Security Budgets Grew 5%. Almost None of It Went to Headcount.
September 18, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Security budgets grew by an average of 5% in 2026, and almost none of that new money went to headcount. It went to AI tooling. For leadership, that raises a sharper question than "buy more tools or hire more people": if your team size isn't changing but your software footprint is, is the next dollar better spent on another license or on the skill to run and secure what you already bought.
Where Is the New Security Budget Actually Going?
It's going to software, and specifically to AI. The 2026 Security Budget Benchmark Report from IANS and Artico Search, based on more than 500 security executives, found that AI is now the leading driver of new cybersecurity investment even though overall budgets grew just 5%, with 45% of organizations reporting no increase at all and 10% reporting a decrease. Seven in ten CISOs named AI their top priority for whatever new dollars they did get.
That shift shows up directly in how the budget pie is cut. Software now accounts for 35% of the average security budget in 2026, up from 29% the year before, putting it within two points of staff and compensation, the closest those two categories have ever been according to Infosecurity Magazine's coverage of the report. Staff and compensation used to be the budget's anchor by a wide margin. It no longer is.
Is AI Spending Actually Shrinking Security Headcount?
No, and that's the part leadership tends to get wrong. The same IANS data found that 81% of CISOs expect AI to create demand for new roles and skills, while 69% do not expect it to reduce existing security headcount. AI is changing what the current team is asked to do, not replacing the team.
That distinction matters for how you plan a budget. If headcount stays flat while software spend climbs, the people already on payroll are the ones who have to absorb new AI-related responsibilities, whether that means vetting an AI-powered detection tool, governing a Copilot rollout, or answering for how a model was secured. Buying the tool without funding the skill to run it is a half-finished purchase.
The Accounting Problem Nobody's Fixed
Part of why this gets missed is that most organizations can't actually see their own AI spending clearly. Only 24% of organizations track AI as a separate line item in the security budget, while 38% embed it in the general security budget and another 38% fund it out of IT, data, or innovation budgets instead, according to CSO Online's reporting on the same benchmark study. Organizations that do track AI spending separately reported budget increases about 70% of the time, versus 42% where it's buried in the general security line.
That fragmented accounting means many leadership teams are underestimating how much they're already spending on AI, and by extension, how little of that spend is going toward the people who have to secure it. You can't budget for a skills gap you can't see on the ledger.
The Gap Nobody's Pricing Correctly
Here's where the mismatch becomes a real risk decision, not just a bookkeeping quirk. Globally, enterprises are pouring far more into AI-powered security tools than into securing the AI those tools and the rest of the business now run on. Gartner's own forecast splits the market into two pieces for the first time: AI-amplified security, meaning AI built into detection and response tools, reached an estimated $49 billion in 2025, while securing AI itself, meaning the models, training data, inference pipelines, and agent workflows, stood at just $2.8 billion, according to analysis of Gartner's AI security forecast. That's roughly a 17-to-1 ratio of spend on AI-powered defense versus spend on defending AI.
Put plainly, most organizations are buying AI to make their existing security stack faster, while leaving the AI systems themselves, and the people who'd need to govern, audit, and incident-respond around them, comparatively unfunded. That's the gap a training investment closes faster than a procurement cycle can.
Why Training the Team You Have Is the Higher-Leverage Move
This is where the budget math tips toward certification rather than another tool purchase or open req. The ISC2 2025 Cybersecurity Workforce Study found that budget constraints have steadied but not disappeared, and drew a direct link between skills investment, or the lack of it, and rising perceived security risk and incident exposure. A year earlier, ISC2's 2024 study had already flagged the mechanism: budget cuts hit training funding directly, and as IBM's analysis of that study noted, two-thirds of respondents said those cuts made closing the skills gap harder, in part because the money for training simply wasn't there.
That's the case for treating certification as capital allocation, not a perk. Training an existing analyst or engineer to handle AI-specific risk costs a fraction of a new hire's fully loaded salary, doesn't add to headcount anyone has to justify next cycle, and can be underway within weeks instead of the months a search takes. A practitioner-level credential built specifically around this gap, such as CompTIA's SecAI+ certification, covers the ground that generic security training doesn't:
- Assessing AI model and pipeline risk before deployment, not just after an incident
- Spotting prompt injection, data poisoning, and other AI-specific attack patterns
- Mapping AI use to governance and compliance obligations leadership already has to answer for
- Securing the AI supply chain, including third-party models and pretrained components
- Building incident response playbooks that actually account for how agentic systems fail
If you're deciding where the next training dollar goes, a side-by-side of what's growing versus what's staffed makes the imbalance concrete.
| Category | 2025 spend or share | Trend |
|---|---|---|
| AI-amplified security tooling | ~$49 billion globally | Growing fast, absorbing new budget |
| Securing AI itself | ~$2.8 billion globally | Roughly 17x smaller |
| Software share of security budget | 35% (2026), up from 29% | Closing in on staff and comp |
| CISOs expecting AI to add new roles | 81% | Skills demand rising |
| CISOs expecting AI to cut headcount | 31% (69% say no) | Headcount largely flat |
None of this means tooling spend is wrong. It means tooling spend without a matched investment in the people running and governing it is an incomplete decision, and one a board or a cyber insurance underwriter will eventually ask about directly. If you want a clearer picture of how a credential like this maps to your team's actual gaps before you commit budget, the certification resources overview walks through curriculum scope and exam structure without a sales call attached. And if the case above matches what you're seeing in your own numbers, you can start training your current team against this gap well before the next budget cycle forces the conversation.
The organizations that get ahead of this aren't the ones buying the most AI-powered tools. They're the ones who can prove, line by line, that every tool has someone certified to run it responsibly.