CISOOnline

Security spending is growing — except for the typical CISO

Who gets to spend appears to depend heavily on the health and structure of the business. Companies that outperformed revenue targets by more than 5% were more than twice as likely to receive a double-digit security-budget increase as companies that hit their targets, 41% versus 15%, while 22% of significantly underperforming companies cut security budgets.

Ownership mattered as well:71% of VC-backed companies increased security budgets, compared with 52% of publicly listed companies, while government and nonprofit organizations saw budgets grow least often and by the smallest margins.

And when CISOs do get more money, a major breach may not be the argument that gets them there. Business or operational risk was the most common reason for budget increases, cited by 48% of CISOs whose budgets grew, while new regulations and stronger board or executive focus produced the largest average increase at 22% and 23%, respectively.



Source link