Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

How to Decide on Your Company’s IT Security Budget

By Alexander Moiseev
budget-enews
January 15, 2020

Global spending on information security products and services has been on the rise for years. According to Gartner, budgets have grown from $114 billion in 2018 to a forecasted growth of more than $124 billion in 2019. IT security leaders in enterprises agree, with 72 percent saying that their budget will increase in 2020. With more money being allocated for information security, it’s interesting to see how these investments are actually shaped.

From my experience, there are two ways to decide about the future. One option is to rely on your intuition and previous experience or simply follow prior protocols. The other is to analyze your unique situation, break it down into small details and try to calculate the probability of these details changing in the near future.

With this in mind, let's take a deeper look at how different companies plan their IT security spending and what we can learn from these two approaches.

The Conventional Approach to Budgeting

The most typical approach to security budgeting is often based on instant needs or on previous experience. This is especially relevant for growing companies that need to be able to quickly equip businesses with the minimum necessary cybersecurity measures and tools to focus on growth.

In organizations at this stage, budget planning most often happens according to the principle of inheritance, whereby the current budget level is maintained for several cycles with minimum changes. There is no practice of setting strategic IT security goals or assessing specific risks, and the money is spent on emerging needs with ad hoc support.

This approach may work well unless sudden and unaccounted business needs emerge, for example, a decision to increase the digital side of the business, implement a cloud-based service for CRM or accounting or open a new branch of an office. All these business decisions mean that the IT security budget, as well as personnel, will be rapidly allocated to fix the closest security gap while previously scheduled tasks and deployments get delayed and piled up for later.

As a result of this, the actual spending on security in these organizations may increase dramatically as whenever something unexpected happens, the organization will need to solve it as quickly as possible, no matter the cost. At the same time, larger organizations with a more mature approach to risk management may end up with a smaller proportion of money spent on information security.

A Risk-Based Approach

It’s not surprising that in 2019, risk management expertise is cited among the top three skills for Information Security Chiefs. In mature enterprises, risk assessment is at the core of business processes, and IT security is no different.

More mature organizations do not try to fix as many gaps as possible. First, they look at critical business risks, whether it’s downtime, service availability, a destroyed reputation, lost business opportunities or any kind of direct monetary losses. For the businesses with this mindset, cybersecurity isn’t a habit or a ‘necessary evil’ investment instigated by scary headlines, it’s reasonable and based on risk calculation.

Cyber threats do not discriminate against industry or size, and all organizations are likely to face specific types of cybersecurity risks. For an ecommerce firm with most of its business in digital, there’s a good chance that DDoS attacks on its web resources would cause massive damage, both monetary and reputational. Meanwhile, financial and government organizations will face significant penalties and fines from regulators should their systems get breached in an advanced cyberattack, so their budgets should focus here. Additionally, software developers and service providers can even be a target themselves, or a step in a supply chain attack against their customers. In other words, there are almost as many threat models as there are types of business, each with a specific and ever-changing set of risks.

Since there is always a certain probability of risk, IT security expertise is becoming a very important part of the risk assessment process. Experts, including external ones, are invited to evaluate possibilities and add their input for a better informed decision and balance the final outcome.

Finally, when a decision about purchasing a cybersecurity solution or service is made based on this approach, there is a transparent process of approval with higher management. This allows a company to avoid a situation when one employee in IT security forces a decision to not buy the most cost-effective and efficient solution — but choose another simply because, for example, they used to work with that platform in the past.

Of course, the risk assessment process differs from one company to another and it is constantly improving. Nonetheless, three key components — experts, risk evaluation, and a transparent decision-making chain — remain essential to help make budget planning more effective and make sure that the company’s investments in IT security are in line with business needs.

Lessons to Learn

In summary, here are a few considerations when approaching an organization’s IT security budget:

  1. When assessing risks, businesses should look at the threats most relevant to their industry and company size and then plan their budget accordingly. Access to the most up-to-date and tailored threat intelligence reports is invaluable in making this work.
  2. It is important to embrace expertise (whether internal, external or the combination of both) to evaluate risks and the potential value of cybersecurity solutions and services. Kaspersky and other vendors offer a variety of training to help organizations improve their level of internal expertise.
  3. Outsourcing is often the best choice for organizations that don’t yet have enough internal expertise or risk assessment processes. At this point, having a guaranteed service level agreement (SLA) and moving expenses from CapEx to OpEx is a way to keep security spending under control.
  4. While an industry benchmark alone isn’t enough information to make a budget decision, tools such as Kaspersky IT Security Calculator can be a good start to dive into the threats, measures and numbers that are worth looking into for the organization of a certain industry, size and region.

When dealing with something as serious as corporate IT security, it’s best to take some time to prepare in advance, consult with experts and plan what to expect.

KEYWORDS: cyber security cybersecurity information security security budget security leadership

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Alexander moiseev2
Alexander Moiseev is the Chief Business Officer of Kaspersky, where he is responsible for sales strategy and marketing globally. Previously, he was Kaspersky’s Chief Sales Officer, where he led global sales and new business development. He graduated from Moscow State University with a degree in engineering with mathematics and cybernetics.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cyber Tactics Column
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity Education & Training
    By: Charles Denyer
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

Popular Stories

Rendered computer with keyboard

16B Login Credentials Exposed in World’s Largest Data Breach

Verizon on phone screen

61M Records Listed for Sale Online, Allegedly Belong to Verizon

Security’s 2025 Women in Security

Security’s 2025 Women in Security

blurry multicolored text on black screen

PowerSchool Education Technology Company Announces Data Breach

Half closed laptop

Sudo Vulnerability Discovered, May Exposes Linux Systems

Events

August 7, 2025

Threats to the Energy Sector: Implications for Corporate and National Security

The energy sector has found itself in the crosshairs of virtually every bad actor on the global stage.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • SEC1119-awareness-Feat-slide1_900px

    Enterprise Cybersecurity: Three Topics to Discuss With Your CISO

    See More
  • hacker

    How to Work with Hackers to Make Your Company More Secure

    See More
  • data privacy

    Accidental database breaches are on the rise – How can your company avoid becoming the next headline?

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

See More Products

Events

View AllSubmit An Event
  • September 25, 2024

    How to Incorporate Security Into Your Company Culture

    ON DEMAND: From this webinar, you will learn how to promote collaboration between IT and physical security teams to streamline corporate security initiatives.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!