Are Cybersecurity Budgets Rising in 2024? Insights from CISOs

  • UserVal Tsanev
  • February 15, 2024
  • 4 min read
  • Facebook Icon
  • Twitter Icon
  • LinkedIn Icon

Cybersecurity is a top concern for businesses of all sizes in 2024. With the increasing sophistication of cyberattacks, organizations are under more pressure than ever to invest in their cybersecurity defenses. But are cybersecurity budgets actually rising to meet these challenges?

A recent survey conducted by Night Dragon delves deeper into the escalating budgets of CISOs, providing additional insights into cyber spending trends and the focal points for 2024.

Key findings from the survey include:

  • Almost 80% of CISOs noted an increase or significant increase in their budgets from 2022 to 2023, a rise from 66% in the previous year.
  • Budget allocations in 2023 were directed towards various categories such as enhancing ransomware resilience, investing in managed detection and response, bolstering identity management, fortifying cloud security, addressing operational technology security, strengthening endpoint security, integrating artificial intelligence, recruiting new team members, and more.
  • The overwhelming majority of CISOs anticipate another budget increase in 2024, with 80% projecting growth in their budgets, marking a rise from 67% reported last year.

bar graph: cyber budget increase or decrease in year 2022 and 2023

(Source: Night Dragon)

Reasons for the Rise:

Escalating Threats: The frequency and severity of cyberattacks are undeniable. Data breaches, ransomware attacks, and supply chain compromises make headlines daily, pushing cybersecurity to the forefront of boardroom discussions.

Regulatory Push: Data privacy regulations like GDPR and CCPA are raising the bar for data security compliance, forcing businesses to invest in robust controls to avoid hefty fines and reputational damage.

Shifting Mindset: As cyber incidents become more common, the perception of cybersecurity is changing. It's no longer seen as a cost center, but rather an investment in business resilience and long-term success.

However, not all CISOs are seeing their budgets increase. A study by CSO found that 37% of CISOs reported flat or declining budgets in 2023. The biggest reason for the cuts was economic pressure, as businesses tightened their belts in the face of a challenging economy.

Reasons for Decline

Economic Downturns: In uncertain economic times, cybersecurity budgets may be seen as discretionary expenses, susceptible to cuts during belt-tightening measures.

Lack of Awareness: Some decision-makers might underestimate the true cost of cyberattacks, failing to grasp the potential financial and reputational damage, leading to inadequate budget allocation.

Skill Shortage: The cybersecurity talent gap makes it difficult to find and retain qualified professionals, leading to inefficient resource allocation and budget constraints.

So, what does this all mean for cybersecurity budgets in 2024? The answer is likely to be mixed. Some businesses will continue to increase their cybersecurity spending, while others will be forced to cut back due to economic constraints.

The Importance of Cybersecurity

There is no doubt that cybersecurity is essential for businesses in today's digital world. Cyberattacks can have a devastating impact on organizations, causing financial losses, reputational damage, and operational disruptions.

According to a report by IBM, the average cost of a data breach is $4.24 million. There are almost 32000 CISOs globally who have been facing the challenge of fighting cyber crimes that occur every 39 seconds.

These statistics highlight the importance of having strong cybersecurity defenses in place. By investing in cybersecurity, businesses can protect themselves from these risks and ensure their continued success.

The Challenges of Cybersecurity

Unfortunately, there are a number of challenges that make it difficult for businesses to adequately fund their cybersecurity needs.

One challenge is the ever-evolving threat landscape. Cybercriminals are constantly developing new and sophisticated attack techniques, which means that businesses need to constantly update their defenses.

Another challenge is the lack of skilled cybersecurity professionals. There is a global shortage of cybersecurity professionals, which can make it difficult for businesses to find and hire the talent they need.

Moreover, cybersecurity can be expensive. Implementing and maintaining effective cybersecurity controls can be costly, especially for small and medium-sized businesses.

The Role of CISOs

CISOs play a critical role in helping businesses to overcome these challenges and secure their data and systems. CISOs are responsible for developing and implementing cybersecurity strategies, managing cybersecurity budgets, and overseeing the organization's overall cybersecurity posture. However, CISOs often face challenges when it comes to approving the budget from the boards.

Ira Winkler, CISO and Vice President at CYE, says “The major problem in cybersecurity is that CISOs get the budgets that they deserve, and not the budget that they need.”

CISOs need to be more than just technical experts. They also need to be strong communicators and advocates for cybersecurity. CISOs need to be able to communicate the risks of cyberattacks to senior management and secure the funding they need to implement effective cybersecurity controls.

Winkler also says that "If you want to get the budget you need, you need to walk into budget-related meetings and say, "If you give me $XX,XXX, I will return $YY,YYY,YYY in reduced risk." It helps to have supporting documentation, and impress them with some mathematics that will stand up to examination."

A Look Ahead

While the future remains uncertain, the need for robust cybersecurity is undeniable. As threats evolve and regulations tighten, we can expect continued pressure on budgets. However, by adopting a strategic approach, CISOs can effectively advocate for necessary resources, ensuring their organizations remain resilient in the face of ever-growing cyber threats.


Cybersecurity budgets may be a mixed bag in 2024, but one thing is clear: investing in cybersecurity is no longer a choice, but a necessity. By understanding the driving forces, adopting strategic approaches, and remembering the human element, organizations can navigate the budgetary maze and build the defenses they need to thrive in the face of ever-evolving cyber threats.

  • Facebook Icon
  • Twitter Icon
  • LinkedIn Icon

Recent Posts

See All
featured image thumbnail for post The Human Risk Factor in Cybersecurity: Things for Cybersecurity Vendors To Consider
featured image thumbnail for post   Top 50+ Cybersecurity Conferences 2024 in the USA
featured image thumbnail for post The Role of Machine Learning and AI in Cybersecurity