Research date: September 14–15, 2026. Figures marked [measured] come from published survey or incident data; [estimate] marks vendor figures, self-reported projections, or composite market ranges. Where a figure is widely repeated but methodologically weak, that is flagged. Educational material, not financial advice.
1. What the world spends
Gartner forecast worldwide end-user spending on information security at $213 billion in 2025, up from $193B in 2024, with subsequent Gartner-based analysis putting 2026 around $244B. Against Gartner's forecast of $6.15 trillion in total worldwide IT spending for 2026, security is roughly 4% of global IT spend at the macro level — though individual-organization benchmarks run much higher, because Gartner's IT figure includes telecom and devices.
2. Security budgets as a share of IT spend
The best public benchmark is the IANS Research / Artico Search Security Budget Benchmark, surveying 587 CISOs in April 2025 [measured, self-reported]:
| Metric | 2024 | 2025 |
|---|---|---|
| Security budget growth, year over year | 8% | 4% — a five-year low |
| Security as a share of IT spend | 11.9% | 10.9% |
| Security as a share of revenue | ~0.7% | ~0.69% |
| CISOs reporting flat or shrinking budgets | — | more than 50% |
| Security staffing growth | — | 7% — a four-year low |
| CISOs who say they are adequately staffed | — | 11% |
Size effects matter more than most benchmarks admit. Companies under $50M in revenue average roughly 26% of IT budget on security, because fixed costs do not scale down, falling to about 11.6% for firms between $600M and $1B.
The rule of thumb for the site: 5–15% of IT spend is normal; below 5% is a red flag for anything holding sensitive data; small companies should expect a higher percentage, not a lower one. Financial services and healthcare sit at the high end; manufacturing and retail historically at the low end.
3. What things actually cost
Tools, per user or per endpoint at list price [estimate — negotiated prices vary widely]: password manager for business roughly $3–$8 per user per month; business EDR roughly $3–$12 per endpoint per month; email security add-on roughly $2–$6 per user per month; security awareness and phishing simulation roughly $1–$4 per user per month; SIEM from free, self-hosting Wazuh or Elastic, to $100K–$1M+ per year at enterprise data volumes. Worth naming explicitly: the "SSO tax" on SaaS products, where enabling single sign-on often forces a plan upgrade costing two to four times the per-seat price — a real and underdiscussed barrier to small organizations doing the right thing.
Staffing, fully loaded at roughly salary times 1.25 to 1.4. A minimal 24/7 in-house SOC needs eight to ten analysts and runs well over $1M per year [estimate] — which is the core argument for outsourcing detection below roughly 1,000 employees.
MDR and MSSP. SMB-market MDR commonly retails around $5–$15 per endpoint per month [estimate], with organization-level contracts covering a mid-size environment at $50,000–$300,000+ per year. Only Huntress ($7.99 per endpoint per month at 100 endpoints) and Red Canary ($10 per endpoint per month via AWS Marketplace) publish rates; everyone else is quote-only.
Incident-response retainers. $10,000–$100,000 per year, with entry agreements around $25,000 [estimate]. Many insurers now include panel-firm access, which makes a separately paid retainer optional for small firms — a useful cost-saving point for the audience.
Penetration testing [vendor estimate, consistent across multiple 2026 buyer's guides]:
| Test type | Typical range |
|---|---|
| Web application | $5,000–$50,000 |
| Network | $150–$1,000 per device |
| Mobile app | $5,000–$40,000 |
| API | $5,000–$30,000 |
| Cloud environment | $5,000–$50,000 |
| Internal network | $10,000–$40,000 |
| Red team | $10,000–$100,000+ |
A credible small-scope test from a reputable boutique rarely comes in under $10K–$20K. A "$500 pentest" is a vulnerability scan with a report template. Price drivers: scope and complexity, manual versus automated methodology, tester credentials, compliance context, and whether retesting is included.
