patch&proof.
← Research library

Economics / Research chapter

Cybersecurity Economics

Research date: September 14–15, 2026. Figures marked measured come from published survey or incident data; estimate marks vendor figures, self-reported projecti

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Research date: September 14–15, 2026. Figures marked [measured] come from published survey or incident data; [estimate] marks vendor figures, self-reported projections, or composite market ranges. Where a figure is widely repeated but methodologically weak, that is flagged. Educational material, not financial advice.


1. What the world spends

Gartner forecast worldwide end-user spending on information security at $213 billion in 2025, up from $193B in 2024, with subsequent Gartner-based analysis putting 2026 around $244B. Against Gartner's forecast of $6.15 trillion in total worldwide IT spending for 2026, security is roughly 4% of global IT spend at the macro level — though individual-organization benchmarks run much higher, because Gartner's IT figure includes telecom and devices.

2. Security budgets as a share of IT spend

The best public benchmark is the IANS Research / Artico Search Security Budget Benchmark, surveying 587 CISOs in April 2025 [measured, self-reported]:

Metric 2024 2025
Security budget growth, year over year 8% 4% — a five-year low
Security as a share of IT spend 11.9% 10.9%
Security as a share of revenue ~0.7% ~0.69%
CISOs reporting flat or shrinking budgets more than 50%
Security staffing growth 7% — a four-year low
CISOs who say they are adequately staffed 11%

Size effects matter more than most benchmarks admit. Companies under $50M in revenue average roughly 26% of IT budget on security, because fixed costs do not scale down, falling to about 11.6% for firms between $600M and $1B.

The rule of thumb for the site: 5–15% of IT spend is normal; below 5% is a red flag for anything holding sensitive data; small companies should expect a higher percentage, not a lower one. Financial services and healthcare sit at the high end; manufacturing and retail historically at the low end.

3. What things actually cost

Tools, per user or per endpoint at list price [estimate — negotiated prices vary widely]: password manager for business roughly $3–$8 per user per month; business EDR roughly $3–$12 per endpoint per month; email security add-on roughly $2–$6 per user per month; security awareness and phishing simulation roughly $1–$4 per user per month; SIEM from free, self-hosting Wazuh or Elastic, to $100K–$1M+ per year at enterprise data volumes. Worth naming explicitly: the "SSO tax" on SaaS products, where enabling single sign-on often forces a plan upgrade costing two to four times the per-seat price — a real and underdiscussed barrier to small organizations doing the right thing.

Staffing, fully loaded at roughly salary times 1.25 to 1.4. A minimal 24/7 in-house SOC needs eight to ten analysts and runs well over $1M per year [estimate] — which is the core argument for outsourcing detection below roughly 1,000 employees.

MDR and MSSP. SMB-market MDR commonly retails around $5–$15 per endpoint per month [estimate], with organization-level contracts covering a mid-size environment at $50,000–$300,000+ per year. Only Huntress ($7.99 per endpoint per month at 100 endpoints) and Red Canary ($10 per endpoint per month via AWS Marketplace) publish rates; everyone else is quote-only.

Incident-response retainers. $10,000–$100,000 per year, with entry agreements around $25,000 [estimate]. Many insurers now include panel-firm access, which makes a separately paid retainer optional for small firms — a useful cost-saving point for the audience.

Penetration testing [vendor estimate, consistent across multiple 2026 buyer's guides]:

Test type Typical range
Web application $5,000–$50,000
Network $150–$1,000 per device
Mobile app $5,000–$40,000
API $5,000–$30,000
Cloud environment $5,000–$50,000
Internal network $10,000–$40,000
Red team $10,000–$100,000+

A credible small-scope test from a reputable boutique rarely comes in under $10K–$20K. A "$500 pentest" is a vulnerability scan with a report template. Price drivers: scope and complexity, manual versus automated methodology, tester credentials, compliance context, and whether retesting is included.

