AI & ML

Evolving Security Budgets: The Shift Towards AI Funding in Cybersecurity

Despite an uptick in overall security spending, many CISOs face stagnant budgets, with AI becoming a primary focus for new investments.

Sep 17, 2026 3 min read
Sign in to save

Cybersecurity budgets are showing growth on the surface, but a deeper look reveals a troubling trend for many Chief Information Security Officers (CISOs). According to the IANS and Artico Search 2026 Security Budget report, while average budgets increased by 5% this year from last year's 4%, the median growth rate stalled at 0%. This means that nearly half of the CISOs surveyed saw their financial resources either shrink or remain unchanged despite heightened threats. A paradox emerges: although budgets may nominally rise, the reality for many practitioners suggests a tightening of resources in response to escalating risks.

Disparities in Budget Allocations

The report is based on insights from over 500 security executives gathered between April and August 2026 and emphasizes the disparities in budget allocations largely driven by organizational performance. Companies that exceeded revenue targets by more than 5% were significantly more likely to experience double-digit budget increases—41% in comparison to a mere 15% for those meeting targets. Alarmingly, 22% of organizations falling short on performance opted to cut their security budgets entirely. This correlation between financial performance and cybersecurity investment underlines a prevalent risk: when organizations face economic challenges, cybersecurity often finds itself on the chopping block, a troubling reality given the increasing sophistication of cyber threats.

This practice raises serious questions about the long-term sustainability of cybersecurity initiatives. If companies see their budgets tied directly to performance metrics, then fluctuations in economic health will also dictate their capacity to defend against potential breaches. What's more, the fact that companies not only hold stable budgets but even cut them during downturns illustrates a shocking lack of understanding about the importance of cybersecurity as a foundational pillar rather than a discretionary expense. If you're working in this space, it’s crucial to advocate for a change in perspective that treats cybersecurity as a core element of business strategy.

Ownership Structure and Budget Growth

Ownership structure also plays a critical role. The data shows that 71% of venture-capital-backed businesses reported increases in their security budgets, whereas only 52% of publicly traded firms could say the same. This discrepancy signals a fundamental difference in risk tolerance and resource availability. Venture-funded firms, often aggressive in their growth trajectories, are likely to prioritize and invest in security as part of their scaling efforts, whereas established companies may be more cautious, particularly in a climate of economic uncertainty.

Government entities and non-profits lagged behind, often seeing minimal growth. This slight in funding may be attributed to tighter budgets and competing priorities within public sectors that frequently overshadow urgent security needs. The implications of this funding gap are stark; if governmental and non-profit organizations—the very entities needed to protect public information—struggle to allocate necessary resources, how can we expect sufficient protection from cyber threats that increasingly target these institutions?

Shifts in Budget Justifications

Interestingly, when CISOs do secure budget increases, the motivations behind them are shifting. Business or operational risks emerged as the predominant justification for budget growth, cited by 48% of survey participants. In contrast, only 3% pointed to major breaches as a reason for funding increases, suggesting a strategic pivot toward proactive risk management rather than reactive measures. This evolving perspective reflects a broader industry trend where organizations are realizing that waiting for a breach to occur is simply too late. Building a resilient security posture around proactive identification and mitigation of risks is essential.

AI Funding: The New Frontier for Security Investment

A substantial portion of these new security dollars is flowing to artificial intelligence initiatives, with 69% of CISOs identifying AI as their top investment priority. As Steve Martano, a partner in Artico Search’s cyber practice, articulated, “Security is gaining tailwinds from other investments in AI and broader technology.” This narrative indicates that a portion of security capabilities may derive funding from unrelated budgets, complicating the financial landscape. While AI-enhanced tools are increasingly vital for modern security measures, the obscured funding sources can lead to mismanagement of budgetary allocations.

Only 24% of organizations track AI as a separate line item in their security budgets, while 38% include it as part of the overall cybersecurity budget and another 38% consider it a funding responsibility of IT or innovation sectors. This fragmented approach leads to underreporting of AI-related spending. Companies that do formally track AI-related funds across their budgets noted that their financial resources increased 70% of the time, in stark contrast to the lower figures of 42% and 31% for those who either embedded AI in their budgets or sourced it externally. This discrepancy underscores an essential fact: clarity in budget tracking directly correlates with increased funding opportunities, so organizations should prioritize specific line items for AI in their planning.

Despite increased funding for AI initiatives, this shift doesn’t appear to correlate with headcount cuts in cybersecurity teams. A noteworthy 81% of CISOs anticipate that AI will create new demands for skills and roles rather than reduce existing staff numbers. According to Martano, teams are evolving: “AI and automation embedded in security workflows has led to the repurposing of team members.” Many CISOs are now focused on hiring people who can manage complex threats and make critical judgments beyond the capabilities of automated systems. The human element remains irreplaceable, and this ongoing evolution highlights the crucial balance between advanced technologies and skilled personnel.

Leadership Perspectives on AI Investment

Organizations planning to boost their AI-security investments by over 10% exhibit a marked distinction in leadership perspectives on AI risks. A striking 79% of these "aggressive AI spenders" reported that their leadership has a solid grasp of AI-related risks, as opposed to just 33% in groups with no AI spending plans. Additionally, 70% of aggressive spenders have clearly defined AI governance, compared to only 34% without dedicated AI funding. This stark contrast suggests that leadership’s understanding and commitment to AI security is pivotal in encouraging expenditure in this area. What this means for you is clear: organizations play a central role in shaping how security budgets reflect and respond to the risks presented by new technologies.

Future Outlook: Navigating the Cybersecurity Challenge

The report advises CISOs to establish a distinct budget line for AI and track spending meticulously as they prepare for the upcoming budget cycle. This proactive approach could prove essential for understanding the real costs associated with AI in security contexts as investment trends continue to evolve. The importance of this meticulous tracking cannot be overstated. Organizations that fail to adequately account for the nuances of security spending will find themselves vulnerable in a landscape increasingly defined by rapid technological change.

As we look ahead, the interplay between budget constraints and the evolving nature of threats will continue to challenge security leaders. Staying ahead will require not only innovative spending but also a cultural shift within organizations. If companies view cybersecurity as an essential component of business resilience rather than a cost center, they may find themselves better equipped to tackle threats effectively. The implications of this shift could be significant for the long-term viability of both cybersecurity strategies and the organizations dependent on them.

Source: Joseph Martinez · www.csoonline.com

Comments

Sign in to join the discussion.