Reinventing cyber budgeting: A wake up call for leaders

Published on
May 20, 2026

The challenge isn’t funding. It’s how cyber investment decisions get made.

Cybersecurity has entered a new phase. Budgets are flattening while cyber risk accelerates. Yet most cyber budgeting still relies on rolling forward last year’s spend, adjusting at the margins, and defending what’s already in place. It feels safe, but it locks organisations into historic decisions that no longer reflect today’s risks.

The result is familiar. Crowded dashboards, long lists of “critical” issues, and budget conversations that centre on tools and headcount – rather than outcomes and trade-offs.

The Reinventing cyber budgeting publication argues that the model needs a reset. Not another framework, but a more deliberate way of deciding where investment actually reduces risk. That means moving from static budgeting to a risk-led investment approach, grounded in measurable outcomes.

This is where cyber risk quantification (CRQ) becomes essential – translating cyber risk into financial terms and enabling clearer, more defensible decisions.

In collaboration with TAG Infosphere, KPMG and CRI leaders explore how organisations can rethink cyber budgeting – challenging legacy assumptions, adopting risk-based models, and using CRQ to make cyber risk actionable.

The question for leaders is no longer how much you spend, it’s how effectively you allocate it against the risks that matter most.

Watch our video below to find out how leaders can stay ahead.

Our blog

Latest Insights

The latest from the CRI community.
Resilience

A risk-based approach to cyber budgets

Cybersecurity budgets are often poorly aligned with the actual level of risk to the organisation. Such misalignment can be driven by local challenges measuring and quantifying cyber risk, but it is compounded by the challenge of mapping perceived risk levels to security staff levels, controls, and approaches to risk mitigation. This article suggests a practical framework for leaders on how risk can become the driver of budgeting decisions.
Akhilesh Tuteja
May 20, 2026
3 min read
Sector insights

Healthcare in the crosshairs: we’ve come a long way

Ransomware is now in healthcare’s “blast radius”, exposing underinvestment and rising risk. Cyber incidents now directly affect patient care - not just IT. The challenge is decision-making. Leaders struggle to quantify risk and prioritise spend. So how can they stay ahead?
Raj Cheema
May 20, 2026
6 min read
Sector insights

Defending against attacks that can shut down power grids

When cyber risk is inseparable from physical harm, a line of code is no longer just data; it is the command that opens a dam, shuts down a power grid, or overrides the safety sensors in a chemical plant. How can leaders anticipate the security and budgetary needs of operational technology?
Dr. Jayne Goble
May 20, 2026
5 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.