Programme Economics·~13 min read·2,667 words

Cybersecurity budget benchmarks: what to spend, where, and how to defend the number

Practitioner reference for CISOs, CFOs, and board members · 2026-05-24 · Drawn from twelve years of programme reviews across Indian and international firms


The question every CISO gets asked

"What should our cybersecurity budget be?"

The honest answer is it depends on what you're protecting and what you can afford to lose. The useful answer requires benchmarks. Boards want a number. Finance wants a number. The CEO wants a number. And the CISO is left calibrating a security programme against an industry frame that nobody has bothered to articulate plainly.

This guide gives you the numbers. The ratios. The audit costs. The benchmarks for India and for international comparisons. Where I am uncertain, I say so. Where industry data is unreliable, I tell you that too.

This is a reference for the people who have to defend the budget to a board that doesn't understand security but does understand percentages, and for the operational security leads who need to know whether their programme is over-invested, under-invested, or about right.


The headline benchmark: cybersecurity as a percentage of IT budget

The most widely cited benchmark globally is 10-15% of total IT spend allocated to cybersecurity for a mature programme. This number comes from a combination of analyst reports (Gartner, Forrester), CISO surveys, and aggregated peer data. It is approximately correct as a starting point and dangerously misleading as a fixed rule.

The right number depends on:

Factor Adjustment
Industry Financial services: 12-18%. Healthcare: 8-12%. Government/defence: 15-25%. SaaS/tech: 10-15%. Retail: 6-10%. Manufacturing: 5-8%
Regulatory exposure Heavily regulated entities (banks, insurers) skew higher because audit and compliance overhead is built into the security budget
Threat landscape Companies with active targeting (high-profile, geopolitically sensitive, large customer data) skew higher
Maturity stage Early-stage programmes spend more as a percentage during build-out (15-25%); mature programmes settle to a steady state
Cloud-vs-onprem mix Cloud-native organisations often see lower absolute IT spend, but security as a percentage may rise because the security budget includes cloud security tooling that wasn't a separate line item in on-prem days
Outsourcing Heavy use of MSSPs shifts the budget mix from internal headcount to vendor spend; total may be lower but visibility differs

For Indian companies specifically:

  • Public sector banks are mandated to spend 8-12% of IT budget on cybersecurity per RBI guidance. Most spend below this.
  • Private sector banks typically spend 10-15%. Some leading private banks exceed 18%.
  • NBFCs and fintechs vary widely — established NBFCs around 8-10%, fintechs (especially those holding payment data) 12-18%.
  • IT services firms with international clients invest heavily — 12-16% — because client contracts demand it.
  • Mid-market Indian SaaS typically falls below the global benchmark at 6-10%, increasing as they pursue SOC 2 and ISO 27001 certifications for international sales.
  • Indian manufacturing and traditional industries are significantly behind at 3-6%, which is a known gap that recent RBI-related supply-chain pressure is slowly closing.

Why these numbers are misleading

The percentage is a ratio. The denominator (IT budget) is calculated inconsistently across organisations. Some include all IT-adjacent costs (cloud, licences, hardware refresh, telecoms, internal IT salaries). Some include only "core" IT. Some exclude the business application development that sits inside business units.

The cleanest way to read the ratio is: of every rupee spent on IT systems and platforms, how many paise are spent on protecting them. By that measure, the 10-15% benchmark is reasonable for a mature programme.

The more honest framing for board conversations is absolute spend benchmarked against revenue or operating expenses:

  • Cybersecurity as % of total revenue: 0.2% to 1.5% depending on sector
  • Cybersecurity as % of operating expenses: 0.5% to 3.0%

Banking sector tends to be at the higher end of both. Manufacturing and traditional industries at the lower end. SaaS companies vary widely depending on stage and data sensitivity.


Where the budget actually goes

The 10-15% IT-budget number, broken down:

Category % of security budget What's included
People (headcount + outsourced services) 40-50% Internal security team, MSSP, SOC, consultants, contractors
Technology / tools 25-35% Endpoint security, SIEM, DLP, IAM, vulnerability scanning, cloud security tools
Compliance and audit 10-15% External audits, certifications, regulatory filings, consultant fees for compliance work
Training and awareness 3-5% Annual training programmes, phishing simulations, role-specific training, certifications
Incident response readiness 5-8% Retainer with IR firm, tabletop exercises, breach insurance
Risk and architecture 5-8% Risk assessment work, security architecture, governance committee operations

These ratios shift over time. Early-stage programmes spend more on tools (build the stack) and less on people. Mature programmes invert this — the stack stabilises, the people cost grows as the team scales.

The most common mis-allocations I see

Over-investing in tools, under-investing in people. A common pattern: company buys best-in-class SIEM, EDR, DLP, and CASB. Then employs two analysts to operate all of it. The tools become shelfware because there isn't enough staff to tune, monitor, or respond. Ratio of tool spend to people spend should not exceed 1:1 except in heavily-automated environments.