Compliance audits [estimate — audit-market composite]: SOC 2 Type 1 auditor fees roughly $7,500–$20,000; Type 2 roughly $12,000–$60,000, with Big Four or complex scope exceeding $100K. First-year SOC 2 total — audit plus automation platform plus penetration test plus staff time — commonly $30,000–$150,000. ISO 27001 certification audit roughly $10,000–$50,000, with a realistic first-year program total of $40,000–$150,000 plus annual surveillance audits. Compliance-automation platforms (Vanta, Drata, Secureframe) commonly report entry contracts around $8,000–$25,000 per year for startups, scaling past $50K with more frameworks and headcount — none publishes list prices, so these are market-reported estimates. They compress audit preparation dramatically but do not replace the auditor's fee.

Cyber insurance. The global market reached roughly $16.3B in 2025 [measured]. Rates have been softening: US average decreases of about 5% in Q4 2024, with a soft market continuing through 2025, and eight consecutive quarters of rate cuts through Q1 2026. But the industry loss ratio rose to roughly 53 — above 50 for the first time since the pandemic-era ransomware spike — with third-party liability claims up about 30% year over year. Chubb led 2025 direct premium; Zurich's acquisition of Beazley will make it the largest cyber insurer going forward. Analysts warn 2026 is a turning point: falling prices plus rising loss ratios plus AI-related claims are not sustainable, so expect requirement tightening and possible re-hardening.

SMB premiums for a $1M limit typically run $1,500–$3,500 per year [estimate]. Only about 17% of small businesses carry cyber insurance, versus 70–80% of large enterprises.

Underwriting now enforces controls — MFA especially on remote access and privileged accounts, EDR, tested offline backups, email authentication, patch and end-of-life management, and an exercised IR plan. Insurtech carriers Coalition and At-Bay pioneered "active insurance," continuously scanning policyholders and alerting them to exposed services as a condition of coverage. Marsh found automated hardening had the greatest ability of any control studied to reduce successful-attack likelihood [measured, insurer claims data].

The framing that lands with small businesses: the insurance application is a free minimum-security checklist. And misrepresenting controls on that application is a leading cause of disputed claims — in Travelers v. ICS (2022) a policy was rescinded over a false MFA attestation.

4. What incidents cost

Breach costs — IBM / Ponemon Cost of a Data Breach [measured survey, with major caveats]. The 2025 edition put the global average at $4.44M, down 9% from $4.88M — the first decline in five years, attributed to faster identification and containment — with the US average at a record ~$10.22M and mean time to identify and contain at 241 days, a nine-year low. The 2026 edition reported a global average of $4.99M, a record and up 12%, with AI-enabled breaches averaging about $6M.

The methodology caveats belong on the page, not in a footnote. IBM's numbers come from Ponemon interviews with roughly 600 breached organizations, use activity-based costing that includes soft costs such as lost business and diverted staff time, exclude mega-breaches, and average across mostly mid-to-large enterprises. They are directionally useful and not predictive for a ten-person company, which will not incur $4.4M. Per-record extrapolations from this dataset are explicitly discouraged, and Verizon's DBIR team has publicly criticized their misuse. Treat it as the best longitudinal index of enterprise breach cost, not a price list.

Ransomware: the ransom is a minority of the cost. This is the single most important teaching point in security economics.

  • Coveware Q2 2025: average payment roughly $1.13M, driven by data-exfiltration extortion.
  • Coveware Q2 2026: average $1.88M but median $150K, with an overall record-low payment rate and only 15% of exfiltration-only victims paying. The average-versus-median gap here is a perfect statistics lesson for readers.
  • Sophos State of Ransomware 2025, surveying 3,400 IT leaders: about 50% paid, with a median payment of $1M against a median demand of $1.32M, average recovery cost excluding ransom of $1.53M (down from $2.73M in 2024), 53% fully recovering within a week, and only 54% restoring from backups — a six-year low.
  • Verizon DBIR 2025 put ransomware in 44% of breaches with a median ransom paid of $115K in a small-org-inclusive dataset — note how much lower that is than Sophos's enterprise-skewed median. DBIR 2026 put ransomware in 48% of breaches with shrinking payouts.
  • Chainalysis: total crypto ransom payments fell roughly 35% year over year to about $813M in 2024 and fell again in 2025 to roughly $820M.
  • Paying does not fix it. Fortinet data indicates 97% recover some data but only about 4% recover all of it, and roughly 80% of payers are attacked again within twelve months [estimate — vendor surveys].

