Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsSome surveys show organizations planning or reporting higher cybersecurity budgets, while breaches and other incidents remain a concern. That does not prove that higher spending caused incidents to increase—or that the spending failed. The available figures come from different populations, periods and measures, and do not track actual spending alongside incident outcomes for the same organizations.
What do the budget and incident figures actually measure?
The figures below illustrate why the headline tension needs context: a plan to spend more, a reported budget increase, the share of organizations reporting an incident and the number of cases handled by a government agency are not interchangeable measures.
| Source and scope | Finding | What it measures |
|---|---|---|
| PwC, 2024 Global Digital Trust Insights | 79% of surveyed business respondents said they planned to increase cyber expenditures in 2024, compared with 64% the previous year. | Intended spending, not audited spending across all organizations. PwC’s business investment-priorities question had a base of 1,925 respondents. |
| ENISA, NIS Investments 2024 findings | Most in-scope organizations expected a one-off or permanent budget increase for NIS 2 compliance; 34% of surveyed SMEs said they could not request the additional budget they needed. | Expectations and reported budget access among organizations in scope of NIS 2, not all European businesses. |
| UK Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/2026 | 43% of businesses and 28% of charities reported a breach or attack in the previous 12 months. | Survey-estimated prevalence in the UK, not a count of all incidents. |
| Australian Signals Directorate, Annual Cyber Threat Report 2024–2025 | The Australian Cyber Security Centre responded to 1,253 incidents in FY2024–25, an 11% increase on the preceding fiscal year. | Incidents to which the agency responded, not every incident in Australia or the share of organizations affected. |
| SANS Institute, 2025 ICS/OT Cybersecurity Budget Survey | 55% of respondents reported ICS/OT security budget growth over two years; 27% said their organization experienced at least one ICS/OT incident in the prior year. | A specialized survey of more than 180 industrial-control and operational-technology practitioners, not a general business estimate. |
| Ponemon Institute survey, as reported in Optiv’s 2024 announcement | 59% of respondents reported year-over-year cyber-budget growth; 61% reported a breach or cybersecurity incident over two years. | A secondary account of survey results. Its two-year incident window is not directly comparable with the UK estimate or Australian agency count. |
ENISA also reported that 90% of the surveyed NIS 2 entities expected attacks to increase in volume, cost, or both in the following year. That is an expectation among those entities, not an observed attack trend or a worldwide forecast.
Are cyber incidents rising everywhere?
No single trend is established by these sources. In the UK survey, business breach-or-attack prevalence was unchanged from the preceding wave and below the 50% reported for 2023/2024. The report notes a wording change in the 2023/2024 survey that limits comparisons with earlier years, so the figures should not be extended into a longer trend without accounting for that break.
#1 Best Overall
Australia’s agency-handled count rose, but the Australian Signals Directorate described fewer high-end incidents alongside increases in successful and unsuccessful low-level malicious attacks. A rise in cases handled by an agency therefore does not, by itself, mean that every category of threat became more severe.
Within the SANS ICS/OT sample, 58% identified an IT compromise spreading into OT/IT networks as the leading initial attack vector. That finding describes the respondents’ specialized environments; it should not be treated as the leading attack route for businesses generally.
Why can budgets rise while incidents continue?
Budget growth can be planned rather than spent
A survey response about intended spending is not proof that an organization approved the budget, hired staff, deployed controls or maintained them. Even reported budget growth says little on its own about how much was spent, where it went or whether it changed exposure.
Some increases meet obligations, not just new threats
ENISA connects anticipated increases among NIS 2 entities to regulatory compliance. That can mean additional investment is driven by a requirement to meet a defined obligation, rather than a claim that an organization has already reduced every source of risk. ENISA’s finding that some SMEs could not request the budget they needed also points to a gap between perceived need and available resources.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
More spending does not mean all exposure has been removed
Organizations face different systems, operating constraints and threat paths. A budget can support protection, monitoring, recovery or compliance without eliminating the possibility of a successful attack. Incidents may continue even where security investment is useful; these surveys do not measure the counterfactual—what would have happened to the same organizations without that investment.
Headcount and readiness matter alongside the budget line
SANS found that only 9% of its ICS/OT survey respondents devoted all their work time to ICS/OT security. That narrow result illustrates why a growing allocation is not the same thing as having enough specialist capacity to put it to work.
Rank #4
What do the preparedness figures tell decision-makers?
The UK survey found that 25% of businesses and 19% of charities had formal incident-response plans. Among businesses that had experienced a breach or attack, 61% took some preventive action afterward. These measures describe reported preparation and follow-up; neither proves that a plan or action was effective.
For a finance leader reviewing a security budget, the practical question is not simply whether the total rose. Connect each proposed expense to a specific obligation, exposure or operational outcome, and distinguish money approved from money actually deployed.
Best Value
- Separate compliance from risk reduction. Identify which costs address a legal or regulatory requirement and which are intended to reduce a defined business exposure.
- Check resourcing as well as spend. Establish whether the organization has the people and time to operate the tools and processes it funds.
- Review incident readiness. Confirm that response responsibilities and procedures are documented and that the organization can act on them; a written plan alone is not a measure of effectiveness.
- Track outcomes with consistent definitions. Compare incidents over the same time period and use the same scope and severity criteria. Do not treat a survey prevalence rate as equivalent to an agency case count.
- Revisit the allocation after incidents and material changes. Use changes in systems, obligations and incident experience to reassess priorities, rather than treating a larger annual budget as proof that risk has fallen.
Does higher cybersecurity spending reduce incidents?
The cited evidence cannot answer that causal question. It does not link verified spending changes to later incident outcomes for the same organizations under a common definition. It shows that some groups planned or reported higher investment while incidents remained present, but it cannot establish whether spending reduced the number or impact of incidents compared with what would otherwise have occurred.
The defensible conclusion is narrower: increased budgets are not a guarantee of incident-free operations, and the available figures do not show that spending is ineffective. To judge a budget, organizations need to assess what was funded, whether it was implemented, and whether relevant risk and readiness measures changed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