Under-investing in training relative to consequences. Training budget gets cut first when budgets are pressured. Then the next phishing campaign succeeds because nobody recognised the lure. Training is one of the cheapest controls per unit of risk reduction; cutting it is almost always a false economy.

Compliance budget growing without compliance maturity. Some organisations spend 25-30% of their security budget on compliance work — audits, consultant fees, certification renewals — while the underlying security maturity barely improves year-over-year. The compliance budget is meant to evidence security, not substitute for it. If your audit findings aren't decreasing despite increasing compliance investment, something is wrong.

No allocation for incident response retainers or breach insurance. The cheapest IR retainer is in the hours after the breach. Without a retainer, you're calling firms during a crisis, paying premium emergency rates, and waiting in line. A small annual retainer (₹5-15 lakh for mid-sized companies) buys priority access. Breach insurance is a separate calculation but increasingly necessary for material risk.


What an ISO audit actually costs

Specifically asked by readers: what should I budget for an ISO 27001 audit?

For initial certification (Stage 1 + Stage 2 + first surveillance) across the three-year cycle, ₹8-25 lakh for a mid-sized Indian organisation, depending on:

  • Certification body (tier matters — top international CBs cost 2-3x top Indian CBs)
  • Scope (number of sites, employees, processes — multi-site adds 30-50%)
  • Number of audit days (calculated by ISO IAF formula based on employee count and scope complexity)
  • Whether you bundle multiple standards (27001 + 27701 + 42001 audited together costs less than separately)

Breakdown of the typical first-year ISO 27001 cost for a mid-sized SaaS company (~200 employees):

Item Estimated cost (INR) Notes
Pre-audit consultant (gap analysis, document preparation, mock audit) ₹4-12 lakh Optional but recommended for first-time; cost depends on consultant tier
Internal team time (typically 4-6 person-months across implementation period) ₹15-30 lakh equivalent Often invisible in budget but very real
Certification body — Stage 1 + Stage 2 audit fees ₹3-8 lakh Lower end: Indian CBs (TÜV India, BSI India). Upper end: international CBs (LRQA, DNV, BSI international)
Certificate issuance + first-year surveillance ₹1-2 lakh
Travel + logistics ₹0.5-2 lakh For auditor on-site days
Tool / platform investments triggered by gap analysis ₹5-20 lakh Highly variable. Common purchases: vulnerability scanning, SIEM, GRC platform, IAM
Total initial certification (Year 0) ₹13-40 lakh visible + ₹15-30 lakh internal time

Surveillance audits (Years 1, 2): ₹2-5 lakh each in CB fees plus internal preparation effort.

Recertification (Year 3): similar to initial Stage 2 cost, maybe 80%.

International CB vs Indian CB. Some buyers will demand specific CBs in their procurement requirements. If you're selling to Fortune 500 customers or EU/UK financial services, a recognised international CB matters. For domestic Indian sales and smaller international customers, an Indian-based CB is fine. Don't over-pay for international branding if your customer base doesn't require it.

What you should also budget for ISO 27701

ISO 27701 stacked on ISO 27001 adds typically 30-50% to the audit fees (one Stage 1 + Stage 2 cycle, just bigger scope). The preparation cost is the larger line item — RoPA completion, DSR procedures, cross-border mechanisms — and typically runs ₹5-15 lakh of consultant + internal time for a mid-sized organisation.

What you should budget for ISO 42001

ISO 42001 is newer and the consultant population is smaller (and more expensive). For a SaaS company with embedded AI features pursuing 42001 as an extension to 27001, expect ₹6-15 lakh of incremental consultant work plus ₹2-4 lakh in additional CB fees. For a company building primary AI products, the preparation is significantly larger — likely ₹15-30 lakh in implementation work because the underlying AI governance framework typically doesn't exist yet.


What other audits cost (India-specific)

Beyond ISO, the audits most Indian organisations run:

SOC 2 (Type I + Type II) — required for selling SaaS to US-based customers. - Auditor fees: ₹8-20 lakh first year, ₹6-15 lakh for Type II reissue - Major variable: scope (Security only vs Security + Availability + Confidentiality + Privacy + Integrity) - US-based audit firms (Big 4, regional firms) cost 2-3x Indian-affiliated firms

RBI SAR (System Audit Report) for fintechs and regulated entities - Auditor (typically CERT-In empanelled): ₹3-10 lakh for fintech-sized scope - Higher for full banks; reduced scope for smaller NBFCs - Annual requirement; SAR submission to RBI

SEBI System Audit for market intermediaries - ₹5-15 lakh depending on size and scope - Specific to broker-dealers, asset managers, depository participants

PCI DSS (for entities processing card data) - Self-Assessment Questionnaire (SAQ): free, internal effort only - ROC (Report on Compliance) via QSA: ₹15-40 lakh, scales with merchant level and scope

CERT-In empanelled audit (cybersecurity audit by CERT-In empanelled organisation — required for government, BFSI, and certain other regulated sectors) - ₹3-12 lakh depending on scope and the panel firm chosen

ITGC audit (IT General Controls, typically as part of statutory financial audit) - Often bundled into the statutory audit fees; not a separate line item - Where it is separate: ₹2-5 lakh for mid-sized organisations - Material part of the statutory audit's scope for any organisation with significant IT-dependent financial reporting

DPDPA readiness audit / DPIA reviews - Newer market; pricing still settling. Currently ₹3-10 lakh for a mid-sized organisation's first comprehensive DPDPA readiness assessment - Will mature with enforcement

For an Indian SaaS company selling to international and domestic enterprise customers, you might be running: ISO 27001, ISO 27701, SOC 2, CERT-In, plus DPDPA readiness. That's ₹40-80 lakh annually in external audit fees alone, before internal effort.