Compliance audits [estimate — audit-market composite]: SOC 2 Type 1 auditor fees roughly $7,500–$20,000; Type 2 roughly $12,000–$60,000, with Big Four or complex scope exceeding $100K. First-year SOC 2 total — audit plus automation platform plus penetration test plus staff time — commonly $30,000–$150,000. ISO 27001 certification audit roughly $10,000–$50,000, with a realistic first-year program total of $40,000–$150,000 plus annual surveillance audits. Compliance-automation platforms (Vanta, Drata, Secureframe) commonly report entry contracts around $8,000–$25,000 per year for startups, scaling past $50K with more frameworks and headcount — none publishes list prices, so these are market-reported estimates. They compress audit preparation dramatically but do not replace the auditor's fee.
Cyber insurance. The global market reached roughly $16.3B in 2025 [measured]. Rates have been softening: US average decreases of about 5% in Q4 2024, with a soft market continuing through 2025, and eight consecutive quarters of rate cuts through Q1 2026. But the industry loss ratio rose to roughly 53 — above 50 for the first time since the pandemic-era ransomware spike — with third-party liability claims up about 30% year over year. Chubb led 2025 direct premium; Zurich's acquisition of Beazley will make it the largest cyber insurer going forward. Analysts warn 2026 is a turning point: falling prices plus rising loss ratios plus AI-related claims are not sustainable, so expect requirement tightening and possible re-hardening.
SMB premiums for a $1M limit typically run $1,500–$3,500 per year [estimate]. Only about 17% of small businesses carry cyber insurance, versus 70–80% of large enterprises.
Underwriting now enforces controls — MFA especially on remote access and privileged accounts, EDR, tested offline backups, email authentication, patch and end-of-life management, and an exercised IR plan. Insurtech carriers Coalition and At-Bay pioneered "active insurance," continuously scanning policyholders and alerting them to exposed services as a condition of coverage. Marsh found automated hardening had the greatest ability of any control studied to reduce successful-attack likelihood [measured, insurer claims data].
The framing that lands with small businesses: the insurance application is a free minimum-security checklist. And misrepresenting controls on that application is a leading cause of disputed claims — in Travelers v. ICS (2022) a policy was rescinded over a false MFA attestation.
4. What incidents cost
Breach costs — IBM / Ponemon Cost of a Data Breach [measured survey, with major caveats]. The 2025 edition put the global average at $4.44M, down 9% from $4.88M — the first decline in five years, attributed to faster identification and containment — with the US average at a record ~$10.22M and mean time to identify and contain at 241 days, a nine-year low. The 2026 edition reported a global average of $4.99M, a record and up 12%, with AI-enabled breaches averaging about $6M.
The methodology caveats belong on the page, not in a footnote. IBM's numbers come from Ponemon interviews with roughly 600 breached organizations, use activity-based costing that includes soft costs such as lost business and diverted staff time, exclude mega-breaches, and average across mostly mid-to-large enterprises. They are directionally useful and not predictive for a ten-person company, which will not incur $4.4M. Per-record extrapolations from this dataset are explicitly discouraged, and Verizon's DBIR team has publicly criticized their misuse. Treat it as the best longitudinal index of enterprise breach cost, not a price list.
Ransomware: the ransom is a minority of the cost. This is the single most important teaching point in security economics.
- Coveware Q2 2025: average payment roughly $1.13M, driven by data-exfiltration extortion.
- Coveware Q2 2026: average $1.88M but median $150K, with an overall record-low payment rate and only 15% of exfiltration-only victims paying. The average-versus-median gap here is a perfect statistics lesson for readers.
- Sophos State of Ransomware 2025, surveying 3,400 IT leaders: about 50% paid, with a median payment of $1M against a median demand of $1.32M, average recovery cost excluding ransom of $1.53M (down from $2.73M in 2024), 53% fully recovering within a week, and only 54% restoring from backups — a six-year low.
- Verizon DBIR 2025 put ransomware in 44% of breaches with a median ransom paid of $115K in a small-org-inclusive dataset — note how much lower that is than Sophos's enterprise-skewed median. DBIR 2026 put ransomware in 48% of breaches with shrinking payouts.
- Chainalysis: total crypto ransom payments fell roughly 35% year over year to about $813M in 2024 and fell again in 2025 to roughly $820M.
- Paying does not fix it. Fortinet data indicates 97% recover some data but only about 4% recover all of it, and roughly 80% of payers are attacked again within twelve months [estimate — vendor surveys].
