This is one of the most reasonable questions a finance leader can ask, and one of the hardest to answer with a single number. You want a figure you can put in next year’s budget. What you usually get back from vendors is either a shrug or a number that conveniently matches whatever they happen to sell. Let’s give you a more honest way to think about it, so you can set a figure you can defend.
Why there is no universal number
A cybersecurity budget depends on things specific to you: how many people you have, how sensitive your data is, what compliance rules apply, and how much downtime would actually cost you. A 12-person dental practice handling protected health information has a very different risk profile from a 12-person retail shop, even though the headcount is identical. The practice carries HIPAA obligations and patient data, which raises both the stakes and the floor of what it should spend.
So anyone who quotes you a one-size dollar figure without asking about your business is guessing or selling. The useful approach is to start from a sensible range, then adjust for your reality.
A reasonable starting range
A common rule of thumb is to think about security as a percentage of your overall IT spend rather than a standalone line you invent from scratch. Industry guidance frequently lands in the range of roughly 8 to 15 percent of the IT budget going toward security, with regulated or higher-risk businesses at the upper end. Broader analyst data, such as the spending breakdowns published by Gartner, shows security and risk consistently growing as a share of IT investment, which tells you the direction of travel is up, not down.
Two cautions on percentages, though. First, if your overall IT spend is too low to begin with, a healthy percentage of an unhealthy number is still not enough. Second, percentages are a sanity check, not a plan. They tell you whether your figure is in a believable zone. They do not tell you what to buy.
Build the budget from the controls, not the percentage
The more reliable method is to start from the protections you actually need and price those, then check the total against the percentage range to see if it is sane.
For most small and mid-sized businesses, the core controls that belong in the budget are the same ones that stop the majority of attacks:
- Multi-factor authentication, often already included in software you license.
- Modern endpoint detection and response on every device.
- Managed monitoring and response, so someone is actually watching outside business hours.
- Secure, tested, immutable backups.
- Security awareness training for staff.
- Email filtering and patch management.
We break down that core set and its rough priority order in our piece on the minimum set of security controls that stops most attacks. Price those for your headcount, add any compliance-driven requirements, and you have a budget grounded in something real rather than a percentage pulled from the air.
Don’t forget the cost of not spending
Budgeting only for the spend, and never for the risk it offsets, leads to chronic underinvestment. The other side of the ledger is what an incident would cost you: the downtime, the recovery, the lost clients, the potential regulatory exposure, and for many businesses now, the cost of failing a cyber insurance renewal because the required controls were not in place. Those same controls are increasingly the price of keeping coverage at all, which we cover in our piece on cyber insurance requirements. For a small business, a serious incident can dwarf years of sensible security spending, which reframes the budget as insurance against a much larger number.
Security lives inside your IT budget
One practical note for finance leaders. Cybersecurity is not a separate world from your managed IT spend, it is woven through it. The same provider managing your devices is patching them, the same monitoring covers both health and security, and good IT hygiene is the foundation security sits on. So the cleanest way to plan is to size your whole IT budget thoughtfully and treat security as an integrated part of it. We walk through how to think about overall managed IT cost, and what drives it, in our managed IT cost and budgeting hub, and how the security layers fit together in our People+ Framework.
Where to start
A defensible cybersecurity budget isn’t a number you guess, it’s one you build from the controls your specific business needs and then sanity-check against a reasonable range. If you’d like help putting an actual figure together for next year, that’s exactly the kind of planning conversation we have with finance leaders. See our full approach to cybersecurity for small business, or book a short call and we’ll help you size it honestly, with no pressure to buy more than you need.