Research: 12 Percent of CISOs Faced Budget Reductions in 2024

IANS Research and Artico Search recently unveiled the 2024 Security Budget Benchmark Report, offering critical insights into the state of security budgets and staffing amidst a backdrop of global economic challenges. This comprehensive study compiled findings from the fifth annual CISO Compensation and Budget Research Survey, including responses gathered from over 750 Chief Information Security Officers (CISOs) between April and August 2024. The report indicates a cautious yet necessary expansion in security spending.

Amidst global economic and geopolitical uncertainty, markets are jittery, companies are spending frugally, and investors remain cautious. Security budgets are also affected by these realities with most budgets remaining flat or increasing modestly.

"As organizations confront an evolving threat landscape, the slight uptick in cybersecurity budgets this year reflects a careful balancing act," said Nick Kakolowski, Sr. Research Director at IANS. "While we see modest increases, it's clear that CISOs are prioritizing strategic investments over broad expansions. The focus is on strengthening defenses against sophisticated threats like AI-driven attacks, even as CISOs navigate tighter fiscal environments. Our research highlights the careful approach security leaders are taking, ensuring that every dollar spent is justified by the most pressing risks."

Key survey findings highlighted in the Security Budget Benchmark Report include:

Security budget growth hits 8%, up from 2023
Nearly two-thirds of CISOs report increasing budgets. The average growth has risen from 6% in 2023 to 8% this year, but this is only about half of growth rates in 2021 (16%) and 2022 (17%). A quarter of CISOs experienced flat budgets while 12% faced declines.

Security Outpaces IT Spend and Annual Revenue Growth
Over the past five years, the security budget as a percentage of IT spending has steadily increased, rising from 8.6% in 2020 to 13.2% in 2024. Similarly, as a percentage of revenue, security budgets have grown from 0.50% to 0.69% during the same period. These trends validate the increasing prioritization of security within organizations, as larger portions of resources are allocated to safeguarding against evolving threats.

External Risks Drive High Growth Scenarios
The research highlights that significant budget increases are often reactive, driven by external factors such as incidents, breaches, or the rising risks such as those associated with AI adoption. Additionally, internal dynamics like rapid company expansion or strategic shifts, including mergers and acquisitions, were cited by CISOs as key contributors to justify accelerated budget growth.

Budget Growth Rebounds in Some Industries but Not Others
Multiyear budget growth trends vary by industry. In the financial services, tech, retail and hospitality, and legal sectors, average security budget growth has improved from 2023 levels but only remains in the mid-to-high single digits. In contrast, the healthcare, business services, and consumer goods and services sectors have seen further declines in average growth rates compared to 2023.

Slower Hiring Amid Cautious Spending
Despite the budget increases, hiring trends tell a different story. Staff growth has slowed significantly, decreasing from 31% in 2022 to 16% in 2023 and further falling to 12% this year. Over a third of CISOs reported maintaining consistent headcount, reflecting a more measured approach to expanding security teams.

“For the last 12 months, it has been difficult for CISOs to add staff even when there's a need in the organization,” said Steve Martano, IANS Faculty and Executive Cyber Recruiter at Artico Search. “Teams are being asked to do more with less and CISOs are finding it difficult to get budget for recruiting and hiring. This puts a lot of pressure not only on CISOs, but also on their teams."

Featured

  • Accelerating a Pathway

    There is a new trend touting the transformational qualities of AI’s ability to deliver actionable data and predictive analysis that in many instances, seems to be a bit of an overpromise. The reality is that very few solutions in the cyber-physical security (CPS) space live up to this high expectation with the one exception being the new generation of Physical Identity and Access Management (PIAM) software – herein recategorized as PIAM+. Read Now

  • Protecting Your Zones

    It is game day. You can feel the crowd’s energy. In the parking lot. At the gate. In the stadium. On the concourse. Fans are eager to party. Food and merchandise vendors ready themselves for the rush. Read Now

  • Street Smarts

    The ongoing acceptance of AI and advanced data analytics has allowed surveillance camera technology to shift from being a tactical tool to a strategic business solution. Combining traditional surveillance technology with AI-based data-driven insights can streamline transportation systems, enhance traffic management, improve situational awareness, optimize resource allocation and streamline emergency response procedures. Read Now

  • The Progress of Biometrics

  • Next-Gen AI for Smart Cities

    The future of smart city technology is not being shaped in Silicon Valley — it is taking root in Dubuque, Iowa. With a population of about 60,000, this mid-sized city has become a live testbed for AI-driven traffic management thanks to a unique public-private collaboration led by Milestone Systems. Project Hafnia demonstrates how cities can transform urban mobility and safety through Responsible Technology—without costly infrastructure overhauls. Read Now

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.