- Cyber
- 18th Aug 2026
- 1 min read
Cybersecurity Budget Benchmarks 2026: The Capacity Gap
- Written by
In Short..
- No external benchmark holds up under scrutiny: a percentage borrowed from an unrelated peer group is easy for a CFO to dismiss once asked where it came from.
- The gap keeps compounding: IDC’s own research on the GRC software market states plainly that "budgets cannot keep pace with hiring demands", and each underfunded cycle becomes the next cycle’s starting point.
- Capacity, not cash, is the actual constraint: even where budget exists, the hiring market cannot supply qualified GRC and security professionals fast enough to spend it.
- Underfunding compounds its own cost: unresolved risk, slower control testing, and a weaker case for next year's ask, on top of the FCA's £15.7m in fines in the first quarter of 2026 alone.
No published benchmark tells a CISO what a security programme should spend in 2026: peer-average figures collapse under the first question about where they came from. A more useful number measures the size of the gap between what security and compliance teams are now asked to cover and what a fixed budget can actually execute. That gap widens every year regulation adds ground without adding headcount to cover it.
Expert View
Matt Davies Chief Product Officer, SureCloud |
What our experts say about building next year’s budget case
"Boards rarely reject a security budget outright. They discount it because the ask reads like a wish list. What lands is separating headcount from capacity as two different requests, because once finance sees a hiring gap it genuinely can’t close, funding the alternative becomes the easier decision." |
Why There's No Usable 2026 Benchmark
Most published security-spend benchmarks answer a narrower question than the one a CISO actually needs answered. A benchmark shows where a programme sits against a peer average on one date. It doesn't explain why that average keeps moving, or why matching last year's figure buys noticeably less coverage this year.
A board asking for a hard external number wants a legitimate but separate thing: a primary data source, such as a named analyst survey or a commissioned customer study, built specifically to answer that question. What follows draws on IDC's analysis of the GRC software market and SureCloud's own operational data. Treat it as a mechanism worth understanding: it explains why the gap keeps opening. Next year's business case still needs its own commissioned figure.
A borrowed benchmark invites an obvious rebuttal: this programme, this regulatory exposure and this starting point look nothing like the comparison group's. A mechanism, clearly explained, is harder to dismiss. It doesn't depend on whether the peer group was ever the right one to begin with.
Why Budgets Keep Losing Ground
IDC's analysis of the GRC software market states the problem directly: "budgets cannot keep pace with hiring demands".1
It's a structural mismatch built into how budgets get set: what security and compliance teams cover, more frameworks, more scrutiny, more real-time evidence obligations, grows faster than the budget lines funding the people who do the work. That mismatch shows up whether the programme is well-run or not.
The pattern repeats even where nobody's put a name to it. A budget request goes in sized to the actual workload: new frameworks to onboard, continuous monitoring obligations that didn't exist three years ago, evidence requirements that moved from annual to near-continuous. What comes back is sized to what finance can justify against last year's baseline plus a modest increase. The difference doesn't vanish; it sits on the register as unresolved risk, waiting for headcount that isn't coming.
Two live regulatory obligations widen that gap without anyone in finance approving a cut. DORA (Regulation (EU) 2022/2554) has applied to in-scope EU financial entities since January 2025 and introduces personal accountability for ICT risk at management-body level under Article 5.
NIS2 is in force across the EU, its transposition deadline already passed in October 2024, with infringement proceedings still running against member states that haven't fully implemented it. UK organisations sit outside NIS2 itself but face a parallel regime through the Cyber Security and Resilience Bill, currently before the House of Lords with Royal Assent expected later in 2026. Both frameworks add evidence, reporting and control-testing obligations that arrive whether or not a matching budget uplift gets approved.
Year over year, that compounds. Each cycle adds obligations without a proportional budget increase, and each cycle's shortfall becomes next cycle's starting deficit. A programme that looked adequately funded three years ago can be materially underfunded today without a single budget cut ever having been approved.
What the budget needs to cover kept growing. The number itself didn't.
Capacity Is the Actual Constraint
This is where the argument needs sharpening. “We need more budget” is a weaker case than “we need more execution capacity,” because a bigger number doesn't automatically convert into people. IDC's own framing draws that distinction directly: the problem is "not a shortage of expertise, but a chronic shortage of execution capacity".1
ISACA's State of Cybersecurity 2025 survey found that 55% of security teams describe themselves as understaffed and 65% carry unfilled positions, with mid-sized organisations reporting the worst shortages. ISC2's 2025 Cybersecurity Workforce Study names GRC expertise among the skills security teams say they lack most. Both point to the same conclusion: hiring alone won't close this gap, because the market can't supply qualified headcount fast enough even where the budget to pay for it exists.
A requisition approved in January can sit open for months in a market this tight, and every month it stays open is a month of uncovered workload regardless of what the budget line says. Put the constraint where it actually sits: how fast an organisation can convert an approved number into people. Increasingly, that conversion is the whole problem.
