Forge University
Industry News

Your Training Budget Just Grew. Here's How to Decide What It Buys First.

September 23, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Balance scale weighing traditional security tools against interconnected AI nodes in a boardroom setting

Fund foundational certifications first, then layer domain-specific ones on top, and treat AI-focused credentials as a distinct budget line rather than folding them into general security training. Nearly three-quarters of security leaders report their training budget grew in the past year, but almost half say AI is the single skill they're most pressed to address, which means the money and the mission aren't automatically aligned.

Why Is Training Budget Growing While Headcount Stays Flat?

Because leadership has concluded that the skills gap, not the staffing gap, is now the bigger operational risk. ISC2's 2026 Security Training Trends report found that almost three-quarters of security leaders (73%) say their security training budget increased over the past 12 months, even as many of the same organizations kept hiring flat. That's a deliberate substitution, not an accident of timing.

The same survey found nearly half of security leaders (47%) say AI is the most pressing skill their organization is addressing or planning to address through cybersecurity training. Pair that with ISC2's separate 2025 workforce study, which surveyed over 16,000 professionals and found that nearly 90% of respondents (88%) have experienced at least one significant cybersecurity event in their organizations due to skills shortages, with 69% reporting more than one event. Executives aren't funding training as a morale perk. They're funding it because skills gaps are already showing up as incidents.

This is also a capital allocation conversation now, not just an HR one. Gartner's CFO Leadership Vision research, based on nearly 5,000 finance leaders, found that top priorities for 2025 include proving AI's return on investment and upskilling teams for a digital future, according to reporting on the CFO's growing role in security budgeting. When finance is asking the same question security leaders are, the training line item stops being discretionary and starts being scrutinized like any other investment.

Which Certifications Should Get Funded First?

Start with whatever closes the risk your organization has already demonstrated, not the certification that's trending in headlines. A useful way to think about this is to separate your team's certification needs into four risk domains and fund them in the order your actual exposure demands, not in the order vendors pitch them.

Risk domainWhat goes wrong if unaddressedCertification to prioritize
Identity and accessCredential compromise, lateral movementCISSP, Microsoft SC-300
Cloud misconfigurationData exposure, compliance failureISC2 CCSP, CompTIA Cloud+
AI and agentic toolingUngoverned AI agents, shadow data flowsCompTIA SecAI+, ISACA AAISM
Detection and response at machine speedSlower containment, alert fatigueCompTIA CySA+, Microsoft SC-200

Most teams already have partial coverage of the first two rows. The gap almost everyone shares is the third. If your organization has deployed any generative AI tooling in the last eighteen months, and most have, that row is where the next dollar of training budget should go, because it's the domain with the least existing bench strength and the fastest-growing exposure.

For a lot of teams, that means the CompTIA SecAI+ certification becomes the next logical purchase, not because it's new, but because it directly answers the exact question the ISC2 data says leaders are asking: who on the team can actually govern and secure AI systems in production. Funding a credential built around a live problem gets budget approval faster than funding one built around a hypothetical.

How Do You Sequence Spending Without Overcommitting the Budget?

Sequence by dependency, not by preference. A team that funds an AI security certification before anyone holds a foundational security credential is building a specialty on a floor that isn't there yet, and that shows up later as inconsistent judgment calls during incidents.

The practical order looks like this for most mid-sized security teams:

  • Confirm foundational coverage first. If your team doesn't already have broad coverage in a credential like CompTIA Security+ or ISC2 CISSP, that gap gets funded before anything specialized, because every downstream certification assumes that baseline.
  • Fund the domain with the most recent incident or audit finding second. If a penetration test flagged cloud misconfiguration, that's your next dollar, not AI, no matter how urgent AI feels in the trade press.
  • Fund the AI and agentic tooling domain third, unless your organization has already deployed autonomous agents into production workflows, in which case it moves to first. The risk profile of ungoverned agentic tools is different enough from traditional AI use that it changes the sequencing math.

This isn't a rigid formula, but it forces a conversation that budget requests often skip: which risk is actually most urgent this cycle, versus which one got the most attention at the last conference. CompTIA's own research on workforce trends backs up why sequencing on evidence matters. Its Workforce and Learning Trends 2026 report found that as a first step in validating the efficacy of training, credentials such as industry-recognized certifications can offer evidence that desired skills have been attained, and the ranking of validating assessments as very important rose slightly, from 56% to 59% year over year. Leadership increasingly wants proof that training dollars produced a verifiable skill, not just a completed course.

What Changes When Certifications Also Function as Hiring Evidence?

Certifications now carry weight in hiring decisions too, which means a training budget decision and a hiring policy decision are converging. More than half of employers, 53 percent, have removed degree requirements as of 2025, according to reporting on the 2026 talent shift away from degrees, up sharply from the year before. As degree requirements fall away, certifications become one of the few remaining external signals a hiring manager can verify without running their own skills test.

That has a direct budget implication. If your organization is hiring against skills rather than degrees, the certifications you fund for existing staff become the same standard you'll expect from new hires, which means underinvesting in your current team's credentials quietly lowers your own hiring bar. A curriculum overview that maps each certification to the specific job function it validates is worth building before you finalize next year's training request, because it turns an abstract budget line into a defensible, role-by-role case.

Building the Case Leadership Will Actually Approve

A training budget request lands better when it's framed the way finance already frames every other investment, as risk reduction per dollar rather than a wish list of courses. The CFO research cited earlier makes the same point from the other side of the table, noting that finance leaders want technology spending tied to measurable outcomes, not general upskilling ambition.

If you're building that case for the first time, or rebuilding it because last year's version got trimmed, the sequencing table above gives you a starting structure. Identify which risk domain has the least coverage, attach a recent incident, audit finding, or vendor requirement to it, and request funding for that domain specifically rather than for "security training" as a category. Specific requests survive budget review better than broad ones. If you want a study plan built around this kind of role-by-role gap analysis, you can start training whenever you're ready to move on it.

The organizations getting this right aren't the ones spending the most. They're the ones who can explain, domain by domain, why this certification, for this person, closes this specific risk, this quarter. That explanation is what turns a training budget increase into an actual reduction in operational risk instead of just a bigger number on next year's spreadsheet.

Start training free at Forge University