How much should we spend on cybersecurity?

I just got back from @RSAConference—one of the most thought-provoking weeks in cybersecurity each year. I had the chance to speak with a lot of sharp and curious people.

One of the best parts of events like RSA is the questions. Whether in small group sessions or late-night rooftop conversations, great questions always surface.

Over the next few weeks, I’ll be unpacking some of the most interesting ones I heard.

This week’s question?

“How much should we be spending on cybersecurity?”

In today’s digital economy, the question “How much should we spend on cybersecurity?” comes up more often—and with more urgency—than ever. Boards, CFOs, CISOs, and founders alike are all wrestling with it. But answering it responsibly means going beyond surface-level budgeting and asking: What are we really trying to accomplish with our cybersecurity spend?

The Problem with “Magic Numbers”

If you do a Google search on “how much should I spend?”, the AI answer is something like “A cybersecurity budget should ideally be between 10% and 15% of the total IT budget, or 1% to 2% of total revenue for smaller businesses.”

And if you were looking for a pat answer or a ballpark, you might stop there. (but we won’t…)

The problem with magic bullets or pat answers is that they mask what might be the real question behind the question. If you are a decision maker, or a board member, or even a business consultant, you might be asking “how much should I spend …”

  • “… so that I am in line with other businesses (because I don’t know how much this should cost)” [Horizontal Parity], or
  • “…so we’re not held liable after we get breached for failure to be proactive” [What if we spend too little?], or
  • “…relative to how much a breach could cost” [Valuation], or
  • “…so that I can sleep well at night.” [Peace of mind]

Let’s take a look at each of these in turn.

Horizontal Parity

One of the first instincts of business leaders is to benchmark: What are companies like ours spending? This instinct—to seek horizontal parity—offers comfort. If your spending is within industry norms, it’s easier to defend your choices to stakeholders, auditors, and insurers. But it’s a double-edged sword. Over-reliance on peer benchmarks can lead to a “check-the-box” mentality, ignoring specific risk factors unique to your business model, infrastructure, or data environment.

Benchmarks are useful starting points, but shouldn’t substitute for tailored risk assessment.

While industry benchmarks are a useful reference point, they should not replace a tailored cyber risk assessment. If decision makers are leaving the budget choices to rules of thumb, we should suggest that a deeper understanding of cybersecurity or a deeper investigation into the needs of the organization is in order. What happens if we don’t invest enough?

Legal and Regulatory Liability: What If We Spend Too Little?

Cybersecurity spending is increasingly seen not just as a best practice but as a legal expectation. Regulators, plaintiffs’ attorneys, and insurers all want to know: Did you take reasonable steps to protect data and systems? Spend too little, and a company could be seen as negligent—opening the door to fines, lawsuits, and reputational damage. In an era of data privacy laws (like GDPR, CCPA, and HIPAA) and increasing SEC scrutiny, organizations are being held accountable for cybersecurity failures.

* Lawsuits after data breaches often cite “inadequate investment in cybersecurity.”

* Regulators may assess whether your budget reflects your risk exposure.

When justifying your cybersecurity spend, be prepared to show that it meets or exceeds current regulatory and legal standards

How do you show your budget was reasonable?

Again, benchmarking is one aspect of this, or at least a place to start. Demonstrating a thorough understanding of your organization’s security posture is another. Can you say, “We spent X dollars and Y hours examining potential vulnerabilities of our organization, and then we spent W dollars and V hours shoring up our defenses”? That plays well in court or in testimony before regulators.

In short, do you view your activities today as if you were being questioned about them in public 5 years from now?

Valuation of Crown Jewels: What Are We Protecting?

The best cybersecurity spending decisions begin with one simple question: **What are our crown jewels?**

Every organization has assets that are disproportionately valuable—whether it’s customer databases, proprietary code, financial systems, or trade secrets. If losing them would materially impact your business, your cybersecurity investment needs to reflect that value.

This is a strategic angle: aligning cybersecurity spend with the value of the assets being protected. Whether it’s customer data, key employees, proprietary algorithms, the UI, supply chain systems, or intellectual property, different assets carry different risk-weighted values. The real question isn’t how much you’re spending—it’s whether your spending makes sense relative to what you stand to lose.

I should note two important things here. One, it might come as no surprise that some organizations omit some key piece of their success. This happens because 1) they take it for granted, 2) they are following someone else’s statement of what was important in another organization, or 3) they’ve never engaged in the practice of looking at their own house from the point of view of a criminal.

Business success can come from many factors. It could be that database you have, or a key employee group, or some piece of IP that allows you a mini monopoly. In helping these organizations see security from an outsider’s point of view, I frequently ask “what would be some ways to cripple your business?”

Note that the question does not ask what I could steal, nor does it ask about endpoints or detection. If the only way your customers can buy from you is your website, then that’s a crown jewel. If customers need to reach you by phone, then that phone access is vital. If you’ve got vital information stored somewhere, then that’s where we consider spending time and resources.

The second important thing is valuation. This is a hard one for the tech people among us, it’s hard for the legal group, and it’s hard for the business people. Why?

Because valuation of our crown jewels involves the expertise of all three groups. I’m going to let this statement marinate for a bit (probably because it could be the subject for an entire course), but we should remember that if I haven’t valued my important things, or I have misvalued them, then my budget will be off.

Peace of Mind: How Much Is Confidence Worth?

Cybersecurity isn’t just a technical issue—it’s emotional. Executives want to sleep at night. Investors want assurance. Boards want to know the company isn’t one click away from disaster. Spending enough to feel protected—without overspending on ineffective tools—is part art, part science.

> **Key Insight**: Decision-makers need to trust their defenses. That requires clear communication, visible controls, and confidence in the team behind the tech.

Here are some questions you might ask about your level of confidence that you’ve done enough to prevent—or at least contain—a breach:

* Are you confident in your incident response plan?

* Do you have cyber insurance?

* Have you done tabletop simulations or audits?

* Do you have someone on staff or retainer whose job is to come up with worst-case scenarios?

Final Thoughts: Spend Smart, Not Just More

So how much *should* you spend on cybersecurity?

There’s no universal number. But if you want to build an informed and defensible cybersecurity budget, make sure you’re thinking about:

* What your peers are doing (but not copying blindly)

* What regulators, courts, and the public might expect

* What you’re protecting and how valuable it is

* How much confidence your leadership and stakeholders need

Ultimately, good cybersecurity spending is not about how much you spend, but whether you’re spending wisely. Remember, the best cybersecurity investments are intentional, proportionate, and evolving.


Leave a Reply

Your email address will not be published. Required fields are marked *