Downtime. Full operational recovery has a long tail — Sophos found median full-restoration timelines exceeding 100 days in some sectors, with government averaging around 140 days [estimate]. Generic per-minute downtime figures ranging from roughly $400 for SMBs to $9,000+ for enterprises are widely cited but dated. Better to teach downtime cost as a formula readers compute for themselves: revenue per hour, plus payroll per hour, plus recovery spend, plus the reputational tail.
5. Return on security investment
FAIR — Factor Analysis of Information Risk — is the open standard for expressing cyber risk in dollars: risk equals loss event frequency times loss magnitude, estimated with calibrated ranges and Monte Carlo simulation rather than red-yellow-green heat maps. Its strength is turning "should we buy this?" into a comparable financial question. Its weakness is garbage in, garbage out — frequency estimates for rare events carry enormous uncertainty, so it is best used for ranking risks and sizing insurance rather than producing false precision.
ROSI = (risk reduction value − cost of control) / cost of control. Honest versions use FAIR-style ranges rather than point estimates.
The practical alternative for small organizations: benchmark against insurer requirements and CIS IG1. The controls insurers price into premiums — MFA, EDR, tested backups — are the ones with the best claims-data evidence of loss reduction. That is a cheaper and more defensible proxy than building a quantification program.
6. The workforce numbers, handled honestly
ISC2's 2024 study claimed a global workforce of roughly 5.5 million and a gap of about 4.8 million. The 2025 study conspicuously de-emphasized the headline gap and reframed the problem as a skills gap rather than a headcount gap: 59% report critical or significant skills needs, up from 44%, while 24% experienced layoffs, 36% budget cuts, 39% hiring freezes, and only 4% report any staff surplus.
Why the multi-million gap claim deserves scrutiny. It is derived by surveying security managers about desired headcount and extrapolating globally — it counts wishes, not funded requisitions. A gap of millions is hard to reconcile with simultaneous layoffs at a quarter of organizations, hiring freezes at nearly 40%, and the observable difficulty juniors have landing a first role. Practitioners have long argued the figure functions as training-industry marketing.
Grounded demand data. CyberSeek recorded 514,359 US cybersecurity job listings between May 2024 and April 2025 [measured job-postings data] — real demand, but concentrated at mid and senior levels, with only about 10% of listings referencing AI skills. BLS projects 21% growth for information security analysts from 2025 to 2035 on a base of 192,900 jobs, with median pay of $129,180 [measured projection].
The honest bottom line: demand is real and growing for experienced practitioners; the entry level is oversupplied and difficult in 2025–26.
7. Open source versus commercial
| Need | Credible free/open source | Commercial equivalent | Trade-off |
|---|---|---|---|
| SIEM / log analysis | Wazuh, Elastic Basic, Security Onion | Splunk, Sentinel, NG-SIEM | OSS costs engineering time; ingest pricing punishes verbosity |
| EDR | Wazuh plus Sysmon plus osquery (partial) | CrowdStrike, Defender, SentinelOne | Commercial detection quality and response tooling are materially better; Defender is bundled in M365 Business Premium |
| Vulnerability scanning | OpenVAS/Greenbone, Nuclei | Tenable, Qualys, Rapid7 | Commercial buys coverage, reporting, prioritization |
| Network monitoring | Zeek, Suricata | Corelight, Darktrace | The same engines underneath — Corelight is Zeek |
| Password management | Bitwarden free tier, KeePassXC | 1Password, Bitwarden Teams | Cheap enough that free versus paid rarely matters; adoption matters |
| MDR | No substitute | Huntress, Expel, Arctic Wolf | MDR is people; this is where you pay |
The rule: open source trades license fees for skilled labor. Below roughly one full-time equivalent of security engineering, bundled commercial suites — Microsoft 365 or Google Workspace security tiers — usually win on total cost.
8. Six realistic annual budgets
All figures are estimates built from the pricing above, with assumptions stated so readers can adapt them.
1. Individual — $0–$300 per year
Assumes personal devices and cloud accounts, no business assets. Password manager $0 (Bitwarden free or platform built-in) to $36. Two hardware security keys, one-time, roughly $30–$60. Automatic updates, disk encryption, and built-in MFA: $0. Cloud backup roughly $0–$120, or an encrypted external drive. Credit freezes: free and high-value. A reputable VPN only if genuinely needed for untrusted networks, $0–$60. Teaching point: the highest-ROI controls for individuals are free.
