October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Cybersecurity Budgets Are Rising, but Incidents Persist: What the Evidence Shows

Surveyed organizations report higher cybersecurity spending plans, while breaches and incidents continue. The figures are not directly comparable and do not prove that spending caused incidents to rise or failed to reduce risk.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some surveys show organizations planning or reporting higher cybersecurity budgets, while breaches and other incidents remain a concern. That does not prove that higher spending caused incidents to increase—or that the spending failed. The available figures come from different populations, periods and measures, and do not track actual spending alongside incident outcomes for the same organizations.

What do the budget and incident figures actually measure?

The figures below illustrate why the headline tension needs context: a plan to spend more, a reported budget increase, the share of organizations reporting an incident and the number of cases handled by a government agency are not interchangeable measures.

Source and scope Finding What it measures
PwC, 2024 Global Digital Trust Insights 79% of surveyed business respondents said they planned to increase cyber expenditures in 2024, compared with 64% the previous year. Intended spending, not audited spending across all organizations. PwC’s business investment-priorities question had a base of 1,925 respondents.
ENISA, NIS Investments 2024 findings Most in-scope organizations expected a one-off or permanent budget increase for NIS 2 compliance; 34% of surveyed SMEs said they could not request the additional budget they needed. Expectations and reported budget access among organizations in scope of NIS 2, not all European businesses.
UK Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/2026 43% of businesses and 28% of charities reported a breach or attack in the previous 12 months. Survey-estimated prevalence in the UK, not a count of all incidents.
Australian Signals Directorate, Annual Cyber Threat Report 2024–2025 The Australian Cyber Security Centre responded to 1,253 incidents in FY2024–25, an 11% increase on the preceding fiscal year. Incidents to which the agency responded, not every incident in Australia or the share of organizations affected.
SANS Institute, 2025 ICS/OT Cybersecurity Budget Survey 55% of respondents reported ICS/OT security budget growth over two years; 27% said their organization experienced at least one ICS/OT incident in the prior year. A specialized survey of more than 180 industrial-control and operational-technology practitioners, not a general business estimate.
Ponemon Institute survey, as reported in Optiv’s 2024 announcement 59% of respondents reported year-over-year cyber-budget growth; 61% reported a breach or cybersecurity incident over two years. A secondary account of survey results. Its two-year incident window is not directly comparable with the UK estimate or Australian agency count.

ENISA also reported that 90% of the surveyed NIS 2 entities expected attacks to increase in volume, cost, or both in the following year. That is an expectation among those entities, not an observed attack trend or a worldwide forecast.

Are cyber incidents rising everywhere?

No single trend is established by these sources. In the UK survey, business breach-or-attack prevalence was unchanged from the preceding wave and below the 50% reported for 2023/2024. The report notes a wording change in the 2023/2024 survey that limits comparisons with earlier years, so the figures should not be extended into a longer trend without accounting for that break.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Australia’s agency-handled count rose, but the Australian Signals Directorate described fewer high-end incidents alongside increases in successful and unsuccessful low-level malicious attacks. A rise in cases handled by an agency therefore does not, by itself, mean that every category of threat became more severe.

Within the SANS ICS/OT sample, 58% identified an IT compromise spreading into OT/IT networks as the leading initial attack vector. That finding describes the respondents’ specialized environments; it should not be treated as the leading attack route for businesses generally.

Why can budgets rise while incidents continue?

Budget growth can be planned rather than spent

A survey response about intended spending is not proof that an organization approved the budget, hired staff, deployed controls or maintained them. Even reported budget growth says little on its own about how much was spent, where it went or whether it changed exposure.

Some increases meet obligations, not just new threats

ENISA connects anticipated increases among NIS 2 entities to regulatory compliance. That can mean additional investment is driven by a requirement to meet a defined obligation, rather than a claim that an organization has already reduced every source of risk. ENISA’s finding that some SMEs could not request the budget they needed also points to a gap between perceived need and available resources.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More spending does not mean all exposure has been removed

Organizations face different systems, operating constraints and threat paths. A budget can support protection, monitoring, recovery or compliance without eliminating the possibility of a successful attack. Incidents may continue even where security investment is useful; these surveys do not measure the counterfactual—what would have happened to the same organizations without that investment.

Headcount and readiness matter alongside the budget line

SANS found that only 9% of its ICS/OT survey respondents devoted all their work time to ICS/OT security. That narrow result illustrates why a growing allocation is not the same thing as having enough specialist capacity to put it to work.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do the preparedness figures tell decision-makers?

The UK survey found that 25% of businesses and 19% of charities had formal incident-response plans. Among businesses that had experienced a breach or attack, 61% took some preventive action afterward. These measures describe reported preparation and follow-up; neither proves that a plan or action was effective.

For a finance leader reviewing a security budget, the practical question is not simply whether the total rose. Connect each proposed expense to a specific obligation, exposure or operational outcome, and distinguish money approved from money actually deployed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Separate compliance from risk reduction. Identify which costs address a legal or regulatory requirement and which are intended to reduce a defined business exposure.
  • Check resourcing as well as spend. Establish whether the organization has the people and time to operate the tools and processes it funds.
  • Review incident readiness. Confirm that response responsibilities and procedures are documented and that the organization can act on them; a written plan alone is not a measure of effectiveness.
  • Track outcomes with consistent definitions. Compare incidents over the same time period and use the same scope and severity criteria. Do not treat a survey prevalence rate as equivalent to an agency case count.
  • Revisit the allocation after incidents and material changes. Use changes in systems, obligations and incident experience to reassess priorities, rather than treating a larger annual budget as proof that risk has fallen.

Does higher cybersecurity spending reduce incidents?

The cited evidence cannot answer that causal question. It does not link verified spending changes to later incident outcomes for the same organizations under a common definition. It shows that some groups planned or reported higher investment while incidents remained present, but it cannot establish whether spending reduced the number or impact of incidents compared with what would otherwise have occurred.

The defensible conclusion is narrower: increased budgets are not a guarantee of incident-free operations, and the available figures do not show that spending is ineffective. To judge a budget, organizations need to assess what was funded, whether it was implemented, and whether relevant risk and readiness measures changed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.