With the first fireworks of 2026 fast approaching, businesses around the world are piecing together their budgets for next year, and a sizeable chunk, as always, will be earmarked for cyber defence and operations.
But those bigger budgets come with bigger burdens attached, and new data shows that CISOs are stretching their resources paper-thin to meet the as-yet unknown risks.
Cloud security firm Wiz has unveiled its 2026 CISO Budget Benchmark, which reveals that although the vast majority (88%) of firms plan to increase their cyber spending next year, more than half (56%) of security leaders say their organisation still isn’t investing enough to counter emerging threats.
That’s despite the vast scale of spending, with 53% of firms investing more than $5 million (£3.8m) a year in cybersecurity, including 20% spending between $5 and $10 million (£7.5m), and 17% committing over $25 million (£18.9m) annually.
Notably, the highest spenders are among the least satisfied in their defences, with Wiz finding that 60% of those allocating more than $25 million say their overall and cloud security budgets still fall short of what’s needed to defend against current threats.
Perhaps because they don’t feel like they’re getting much out of these swollen budgets, large enterprises (those with more than 25,000 staff) are less likely to plough in more cash. Wiz found that just 41% of these firms will increase their cyber spend by more than five per cent next year, compared to 64% of wider firms.
So, if the goal is getting more bang for their buck, how should CISOs plan their security budgets for 2026?
Regain Control of Cloud Complexity
According to Wiz, next year will see cloud security consume more of every dollar and every hour.
Nearly a third (32%) of firms are focusing more than half of their valuable human resources on the cloud, jumping to 38% of large enterprises, but the majority (88%) of security leads plan to increase their team’s focus on protecting and maintaining cloud environments over the near future.
However, for half of organisations (49%), rising cloud complexity is already a barrier to effectiveness, overwhelming manual processes and opening gaps in protection. Wiz argues that the goal shouldn’t be to spend more time and money on the cloud, but to invest smarter.
That can be achieved, says the report, by using a platform-driven approach, ‘grounded in automation and consolidation’. Making cloud operations leaner not only has the benefit of reducing the security team’s burden, but could help orgs move faster than their competitors.
Reign in Tool Sprawl
The study found that more than half (58%) of organisations now operate 25 or more security tools, rising to 71% of those companies with the biggest cyber budgets, while more than a third of large enterprises (35%) run fifty or more.
Wiz warns that piling on security tools can backfire, however, with each one adding complexity, noise, and overhead that dilute the value of the overall investment, and is likely a key reason why those spending more are less satisfied with the results.
Instead of adding more tools to an overwhelmed SOC, cyber leaders should instead focus on decommissioning as a budget line by retiring or consolidating lower-value tools, and leaving funds for high-yield programmes, like automation, analytics, and staff development.
Adapt (Quickly) to AI
AI has become both a budget priority and a boardroom concern, with 99% of CISOs agreeing it will reshape cybersecurity. But for many, the impact is still more promise than reality, with only around half saying that transformation is happening now.
Wiz found that the desire to invest in AI-powered security solutions was the main factor driving security spending plans, with 76% of large enterprises prioritising automation in their budgeting.
Recommended reading
- AI Threat Hunting and Quantum Top Cyber Agenda, Finds PwC
- Cyber Leaders Are Dreading AI-driven Cyber Threats for 2026
- AI Stoking Fears of Cyber Warfare
But while more than half (54%) of security executives believe that AI’s impact on cloud security is already significant, 75% of CISOs are concerned about emerging AI risks that they don’t have the right tools or frameworks to tackle.
As AI becomes part of the security fabric, Wiz said it’s vital that firms invest in tools designed to prioritise risk, detect threats, and respond in real time, as defending these systems is key to staying resilient.
“CISOs are entering 2026 with bigger budgets, greater scrutiny, and higher expectations,” concludes the report.
“The measure of success will be how effectively those funds translate into measurable reductions in risk. CISOs who can demonstrate that each dollar buys more protection, insight, or speed than it did a year ago will set the benchmark for 2026 and beyond.”





