According to Cybercrime Magazine, total global spending on cybersecurity services and products is expected to reach $520 billion in 2026 — double the total from five years previously.
It’s easy to understand why that spending has increased. Just think of all the major changes we’ve seen in the world of work between 2021 and today:
- Flexible work: many employees still work from home some or all of the time, bringing a new level of challenges around secure connectivity, networking, and keeping data and applications safe.
- AI: the sudden explosion in AI use has left many IT and security teams scrambling to rein in their employees’ ambition and ensure AI tools are used responsibly.
- Shadow IT: more applications are being installed by employees unilaterally, bypassing traditional security and governance, placing extra demands on security teams to react when problems arise.
- Estate complexity: the scale of systems and applications used by a typical business is expanding all the time, especially with the proliferation of SaaS applications.
- Rising cybercrime threats: cybercriminals are becoming smarter, better-resourced, and more sophisticated in their approaches all the time.
But that headline figure is a little misleading. Just because more is being spent on cybersecurity doesn’t necessarily mean everything is safer.
Trying to do a lot more, with a lot less
Indeed, all those changes and added complications mean that extra investment is often swallowed up just maintaining current security levels, rather than strengthening in areas that are vulnerable.
Indeed, the security teams in many businesses — especially smaller and medium-sized organisations where budgets — are finding that they’re actually becoming more and more stretched. With the average cost of a breach now $4.4 million (according to IBM), senior leaders are ramping up the pressure on security operations to deliver enterprise-level security outcomes with mid-market budgets and resources.
This situation is only likely to worsen in the months and years ahead, especially as the use of AI becomes more and more ubiquitous in business settings. Complexity will increase, and security teams will still be expected to deliver results — whatever the level of the budget they’ve been given. Something may well have to give.
Making security spending smarter
So what’s the answer? Simply throwing money at the problem and buying in more security solutions is probably a non-starter, for two reasons: you probably won’t get the chance to spend that kind of cash; and buying the best doesn’t always deliver the best results[1.1].
Instead, the answer is efficiency, and trying to make sure that every pound, euro or dollar that you spend on cybersecurity is having the biggest positive impact in as many different areas as possible.
There are two ways to look at efficiency here. The first is in the solutions themselves: eliminating areas where different solutions overlap, and looking for ways to apply existing technologies to new security demands and applications as they emerge.
The second is in procurement. As IT estates have gradually grown in size and complexity over the years, new security platforms and vendors naturally get added to cover new requirements. Left unchecked, this can lead to a sprawling mass of solutions, vendors, contracts and SLAs that can be hugely cost-inefficient (and consume time and money to manage). Cutting down the number of vendors and contracts through combination and consolidation can free up valuable funding to apply elsewhere, without compromising protection in the process.
Addressing this second point starts with understanding just how far your vendor sprawl has spread.