What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Cybersecurity budgets were expected to rise or hold steady in 2022, but the important change was where organizations planned to put the money. Surveys pointed to greater emphasis on cloud security, identity, managed services, staffing, resilience and third-party risk—not simply more security products. Because the source forecasts were published in late 2021, these figures describe expectations for calendar 2022 rather than an audited total of what every organization ultimately spent.
How much cybersecurity spending was expected in 2022?
Three different measures are often quoted together, although they answer different questions.
| Measure | 2022 expectation | What it represents |
|---|---|---|
| CSO Security Priorities Study | 44% expected an increase; 54% expected level funding; 2% expected a decrease | Security leaders’ expectations for their own budgets over the following 12 months |
| PwC 2022 Global Digital Trust Insights | 69% expected cyber spending to rise; 26% expected an increase of at least 10% | Global executive survey; the budget question had its own respondent base within the wider survey |
| Gartner forecast reported by CSO | $172 billion worldwide, versus $155 billion in 2021 and $137 billion in 2020 | Global information-security and risk-management market spending, not an average company budget |
The CSO survey’s 44% increase figure was close to the prior year’s 41%, while the share expecting a decrease fell from 6% to 2%. PwC surveyed roughly 3,600 business, technology and security executives across more than 60 territories; its report identifies 1,638 technology and security executives for the budget-change question. The figures therefore should not be averaged into a single “global budget growth rate.” See the CSO analysis and PwC report.
What counted as cybersecurity spending?
Organizations and market analysts used different boundaries. A company budget might include software and hardware, security employees, consultants, managed monitoring, incident response, awareness training, compliance work, identity and access management, cloud and application security, governance and risk management, and security operations. Gartner’s “information security and risk management” market is broader than a typical security department cost center. Comparing a market forecast with an internal budget without defining the scope can produce a misleading conclusion.
Recommended Free Tools
#1 Best Overall
Why budgets were rising or staying protected
Threats with business consequences
Ransomware, financially motivated attacks and criminal marketplaces increased the potential cost of downtime, extortion, data loss and recovery. Interconnected systems and critical infrastructure made a security incident a continuity and reputation issue, not merely an IT problem. Executives also faced the possibility that a breach would become a public crisis affecting customers, investors and partners.
Remote work and cloud transformation
Hybrid work expanded the number of locations, devices and networks requiring protection. Cloud migration changed where identities, applications and data were managed. In the CSO survey, hybrid or remote work influenced 41% of respondents, while digital transformation and cloud migration influenced 38%.
Rules, customers and boards
Best practices and compliance, regulations or mandates were each cited by 49% of CSO respondents; those answers could overlap and do not establish causation. Boards and customers increasingly asked for evidence of security capability, while suppliers were assessed as part of broader business risk. The May 2021 U.S. executive order on cybersecurity was one influence, particularly for organizations serving the federal government or Department of Defense; it did not impose identical obligations on every company.
Recent incidents
A security incident in the respondent’s own organization influenced 35% of CSO respondents, and an incident at another organization influenced 25%. PwC also reported that more than half of executives expected an increase in reportable incidents in 2022. That was a pre-2022 expectation, not a verified count of incidents that occurred.
Free tools Windows power users keep installed
One-click scans. No signup required.
Where organizations planned to put the money
The CSO survey reported this allocation of security spending. These are survey results, not recommended ratios or a universal industry budget.
| Category | Share of surveyed allocations |
|---|---|
| On-premises infrastructure and hardware | 20% |
| Skilled security staff | 19% |
| On-premises tools and software | 16% |
| Cloud-based security solutions | 10% |
| Consulting services | 7% |
| Cloud-based security monitoring services | 7% |
| Security awareness training | 7% |
| Contracted evaluation services | 6% |
| External incident-response services | 5% |
CSO’s report, which attributes the following figures to Gartner, estimated 2022 spending by broader market category as follows:
| Gartner category | Estimated 2022 spending |
|---|---|
| Security services | Nearly $77 billion |
| Infrastructure protection | $30 billion |
| Network security equipment | $19 billion |
| Identity and access management | $17 billion |
| Application security | $6.6 billion |
| Integrated risk management | $6.4 billion |
| Data security | $4 billion |
| Security software | $2.7 billion |
| Cloud security | $1.4 billion |
“Security services” can include consulting, managed services, support and other labor-intensive work, so its nearly $77 billion estimate is not directly comparable with a single software category. Gartner’s category definitions may also place some cloud-related activity elsewhere.
The strategic priorities behind the spending
Identity and a staged zero-trust program
As users, devices, applications and workloads operated from different locations, identity became a primary control point. Practical investments included multi-factor authentication, stronger authentication methods, role-based access, privileged-access management, behavior analytics and microsegmentation.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
Zero trust is an architectural and policy approach, not a product or guarantee. A workable program requires asset visibility, identity governance, segmentation, monitoring and continual policy enforcement. Buying a “zero-trust” tool without those foundations can leave the core risk unchanged.
Cloud and application security
Cloud protection involved misconfiguration prevention and detection, cloud entitlement management, workload and container security, encryption, logging, application programming interface security, infrastructure-as-code scanning, secrets management and secure development practices. Shared-responsibility boundaries had to be explicit. Cloud platforms can provide scalable security capabilities, but they also increase the complexity of identities, data flows, configurations and third-party dependencies.