What IDC found on the market’s execution gap
IDC’s Market Note describes SureCloud as having built "a virtual GRC team of autonomous, persona-based agents capable of executing over 250 distinct platform actions", alongside a separately cited benefit noting that its coverage "spans risk, compliance, audit, privacy, and third-party management"1
|
What Underfunded Security Costs
The cost of getting this wrong is live right now, before the next budget cycle even arrives. The FCA issued £15.7m in fines in the first quarter of 2026 alone, a reminder that regulatory exposure keeps accruing while a budget request works its way through committee. A board that treats security funding as a line item to trim in a tight year is pricing in that exposure whether it's noticed or not.
The less visible cost moves slower and is harder to point to in a single quarter: the control tested less often than it should be, the third-party assessment waved through because nobody has capacity to chase evidence properly, the framework onboarding pushed back a cycle. None of that produces a headline fine. Most of it surfaces eventually, usually the moment a regulator, auditor or customer asks the exact question the underfunded process was never built to answer.
There's a compounding cost that rarely makes it into a budget paper: the credibility cost of asking for more next year with nothing to show for this year's ask. A CISO who requested budget last cycle, didn't get it, and now has to explain a control-testing gap negotiates from a weaker position than one making the case for the first time. Underfunding leaves risk on the register. It erodes the credibility of the next request, and that makes closing the gap harder with every cycle it goes unaddressed.
Getting More From the Budget Already Approved
More money doesn't reliably convert into more capacity in a market this constrained, so the more useful question is what the existing budget can be made to cover. A senior GRC hire in the UK now carries a median salary of £72,500, before the months it often takes to recruit into a market where the skills gap is the whole problem in the first place, according to IT Jobs Watch salary data.
Execution capacity that doesn't depend on adding headcount changes that maths. A virtual GRC team of Gracie AI Agents with Personas and Skills performs the record management, evidence chasing and assessment work that would otherwise queue up behind a hiring plan. Budget that would have funded one more hire, eventually, can instead fund capacity that's available immediately and scales with the workload.
The scale of that shift is concrete. SureCloud's own published data shows a 75% reduction in audit preparation time and a 50 to 65% reduction in manual evidence collection once compliance automation is running. Neither figure reflects a bigger team.
Both reflect the same team covering more ground with the budget it already has. That's the argument a CFO can act on when headcount isn't the lever available to pull.
Call it the practical version of doing more with the same line: greater output from a budget that stays the same size. It's a different pitch to a CFO than a headcount request, and arguably a more honest one, because it doesn't depend on a hiring market delivering people it currently can't supply.
See the execution-capacity model in detail
SureCloud's guide for security leaders sets out how an executable GRC platform absorbs record management, evidence chasing and assessment work without adding headcount.
|
Bringing This Into Your Own Budget Conversation
Don't lead with a benchmark that can't be defended. A CFO who asks where a number came from and gets a vague answer will discount everything else in the paper alongside it. Separate the budget ask from the headcount ask explicitly, because conflating them invites the response “we approved budget, why hasn't the gap closed” when the honest answer is that the hiring market, not the budget line, was the constraint.
Frame any request for execution capacity, whether that's automation, tooling or additional support, against the workload it removes from a team that's already stretched. Finance departments fund workload relief they can see and stay sceptical of posture improvements they can't.
Revisit the request at the next cycle rather than treating this year's answer as final. A capacity argument that doesn't land this round often lands the next one, once the cost of the gap becomes visible in a missed deadline or a control that slipped. Keep the argument on file and update it with what actually happened each time, so the conversation builds on the last one.
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
See What a Virtual GRC Team Does to Your Capacity Numbers
FAQ’s
Is there an official cybersecurity budget benchmark for 2026?
No single, universally agreed benchmark exists for what a security programme should spend in 2026 as a percentage of revenue. Peer-average figures vary by sector, regulatory exposure and programme maturity, and a number pulled from an unrelated peer group rarely survives a CFO's first question about where it came from. A board that wants a defensible external benchmark needs a primary data source, such as a named analyst survey, something with a named methodology behind it.
Why do cybersecurity budgets fall behind demand even when they increase?
Because the scope of what a security and compliance team is asked to cover, more frameworks, more scrutiny, more continuous evidence obligations, tends to grow faster than the budget line funding the people to do it. IDC's analysis of the GRC software market describes this directly: "budgets cannot keep pace with hiring demands". Each funding cycle that falls short compounds into the next cycle's starting deficit.
What's driving regulatory pressure on security budgets in 2026?
DORA has applied to in-scope EU financial entities since January 2025 and carries personal accountability duties for management bodies. NIS2 is in force across the EU, and UK organisations face a comparable regime through the forthcoming Cyber Security and Resilience Bill. Both add evidence, reporting and control-testing obligations that arrive regardless of whether a matching budget uplift was approved.
How can a CISO build a stronger case than a benchmark comparison?
By explaining the mechanism behind the gap instead of quoting a number borrowed from an unrelated peer group. A benchmark can be argued with. A clear explanation of why obligations are outgrowing headcount is harder to dismiss, because it doesn't depend on whether the comparison group was the right one.
Does hiring more people close the capacity gap?
Rarely on its own. Even where budget exists to fund a new role, qualified GRC and security professionals are in short supply, and a requisition can sit open for months in a constrained market. Execution capacity that doesn't depend on adding headcount, such as AI agents performing evidence collection and assessment work, scales with the workload instead of waiting on a hiring pipeline.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.