This is one reason mid-sized Indian SaaS companies hit a "compliance ceiling" — the audit burden grows non-linearly with customer base, and at some point the audit costs require dedicated full-time staffing to manage.


How to defend the budget number to the board

The board doesn't want to hear about specific tools. They want to hear:

  1. What are we protecting? (Data, systems, brand, regulatory standing.)
  2. What's the loss if we fail? (Quantified breach scenarios, regulatory fines, business interruption costs.)
  3. What's our peer benchmark? (The ratios in this guide; specific industry benchmarks.)
  4. What's our current security posture and where are we weak? (Maturity assessment results.)
  5. What does the budget buy us? (Specific capability improvements with timelines.)

The board responds to:

  • Loss scenarios with specific numbers. "A ransomware event in our environment is estimated at ₹X-Y impact, with X reflecting recoverable scenarios and Y reflecting prolonged outage."
  • Regulatory exposure. "Failure to meet DPDPA enforcement could result in ₹250 crore in penalties." (Yes, this hyperbole works.)
  • Peer comparison. "Our spending is at 6% of IT, industry benchmark is 10-12%. Closing this gap requires ₹X."
  • Discrete capability improvements. Not "more security." Specific: "24/7 SOC coverage we currently lack, reducing time-to-detect from 24 hours to 1 hour."

The board does not respond to:

  • Generic threat statistics. "Cyber attacks are increasing globally" is wallpaper.
  • Tool-level discussions. They don't care which EDR product. They care about the function.
  • Maturity ladder language without business translation. "We are at CMMI 2; we want to be at CMMI 3" means nothing to a board.
  • FUD. Fear-uncertainty-doubt drives short-term spend and erodes credibility long-term.

A useful board template for budget defence:

  1. Last year, we faced X significant incidents/audits/events. (Concrete proof points.)
  2. Our current maturity is Y, benchmarked against industry Z. (Honest gap analysis.)
  3. The next year's investment of ₹X advances us to Y+1, addressing the specific gaps of A, B, C.
  4. The risk we are not addressing with this budget is D, which I'm flagging for board awareness. (Transparency about what isn't being funded.)
  5. Our planned outcomes (measured) are: faster detection (from N to M hours), broader monitoring coverage (from X% to Y% of systems), reduced audit findings (from N to M). (Outcome-oriented.)

This template gets budget approved more often than the alternative. The board likes feeling informed and respected. The CISO likes getting the budget.


The one thing I would tell every CISO about budgets

Don't ask for a budget. Ask for a programme.

A budget request is "I need ₹X." Easy to deny, easy to cut, easy to lose in next year's negotiation.

A programme request is "Here is the security capability we need to build over the next three years. The investment profile is ₹X / ₹Y / ₹Z. The outcomes are A, B, C, D. The risk if we don't fund this is E. The decision before the board is whether to accept E or to fund the programme."

The programme framing makes the conversation about strategic decisions, not line items. It positions the CISO as the executive responsible for an outcome, not the manager asking for money. It gives the board real choices to make rather than just a number to approve.

It also forces the CISO to think in terms of capabilities and outcomes rather than tools and headcount. That discipline tends to produce better programmes overall.


Final notes — what isn't on this list

This guide deliberately doesn't cover:

  • Cyber insurance economics. This is its own complex topic — coverage gaps, premium escalation post-incident, exclusion clauses. Plan to write a dedicated piece on this.
  • Headcount benchmarks. I have views (the 1-security-person-per-200-employees ratio, the CISO-as-direct-report-to-CEO-or-CFO question) but they vary enough by context that broad benchmarks mislead more than they help.
  • Tool stack recommendations. Different question. Different guide.
  • Outsourcing economics. MSSP vs in-house SOC is a context-specific calculation; I would tell you to do the build-vs-buy analysis with real numbers, not from a benchmark.

For the rough question — what should our cyber budget be — the answer is in this guide. For the deeper question — what should our cyber programme do — the answer requires the kind of conversation that doesn't fit in a benchmark.


This guide draws on observed budget patterns across Indian and international firms over twelve years of programme reviews and CISO advisory work. Specific numbers vary significantly by organisation; treat the ranges as starting points for your own calibration. This is not financial advice.

ControlForge maps controls across all major frameworks and provides tools for the operational work of compliance and security programmes. The Audit Readiness Score tool generates a quick gap assessment; the Checklist Generator builds an evidence-mapped pre-audit control list.