2. Ten-person small business — $10,000–$30,000 per year
Assumes no dedicated IT or security staff, outsourced to an MSP, on Microsoft 365 or Google Workspace. M365 Business Premium at roughly $26.40 per user per month ≈ $3,170. Password manager for ten seats, $400–$700. Managed EDR or MDR, $600–$1,800. Backup for SaaS and endpoints, tested, $1,000–$2,500. Phishing training, $250–$500. Cyber insurance at $1M limit, $1,500–$3,000. MSP security management share, $2,000–$15,000. Annual external vulnerability assessment, not a full penetration test, $1,000–$5,000. No SIEM, no penetration test, no compliance platform unless a customer demands it.
3. Fifty-person B2B SaaS startup — $280,000–$460,000 per year
Assumes SOC 2 pressure from customers, cloud-native on AWS, first security hire. One security engineer fully loaded, $180,000–$230,000. SOC 2 Type 2: automation platform $15,000–$25,000 plus auditor $20,000–$40,000. Annual web application and cloud penetration test, $15,000–$30,000. EDR, identity, email security, and password management for 50 seats, $15,000–$30,000. MDR, $25,000–$60,000. Cloud security posture, $0–$25,000. Cyber and E&O insurance, $5,000–$15,000. Awareness training and a tabletop exercise, $3,000–$8,000. Roughly half is one salary — staffing dominates security economics at every size.
4. Five-hundred-person mid-size company — $1.5M–$3.5M per year
Assumes roughly $100M revenue and an $8–12M IT budget, so 10–15% of IT. A team of four to seven (CISO or director, two to three engineers, a GRC analyst, an IR/SOC lead), $900K–$1.6M loaded. Managed SOC, $100K–$300K. Tooling stack covering EDR, SIEM, identity and PAM, email, vulnerability management, and CSPM, $250K–$700K. Penetration testing plus light purple teaming, $40K–$120K. Compliance, $60K–$150K. Insurance at $5–10M limits, $50K–$150K. IR retainer, training, and awareness, $50K–$120K.
5. Regulated enterprise, 5,000+ employees — $20M–$60M+ per year
Assumes $2–5B revenue, financial-sector norms near the top of the IANS range. Security organization of 50–150 FTE, $10M–$30M. Hybrid 24/7 SOC, threat intelligence, and red team, $3M–$10M. Enterprise tool stack plus data security and fraud, $5M–$15M. Compliance and audit across SOX, PCI, HIPAA or GLBA, state regulations, and DORA if EU-exposed, $2M–$8M. Insurance tower at $50M+ limits, $1M–$3M+. Roughly 0.5–1.5% of revenue.
6. Critical-infrastructure operator, mid-size utility (~1,500 employees) — $8M–$25M per year
Everything in tier 4 plus OT: asset inventory and passive monitoring for OT networks (Claroty or Dragos class, roughly $500K–$2M), IT/OT segmentation projects, which are capital expenditure often exceeding $1M across multiple years, NERC CIP or TSA directive compliance staffing, engineering-workstation hardening, and OT-specific IR retainers. Benchmarked against the CISA CPGs as the regulator-recognized floor. Key teaching point: OT security budgets are dominated by engineering and segmentation projects, not software licenses.
9. Five economic arguments worth making on the site
- The ransom is a minority of ransomware cost. Recovery, downtime, notification, legal, and insurance consequences dwarf it — and paying does not reliably restore data or prevent recurrence.
- Staffing dominates every budget at every size. Any analysis that compares tool prices without comparing operating burden is wrong.
- Free controls carry the most weight at the small end. Credit freezes, MFA, updates, DMARC, and CISA's free services genuinely move the needle for individuals and small businesses.
- The insurance application is a free security checklist — and truthfully meeting what it asks is both cheaper than a breach and a precondition of the claim paying.
- Buying maturity you cannot operate is the most expensive mistake available. Threat intelligence platforms and deception technology purchased at Level 1 maturity are pure waste; the maturity model in
13-risks-and-pitfalls.mdexists to sequence spending.