Security budgets increased by an average of 5% in 2026, up from 4% the prior year, but more than half of chief information security officers saw their budgets stay flat or shrink, according to the IANS and Artico Search 2026 Security Budget report released this month. The report, which gathered responses from over 500 security executives between April and August 2026, found that while 64% of CISOs requested budget increases this cycle, only 45% received them—leaving 55% with stagnant or reduced funding. The average growth figure masks a far weaker reality: the median budget increase remained at 0%.

Who receives additional funding depends largely on corporate financial health and ownership structure. Firms that exceeded revenue goals by more than 5% were over twice as likely to grant double-digit security budget increases compared to those meeting targets—41% versus 15%—while 22% of significantly underperforming organizations reduced security spending. Venture capital-backed firms increased security budgets 71% of the time, compared with 52% at publicly traded companies, and government and nonprofit entities saw the smallest and least frequent increases. When CISOs do secure more money, business or operational risk was the most frequently cited reason at 48%, while new regulations and stronger board or executive attention produced the largest average increases at 22% and 23%, respectively. Major breaches, meanwhile, were cited by just 3% as a justification for obtaining additional funds.

Artificial intelligence has become the primary destination for new security dollars, with 69% of CISOs naming it their top net-new priority, the report finds. Steve Martano, IANS Faculty and partner in Artico Search's cyber practice, said security is "gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else's budget." Only 24% of organizations track AI as a separate security budget line or subcategory, while 38% have AI embedded within the security budget and another 38% fund it through IT, data, or innovation departments. The fragmented accounting means security budgets understate the money directed toward securing AI, with organizations formally tracking AI funding reporting increases roughly 70% of the time, compared to 42% where AI is embedded in general security budgets and 31% where it's funded elsewhere. Despite AI claiming a larger share of security spending, 81% of CISOs expect AI to generate demand for new roles and skills, while 69% anticipate no reduction in existing headcount.

The report reveals a sharp divide between organizations planning to increase AI security spending by more than 10%—termed aggressive AI spenders—and those with no AI-specific spending planned, though it doesn't specify whether organizational maturity drives spending or vice versa. Among aggressive spenders, 79% reported that leadership has at least a fair understanding of AI risks, compared to 33% in organizations without AI-specific spending plans, while 70% of aggressive spenders have clearly defined AI governance ownership versus 34% in the non-spending group. Half of aggressive AI spenders reported having a mature AI security program compared to 17% of non-spenders. Increased AI security spending correlates strongly with overall security budget growth: 45% of aggressive AI spenders increased their total security budget by more than 5%, and 51% expect to do so next year, while only 12% of non-AI-spenders increased overall budgets by more than 5%, and just 9% expect to next year. For CISOs trying to keep pace, the report advises creating a dedicated AI budget line and tracking actual costs before the next budget cycle. The practical challenge for security leaders is that proving value in AI spending may require the very governance maturity that budget constraints prevent them from building. Organizations unwilling to invest transparently in AI security risk falling further behind peers who've already secured executive buy-in and operational clarity.