Skip to content
AI the Top Priority for New Spend as Cyber Budgets Flatline

AI the Top Priority for New Spend as Cyber Budgets Flatline

Infosecurity-Magazine September 15, 2026

AI is the biggest priority for net-new budget dollars, with around a quarter of US CISOs expecting to aggressively grow their spend year, according to new data from IANS.

The cyber research and advisory firm compiled its 2026 Security Budget Benchmark Report from interviews with 500 security executives nationwide.

AI was by far the most popular area of focus for incremental budget, cited by 69% of respondents. It could be even more, given that other categories such as SecOps automation (51%) and IAM enhancements (39%) are AI-mature areas.

This increase has pushed software to account for 35% of the security budget in 2026, up from 29% last year and just two percentage points behind “staff & compensation”; the closest it’s ever been.

Rather than be a threat to cybersecurity jobs, AI is likely to help the market, IANS claimed.

More than two-thirds (69%) of CISOs said they don’t expect to cut existing headcount due to AI, and 81% anticipate the technology will create demand for new roles and skills.

An overwhelming majority of respondents said the technology is helping teams become more productive (91%), creating a need for new roles (81%), and enabling redeployment to higher value work (79%).

Budgets Stay Flat Overall

However, the AI surge is only one part of the story.

Overall, median growth remained flat, and over half (55%) of respondents kept budgets flat or made cuts due to economic headwinds. This is the second year in a row that IANS has recorded a majority of respondents with flat to negative growth.

“Two organizational factors matter most for budget growth: ownership structure, which shapes an organization’s underlying appetite to invest in security, and financial performance, which determines whether it currently has the resources to act on that appetite,” the report said.

To that end, 71% of VC-backed companies increased security budgets, most often by more than 10%. However, the figure for publicly listed companies was just 52%.

Despite surging investment in AI, security functions still need human team members to “find anomalies, elevate relevant threats and make judgment calls,” argued Steve Martano, IANS faculty member and partner at Artico .

"Organizations that align AI security investments with broader business objectives, establish clear governance, and invest in developing new skills will be better positioned to manage risk while enabling innovation,” he added.

Infosecurity Europe: AI SOCs Will Still Need SOC Analysts, Security Vendors Say News 1 June 2026

Infosecurity Europe: AI SOCs Will Still Need SOC Analysts, Security Vendors Say

Legacy Security Tools Failing Data Protection, Capital One Software Report Finds News 7 May 2026

Legacy Security Tools Failing Data Protection, Capital One Software Report Finds

#CyberMonth: The Importance of Identity and Access Management in Safeguarding Your Enterprise Blog 14 October 2024

#CyberMonth: The Importance of Identity and Access Management in Safeguarding Your Enterprise

Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS News 17 June 2026

Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS

Cyber Pros Embrace AI, Over 80% Believe It Will Enhance Jobs News 22 February 2024

Cyber Pros Embrace AI, Over 80% Believe It Will Enhance Jobs

What’s Hot on Infosecurity Magazine?

Revolut Confirms Data Breach Through Fake Government Requests

Hackers Exploit Maximum Severity Flaw in GitLab

OpenAI Agent Swarm Hacks RubyGems Package Manager

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

CISA Updates Insider Threat Guide With New Mitigation Advice

Anthropic Reveals Yet Another Cybersecurity Incident

Anthropic Reveals Yet Another Cybersecurity Incident

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How to Manage Enterprise Cyber Resilience in the Age of AI

How To Enhance Security Operations with AI-Powered Defenses

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Industries (1)

Ransomware Groups (1)