Site navigation

Cybersecurity Budget Growth Hits Five-Year Low, Hiring Slows

Graham Turner

,

Cybersecurity budget slowdown
Researchers warn that budget and staffing constraints are leaving many security teams under-resourced and at greater organisational risk.

Cybersecurity teams are facing their lowest rate of budget growth in five years, with hiring also slowing sharply, according to new research by IANS and Artico.

The IANS Security 2025 Budget Benchmark Report, produced in partnership with Artico Search, found that average annual security budget growth fell to 4% in 2025 — down from 8% in 2024 — marking the steepest slowdown since 2020. Just 47% of CISOs reported any budget increase this year, compared with 62% in 2024, while 39% said their budgets were flat, up from 26% last year.

Healthcare, professional and business services, and retail and hospitality saw the weakest growth rates, while financial services, insurance and technology fared better than average.

Between 2020 and 2024, security budgets as a share of IT spend grew from 8.6% to 11.9%, but this year dropped by one percentage point to 10.9%. Researchers said the decline was likely due to a rebound in core IT investments, particularly in AI and cloud infrastructure.

The report also found that security budgets as a percentage of revenue slowed slightly, suggesting company revenues grew faster or at a similar pace to security spend. Global market volatility, geopolitical tensions, uncertainty over tariffs, and fluctuating inflation and interest rates were cited as the main factors driving spending caution.

“In response, companies have become more cautious in their spending and hiring. More than in prior years, security organisations are affected as well, manifested by declining rates of growth for budgets and staff levels,” the researchers wrote.

Staffing Growth at Four-Year Low

The slowdown in budget growth has had a knock-on effect on hiring, with security team expansion falling to an average of 7% in 2025 — the lowest in four years. Almost half (47%) of firms have kept team sizes flat, while only 45% added staff this year. That compares to 67% in 2022, 55% in 2023 and 51% in 2024.

Nearly nine in ten (89%) CISOs said their teams are low or understaffed, with budget and hiring constraints the primary reasons. Staffing shortages have led to delays and cancellations of security initiatives, lower morale, higher non-compliance risk, and greater organisational risk overall.

“They also note staffing shortages led to delays and cancellations of security initiatives, cause morale issues, increase the risk of noncompliance, and elevate organisational risk in general,” the report stated.

On average, CISOs allocate 39% of their budgets to staff salaries, 29% to software, and 12% to outsourcing. Smaller proportions go towards projects, hardware and training — a breakdown that has remained relatively stable over the past five years.


Recommended reading


Steve Martano, IANS Faculty and partner in Artico Search’s cyber practice, said: “Once again, we find that security is not immune to macro conditions. Most CISOs are not receiving budget increases despite security typically being identified in the top five risks for companies.”

He added that many organisations have the budget for tools but not for the staff to fully leverage them: “We continue to hear that CISOs have budget for tooling but not for staff increases, which leads to teams not being staffed adequately to take advantage of a tool’s full capabilities.

“As AI capabilities create efficiencies in repeatable tasks, more team members are able to find the time to utilise a platform’s capabilities.”

Graham Turner

Sub Editor

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far