Downtime. Full operational recovery has a long tail — Sophos found median full-restoration timelines exceeding 100 days in some sectors, with government averaging around 140 days [estimate]. Generic per-minute downtime figures ranging from roughly $400 for SMBs to $9,000+ for enterprises are widely cited but dated. Better to teach downtime cost as a formula readers compute for themselves: revenue per hour, plus payroll per hour, plus recovery spend, plus the reputational tail.

5. Return on security investment

FAIR — Factor Analysis of Information Risk — is the open standard for expressing cyber risk in dollars: risk equals loss event frequency times loss magnitude, estimated with calibrated ranges and Monte Carlo simulation rather than red-yellow-green heat maps. Its strength is turning "should we buy this?" into a comparable financial question. Its weakness is garbage in, garbage out — frequency estimates for rare events carry enormous uncertainty, so it is best used for ranking risks and sizing insurance rather than producing false precision.

ROSI = (risk reduction value − cost of control) / cost of control. Honest versions use FAIR-style ranges rather than point estimates.

The practical alternative for small organizations: benchmark against insurer requirements and CIS IG1. The controls insurers price into premiums — MFA, EDR, tested backups — are the ones with the best claims-data evidence of loss reduction. That is a cheaper and more defensible proxy than building a quantification program.

6. The workforce numbers, handled honestly

ISC2's 2024 study claimed a global workforce of roughly 5.5 million and a gap of about 4.8 million. The 2025 study conspicuously de-emphasized the headline gap and reframed the problem as a skills gap rather than a headcount gap: 59% report critical or significant skills needs, up from 44%, while 24% experienced layoffs, 36% budget cuts, 39% hiring freezes, and only 4% report any staff surplus.

Why the multi-million gap claim deserves scrutiny. It is derived by surveying security managers about desired headcount and extrapolating globally — it counts wishes, not funded requisitions. A gap of millions is hard to reconcile with simultaneous layoffs at a quarter of organizations, hiring freezes at nearly 40%, and the observable difficulty juniors have landing a first role. Practitioners have long argued the figure functions as training-industry marketing.

Grounded demand data. CyberSeek recorded 514,359 US cybersecurity job listings between May 2024 and April 2025 [measured job-postings data] — real demand, but concentrated at mid and senior levels, with only about 10% of listings referencing AI skills. BLS projects 21% growth for information security analysts from 2025 to 2035 on a base of 192,900 jobs, with median pay of $129,180 [measured projection].

The honest bottom line: demand is real and growing for experienced practitioners; the entry level is oversupplied and difficult in 2025–26.

7. Open source versus commercial

Need Credible free/open source Commercial equivalent Trade-off
SIEM / log analysis Wazuh, Elastic Basic, Security Onion Splunk, Sentinel, NG-SIEM OSS costs engineering time; ingest pricing punishes verbosity
EDR Wazuh plus Sysmon plus osquery (partial) CrowdStrike, Defender, SentinelOne Commercial detection quality and response tooling are materially better; Defender is bundled in M365 Business Premium
Vulnerability scanning OpenVAS/Greenbone, Nuclei Tenable, Qualys, Rapid7 Commercial buys coverage, reporting, prioritization
Network monitoring Zeek, Suricata Corelight, Darktrace The same engines underneath — Corelight is Zeek
Password management Bitwarden free tier, KeePassXC 1Password, Bitwarden Teams Cheap enough that free versus paid rarely matters; adoption matters
MDR No substitute Huntress, Expel, Arctic Wolf MDR is people; this is where you pay

The rule: open source trades license fees for skilled labor. Below roughly one full-time equivalent of security engineering, bundled commercial suites — Microsoft 365 or Google Workspace security tiers — usually win on total cost.

8. Six realistic annual budgets

All figures are estimates built from the pricing above, with assumptions stated so readers can adapt them.

1. Individual — $0–$300 per year

Assumes personal devices and cloud accounts, no business assets. Password manager $0 (Bitwarden free or platform built-in) to $36. Two hardware security keys, one-time, roughly $30–$60. Automatic updates, disk encryption, and built-in MFA: $0. Cloud backup roughly $0–$120, or an encrypted external drive. Credit freezes: free and high-value. A reputable VPN only if genuinely needed for untrusted networks, $0–$60. Teaching point: the highest-ROI controls for individuals are free.

