Leadership1 publisher3 min readPublished
Revenue performance was one of several factors shaping security budget growth in 2026
The IANS and Artico Search survey of more than 500 security executives puts average budget growth at 5% for 2026 and median growth at zero, with companies that beat revenue targets by more than 5% the likeliest to win double-digit increases.
The Board Room · Leadership desk

What happened
- Security budgets grew 5% on average in 2026, up from 4% a year earlier, in the IANS and Artico Search report drawn from more than 500 security executives surveyed between April and August 2026.
- Median budget growth was 0%, and 55% of CISOs finished the cycle with budgets that were flat or cut.
- Companies that beat revenue targets by more than 5% were more than twice as likely to get a double-digit security-budget increase as companies that merely hit their targets, 41% against 15%.
- Seventy-one percent of VC-backed companies increased security budgets against 52% of publicly listed ones, while government and nonprofit organizations raised budgets least often and by the smallest margins.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- cost A flat budget with AI as the top net-new priority means the AI work is paid for by displacing something already funded, and the median security organization is the one doing the displacing.
- constraint A 2027 plan benchmarked to reported market growth of 5% is built on the upper half of the distribution, so a CISO quoting peer growth in a board paper is quoting a number most peers did not receive.
- decision Whether AI security gets its own budget line is now a funding decision, and the report tells CISOs to create the line and cost it before the next cycle opens.
- exposure A revenue miss now reaches the security program inside the same budget cycle. Part of a CISO's exposure is set by the sales forecast.
The gap between asking and getting is where this cycle sits. Sixty-four percent of CISOs requested an increase and 45% received one, a spread of 19 percentage points [3][1]. If every increase went to somebody who asked for it, close to a third of the requests were turned down [2].
Among the CISOs whose budgets did grow, the winning argument was ordinary business risk. Business or operational risk was the most common reason, cited by 48% [9]. New regulations and stronger board or executive focus produced the largest average increases, at 22% and 23% [10]. A major breach was cited by 3% [11].
Companies that significantly underperformed on revenue cut security budgets 22% of the time [7]. The 5% average is not a fiction: somebody is receiving the money, and the report says who [1]. A CISO at a company that missed its numbers is arguing against the same forecast that set the budget.
Sixty-nine percent of CISOs named AI their top net-new priority [12]. Only 24% track AI as a separate security-budget line or subcategory, while 38% have it embedded in the security budget and another 38% fund it through IT, data or innovation [13]. "Security is gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else's budget," said Steve Martano, IANS Faculty and partner in Artico Search's cyber practice [14].
Where the money is tracked correlates with whether it arrives. Organizations formally tracking AI funding reported increases about 70% of the time, against 42% where AI sits inside the general security budget and 31% where it is funded elsewhere [15].
On staffing, the expectation runs the other way: 81% of CISOs expect AI to create demand for new roles and skills, and 69% expect no reduction in existing headcount [16]. "AI and automation embedded in security workflows has led to the repurposing of team members and a change in hiring and resourcing," Martano said [17].
Next year's split is already visible in the plans. Among organizations raising AI-security spending by more than 10%, 45% increased their overall security budget by more than 5% this year and 51% expect to do so again next year; among those with no AI-specific spending planned, the figures are 12% and 9% [18]. The first group grew overall budgets past 5% at nearly four times the rate of the second [3]. That group also reports leadership with at least a fair understanding of AI risks in 79% of cases against 33%, and clearly defined AI governance ownership at 70% against 34% [19]. IANS did not say whether the spending produced those foundations or the foundations produced the spending [21].
What to watch
- Whether the next IANS and Artico Search cycle moves the median off 0%, or leaves the average carried by the top half.
- Whether CISOs who create a dedicated AI security budget line convert it into funding next cycle.
- Whether VC-backed budget growth holds if late-stage funding conditions tighten.