Security spending is growing — except for the typical CISO

Wait 5 sec.

Security budgets may be growing on paper, but for a majority of CISOs, the money isn’t moving in quite the same direction.The budgets grew by 5% on average in 2026, up from 4% last year. But that average hides a much weaker picture: median budget growth remained at 0%. And while 64% of CISOs asked for an increase this cycle, only 45% received one, meaning 55% of CISOs saw their budgets either remain flat or get cut.The findings come from the IANS and Artico Search 2026 Security Budget report, based on responses from over 500 security executives between April and August 2026.Who gets to spend appears to depend heavily on the health and structure of the business. Companies that outperformed revenue targets by more than 5% were more than twice as likely to receive a double-digit security-budget increase as companies that hit their targets, 41% versus 15%, while 22% of significantly underperforming companies cut security budgets.Ownership mattered as well:71% of VC-backed companies increased security budgets, compared with 52% of publicly listed companies, while government and nonprofit organizations saw budgets grow least often and by the smallest margins.And when CISOs do get more money, a major breach may not be the argument that gets them there. Business or operational risk was the most common reason for budget increases, cited by 48% of CISOs whose budgets grew, while new regulations and stronger board or executive focus produced the largest average increase at 22% and 23%, respectively.A major breach, meanwhile, was cited by just 3% as a reason for landing more money.AI isn’t named on the check, but it’s getting paidMost of the new security dollars are going to AI, named by 69% of CISOs as their top net-new priority.“Security is gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else’s budget,” said Steve Martano, IANS Faculty and partner in Artico Search’s cyber practice.Just 24% track AI as a separate security-budget line or subcategory, while 38% have AI embedded in the security budget and another 38% fund it through IT, data or innovation.The fragmented accounting led to security budgets understating the money being directed toward securing AI. The report found that organizations formally tracking AI funding reported increases about 70% of the time, compared to 42% where AI is embedded in the general security budget and 31% where it is funded elsewhere.AI taking a larger share of security spending isn’t directly translating into headcount reductions, though: 81% of CISOs expect AI to create demand for new roles and skills, while 69% expect no reduction in existing headcount.“AI and automation embedded in security workflows has led to the repurposing of team members and a change in hiring and resourcing,” Martano said, adding CISOs now want staff to handle threats and make judgement calls that AI systems can’t.There was a marked difference in planning and leadership attitudes around AI security between organizations planning to increase AI-security spending by more than 10% (aggressive AI spenders) and those with no AI-specific spending planned — although whether this was cause or effect, IANS didn’t say. Aggressive AI spenders are substantially more likely to have the organizational foundations needed to support that investment with respondents in 79% of such organizations saying their leadership has at least a fair understanding of AI risks, compared to 33% among organizations with no AI-specific spending plans, and 70% of aggressive spenders having clearly defined AI governance ownership, compared to 34% in the non-spending group.Similarly, 50% of aggressive AI spenders reported having a mature AI-security program versus 17% of non-AI-spenders.Increased spending on AI security happens when organizations spend more on security overall: 45% of aggressive AI spenders increased their overall security budget by more than 5%, and 51% expect to do so again next year, while only 12% of non-AI-spenders increased their overall budget by more than 5%, and only 9% expect to next year.For CISOs trying to keep pace, the report’s advice is to give AI its own budget line and start tracking what it actually costs before the next budget cycle.