2. Ten-person small business — $10,000–$30,000 per year

Assumes no dedicated IT or security staff, outsourced to an MSP, on Microsoft 365 or Google Workspace. M365 Business Premium at roughly $26.40 per user per month ≈ $3,170. Password manager for ten seats, $400–$700. Managed EDR or MDR, $600–$1,800. Backup for SaaS and endpoints, tested, $1,000–$2,500. Phishing training, $250–$500. Cyber insurance at $1M limit, $1,500–$3,000. MSP security management share, $2,000–$15,000. Annual external vulnerability assessment, not a full penetration test, $1,000–$5,000. No SIEM, no penetration test, no compliance platform unless a customer demands it.

3. Fifty-person B2B SaaS startup — $280,000–$460,000 per year

Assumes SOC 2 pressure from customers, cloud-native on AWS, first security hire. One security engineer fully loaded, $180,000–$230,000. SOC 2 Type 2: automation platform $15,000–$25,000 plus auditor $20,000–$40,000. Annual web application and cloud penetration test, $15,000–$30,000. EDR, identity, email security, and password management for 50 seats, $15,000–$30,000. MDR, $25,000–$60,000. Cloud security posture, $0–$25,000. Cyber and E&O insurance, $5,000–$15,000. Awareness training and a tabletop exercise, $3,000–$8,000. Roughly half is one salary — staffing dominates security economics at every size.

4. Five-hundred-person mid-size company — $1.5M–$3.5M per year

Assumes roughly $100M revenue and an $8–12M IT budget, so 10–15% of IT. A team of four to seven (CISO or director, two to three engineers, a GRC analyst, an IR/SOC lead), $900K–$1.6M loaded. Managed SOC, $100K–$300K. Tooling stack covering EDR, SIEM, identity and PAM, email, vulnerability management, and CSPM, $250K–$700K. Penetration testing plus light purple teaming, $40K–$120K. Compliance, $60K–$150K. Insurance at $5–10M limits, $50K–$150K. IR retainer, training, and awareness, $50K–$120K.

5. Regulated enterprise, 5,000+ employees — $20M–$60M+ per year

Assumes $2–5B revenue, financial-sector norms near the top of the IANS range. Security organization of 50–150 FTE, $10M–$30M. Hybrid 24/7 SOC, threat intelligence, and red team, $3M–$10M. Enterprise tool stack plus data security and fraud, $5M–$15M. Compliance and audit across SOX, PCI, HIPAA or GLBA, state regulations, and DORA if EU-exposed, $2M–$8M. Insurance tower at $50M+ limits, $1M–$3M+. Roughly 0.5–1.5% of revenue.

6. Critical-infrastructure operator, mid-size utility (~1,500 employees) — $8M–$25M per year

Everything in tier 4 plus OT: asset inventory and passive monitoring for OT networks (Claroty or Dragos class, roughly $500K–$2M), IT/OT segmentation projects, which are capital expenditure often exceeding $1M across multiple years, NERC CIP or TSA directive compliance staffing, engineering-workstation hardening, and OT-specific IR retainers. Benchmarked against the CISA CPGs as the regulator-recognized floor. Key teaching point: OT security budgets are dominated by engineering and segmentation projects, not software licenses.


9. Five economic arguments worth making on the site

  1. The ransom is a minority of ransomware cost. Recovery, downtime, notification, legal, and insurance consequences dwarf it — and paying does not reliably restore data or prevent recurrence.
  2. Staffing dominates every budget at every size. Any analysis that compares tool prices without comparing operating burden is wrong.
  3. Free controls carry the most weight at the small end. Credit freezes, MFA, updates, DMARC, and CISA's free services genuinely move the needle for individuals and small businesses.
  4. The insurance application is a free security checklist — and truthfully meeting what it asks is both cheaper than a breach and a precondition of the claim paying.
  5. Buying maturity you cannot operate is the most expensive mistake available. Threat intelligence platforms and deception technology purchased at Level 1 maturity are pure waste; the maturity model in 13-risks-and-pitfalls.md exists to sequence spending.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval