopt new technology, employees work differently, and attackers
constantly change their tactics. If your budget isn’t evolving alongside those changes, there’s a
good chance it’s no longer protecting the parts of your business that matter most.
Start with a risk assessment, not a shopping list
If you’re wondering how to create a cyber security budget, the first step isn’t choosing new
security tools. It’s understanding what you’re actually trying to protect.
This is where risk-based budgeting comes in. Rather than buying cyber security solutions
because they’re popular or because a supplier recommends them, you identify the risks that are
most likely to affect your business and prioritise investment accordingly.
A formal risk assessment helps you answer questions such as:
● What are our most valuable assets?
● Which threats are most likely to affect us?
● What would the financial or operational impact be?
● Where are our biggest weaknesses?
Once you understand those answers, your cyber security budget becomes much easier to
justify, especially to the board, because every pound is linked to reducing a genuine business
risk rather than ticking a compliance box.
(Read more: Your guide to reporting cyber risk to your board)
How should you categorise cyber security spending?
An effective budget isn’t just about technology. Strong security comes from balancing
investment across people, processes and technical controls.
- People
Employee awareness training is often seen as an optional extra, but the evidence says
otherwise. The Verizon Data Breach Investigations Report found that the human element was
present in 62% of breaches analysed in its 2026 edition.
The data shows that investing in employee training is one of the highest-value areas of your
cyber security budget. Helping people recognise phishing emails, use strong passwords and
report suspicious activity can prevent incidents long before technology gets involved. - Process
Policies, incident response plans, backup testing and regular risk reviews all fall into this
category.
Good processes help people know what to do before, during and after an incident. They’re also
increasingly important when demonstrating compliance to regulators, insurers and customers. - Technology
Technology still matters, of course. Firewalls, endpoint protection, multi-factor authentication,
vulnerability management and monitoring tools all have an important role to play.
The key is making sure those investments solve an identified business risk rather than simply
adding another security product to the stack.
A pattern we see repeatedly at Incursion Cyber Security in penetration testing engagements:
organisations with substantial tooling budgets still failing on fundamentals that cost a fraction of
the spend. An unpatched externally facing service, a shared admin credential, an MFA gap on a
legacy VPN. Before you add another product to the stack, test whether the controls you already
own actually work.
How do you justify cyber security spending to the board?
One of the biggest challenges for leaders is justifying cyber security spending to senior
management or the board.
The conversation becomes much easier when you stop talking about software and start talking
about risk.
Instead of saying:
“We need £15,000 for a new security platform.”
Frame it in terms of business outcomes:
“We’re investing £15,000 to reduce the likelihood of ransomware disrupting business
operations.”
Using recognised risk management terminology can also help. For example:
● We’re spending this amount to mitigate our highest risks.
● We’re transferring some financial risk through cyber insurance.
● We’ve chosen to accept certain low-level risks because the cost of removing them
outweighs the potential impact.
This approach makes the rationale for spending far easier to explain because every decision
has a clear business justification.
How much should you be spending on your cybersecurity?
One of the most common questions we’re asked is how much UK organisations set aside each
year.
The IANS/Artico Security Budget Benchmark measured average security spend at 10.9% of IT
budget in 2025, down from 11.9% in 2024, and analysts commonly recommend 10 to 15% for
most organisations, more in regulated sectors. While that’s a useful benchmark, it shouldn’t
become the target.
A business handling sensitive customer data will almost certainly need to invest more than one
operating in a lower-risk environment. Likewise, a company working towards certifications or
meeting strict regulatory requirements may have very different priorities.
Benchmarks provide context, but they shouldn’t replace a proper assessment of your own risks.
Don’t forget the unexpected costs
No matter how well prepared you are, incidents can still happen.
The UK government’s Cyber Security Breaches Survey 2025/2026 found 43% of businesses
identified a breach or attack in the past year, yet only 25% have a formal incident response
plan.
That’s why every cyber security budget for small, medium and enterprise businesses should
include some provision for responding to an incident.
For many organisations, maintaining a full-time incident response team isn’t realistic. A more
practical option is an incident response retainer with a specialist cyber security provider.
Budgeting for response is only half the picture. The cheapest incident is the one that never
lands, which is why validation work such as penetration testing and Cyber Essentials belongs in
the same budget line as your response provision.
This gives you access to experienced professionals when you need them most without carrying
the cost of employing a dedicated in-house team year-round. When every minute counts during
a security incident, having experts ready to step in can make a significant difference to both
recovery time and overall costs.
Cyber security is an investment, not just a cost
Cyber security can often be viewed as just another business expense, especially by boards who
haven’t heard about why it matters to a business, but a well-planned budget delivers far more
than technical protection.
It helps reduce operational risk, supports regulatory compliance, strengthens customer
confidence and demonstrates to auditors, insurers and clients that cyber risk is being managed
in a structured and responsible way.
When your budget is built around genuine business risks, it becomes much easier to explain
where the money is going and why it’s being spent.
Instead of being seen as a cost centre, cyber security becomes an investment in business
resilience.
Ready to build a budget that makes sense?
If your current security budget is based on guesswork or simply repeats last year’s figures, now
is the perfect time to take a different approach.
We help you replace assumptions with evidence. A precisely scoped penetration test or Cyber
Essentials assessment shows you exactly where your business needs investment, and where it
doesn’t.
Get in touch now for a chat about how we can help.