Skip to main content
Cybersecurity

CISOs Redirect Budgets to AI Amid Flat Cyber Spending

Security executive stands near large screen in modern office interior.

"Organizations that align AI security investments with broader business objectives, establish clear governance, and invest in developing new skills will be better positioned to manage risk while enabling innovation,” Steve Martano said.

IANS: AI is the top destination for net‑new security spend

The cyber research and advisory firm IANS found that artificial intelligence dominates plans for incremental security budgets in its 2026 Security Budget Benchmark Report. Compiled from interviews with 500 security executives nationwide, the report shows 69% of respondents cited AI as the area they will prioritize for net‑new dollars. Close but distinct priorities included SecOps automation (51%) and identity and access management enhancements (39%) — categories the report notes are already “AI‑mature” in many organizations.

Software’s share of the security budget climbs

The shift to AI is visible in how organizations allocate line items. IANS reported that software now comprises 35% of the security budget in 2026, up from 29% the prior year. That increase brings software to within two percentage points of “staff & compensation,” the closest gap the survey has recorded between those categories. The report frames this as a structural move toward purchased capabilities — many of them AI‑enabled — rather than purely personnel‑led defenses.

Median budgets remain flat as macro pressure bites

Despite the surge of interest in AI, the report makes clear that new AI spending is not expanding overall cybersecurity budgets. Median growth remained flat, and 55% of respondents either held budgets flat or reduced them citing economic headwinds. IANS noted this is the second consecutive year in which a majority of respondents reported flat to negative budget growth. The report highlighted two organizational factors that most strongly influence budget growth: ownership structure, which affects an organization’s appetite to invest in security, and financial performance, which determines whether it has the resources to act on that appetite.

VC‑backed companies invest; public companies lag

Ownership structure shows up in the numbers. IANS found that 71% of VC‑backed companies increased security budgets in the survey period, most often by more than 10%. By contrast, just 52% of publicly listed companies increased security budgets. The divergence illustrates how capital structure and short‑term financial constraints are shaping which organizations can translate strategic priorities into spending decisions.

CISOs and teams: AI to create jobs and change work, not wholesale cuts

IANS reported that respondents do not broadly view AI as an immediate threat to headcount. More than two‑thirds of CISOs (69%) said they don’t expect to cut existing headcount because of AI, while 81% anticipate the technology will create demand for new roles and skills. An overwhelming share said AI is already reshaping work: 91% said it helps teams become more productive, 81% said it creates a need for new roles, and 79% said it enables redeployment to higher‑value work. Steve Martano reinforced the human element, arguing organizations still need people to “find anomalies, elevate relevant threats and make judgment calls.”

What this means for CISOs and security teams, VC‑backed and publicly listed companies, and procurement leaders

  • CISOs and security teams: Expect targeted investment in AI and AI‑mature capabilities, accompanied by a growing emphasis on new roles and skills rather than immediate headcount reductions.
  • VC‑backed and publicly listed companies: VC‑backed firms are more likely to increase security budgets — often by double digits — while publicly listed firms have been more constrained, reflecting the report’s finding that ownership structure and financial performance drive budget choices.
  • Procurement leaders: Software spending is rising to 35% of security budgets, signaling stronger demand for AI‑capable security tools and the need to align purchases with governance and skills development.

The snapshot IANS provides is clear: organizations are carving out incremental dollars for AI even as overall budgets stall. The practical test now is whether those AI investments are matched by governance, training and alignment with business objectives — the very steps Steve Martano flagged as necessary to “manage risk while enabling innovation.” The report’s numbers — 69% prioritizing AI, software at 35% of budgets, 55% with flat or reduced budgets, and a split between 71% of VC‑backed firms and 52% of public firms increasing spend — leave a pointed question for security leaders: can targeted AI investment deliver measurable security gains without new overall funding?

Original story