Services, staffing and automation
Security services were large because experienced defenders were scarce and many organizations could not operate a 24/7 security operations center alone. Managed security providers, threat hunting, incident-response retainers and specialist cloud or compliance consulting could add coverage without matching every capability with full-time hires.
The choice was not “people or technology.” Hiring and retaining defenders, upskilling IT and engineering teams, training the wider workforce, automating repetitive triage and using managed detection and response all had to fit one operating model. Automation fails when data quality, integrations, ownership or response playbooks are weak; adding analysts fails when fragmented tools create unmanageable alert volume.
Rank #4
Third-party and supply-chain risk
PwC found that 60% of respondents had less than a thorough understanding of breach risk through third parties, including 20% who had little or no understanding. The survey covered 3,602 executives in July and August 2021; see the PwC announcement.
Budget implications included a vendor inventory, critical-supplier classification, selective evidence-based assessments, contractual security and incident-notification terms, continuous monitoring for important providers, software-dependency visibility where relevant, access reviews, continuity testing and concentration-risk analysis. Questionnaires alone could not provide that assurance.
Incident response and resilience
Prevention did not remove the need to detect, contain and recover. Organizations funded external response retainers, tested playbooks, backup restoration, ransomware exercises, recovery objectives, crisis communications and continuity planning. A prevention-heavy budget that leaves restoration untested can still produce prolonged business disruption.
Why more spending did not automatically mean better security
- More products can create duplicate telemetry, conflicting alerts, multiple consoles and unclear ownership.
- A platform consolidation can simplify operations but create vendor lock-in or leave coverage gaps.
- Licensing is only part of total cost; implementation, integration, staffing, training, data retention and renewals also matter.
- Compliance establishes a required baseline, but an audit-ready control may not address the most consequential attack path.
- Outsourcing provides coverage and expertise, but accountability remains internal. Contracts need service levels, data-handling rules, escalation authority, logging access, performance validation and an exit plan.
- Cloud adoption does not remove identity, configuration, data-flow or supplier risk.
How to prioritize a cybersecurity investment
Use a consistent business-risk score rather than selecting the most fashionable category. For each proposed investment, document:
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- Business criticality: Identify the revenue stream, customer service, regulated data or operational capability at stake.
- Threat and exposure: Name the credible attack path and the systems, identities or suppliers exposed to it.
- Control gap: Describe what is missing, ineffective or untested today.
- Effectiveness: State how the control should reduce likelihood, limit impact, improve detection or speed recovery.
- Coverage and integration: Check cloud, on-premises, remote, mobile and third-party environments, along with identity, endpoint, ticketing and response integrations.
- Operating burden: Assign configuration, monitoring, tuning, maintenance and escalation ownership.
- Total cost and exit risk: Include implementation, personnel, training, renewal and data-export or replacement requirements.
- Measurement: Set a baseline, target and review date before approving the spend.
Metrics that show whether the investment worked
Exposure and prevention
- Percentage of critical assets inventoried.
- Multi-factor authentication coverage for employees, contractors and privileged users.
- Time to remediate critical vulnerabilities.
- Internet-exposed assets with unacceptable risk.
- Secure-configuration compliance and critical-vendor assessment coverage.
Detection and response
- Mean time to detect, contain and recover.
- Alert-to-incident conversion rate and high-severity alert backlog.
- Coverage of endpoint, identity, cloud and network telemetry.
- Percentage of incidents handled according to tested playbooks.
Resilience and business alignment
- Recovery-point and recovery-time performance.
- Backup restoration test results and ransomware tabletop completion.
- Business-continuity exercise results.
- Risk reduction per dollar, reduced material attack paths and control coverage for revenue-critical services.
- Board-approved risk acceptance and residual-risk reporting.
These measures demonstrate preparedness, coverage and risk reduction; they cannot prove that a breach will never occur.
How to present the budget to a board or CFO
Frame the request around business services and scenarios rather than a product list. Show the current exposure, the control gap, the expected reduction in likelihood or impact, recovery objectives, alternatives considered, total cost over the planning period and the residual risk that would remain. Assign an owner and review date to every material outcome. This makes a flat budget defensible when it funds the highest-risk gaps, and it makes an increase defensible when existing controls cannot meet the organization’s resilience or regulatory obligations.
For readers evaluating vendors, examples of relevant categories include identity platforms such as Microsoft Entra ID, Okta Workforce Identity and Cisco Duo; endpoint and response platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon and SentinelOne Singularity; and managed services such as Arctic Wolf MDR, Secureworks Taegis and Red Canary MDR. These are examples, not endorsements. Current enterprise prices were not confirmed, and quote-based costs vary with users, endpoints, data volume, modules, geography, implementation and contract term.
The Bottom Line
2022’s outlook pointed to protected or growing cybersecurity budgets, but the durable lesson is allocation: combine identity, cloud controls, capable people, managed expertise, third-party oversight and tested recovery, then measure the reduction in business risk. A larger tool budget without ownership, integration and evidence of outcomes is not the same as better security.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




