The 2026 Security Budget Benchmark Report from IANS Research and Artico Search found that security budgets grew by an average of 5% in 2026, but that average hides the constraint facing most CISOs. The distribution shows that growth reached fewer than half of security organizations:
| 2026 budget change | Share of CISOs |
|---|---|
| Budget increased | 45% |
| No increase | 45% |
| Budget decreased | 10% |
The same report found that 69% identified AI for security as their top priority for new budget dollars. The immediate AI decision is therefore about allocation: where money, automation and human judgment can reduce meaningful business exposure.
AI security spending is an allocation problem
The 2026 Security Budget Benchmark Report from IANS Research and Artico Search makes that allocation problem especially important. In total, 55% of organizations were working with flat or declining budgets even as average security spending rose. The average can suggest broad spending capacity, while the distribution shows how many security organizations lacked it. For those CISOs, making AI a priority requires reallocating a constrained plan and making the case for selective additions.
Those choices extend beyond technology purchases because AI changes security and governance work across the business. It changes which tasks machines can perform, affects hiring decisions and raises new questions about where expert judgment produces the most value. CISOs must make those choices while explaining risk and spending to boards in terms the wider business can evaluate. The same allocation method therefore has to cover technology, people and governance.
The method also has to account for organizations receiving more money. AI is the leading destination for new dollars among the CISOs surveyed, so the distribution of budget growth matters as much as its average. An organization needs to determine its capacity from its own budget and exposure. From there, the CISO can decide which additional spending deserves funding and which existing work can change to release capacity.
The business case starts with exposure
The allocation method starts with business exposure because the strongest reported spending driver comes from inside the organization. Among CISOs whose budgets were growing, 48% cited increased business or operational risk as a driver, while 3% cited a major industry breach as a primary driver. The gap matters in board discussions because changes in the company’s own exposure provide a stronger basis for spending than reactions to high-profile events elsewhere. That basis connects a security request to a business condition the board can evaluate.
Steve Martano, IANS faculty and partner at Artico Search, told TechTarget Cybersecurity: “The most effective way to get the budget and resourcing needed to lead a business-enabling security function is to tell the story of security in the context of business objectives,” Artico Search works in a market that benefits when organizations invest in security leadership and resourcing, so Martano has a commercial interest in that broader investment. His proposed method is concrete: start with what the company is trying to accomplish and identify the security conditions attached to it. That framing makes AI security part of a business initiative with consequences the board can evaluate.
Those security conditions change with the company’s direction. “Where a company is on the AI journey, the growth trajectory and market positioning all have security implications. By saying ‘yes, we are eager to support these initiatives and here’s what the security implications are…’ a CISO can tell a business-driven security story,” Martano said. For a company expanding its use of AI, the initiative becomes the starting point. The CISO can identify the systems and operations involved, then connect those changes to the exposure they create.
Once the initiative is clear, the CISO can translate its security implications into exposure the board can compare with other business decisions. Ivan Milenkovic, vice president of risk technology at enterprise security firm Qualys, argues that CISOs should identify which systems are affected, what those systems are worth to the organization, and what downtime or disruption would cost. Qualys benefits commercially when organizations invest in security and risk technology, so Milenkovic’s recommendations should be read with that interest in view. The resulting request can state the risk being addressed, the required investment and the exposure the company would retain without it.
The CISO can then test that exposure against the organization’s existing risk appetite, meaning the amount and type of risk it has decided it is willing to accept. The policy gives the board and CISO a business-defined boundary for evaluating a security request. “Go and read [the policy], then change the ask you make to the board,” Milenkovic said. Working from that policy separates exposure the organization has chosen to tolerate from exposure outside its accepted boundaries.
With those boundaries established, the board can compare priced risk outcomes. “Provide three options, each with a cost, a risk it removes and a risk you would still be carrying,” Milenkovic said. Each choice makes the trade-off explicit: spend a given amount, remove a stated risk and knowingly retain the remainder. The same allocation rule can guide staffing and day-to-day security operations because both require choices about where scarce resources reduce the most consequential exposure.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
AI changes security labor by redistributing judgment
Staffing data show how that allocation rule applies to people. IANS found strong expectations of productivity gains, new skill requirements and continued demand for existing security headcount over the next 12 months:
| CISO expectation | Share |
|---|---|
| AI will make security teams more productive | 91% |
| AI will generate demand for new roles and skills | 81% |
| Existing security headcount will not fall | 69% |
Together, those expectations point toward redesigned work and new expertise alongside automation. Productivity gains can come from changing the work people perform while organizations continue to need security staff.
Nick Kakolowski, senior research director at IANS, describes two changes happening together. “We‘re seeing two changes,” he said. The first affects whom leaders may be willing to hire because AI can shift the balance between technical knowledge a candidate already possesses and the capabilities the organization expects automation to supply. The second appears in the new work required to build and manage AI inside security teams.
Kakolowski connected both changes directly: “Leaders are considering hiring individuals who are stretch candidates for roles if they have the right soft skills, expecting AI to fill in some of the technical skill gaps. We are also seeing a growing need for roles around building, assessing and managing AI capabilities within the security team,” Kakolowski said. A stretch candidate can become viable when the candidate brings suitable judgment and interpersonal skills while AI supplements bounded areas of technical work. At the same time, AI adoption creates specialist responsibilities for constructing, evaluating and operating those capabilities.
