Forge University
Industry News

The Training Line Item Cybersecurity Leaders Protect When Budgets Get Cut

September 9, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Illustration of a bridge made of books spanning a gap between two buildings under a padlock-shaped sky

When a security budget gets trimmed, certification and upskilling spending tends to survive longer than new tooling or headcount because it produces measurable output from people already on payroll. Recent workforce data backs this up directly: budget cuts and layoffs have leveled off industry-wide, but the 2025 ISC2 Cybersecurity Workforce Study found skills gaps, not headcount, are now the bigger operational risk.

That distinction matters for anyone who owns a training line item this year. Cutting a tool subscription is a one-time decision with a known blast radius. Cutting certification funding is a bet that your current team's skills won't need to stretch further as threats, audits, and AI adoption all move faster than hiring can.

Why Does Certification Spending Survive When Tools and Headcount Get Cut?

Certification spending survives because it is one of the few line items that directly reduces the need for future hiring, and hiring is the most expensive lever a security leader has. The ISC2 2025 Workforce Study reported that budget cuts and layoffs, after surging in 2024, showed signs of stabilizing in 2025, even as 95 percent of respondents said they were dealing with at least one skills gap on their team. Large organizations felt this hardest, with close to half reporting budget cuts and roughly a third reporting layoffs, yet the demand for specific technical skills kept climbing regardless of headcount.

That gap between "we can't hire" and "we still need the skill" is exactly what training budgets are built to close. Independent research backs the financial logic: an IDC white paper commissioned by SANS found organizations using structured certification training needed 26.9 percent fewer new hires annually, translating into measurable annual hiring cost reductions. That is not a soft benefit. It is a number a CFO can put next to a headcount request and use to justify approving training instead.

The tension is that this logic only works if the certifications funded are the ones actually tied to open risk, not the ones easiest to schedule. ISACA's own State of Cybersecurity 2025 report found something worth sitting with: even though more than half of teams are understaffed, the share of enterprises training non-security staff to move into security roles actually dropped, from 41 percent the prior year down to 29 percent. Budgets are being protected in principle but not always deployed with intent.

Which Certifications Actually Move the Needle on a Budget Committee?

The certifications that survive scrutiny are the ones a leader can tie to a specific, named risk the organization already knows it carries, not a general skills upgrade. Auditors want to see qualified individuals behind risk assessments. Boards want to see AI governance addressed before regulators ask about it. Incident response plans need people who have actually practiced the scenario, not read about it.

This is why management-track certifications tend to get funded even when technical tool budgets get cut. A CISM certification signals that a manager can translate technical risk into business risk language a board understands, which is precisely the skill ISACA's research flags as under strain when teams lose staff who could previously mentor that judgment into junior hires. It is also why certifications tied to AI oversight are showing up in funding requests that would have been rejected outright two years ago. Seventy percent of professionals surveyed by ISACA said they expect demand for technical cybersecurity professionals to keep rising over the next year, even inside flat-budget organizations.

Budget benchmarking research points to the same pattern from the finance side. The IANS 2025-2026 Security Budget Benchmark Report found that overall budget growth is tapering and security teams are being asked to deliver more without more staff, which pushes leaders toward automation and toward getting more capability out of the people already on the team. Training that produces a verifiable, third-party-audited credential is one of the few ways to prove that capability increase happened.

How Should Security Leaders Decide Which Certifications to Fund First?

Fund the certifications that close a gap tied to a named risk, audit finding, or regulatory requirement before funding the ones that sound impressive on a resume. A useful way to sort a training request list is by what it protects against operationally, not by title recognition.

Business pressureCertification track that answers itWhat the budget committee actually wants to see
Board and audit scrutiny of AI governanceCISM or AAISMDocumented ownership of AI-related risk decisions
Understaffed SOC, rising alert volumeCySA+ or SC-200Fewer escalations needing outside consultants
Regulatory exposure across jurisdictionsCIPP/US or CIPP/EFewer compliance gaps found in the next audit cycle
Cloud migration outpacing security reviewCCSP or SecurityXReviewed architecture before, not after, deployment

None of these choices are permanent. The point of building the case this way is that a training budget defended with a named risk survives the next round of cuts, while one defended with "the team wants to grow" usually does not. If you want a structured way to compare what each certification track actually covers before committing budget to it, the certification resource library breaks down exam domains and prerequisites so the decision isn't made on marketing copy alone.

The AI Variable Nobody's Budget Model Accounted For

AI is quietly rewriting which certifications get prioritized, and most training budgets built even eighteen months ago did not plan for it. Evanta's 2025 survey of more than 1,100 CISOs found that 35 percent planned to spend on generative and traditional AI tools and solutions this year, a category that barely existed in budget planning cycles a few years ago. ISACA's research found something similar on the individual side, with a large share of professionals already pursuing AI-focused qualifications on their own initiative, ahead of formal employer mandates.

That creates a specific problem for leaders sitting on a fixed training budget. Funding AI-adjacent certifications now, before a regulator or auditor asks for proof of oversight, is cheaper than funding them under deadline pressure later. The same logic that made CISM and CISSP indispensable for governance conversations now applies to the newer credentials layered on top of them. If your team hasn't started, you can build a study plan and start training around the specific gap your last audit or incident actually surfaced, rather than the gap that sounds most current in a vendor pitch.

Building the Case Your CFO Will Actually Approve

A training request survives a budget review when it answers three questions a spreadsheet alone cannot: which risk does this close, how do we know the person retained the skill, and what happens if we skip it this cycle. Certification exams answer the second question by design, since they are independently proctored and tied to defined domains rather than internal self-assessment.

The first and third questions are where most requests fail. A request that says "our SOC needs more training" gets deprioritized. A request that says "we had three escalations last quarter that a certified analyst could have triaged internally, and our cyber insurance renewal asks about documented training" gets funded, because it ties directly to the ISC2 finding that 72 percent of respondents believe reduced staffing increases breach likelihood. That is a sentence a CFO can repeat back to the board.

The organizations getting the most out of flat or shrinking security budgets right now are not the ones spending the most on training. They are the ones spending it on the narrowest, best-documented gaps, and renewing that spend every cycle instead of treating certification as a one-time onboarding cost. That discipline, more than the size of the budget itself, is what determines whether a security team can keep pace with the risks it's actually being asked to cover.

Start training free at Forge University