Cybersecurity Budget as a Percentage of Revenue: What the Ranges Really Tell You
Ask around and you will hear the same rough figures repeated: small and mid-sized businesses tend to spend somewhere in the range of 2–6% of revenue on IT overall, and security is often discussed as taking somewhere between 5% and 15% of that IT budget. Run the math and most small businesses land well under 1% of revenue on security specifically — often closer to a quarter or half a percent. Those are ranges practitioners discuss, not audited statistics, and they vary widely by industry.
Here is the honest answer to the question: percentage of revenue is a sanity check, not a sizing method. It is useful for telling an owner "you are spending almost nothing and that is a problem" or "you are way outside the norm, let’s see why." It is nearly useless for deciding what your actual number should be. The better approach is to build the budget bottom-up from your risk and your headcount, then compare the result against the ranges to see whether you have wandered somewhere strange.
Why the quoted ranges are so slippery
The benchmarks come from vendor and analyst surveys, and those surveys disagree with each other for structural reasons. They define "security spend" differently — one counts only dedicated tools, another folds in staff time, firewalls, backup, and compliance work. They mix company sizes, where a 20-person firm and a 2,000-person firm have completely different cost curves. And they average across industries where the real numbers legitimately differ: a medical practice or accounting firm holding sensitive records carries obligations a landscaping company does not.
So treat any single percentage you read online as a data point about who was surveyed, not a target for your business.
Why revenue is the wrong denominator anyway
- Two businesses with identical revenue can carry wildly different risk. A machine shop and a healthcare clinic billing the same amount do not face the same threats, regulations, or breach costs.
- Revenue moves; threats do not. A slow year does not make phishing stop. Tying security spend to top-line swings guarantees you cut protection exactly when you can least afford an incident.
- It invites backing into a number. Deciding "we will spend X% because a chart said so" skips the only question that matters: what are we protecting, and from what?
A better method, part one: start from risk
Before pricing a single tool, put honest ranges on four things:
- Downtime cost. What does a day of your business being unable to work cost in payroll, missed revenue, and catch-up overtime?
- Data exposure. What do you hold that someone would want — patient records, client financials, payment data, employee SSNs — and what would notification and cleanup cost if it leaked?
- Fraud exposure. How much money moves by wire or ACH on your team’s say-so? Business email compromise targets exactly that.
- Obligations. What do your cyber insurance application, customer contracts, and regulations (HIPAA, FTC Safeguards, CMMC, PCI) actually require? These are floor requirements, not suggestions.
Those answers tell you which controls are non-negotiable for your business and which are nice-to-have. That is the shape of the budget before any percentages enter the room.
A better method, part two: price it per seat
Most modern security tooling is priced per user or per device, which makes bottom-up budgeting straightforward. Build a per-seat stack — identity and MFA, endpoint detection and response or managed detection and response, email filtering, security awareness training, backup — multiply by headcount, then add the fixed costs that do not scale per person: firewall hardware and subscriptions, vulnerability scanning, an annual assessment, incident response readiness. Per-seat pricing changes often enough that quoting numbers here would date badly, so check current pricing with your provider — but the structure holds, and it produces a number you can defend line by line instead of a percentage you copied from a survey.
What belongs in the cybersecurity budget
- Identity: MFA everywhere, conditional access, a password manager, timely offboarding.
- Endpoints: EDR or MDR with someone actually watching the alerts.
- Email: advanced filtering plus SPF, DKIM, and DMARC done correctly.
- Backup and recovery: immutable copies, offsite, and periodic tested restores.
- People: ongoing awareness training and phishing simulations.
- Hygiene: patch management, vulnerability scanning, firmware updates.
- Paper: cyber insurance premiums, compliance work, an incident response plan someone has rehearsed.
Two things people forget: staff or MSP time to run all of this is part of the spend, and aging hardware is a security cost too — an unsupported operating system undermines every tool layered on top of it.
Putting the ranges back in their place
Once you have a bottom-up number, then the percentages earn their keep. If your build-up lands at a fraction of what similar businesses discuss spending, you have probably skipped a control and should find it. If you land far above, look for overlapping tools doing the same job. Used that way — as a rearview mirror instead of a steering wheel — the benchmark ranges are genuinely helpful.
Equal Tech Solutions builds and runs security programs for small and mid-sized businesses across Cleveland, Chattanooga, and the Southeast US, and we are happy to walk through a bottom-up budget for your environment — what you have, what your insurer expects, and what it should cost per seat. Learn more about our managed cybersecurity services, or contact Equal Tech Solutions to put a real number behind your security plan.