For an existing team, the same division of labor determines which tasks should move to machines. Repetitive, well-bounded technical work is a candidate for automation, which frees security professionals to focus on decisions where context, consequences and uncertainty demand human judgment. The productivity gain comes from reallocating expertise across tasks. Workforce planning can then focus on which decisions still require people and which competencies they need as routine work moves elsewhere.
That shift also changes hiring criteria because teams can give different weight to capabilities people must exercise directly. At the same time, the organization needs skills for governing the AI systems on which the team increasingly depends. Higher productivity and increased demand for skills can therefore occur together. Vulnerability management shows how this redistribution can work inside a specific security workflow.
Vulnerability management shows risk-based reallocation in practice
Vulnerability management makes the redistribution concrete because the raw volume of findings is much larger than a tightly defined high-priority subset. Qualys identified 357 of the 48,172 vulnerabilities disclosed in 2025 that met three conditions: they were remotely exploitable, actively weaponized and supported by working exploit code. Those 357 are a subset selected through operational criteria for a particular form of prioritization, while other vulnerabilities can still matter under different conditions.
AI can perform much of the filtering and remediation work that comes before cases requiring human judgment. “AI is very good at removing that work: sorting findings against live exploitation, reading a patch and what it is likely to break, deploying the safe ones without a human in the loop,” Milenkovic told TechTarget Cybersecurity. In that sequence, automation first relates a finding to actual exploitation, then evaluates potential patch effects and proceeds automatically when remediation is assessed as safe. Human attention can then concentrate on cases with greater exposure or more difficult consequences.
Asset inventory extends the same mechanism beyond a vulnerability feed. Milenkovic said AI can search an organization’s inventory for possible issues, evaluate patches and automatically apply lower-risk fixes. Routine discovery and safer remediation can therefore be processed before the remaining vulnerabilities reach a security professional. The team gains capacity because less low-judgment work competes for the same people.
That workflow applies the board-level allocation rule at a different scale. Milenkovic’s three-option board approach prices risk removed and risk retained, while vulnerability triage uses exploitation evidence, asset context, patch consequences and remaining exposure to direct operational effort. A proposed AI investment can use the same test by specifying the risk it reduces, the work it can safely automate and the human capacity that automation releases. Vulnerability management makes those effects observable in the workflow itself.
Governance belongs inside the allocation decision
The productivity case becomes more demanding when AI adoption elsewhere in the business creates more work for the security team. Separate Absolute Security research surveyed 1,001 CISOs in the U.S. and UK and found that 60% said board pressure to adopt AI was moving faster than their ability to secure and govern it. Employee use in everyday workflows can advance while controls are still developing. Security leaders consequently have to allocate resources to governing business adoption while also using AI within security.
The same collision is already visible inside security operations. Absolute Security found that 83% of organizations were piloting or running agentic AI there, meaning AI systems capable of taking actions toward objectives instead of simply producing a response for a user. High adoption can coexist with constrained governance capacity, which makes controlled deployment the immediate operational problem. Security teams need capacity to decide where autonomous action is appropriate and which controls should govern it.
Vimal Raj, head of technical, UK and Ireland at ManageEngine, described that pressure directly: “AI has left IT teams in a race to regain control,” Raj recommends “upskilling, including AI literacy” and closer integration between IT and business teams. As a ManageEngine executive, Raj has a commercial interest in how enterprises manage and govern IT operations, so his recommendations intersect with the market his company serves. AI literacy supports governance by helping employees and decision-makers understand the systems they use, while closer IT-business integration brings adoption decisions into contact with the teams responsible for securing them.
Those governance requirements also affect deployment priorities. Raj argues for identifying operations where AI can genuinely improve work and giving employees approved, governed AI tools. The allocation decision therefore has to fund training, control and coordination alongside the AI capability itself. Because board demand for faster adoption is helping create the resource pressure, governance needs capacity as adoption expands.
Redesign can still require more resources
Governance exposes a limit of reallocating existing capacity: the amount of work can grow as AI adoption grows. Fewer than half of CISOs received budget growth in 2026, yet IANS found that 64% expect their security budgets to increase in 2027. That expectation is consistent with continued demand for security headcount and new roles and skills. AI can raise productivity while creating additional responsibilities that require funding.
Incremental resources can then be tied to the exposure that remains after work has been redesigned. Automation may release capacity from repetitive tasks, while governance, assessment, management and new skills create demands elsewhere in the security function. The case for additional budget rests on the cost and consequence of the remaining exposure. That gives the CISO a basis for deciding where added money and human judgment can produce the greatest reduction in business risk.
Key highlights
- Tie AI spending to business exposure: CISOs can strengthen budget decisions by connecting AI investments to specific systems, operational risks and the company’s stated risk appetite. Present options with the cost, risk reduced and exposure retained.
- Reallocate security work around human judgment: AI can absorb repetitive, bounded technical tasks while security professionals focus on decisions requiring context and judgment. Hiring plans can emphasize those capabilities alongside new skills for building, assessing and managing AI.
- Automate vulnerability work selectively: Security teams can use AI to filter findings against exploitation evidence, assess patch effects and automate lower-risk remediation. Human attention can then concentrate on vulnerabilities with greater exposure or uncertain consequences.
- Fund governance alongside AI adoption: CISOs need capacity for AI literacy, approved tools, controls and coordination as AI spreads across business and security operations. Governance requirements belong in the allocation decision from the start.
- Price the exposure that remains after automation: AI productivity gains can release capacity while creating new work in governance, assessment and specialist roles. CISOs seeking additional resources can base the request on the business impact of the risk that remains after workflows are redesigned.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


